Author Topic: VBS  (Read 12447 times)

0 Members and 1 Guest are viewing this topic.

brickman

  • Guest
VBS
« on: November 16, 2009, 12:26:24 PM »
Hi, my Avast told me that my pc has the following virus:

File name:       H:\Autorun.inf
Malware name:     VBS: Malware-gen
VPS Version:    091112-0, 11/12/2009
 
I ran Malwarebytes' Anti-Malware, CounterSpy, and Livecare; none of the three found anything wrong. Could it be a bluff from Avast since my free trial is about to expire? Any help will be greatly appreciated.

Thank you.

Offline nmb

  • Avast Evangelist
  • Massive Poster
  • ***
  • Posts: 3054
Re: VBS
« Reply #1 on: November 16, 2009, 01:17:09 PM »
Hello brickman

bluffing is done by rogue av's and avast is no rogue.

well it might be a false positive.

go to cmd

change directory to h: (or the drive where the virus was found)

type "edit Autorun.inf"

copy and paste the contents of the opened autorun.inf file in the editor here.

close cmd.

well let you know whether it is a fp or not.

alternatively, get panda usb vaccine : http://download.softpedia.com/dl/94db7ef081ce0aa64a36449ca7faeb8e/4b01426f/100122684/software/security/USBVaccineSetup.exe

install without the ntfs support and vaccinate your computer. install this update : http://support.microsoft.com/kb/971029 by downloading the required updater based on your os.

nmb
« Last Edit: November 16, 2009, 01:27:07 PM by nmb »

brickman

  • Guest
Re: VBS
« Reply #2 on: November 16, 2009, 01:55:08 PM »
Hello brickman

bluffing is done by rogue av's and avast is no rogue.

well it might be a false positive.

go to cmd

change directory to h: (or the drive where the virus was found)

type "edit Autorun.inf"

copy and paste the contents of the opened autorun.inf file in the editor here.

close cmd.

well let you know whether it is a fp or not.

alternatively, get panda usb vaccine : http://download.softpedia.com/dl/94db7ef081ce0aa64a36449ca7faeb8e/4b01426f/100122684/software/security/USBVaccineSetup.exe

install without the ntfs support and vaccinate your computer. install this update : http://support.microsoft.com/kb/971029 by downloading the required updater based on your os.

nmb
call me dumb, but what is cmd?, and by the way, I don't think I have an H drive at all.

Offline nmb

  • Avast Evangelist
  • Massive Poster
  • ***
  • Posts: 3054
Re: VBS
« Reply #3 on: November 16, 2009, 02:05:27 PM »
oki.

if you read your first post again, you can see

Quote
File name:       H:\Autorun.inf
- probably its a usb drive.

insert the usb drive again. close the autorun window, if you get any.

do not open the usb folder. just check the drive whether h: or any other.

open run command : windows key(keyboard) + R , type "cmd" without quotes hit enter you should see a dark background windows open.

now type : "cd drive:" replace drive: with the drive of your usb. again without quotes

type "edit Autorun.inf" hit enter - again without quotes

now you will see a editor with blue background.

select all the contents of it, copy and paste(post) here.

close the cmd window.

and then

get panda usb vaccine : http://download.softpedia.com/dl/94db7ef081ce0aa64a36449ca7faeb8e/4b01426f/100122684/software/security/USBVaccineSetup.exe

install without the ntfs support and vaccinate your computer.

install this update : http://support.microsoft.com/kb/971029 by downloading the required updater based on your os.

nmb
« Last Edit: November 16, 2009, 02:21:49 PM by nmb »

brickman

  • Guest
Re: VBS
« Reply #4 on: November 16, 2009, 02:25:03 PM »
oki.

if you read your first post again, you can see

Quote
File name:       H:\Autorun.inf
- probably its a usb drive.

insert the usb drive again. close the autorun window, if you get any.

do not open the usb folder. just check the drive whether h: or any other.

open run command : windows key(keyboard) + R , type "cmd" without quotes hit enter you should see a dark background windows open.

now type : "cd drive:" replace drive: with the drive of your usb. again without quotes

type "edit Autorun.inf" hit enter - again without quotes

now you will see a editor with blue background.

select all the contents of it, copy and paste here.

close the cmd window.

and then

get panda usb vaccine : http://download.softpedia.com/dl/94db7ef081ce0aa64a36449ca7faeb8e/4b01426f/100122684/software/security/USBVaccineSetup.exe

install without the ntfs support and vaccinate your computer. install this update : http://support.microsoft.com/kb/971029 by downloading the required updater based on your os.

nmb
Hello brickman

bluffing is done by rogue av's and avast is no rogue.

well it might be a false positive.

go to cmd

change directory to h: (or the drive where the virus was found)

type "edit Autorun.inf"

copy and paste the contents of the opened autorun.inf file in the editor here.

close cmd.

well let you know whether it is a fp or not.

alternatively, get panda usb vaccine : http://download.softpedia.com/dl/94db7ef081ce0aa64a36449ca7faeb8e/4b01426f/100122684/software/security/USBVaccineSetup.exe

install without the ntfs support and vaccinate your computer. install this update : http://support.microsoft.com/kb/971029 by downloading the required updater based on your os.

nmb

the blue screen comes out empty.

Offline nmb

  • Avast Evangelist
  • Massive Poster
  • ***
  • Posts: 3054
Re: VBS
« Reply #5 on: November 16, 2009, 02:28:02 PM »
are you sure you checked the usb autorun.inf ?

did you install the tools I asked you to? : panda usb vaccine and ms update?

nmb

brickman

  • Guest
Re: VBS
« Reply #6 on: November 16, 2009, 02:31:33 PM »
are you sure you checked the usb autorun.inf ?

did you install the tools I asked you to? : panda usb vaccine and ms update?

nmb

I will in a minute, I thought the cmd was first. I will let you know.

brickman

  • Guest
Re: VBS
« Reply #7 on: November 16, 2009, 02:49:44 PM »
are you sure you checked the usb autorun.inf ?

did you install the tools I asked you to? : panda usb vaccine and ms update?

nmb

I will in a minute, I thought the cmd was first. I will let you know.

OK, computer and g drive (usb memory stick) vaccinated . Also downloaded ms update, did a cmd for drive g and came out with an empty blue screen, H drive is not found by the system

C:\Documents and Settings\RAUL SR>H:
The system cannot find the drive specified.

C:\Documents and Settings\RAUL SR>

Offline nmb

  • Avast Evangelist
  • Massive Poster
  • ***
  • Posts: 3054
Re: VBS
« Reply #8 on: November 16, 2009, 03:44:02 PM »
now nothing to worry. your system is protected from virus being automatically executed when you insert the key. make sure you scan your usb key everytime you insert.

do you see a file autorun_.inf any of the drives?..

nmb

brickman

  • Guest
Re: VBS
« Reply #9 on: November 16, 2009, 04:54:33 PM »
now nothing to worry. your system is protected from virus being automatically executed when you insert the key. make sure you scan your usb key everytime you insert.

do you see a file autorun_.inf any of the drives?..

nmb

the only one is in my Magicjack (voip) :


[AutoRun]
action= "Start  magicJack"
icon= autorun.ico
defaultaction=autorun.ico
label=magicJack
open=autorun.exe
shell\phone\command=autorun.exe
shell\phone=Start &magicJack
shell=phone

[Content]
MusicFiles=0
PictureFiles=0
VideoFiles=0

[IgnoreContentPaths]

[DeviceInstall]
;DriverPath=




Offline nmb

  • Avast Evangelist
  • Massive Poster
  • ***
  • Posts: 3054
Re: VBS
« Reply #10 on: November 16, 2009, 04:56:54 PM »
search for autorun.exe in your drive and upload it to virustotal.com and give us the link.

nmb

brickman

  • Guest
Re: VBS
« Reply #11 on: November 16, 2009, 04:59:42 PM »
search for autorun.exe in your drive and upload it to virustotal.com and give us the link.

nmb

got to go, will try later, thank you.

brickman

  • Guest
Re: VBS
« Reply #12 on: November 16, 2009, 09:14:21 PM »
search for autorun.exe in your drive and upload it to virustotal.com and give us the link.

nmb

got to go, will try later, thank you.

the only autorun.exe is in my e drive, like I said before, which is a VOIP, is that the one you want?

Jastis Bago

  • Guest
Re: VBS
« Reply #13 on: November 17, 2009, 05:51:59 AM »
its problem ??

Offline nmb

  • Avast Evangelist
  • Massive Poster
  • ***
  • Posts: 3054
Re: VBS
« Reply #14 on: November 17, 2009, 06:40:13 AM »
the only autorun.exe is in my e drive, like I said before, which is a VOIP, is that the one you want?

yes you can upload it to virustotal.com and give the link.

nmb