maybe a flashdrive infection?

Discussion in 'Malware Help - MG (A Specialist Will Reply)' started by ybrush, Aug 6, 2007.

  1. ybrush

    ybrush Private E-2

    hi chaslang or anybodody else

    // I FOLLOWED THE MALWARE REMOVAL GUIDE //

    i 'm dual booting (MacOSX & XP sp2) and i bought a new external hd i that i formatted for mac (HFS+), for that i tried to use macdrive to be able to read and write when i am on xp
    when i tried to use it i saw some strange things in the right click menu and when i tried to open the new drive or the mac partition, avast detected VBS small.
    after that i started some scans. I remember the first times i tried with spybot, was detecting vbs small a and some other variant i think, but was stuck in the registry, and i had to force quit it. Then i did some bitDefender scans and it also found some VBS. I think after the second BitDef scan it found something in the registry and after that spybot was able to complete the scan but after all these was clean, also bit defender was also clean.
    I was never able to complete an active Panda, without quitting IE with no msg, so i can't post this log (i also tried in the past ith the same results)

    also after the first cleaning process and while i still had the macdrive app i remember when i tried to open the new drive or the partition of the internal drive or a usb there was an error, something with like script error. I know that this happen when an AV deletes something and something in the registry has to change (sorry for the somethings!)

    so i am attaching the latest logs that are clean! (i think)

    and what do you think is the best approach for checking the removable drives and fixing the errors

    thanks for your amazing help in advance , you 've helped in the past once!
     

    Attached Files:

  2. ybrush

    ybrush Private E-2

    the other logs
     

    Attached Files:

  3. ybrush

    ybrush Private E-2

    forgot to add

    Sorry i forgot to to say that the online BitDefender scan was in normal mode because wifi and my keyboard doesn't work on safe mode, spybot and counterspy was in safe

    thanks
     
  4. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Re: forgot to add

    I'm not exactly sure what you are asking with all of the rather confusing post.

    Your logs are clean but you can have HJT fix the below line:
    R3 - URLSearchHook: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - (no file)

    I do question what all of the below are for. Perhaps you know if they are related to this dual boot config and Apple software:

    F2 - REG:system.ini: UserInit=userinit.exe,autorun.bat
    O4 - HKLM\..\Run: [Brightness] C:\WINDOWS\system32\Brightness.exe
    O4 - HKLM\..\Run: [arc] C:\WINDOWS\system32\arc.exe
    O4 - HKLM\..\Run: [IRW] C:\WINDOWS\system32\IRW.exe
     
  5. ybrush

    ybrush Private E-2

    hi chaslang

    i 'm sorry about the "rather confusing post", but i was very tired!

    about your question:

    these :
    O4 - HKLM\..\Run: [Brightness] C:\WINDOWS\system32\Brightness.exe
    O4 - HKLM\..\Run: [arc] C:\WINDOWS\system32\arc.exe
    O4 - HKLM\..\Run: [IRW] C:\WINDOWS\system32\IRW.exe

    are connected to the dual boot as you mentioned.

    i will try now to express my question better.

    As you said my logs are clean, but all my removable drives are infected but all these tests checked the ntfs partition of the drive, the other partition (mac formatted) that i have never ran it, this drive can be read and written with an application called macdrive, that i just downloaded the trial version to run a some tests because i want to be able to use it when i work on Xp.
    i also Mac formatted a new external HD that i also run a test and two USB mass storage devices.

    i run these tests with avast and all were infected and i am attaching the logs from avast,

    is it is safe to open these drives after deletion with avast?
    or i have to do all the other tests with the macdrive enabled?
    so i can scan the mac formatted partition and the new external drive?
    (i can format this one because it's empty)

    and i think that i after the deletion of some viruses(you van see that on the log) that are found in autorun.bat you have an error message when you try to access them, i don't want to try till it is safe to reproduce the error mesage,

    i hope it was less confusing!

    thanks again
     

    Attached Files:

  6. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    You have an unusual setup and there may be no guarantees on what's infected and what is not.

    Do the below files still exist? If so, put them into a ZIP file and attach them here:
    F:\autorun.vbs
    E:\autorun.vbs <--- if this has the same contents as the above one, just attach one otherwise rename it before ZIPing
    E:\infrom.exe
    E:\AUTORUN.INF
    E:\autorun.bat


    Where did the below files come from? Are they legit, or are they illegal downloads? Delete if not legit!
    F:\downloads\acdsee(windows)\acdseepowerpack.exe
    F:\downloads\vuescan pro(Windows)\VueScan.Professional.Edition.8.3.63\vuesca83.exe
    F:\Users\yiannis\Shared\THE_FOUNDRY_KEYLIGHT_V1.2V1_FOR_AE7-XFORCE.zip\THE_FOUNDRY_KEYLIGHT_V1.2V1_FOR_AE7-XFORCE\Keylight1.2v1_AE7.0-win-x86-release-32-Pro.exe
     
    Last edited: Aug 8, 2007
  7. ybrush

    ybrush Private E-2

    hmm some of them are trial and one it was given by someone but i don't use them anyway and i already delete them.

    I formatted e: drive so i cannot find anything,

    the f: is the mac partition of the internal drive and i have not open it after infection's apearrance. I did a Search from the windows side and it didn't find anything. Ss there a better way than search from windows? I 'm going to search it from the mac side that is realtime fast and reliable to see if it is there , the freshly formatted disk works great without the error that i had once after deleting these infected files.

    so...what do you suggest to do,

    do you think it is a good idea to do the "Usual Scans" in the F drive only? (if it is possible)
     
  8. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    You can try running scans on the F drive. Some of them including the online scans should have defaulted to scanning all drives anyway. I have no idea how the scans will work on a MAC partition. You are in non-standard territory.
     
  9. ybrush

    ybrush Private E-2

    i think it is the same like scanning an NTFS disk

    i tried to do a scan with Bitdefender but cause there are many files ,the time needed was to much. I am going to do it over the night and see what's happening

    thanks
     
  10. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    You may only find the same files list for the E drive:

    F:\autorun.vbs
    F:\AUTORUN.INF
    F:\autorun.bat

    Do these exist or did Avast already delete them? They are not necessarily bad.
     
  11. ybrush

    ybrush Private E-2

    some of them exist and Avast did not delete them, these files were in the new western digital HD for some properties to work.

    i run the online scan (BD), only in the F and G (it is a usb drive that Avast found infected).
    it found the a trojan in both : trojan.reggger.q as you going to see on the bdscan log

    thank you
     

    Attached Files:

  12. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Put the G:\AutoRun.reg (or the F:\AutoRun.reg ) file into a ZIP file and attach it here. I tend to doubt these are problems. They are probably just related to the hardware and software you are using in you PC setup.
     
  13. ybrush

    ybrush Private E-2

    as you saw in the bdscan, disinfection failed ,so the files were deleted. or am i wrong?

    but as i told you they were 2 usb flash drives infected so i was able to find the file in the non bdscanned usb so i am attaching this file


    thank you again
     

    Attached Files:

  14. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Does this other USB drive also still have a copy of the autorun.bat file that you can put into a ZIP file and attach it here.

    The autorun.reg file does seem a little suspicious. It loads the autorun.bat file at windows login and also disables viewing of system files.
     
  15. ybrush

    ybrush Private E-2

    i cannot find it,
    this file was found by Avast and deleted,

    My claim that all(mac partition,mac external and the 2 usb flashdrives) were infected was based on Avast scan. Then i scanned them all with bdscan except C:(that was already scanned) and the last usb.

    i am sorry if i repeat things you already know!

    thanks
     
  16. ybrush

    ybrush Private E-2

    the smilie is a typo
     
  17. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Okay then either way it sounds like you are clean and have nothing to worry about since Avast deleted the file anyway. I do recommend that you use HijackThis to fix the below lines though if they still show in your log:


    R3 - URLSearchHook: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - (no file)
    F2 - REG:system.ini: UserInit=userinit.exe,autorun.bat
    O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
     
  18. ybrush

    ybrush Private E-2

    ok i am going to fix them and post a hijackthis log if you don't mind.

    thank you
     
  19. ybrush

    ybrush Private E-2

    ok this is the last HJT log.

    thank you so much for your help. It is so good to have someone for professional assistance

    unfortunately i am going to need you, to check my other pc (MacBookPro) that has a similar setup. i have already done the required scans but i am thinking of doing them after installing macdrive so it is able to check the mac disk(i 've never done that in that pc so the windows side has never "seen" the files that are on he mac side, the macosx can of course read by default the NTFS(windows) partition.

    so do you think it is more convenient to post these logs in the same thread or start a new one?
     

    Attached Files:

  20. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    It's fine now.


    New PC, new thread! Just be sure to state this is another PC so no one confuses it with this thread and this PC.
     
  21. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    If you are not having any other malware problems, it is time to do our final steps:
    1. If we used Pocket Killbox during your cleanup, do the below
      • Run Pocket Killbox and select File, Cleanup, Delete All Backups
    2. If we used ComboFix, you can delete the ComboFix.exe file, C:\ComboFix folder, C:\QooBox folder, C:\WINDOWS\nircmd.exe, and the C:\combofix.txt log that was created.
    3. If we user SDFix you can delete all the SDFix related files and folders from your Desktop or whereever you installed it.
    4. If we used SmitFraudFix, you can delete all files and folders related to it now including the c:\rapport.txt log.
    5. If we used VundoFix, you can delete the VundoFix.exe file and the C:\VundoFix Backups folder and C:\vundofix.txt log that was created.
    6. If we had your run FixWareOut, you can delete the Fixwareout.exe file and the C:\fixwareout folder.
    7. If we had you run Avenger, you can delete all files related to Avenger now.
    8. If we had you download any registry patches like fixme.reg or fixWLK.reg (or any others), you can delete these files now.
    9. You can delete the ShowNew.Zip and GetRunkey.Zip files and the files that you extracted from the ZIP files. You can also delete the C:\newfiles.txt and C:\runkeys.txt logs that were created
    10. If you are running Windows XP or Windows ME, do the below:
      • go back to step 8 of the READ & RUN ME to Disable System Restore which will flush your Restore Points.
      • Then reboot and Enable System Restore to create a new clean Restore Point.
    11. After doing the above, you should work thru the below link:
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds