usb_run.exe!

Discussion in 'Malware Help (A Specialist Will Reply)' started by Amjad, Feb 21, 2010.

  1. Amjad

    Amjad Corporal

    Hi everybody,

    I have the following hidden file son my USB Flash Drive, it is named usb_run.exe
    There was of course an autorun file that points to that file in order to execute it when I double click the flash drive, but of course I didn't.

    Anyway, I am just frustrated because I just moved from Avira to AVG because I was having a problem with these new threats and malware, but I'm pointing to the file itself and asking AVG to scan it, and AVG says there was nothing (not infected).

    By the way AVG is updated to the latest version (both program modules and virus definitions).

    Is there a way that we can analyze this file or can I send it to someone specialist to do it?

    :confused:(
     
  2. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    • Click on the following link and use the below steps to scan a file: Virustotal
      • Click the Browse... button.
      • Navigate to the file FileToBeScanned
        • Where FileToBeScanned is the actual file to be scanned. Like C:\WINDOWS\System32\vdmt16.sys
      • Click the Open button.
      • Click the Send button.
      • Repeat the above for each file to be scanned
    • Copy and paste the results in Notepad, and save them to your desktop, so you can attach them to your next reply.
     
  3. Amjad

    Amjad Corporal


    Dear TimW,
    Thanks. I've done it and here's the result.
     

    Attached Files:

  4. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    I can't find any info on that file and the scan of that file leaves a lot to speculate on. I would suggest that to be on the safe side, you just rename the file to usb_run.exe.old andsee if it effects your drive usage. If your thumb drive still works properly, then you can delete it.
     
  5. Amjad

    Amjad Corporal

    Thanks TimW,

    About the usage, I was experiencing a lot of threats reported by AVG and they all were caught inside Temporary Internet Files, the files were 790.exe, 980.exe, dol3.exe and things like those, but I don't know if usb_run.exe has anything to do with these threats...

    However, when AVG removes them, they are coming back...

    The website you gave me said that usb_run.exe was only identified by Symantec and PrevX and a third product which I don't remember...
    All other products failed to identify it...

    I scanned my flash drive on a computer running Symantec Endpoint Protection and it really removed the file after analyzing it...

    This is good but it's not like this for people relying on Avira and AVG and other free antivirus applications...

    :(
     
  6. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

  7. Amjad

    Amjad Corporal

    OK I really have to do it. My system is suffering, and Symantec Endpoint Protection is completely dead! I didn't expect this, it's not running at all, as if all processes and services of Symantec are now stopped!
    :(:cry

    I will report you back...
     
  8. Amjad

    Amjad Corporal

    Actually, here's the full scenario:

    This problem is found on my laptop, and I was setting up a new laptop (installing XP and applications) so I think it got infected too (but not as awful as my laptop).

    Anyway, I'm having this issue with the new laptop: Whenever I open a command prompt (run cmd.exe) the screen of cmd closes by itself after 4 or 5 second!

    I did all steps in the READ AND RUN ME guide, so I will post the logs now...
    I will also do the steps on my laptop and post the logs, but for now, I hope that the new laptop is clean! :(:confused
     

    Attached Files:

  9. Amjad

    Amjad Corporal

    And here's the MG ones:
     

    Attached Files:

  10. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Try opening the command prompt by right clicking and choosing run as administrator.

    Did you install AutoEater?

    Am I to assume that when you ran MBAM you did have it fix what it found> the log states that you didn't.

    You will need to start a separate thread for another computer. This one is only reporting a messenger file as infected, so we can do this:

    * Make sure that combofix.exe that you downloaded while doing the READ & RUN ME is on your Desktop but Do not run it!
    If it is not on your Desktop, the below will not work.
    * Also make sure you have shut down all protection software (antivirus, antispyware...etc) or they may get in the way of allowing ComboFix to run properly.
    * If ComboFix tells you it needs to update to a new version, make sure you allow it to update.
    * Open Notepad and copy/paste the text in the below code box into it (make sure you scroll all the way down in the code box to get all lines selected ):
    Code:
    KILLALL::
    
    FCopy::
    c:\windows\ERDNT\cache\msgsvc.dll | c:\windows\system32\msgsvc.dll
    
    
    * Save the above as CFscript.txt and make sure you save it to the same location (should be on your Desktop) as ComboFix.exe
    * At this point, you MUST EXIT ALL BROWSERS NOW before continuing!
    * You should have both the ComboFix.exe and CFScript.txt icons on your Desktop.
    If it asks you to overide the prvevious file with the same name, click YES.
    * Now use your mouse to drag CFscript.txt on top of ComboFix.exe
    http://img.photobucket.com/albums/v666/sUBs/CFScriptB-4.gif
    * Follow the prompts.
    * When it finishes, a log will be produced named c:\combofix.txt
    * I will ask for this log below

    Note:

    Do not mouseclick combofix's window while it is running. That may cause it to stall.

    Now run the C:\MGtools\GetLogs.bat file by double clicking on it (Note: if using Vista, don't double click, use right click and select Run As Administrator).

    Then attach the below logs:

    * C:\ComboFix.txt
    * C:\MGlogs.zip

    Make sure you tell me how things are working now!
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds