Results 1 to 4 of 4

Thread: malware from school - cleaning usb flash drive

  1. #1
    Junior Member
    Join Date
    Aug 2008
    Posts
    12

    Default malware from school - cleaning usb flash drive

    Apparently we have viruses at school.. They are running Norman Virus Control with people doing what-not on facebook etc..

    I think my USB-flash drive got infected since when i popped it in at home avira started yelling at me..
    The file 'I:\X\DELETED\MarCh3.exe'
    contained a virus or unwanted program 'TR/Dropper.Gen' [trojan]
    Action(s) taken:
    The file was moved to the quarantine directory under the name '037fdab1.qua'.
    I ran a scan of it and got 3 threats (can provide report if requested)
    I checked the log and noticed some folders/files were still left on the disk, not created by me, hidden. I downloaded file shredder to remove them, but it says they are in use and that is when i decided to check with you guys, since it must be running on my computer. When I add the USB-drive to the list of files to remove in file shredder it shows 6 folders with children which i havnt created myself most with files in it, such as; DeSkToP.InI etc.
    anyway, to go from here...

    HJT:
    Logfile of Trend Micro HijackThis v2.0.2
    Scan saved at 17:14:54, on 2010-03-30
    Platform: Unknown Windows (WinNT 6.01.3504)
    MSIE: Internet Explorer v8.00 (8.00.7600.16385)
    Boot mode: Normal

    Running processes:
    C:\Program Files (x86)\Personal\bin\Personal.exe
    C:\Program Files (x86)\Avira\AntiVir Desktop\avgnt.exe
    C:\program files (x86)\avira\antivir desktop\avcenter.exe
    C:\Users\Daniel\AppData\Local\Google\Chrome\Application\chrome.exe
    C:\Users\Daniel\AppData\Local\Google\Chrome\Application\chrome.exe
    C:\Users\Daniel\AppData\Local\Google\Chrome\Application\chrome.exe
    C:\Users\Daniel\AppData\Local\Google\Chrome\Application\chrome.exe
    C:\Users\Daniel\AppData\Local\Google\Chrome\Application\chrome.exe
    C:\Users\Daniel\AppData\Local\Google\Chrome\Application\chrome.exe
    C:\Users\Daniel\AppData\Local\Google\Chrome\Application\chrome.exe
    C:\Users\Daniel\AppData\Local\Google\Chrome\Application\chrome.exe
    C:\Users\Daniel\AppData\Local\Google\Chrome\Application\chrome.exe
    C:\Users\Daniel\AppData\Local\Google\Chrome\Application\chrome.exe
    C:\Users\Daniel\AppData\Local\Google\Chrome\Application\chrome.exe
    C:\Users\Daniel\AppData\Local\Google\Chrome\Application\chrome.exe
    C:\Users\Daniel\AppData\Local\Google\Chrome\Application\chrome.exe
    C:\Users\Daniel\AppData\Local\Google\Chrome\Application\chrome.exe
    C:\Users\Daniel\AppData\Local\Google\Chrome\Application\chrome.exe
    C:\Users\Daniel\AppData\Local\Google\Chrome\Application\chrome.exe
    C:\PROGRA~2\FOXITS~1\FOXITR~1\FOXITR~1.EXE
    C:\Program Files (x86)\File Shredder\Shredder.exe
    C:\Users\Daniel\AppData\Local\Google\Chrome\Application\chrome.exe
    C:\Users\Daniel\AppData\Local\Google\Chrome\Application\chrome.exe
    C:\Program Files (x86)\Trend Micro\HijackThis\HijackThis.exe

    R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
    R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
    R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
    R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
    R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
    R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
    R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant =
    R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch =
    R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Local Page = C:\Windows\SysWOW64\blank.htm
    R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
    F2 - REG:system.ini: UserInit=userinit.exe
    O2 - BHO: Windows Live inloggningshjälpen - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files (x86)\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
    O4 - HKLM\..\Run: [avgnt] "C:\Program Files (x86)\Avira\AntiVir Desktop\avgnt.exe" /min
    O4 - HKLM\..\Run: [StartCCC] "C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe" MSRun
    O4 - HKCU\..\Run: [Google Update] "C:\Users\Daniel\AppData\Local\Google\Update\GoogleUpdate.exe" /c
    O4 - HKCU\..\Run: [Skype] "C:\Program Files (x86)\Skype\Phone\Skype.exe" /nosplash /minimized
    O4 - HKCU\..\Run: [msnmsgr] "C:\Program Files (x86)\Windows Live\Messenger\msnmsgr.exe" /background
    O4 - HKUS\S-1-5-19\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /autoRun (User 'LOCAL SERVICE')
    O4 - HKUS\S-1-5-19\..\RunOnce: [mctadmin] C:\Windows\System32\mctadmin.exe (User 'LOCAL SERVICE')
    O4 - HKUS\S-1-5-20\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /autoRun (User 'NETWORK SERVICE')
    O4 - HKUS\S-1-5-20\..\RunOnce: [mctadmin] C:\Windows\System32\mctadmin.exe (User 'NETWORK SERVICE')
    O4 - Global Startup: BankID Security Application.lnk = C:\Program Files (x86)\Personal\bin\Personal.exe
    O13 - Gopher Prefix:
    O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) - http://fpdownload2.macromedia.com/ge...sh/swflash.cab
    O18 - Protocol: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\PROGRA~2\COMMON~1\Skype\SKYPE4~1.DLL
    O23 - Service: @%SystemRoot%\system32\Alg.exe,-112 (ALG) - Unknown owner - C:\Windows\System32\alg.exe (file missing)
    O23 - Service: AMD External Events Utility - Unknown owner - C:\Windows\system32\atiesrxx.exe (file missing)
    O23 - Service: Avira AntiVir Scheduler (AntiVirSchedulerService) - Avira GmbH - C:\Program Files (x86)\Avira\AntiVir Desktop\sched.exe
    O23 - Service: Avira AntiVir Guard (AntiVirService) - Avira GmbH - C:\Program Files (x86)\Avira\AntiVir Desktop\avguard.exe
    O23 - Service: @%SystemRoot%\system32\efssvc.dll,-100 (EFS) - Unknown owner - C:\Windows\System32\lsass.exe (file missing)
    O23 - Service: @%systemroot%\system32\fxsresm.dll,-118 (Fax) - Unknown owner - C:\Windows\system32\fxssvc.exe (file missing)
    O23 - Service: @keyiso.dll,-100 (KeyIso) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
    O23 - Service: @comres.dll,-2797 (MSDTC) - Unknown owner - C:\Windows\System32\msdtc.exe (file missing)
    O23 - Service: @%SystemRoot%\System32\netlogon.dll,-102 (Netlogon) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
    O23 - Service: @%systemroot%\system32\psbase.dll,-300 (ProtectedStorage) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
    O23 - Service: @%systemroot%\system32\Locator.exe,-2 (RpcLocator) - Unknown owner - C:\Windows\system32\locator.exe (file missing)
    O23 - Service: @%SystemRoot%\system32\samsrv.dll,-1 (SamSs) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
    O23 - Service: @%SystemRoot%\system32\snmptrap.exe,-3 (SNMPTRAP) - Unknown owner - C:\Windows\System32\snmptrap.exe (file missing)
    O23 - Service: @%systemroot%\system32\spoolsv.exe,-1 (Spooler) - Unknown owner - C:\Windows\System32\spoolsv.exe (file missing)
    O23 - Service: @%SystemRoot%\system32\sppsvc.exe,-101 (sppsvc) - Unknown owner - C:\Windows\system32\sppsvc.exe (file missing)
    O23 - Service: @%SystemRoot%\system32\ui0detect.exe,-101 (UI0Detect) - Unknown owner - C:\Windows\system32\UI0Detect.exe (file missing)
    O23 - Service: @%SystemRoot%\system32\vaultsvc.dll,-1003 (VaultSvc) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
    O23 - Service: @%SystemRoot%\system32\vds.exe,-100 (vds) - Unknown owner - C:\Windows\System32\vds.exe (file missing)
    O23 - Service: @%systemroot%\system32\vssvc.exe,-102 (VSS) - Unknown owner - C:\Windows\system32\vssvc.exe (file missing)
    O23 - Service: @%systemroot%\system32\wbengine.exe,-104 (wbengine) - Unknown owner - C:\Windows\system32\wbengine.exe (file missing)
    O23 - Service: @%Systemroot%\system32\wbem\wmiapsrv.exe,-110 (wmiApSrv) - Unknown owner - C:\Windows\system32\wbem\WmiApSrv.exe (file missing)
    O23 - Service: @%PROGRAMFILES%\Windows Media Player\wmpnetwk.exe,-101 (WMPNetworkSvc) - Unknown owner - C:\Program Files (x86)\Windows Media Player\wmpnetwk.exe (file missing)

    --
    End of file - 7154 bytes

    Thanks for your assistance!

  2. #2
    Security Expert: Emeritus Blade81's Avatar
    Join Date
    Oct 2006
    Location
    Finland
    Posts
    25,288

    Default

    Hi,

    1. Download Flash_Disinfector and save it to your Desktop.
    2. After downloading, double-click on Flash_Disinfector to run it.
    3. Just follow the prompts and continue until it begin scanning.
    4. If asked to insert your flash drive or any removable device including USB Pen Drive and Memory Stick, please do so.
    5. It will scan removable drives, wait for the scan to finish. Done.

    After that run Kaspersky Online Scanner to check your USB drive.
    Microsoft Windows Insider MVP 2016-2020
    Microsoft MVP Consumer Security 2008-2015
    UNITE member since 2006

    If you have problems create a thread in the forum, please.

    Malware removal instructions are for the correspondent user's case only.

  3. #3
    Junior Member
    Join Date
    Aug 2008
    Posts
    12

    Default

    ok, there was nothing else to be read from hjt log? wow... im impressed... by avira :p i definitley thought it would let through a trojan covering a more nasty one (or maybe that is just my wild imagination :s). well thanks for the info then, will do that once i get a new PSU installed.. Mine died 2 days ago but apparently not related to any possible virus which i almost had in mind, but rather old age x)

    Anyway, thanks for the response! Cheers! You guys

  4. #4
    Security Expert: Emeritus Blade81's Avatar
    Join Date
    Oct 2006
    Location
    Finland
    Posts
    25,288

    Default

    Yep, hjt log didn't give a signal of infection. I'll leave the topic open for a few days in case you can post back a status update.
    Microsoft Windows Insider MVP 2016-2020
    Microsoft MVP Consumer Security 2008-2015
    UNITE member since 2006

    If you have problems create a thread in the forum, please.

    Malware removal instructions are for the correspondent user's case only.

Posting Permissions

  • You may not post new threads
  • You may not post replies
  • You may not post attachments
  • You may not edit your posts
  •