CastleCops, Internet Crime Fighters
Need help? Click here to register for free! Absolutely zero advertisements on this site!

Donation/Premium
spacer
block bottom
Security Central
spacer
· Home
· PIRT/Fried Phish
· MIRT
· SIRT
· Deutsch
· Wiki
· Newsletter
· O16/ActiveX
· CLSID List
· Contest2007
· Downloads
· Feedback (send)
· Forums
· HijackThis
· Hijacktrend
· LSPs
· My Downloads
· O18
· O20
· O21
· O22
· O23
· O9
· Premium
· Private Messages
· Proxomitron
· Reviews
· Search
· StartupList
· Stories Archive
· Submit News
· WsIRT
· Your Account
· Acceptable Use Policy
block bottom
spacer spacer

autorun.inf, x.com, u.bat awda2.exe?

 
Post new topic   Reply to topic       All -> FavForums -> MIRT Discussion [del.icio.us!] [digg it!] [reddit!]
View previous topic :: View next topic  
Author Message
Saxenhauser

Cadet
Cadet


Joined: Jan 03, 2008
Posts: 8


PostPosted: Sun Feb 17, 2008 5:15 am    Post subject: autorun.inf, x.com, u.bat awda2.exe?
Reply with quote

I have malicious software that spreads to every external memory. My PC got infected from a USB memory stick.

It consists of 2 files: autorun.inf (525 bytes) and x.com ( 102.211 bytes). These files are HRS (hidden, read only, system) and cannot be deleted, edited or renamed and the attributes cannot be altered.

The content of autorun.inf is like this:

;
[AutoRun]
;
open=x.com
;
shell\open\Command=x.com
;
shell\open\Default=1
;
shell\explore\Command=x.com
;

Behind the semicolons there is some code but I will not publish it here because I fear it contents sensible information.

On some memory sticks there is also u.bat and awda2.exe.

What does it do? How can I get rid of it?

Back to top
View users profile Send private message
Saxenhauser

Cadet
Cadet


Joined: Jan 03, 2008
Posts: 8


PostPosted: Sun Feb 17, 2008 5:20 am    Post subject: more info
Reply with quote

The file x.com contains this line:

KERNEL32.DLL LoadLibraryA ExitProcess GetProcAddress

Back to top
View users profile Send private message
tetak

MIRT Team Lead
Premium Member

Joined: Jan 19, 2007
Posts: 5879

MIRT Premium

PostPosted: Sun Feb 17, 2008 2:27 pm    Post subject:
Reply with quote

Please can you add all the malware files into a .zip file and upload the .zip file to this post as an attachment.

Next follow this http://wiki.castlecops.com/MRP

If that doesn't help post a Hijackthis log in this forum.

CastleCops Link/f67-Hijackthis_Spyware_Viruses_Worms_Trojans_Oh_My.html

I also suggest you install Windows Defender (if you use Windows XP), which is free and is available from http://www.microsoft.com/athome/security/spyware/software/default.mspx


_________________
Got Windows XP? Help protect your PC from malware with Microsofts anti-spyware program Windows Defender.

Download it for free from http://www.microsoft.com/athome/security/spyware/software/default.mspx
Back to top
View users profile Send private message
Saxenhauser

Cadet
Cadet


Joined: Jan 03, 2008
Posts: 8


PostPosted: Sun Feb 17, 2008 5:55 pm    Post subject: ZIP is not possible
Reply with quote

wrote:
Please can you add all the malware files into a .zip file and upload the .zip file to this post as an attachment.

Next follow this http://wiki.castlecops.com/MRP

If that doesn't help post a Hijackthis log in this forum.

CastleCops Link/f67-Hijackthis_Spyware_Viruses_Worms_Trojans_Oh_My.html

I also suggest you install Windows Defender (if you use Windows XP), which is free and is available from http://www.microsoft.com/athome/security/spyware/software/default.mspx
I cannot zip them because WinZIP does not "see" or recognize the 2 files because they are HRS. I can only see them in the DOS shell with dir/a. There is no attribute change possible neither in in the DOS shell nor with Windows XP. I guess this malware does key logging.

Back to top
View users profile Send private message
tetak

MIRT Team Lead
Premium Member

Joined: Jan 19, 2007
Posts: 5879

MIRT Premium

PostPosted: Sun Feb 17, 2008 8:08 pm    Post subject:
Reply with quote

Try opening My Computer, click on Tools -> Folder Options -> View -> Show hidden files and folders -> Ok.

You may now be able to see the files.


_________________
Got Windows XP? Help protect your PC from malware with Microsofts anti-spyware program Windows Defender.

Download it for free from http://www.microsoft.com/athome/security/spyware/software/default.mspx
Back to top
View users profile Send private message
Saxenhauser

Cadet
Cadet


Joined: Jan 03, 2008
Posts: 8


PostPosted: Wed Mar 12, 2008 9:44 pm    Post subject:
Reply with quote

Thanks for help!

MicroSoft defender is downloaded, installed and running, and it reported 1 problem to the MS-center.

Quote:
Try opening My Computer, click on Tools -> Folder Options -> View -> Show hidden files and folders -> Ok.


There is no way to change the attribute setting. I cannot add the 2 files to .zip. WINZIP does not detect these HSR files. Only NeroBurningRom shows them. If they are deleted with NeroBurningRom about 20s later they reappear. Last time I had this kind of malware I had to edit the registry while in Windows safemode.

Do you know how to edit the registry do get rid of this malware?


I posted my HJT-log there:

autorun.inf, x.com. Infected by USB memory stick.

Back to top
View users profile Send private message
tetak

MIRT Team Lead
Premium Member

Joined: Jan 19, 2007
Posts: 5879

MIRT Premium

PostPosted: Wed Mar 12, 2008 9:56 pm    Post subject:
Reply with quote

A 1st responder or security expert will reply in your other post with instructions that should help you.


_________________
Got Windows XP? Help protect your PC from malware with Microsofts anti-spyware program Windows Defender.

Download it for free from http://www.microsoft.com/athome/security/spyware/software/default.mspx
Back to top
View users profile Send private message
Display posts from previous:   
Post new topic   Reply to topic       All -> FavForums -> MIRT Discussion All times are GMT
Page 1 of 1

 
Quick Reply:
Username: 

Quote the last message
Attach signature (signatures can be changed in profile)
 
You can post new topics in this forum
You can reply to topics in this forum
You cannot edit your posts in this forum
You cannot delete your posts in this forum
You cannot vote in polls in this forum
You can attach files in this forum
You cannot download files in this forum


Powered by phpBB © 2001 phpBB Group
spacer spacer