Lowyat.NET Forums

Welcome Guest ( Log In | Register )

 
RSS feedBump TopicReply to this topicStart new topicStart Poll

Outline · [ Standard ] · Linear+

> Anyone ever occured this?, Win32/AutoRun.KS.worm

themanwithnoname
post Aug 2 2008, 08:35 AM
Show posts by this member only |This post's rating (0+, 0-) | Post #1


"Kasi murah kalkulator Encik Tabo!"
*****

Group: Senior Member
Posts: 903
Ratings earned: 0+, 0-
Ratings given: 0+, 0-

Joined: Dec 2006
From: Soviet Sarawak





Greetings.

First of all, i'm sorry if im posting this in the wrong section.

user posted image


icon_question.gif

I got this popup warning from ESET NOD32 Antivirus, everytime i plug in any USB Device that have a storage, (memory stick,USB Pendrive,even my MP4 player! ) And really annoying, rclxub.gif because it will pop out every 2 seconds. So i guess this 'worm' is 'undeleteable' by the AV that im using.

Here is my HJT log and DSS log.

HJT
» Click to show Spoiler - click again to hide... «


DSS
» Click to show Spoiler - click again to hide... «


I hope someone can help me to destroy this bugging worm .
TQ. icon_question.gif
User is online!Profile CardPM
Go to the top of the page
+Quote Post
fariz
post Aug 2 2008, 10:48 AM
Show posts by this member only |This post's rating (0+, 0-) | Post #2


Tan Sri F
Group Icon

Group: Staff
Posts: 13,769
Ratings earned: 0+, 0-
Ratings given: 0+, 0-

Joined: Jan 2003
From: Siberia





these look suspicious
QUOTE
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{1e54c7a3-3e13-11dd-8b78-001d602922bd}]
AutoRun\command- I:\RECYCLER\S-1-5-21-1482476501-1644491937-682003330-1013\ipse32.exe
open\command- I:\RECYCLER\S-1-5-21-1482476501-1644491937-682003330-1013\ipse32.exe

[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{81cad7b6-4405-11dd-8b79-001d602922bd}]
AutoRun\command- I:\lgrncie.bat
explore\Command- I:\lgrncie.bat
open\Command- I:\lgrncie.bat

[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{c5d120d9-503a-11dd-8b7e-001d602922bd}]
AutoRun\command- I:\RECYCLER\S-1-5-21-1482476501-1644491937-682003330-1013\winse32.exe
open\command- I:\RECYCLER\S-1-5-21-1482476501-1644491937-682003330-1013\winse32.exe

[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{d2dfae45-2b46-11dd-8b6a-001d602922bd}]
AutoOpen\command- .\MSOCache\90000804-6000-11D3-8CFE-0150048383C9\KB915865.exe
AutoRun\command- C:\WINDOWS\system32\RunDLL32.EXE Shell32.DLL,ShellExec_RunDLL .\MSOCache\90000804-6000-11D3-8CFE-0150048383C9\KB915865.exe

[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{d2ef41d4-5556-11dd-8b80-001d602922bd}]
AutoRun\command- I:\photos.zip.exe %1
Explore\command- I:\photos.zip.exe %1
Open\command- I:\photos.zip.exe %1

[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{f92bf083-5bcd-11dd-8b82-001d602922bd}]
AutoRun\command- I:\RECYCLER\S-1-5-21-1482476501-1644491937-682003330-1013\winse32.exe
open\command- I:\RECYCLER\S-1-5-21-1482476501-1644491937-682003330-1013\winse32.exe


[HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{28ABC5C0-4FCB-11CF-AAX5-81CX1C635612}]
C:\RECYCLER\S-1-5-21-1482476501-1644491937-682003330-1013\winse32.exe
User is offlineProfile CardPM
Go to the top of the page
+Quote Post
Gormaz
post Aug 2 2008, 11:50 AM
Show posts by this member only |This post's rating (0+, 0-) | Post #3


Regular
***

Group: Junior Member
Posts: 359
Ratings earned: 0+, 0-
Ratings given: 0+, 0-

Joined: May 2008
From: PJ





Did you try a full scan of your computer (with the external devices plugged in so they also get disinfected) in safe mode?
Seems indeed you got a virus and it tries to spread to your usb devices. At least your antivirus seems to be able to detect it, a full scan should hopefully give you good results.

Make sure to run the scan in safe mode to not have issues with read only or system files.
User is offlineProfile CardPM
Go to the top of the page
+Quote Post
tan_pang
post Aug 2 2008, 12:51 PM
Show posts by this member only |This post's rating (0+, 0-) | Post #4


Look at all my stars!!
*******

Group: Senior Member
Posts: 3,019
Ratings earned: 0+, 0-
Ratings given: 0+, 0-

Joined: Jun 2005





QUOTE(umikosan @ Aug 2 2008, 11:55 AM)
download SmitfraudFix, boot in safe-mode and run the program... make sure u disable the windows restore
*


This is not Smitfraud and don't instruct other people to use SmitfraudFix!!!

And also, do NOT ever disable System Restore especially when infected with malware!!

This post has been edited by tan_pang: Aug 2 2008, 12:52 PM
User is online!Profile CardPM
Go to the top of the page
+Quote Post
themanwithnoname
post Aug 2 2008, 08:09 PM
Show posts by this member only |This post's rating (0+, 0-) | Post #5


"Kasi murah kalkulator Encik Tabo!"
*****

Group: Senior Member
Posts: 903
Ratings earned: 0+, 0-
Ratings given: 0+, 0-

Joined: Dec 2006
From: Soviet Sarawak





Oh, which one should i follow? hmm.gif cry.gif


Added on August 7, 2008, 11:00 pmShould i bump this thread?

This post has been edited by themanwithnoname: Aug 7 2008, 11:00 PM
User is online!Profile CardPM
Go to the top of the page
+Quote Post
sUBs
post Aug 19 2008, 01:58 PM
Show posts by this member only |This post's rating (0+, 0-) | Post #6


RIP
Group Icon
Retired Tech Support mod

Group: VIP
Posts: 3,931
Ratings earned: 0+, 0-
Ratings given: 0+, 0-

Joined: Jan 2005




Mod Note: Deleted 2 posts.

* One for giving uninformed advice about Smitfraudfix

* One for linking to software of dubious nature

Do it one more time & you shall both receive warnings
User is offlineProfile CardPM
Go to the top of the page
+Quote Post
[AM]
post Aug 19 2008, 07:22 PM
Show posts by this member only |This post's rating (0+, 0-) | Post #7


Regular
***

Group: Junior Member
Posts: 360
Ratings earned: 0+, 0-
Ratings given: 0+, 0-

Joined: Aug 2008
From: Kuantan, Pahang





QUOTE(sUBs @ Aug 19 2008, 01:58 PM)
Mod Note: Deleted 2 posts.

* One for giving uninformed advice about Smitfraudfix

* One for linking to software of dubious nature

Do it one more time & you shall both receive warnings

*



dubious nature? i have try it and comfirm working.. no virus

U May Want to look here


This post has been edited by [AM]: Aug 19 2008, 07:24 PM
User is offlineProfile CardPM
Go to the top of the page
+Quote Post
sUBs
post Aug 19 2008, 07:56 PM
Show posts by this member only |This post's rating (0+, 0-) | Post #8


RIP
Group Icon
Retired Tech Support mod

Group: VIP
Posts: 3,931
Ratings earned: 0+, 0-
Ratings given: 0+, 0-

Joined: Jan 2005




It is dubios for one simple reason. File is on rapidshare. There's is no way to authenticate it. Downloading & running an unauthenticated file is often the reason why so many machines are infected.
User is offlineProfile CardPM
Go to the top of the page
+Quote Post
[AM]
post Aug 19 2008, 09:57 PM
Show posts by this member only |This post's rating (0+, 0-) | Post #9


Regular
***

Group: Junior Member
Posts: 360
Ratings earned: 0+, 0-
Ratings given: 0+, 0-

Joined: Aug 2008
From: Kuantan, Pahang





QUOTE(sUBs @ Aug 19 2008, 07:56 PM)
It is dubios for one simple reason. File is on rapidshare. There's is no way to authenticate it. Downloading & running an unauthenticated file is often the reason why so many machines are infected.
*


can you recommend me where to upload files that r free? biggrin.gif
User is offlineProfile CardPM
Go to the top of the page
+Quote Post
chrisling
post Aug 19 2008, 10:04 PM
Show posts by this member only |This post's rating (0+, 0-) | Post #10


Helper Trainee
******

Group: Senior Member
Posts: 1,046
Ratings earned: 0+, 0-
Ratings given: 0+, 0-

Joined: Nov 2006





If you decided to use some unauthenticated file please use it at your own risk. By the way it's different with those great tool that created for human sake, such as sUBs's ComboFix and Andy's SDFix. Those tools I believe should had gone through many observations and testing to ensure they aren't harmful, which what we so called rogue softwares.

They're different, if you want to use the files that uploaded in RapidShare, use it at your own risk and please, don't recommend users to use it if you didn't plan you want to bear the responsibility. smile.gif
User is offlineProfile CardPM
Go to the top of the page
+Quote Post
[AM]
post Aug 19 2008, 11:22 PM
Show posts by this member only |This post's rating (0+, 0-) | Post #11


Regular
***

Group: Junior Member
Posts: 360
Ratings earned: 0+, 0-
Ratings given: 0+, 0-

Joined: Aug 2008
From: Kuantan, Pahang





hmm okay.. who wants to test it just PM me
User is offlineProfile CardPM
Go to the top of the page
+Quote Post
sUBs
post Aug 20 2008, 05:50 AM
Show posts by this member only |This post's rating (0+, 0-) | Post #12


RIP
Group Icon
Retired Tech Support mod

Group: VIP
Posts: 3,931
Ratings earned: 0+, 0-
Ratings given: 0+, 0-

Joined: Jan 2005




Distributing someone else's work without due permission is improper.

It would be much better if you find & post the author's homepage. That way, if anything untoward occurs during the course of a disinfection, users will have a mean of seeking proper support.

I'm sorry but I simply cannot condone the unauthorised distribution of intellectual property.
User is offlineProfile CardPM
Go to the top of the page
+Quote Post
themanwithnoname
post Aug 21 2008, 11:01 PM
Show posts by this member only |This post's rating (0+, 0-) | Post #13


"Kasi murah kalkulator Encik Tabo!"
*****

Group: Senior Member
Posts: 903
Ratings earned: 0+, 0-
Ratings given: 0+, 0-

Joined: Dec 2006
From: Soviet Sarawak





Guess that the worm will stay forever in my portable drives.. sad.gif cry.gif
User is online!Profile CardPM
Go to the top of the page
+Quote Post
[AM]
post Aug 23 2008, 02:23 PM
Show posts by this member only |This post's rating (0+, 0-) | Post #14


Regular
***

Group: Junior Member
Posts: 360
Ratings earned: 0+, 0-
Ratings given: 0+, 0-

Joined: Aug 2008
From: Kuantan, Pahang





User is offlineProfile CardPM
Go to the top of the page
+Quote Post

Bump TopicReply to this topicTopic OptionsStart new topic
 

Lo-Fi Version Time is now: 4th July 2009 - 10:04 PM
All Rights Reserved 2003-2009 Vijandren Ramadass (~looking for Mikaela~)