Welcome guest. Before posting on our computer help forum, you must register. Click here it's easy and free.

Author Topic: Autorun Infections on USB Drives  (Read 20644 times)

0 Members and 1 Guest are viewing this topic.

evilfantasy

  • Malware Removal Specialist
  • Moderator


  • Genius
  • Calm like a bomb
  • Thanked: 493
  • Experience: Experienced
  • OS: Windows 11
Re: Autorun Infections on USB Drives
« Reply #45 on: February 10, 2010, 12:31:50 PM »
Yes that would be best.

Tatterdemalion

    Topic Starter


    Intermediate

    Re: Autorun Infections on USB Drives
    « Reply #46 on: February 10, 2010, 01:17:01 PM »
    When I tried to drag the CFScript.txt onto the ComboFix icon I think it asked to Run and I think I said O.K. then I realised my browser was still open and so I tried to delay the ComboFix program while I closed it.

    The browser is now shut.

    However, I have a couple of warning screens saying that Avast and BOClean are active.

    Will I be able to shut them from the icons on the TaskBar while the warning boxes are still visible ?

    Should something ELSE have happened ?

    What should I do ?

    Again massive thanks for your patience.


    evilfantasy

    • Malware Removal Specialist
    • Moderator


    • Genius
    • Calm like a bomb
    • Thanked: 493
    • Experience: Experienced
    • OS: Windows 11
    Re: Autorun Infections on USB Drives
    « Reply #47 on: February 10, 2010, 01:30:13 PM »
    Quote
    Will I be able to shut them from the icons on the TaskBar while the warning boxes are still visible ?

    Yes shut them down now and then let CF continue.

    Tatterdemalion

      Topic Starter


      Intermediate

      Re: Autorun Infections on USB Drives
      « Reply #48 on: February 10, 2010, 01:43:33 PM »
      I've closed Avast and BOClean and the ComboFix Blue area has appeared.

      It has given a message that there is a new version of ComboFix available and is asking if I want to download it.

      Should I update now or proceed with the scan ?

      evilfantasy

      • Malware Removal Specialist
      • Moderator


      • Genius
      • Calm like a bomb
      • Thanked: 493
      • Experience: Experienced
      • OS: Windows 11
      Re: Autorun Infections on USB Drives
      « Reply #49 on: February 10, 2010, 01:45:53 PM »
      Yes update it before continuing.

      Tatterdemalion

        Topic Starter


        Intermediate

        Re: Autorun Infections on USB Drives
        « Reply #50 on: February 10, 2010, 03:00:57 PM »
        In case it is important, I thought I had better mention that both times after ComboFix re-booted the Lenovo it has briefly displayed a text line saying that it couldn't find combofix.sys.

        I have attached the ComboFix Report generated after starting it with the CFScript.

        I have run the Temp File Cleaner. It removed 68.00MB.

        [Saving space, attachment deleted by admin]

        evilfantasy

        • Malware Removal Specialist
        • Moderator


        • Genius
        • Calm like a bomb
        • Thanked: 493
        • Experience: Experienced
        • OS: Windows 11
        Re: Autorun Infections on USB Drives
        « Reply #51 on: February 10, 2010, 03:14:11 PM »
        That looks good now.

        I'm confident that the computer is clean and it should perform a little better with all of the Norton stuff gone.


        Let's clear out the programs we've been using to clean up your computer, they are not suitable for general malware removal and could cause damage if launched accidentally. These steps will also help secure the work you have done.

        * Click START then RUN
        * Now type Combofix /Uninstall in the runbox
        * Make sure there's a space between Combofix and /Uninstall
        * Then hit Enter.

        The above procedure will:
        * Delete: ComboFix and its associated files and folders.
        * Reset the clock settings.
        * Hide file extensions, if required.
        * Hide System/Hidden files, if required.
        * Set a new, clean Restore Point.

        ----------

        Here are some more suggestions to help tighten up your computers security.

        Use the Secunia Software Inspector to check for out of date software.

        * Click Start Now
        * Check the box next to Enable thorough system inspection.
        * Click Start
        * Allow the scan to finish and scroll down to see if any updates are needed.
        * Update anything listed.

        ----------

        Go to Microsoft Windows Update and get all critical updates.

        ----------

        If you are using or have installed IE6 you are using an outdated and soon to be unsupported version of Internet Explorer and I strongly suggest you update to the latest version directly from Microsoft Internet Explorer 8: Home page.

        ----------

        I recommend you keep SUPERAntiSpyware and Malwarebytes Anti-Malware for scanning/removal of malware. Unless you purchase them, they provide no realtime protection so will not interfere with each other. They do not use any significant amount of resources (except a little disk space) until you run a scan.

        I suggest using WOT - Web of Trust. WOT is a free Internet security addon for your browser. It will keep you safe from online scams, identity theft, spyware, spam, viruses and unreliable shopping sites. WOT warns you before you interact with a risky website. It's easy and it's free.

        SpywareBlaster - Secure your Internet Explorer to make it harder for ActiveX programs to run on your computer. Also stop certain cookies from being added to your computer when running Mozilla based browsers like Firefox.
        * Using SpywareBlaster to protect your computer from Spyware and Malware
        * If you don't know what ActiveX controls are, see here

        Protect yourself against spyware using the Immunize feature in Spybot - Search & Destroy. Guide: Use Spybot's Immunize Feature to prevent spyware infection in real-time. Note: To ensure you have the latest Immunizations always update Spybot - Search & Destroy before Immunizing. Spybot - Search & Destroy FAQ

        Check out Keeping Yourself Safe On The Web for tips and free tools to help keep you safe in the future.

        Also see Slow Computer? It May Not Be Malware for free cleaning/maintenance tools to help keep your computer running smooth.

        Tatterdemalion

          Topic Starter


          Intermediate

          Re: Autorun Infections on USB Drives
          « Reply #52 on: February 11, 2010, 03:16:15 AM »
          Hi. Thank you for your help.

          I am trying to uninstall ComboFix.

          I have typed the command in the RUN box.

          BOClean hs produced this message :

          RSK-HIDE.SAA MALWARE STOPPED by BOCLEAN

          Location of startup : FILE
          C:\32788R22FW\HIDEC.EXE

          This trojan horse was found on your machine.
          It has been shut down, but the FILE from which it
          started still remains and can be started up again.

          Do you want the file removed also ?

          YES/NO

          Please advise.

          evilfantasy

          • Malware Removal Specialist
          • Moderator


          • Genius
          • Calm like a bomb
          • Thanked: 493
          • Experience: Experienced
          • OS: Windows 11
          Re: Autorun Infections on USB Drives
          « Reply #53 on: February 11, 2010, 08:37:02 AM »
          Disable BOClean before uninstalling ComboFix.

          Tatterdemalion

            Topic Starter


            Intermediate

            Re: Autorun Infections on USB Drives
            « Reply #54 on: February 11, 2010, 08:51:59 AM »
            I closed down BOClean and Avast so that the unistallation would continue.

            I have an "Info" Box on screen that says "ComboFix is ininstalled".

            It appeared really quickly, there were no other screens and the computer did not re-boot.

            Is that O.K?

            evilfantasy

            • Malware Removal Specialist
            • Moderator


            • Genius
            • Calm like a bomb
            • Thanked: 493
            • Experience: Experienced
            • OS: Windows 11
            Re: Autorun Infections on USB Drives
            « Reply #55 on: February 11, 2010, 09:17:12 AM »
            Yes it's gone. It happens very fast.


            You should be good to go on cleaning the other drives now. Nothing on the computer will spread to them. Just don't let the drives auto launch before you are sure they're cleaned.

            Tatterdemalion

              Topic Starter


              Intermediate

              Re: Autorun Infections on USB Drives
              « Reply #56 on: February 11, 2010, 12:37:18 PM »
              In the process of using a 250GB Iomega Hard Drive, that has not had contact with the Lenovo, to transport Flash Disinfector, Panda USB Vaccine and Avira Anti-Virus to my Toshiba laptop, I discovered that I had not been following your TWEAK UI Auto-Run instructions properly.

              What I have found is that if you -->

              Open Tweak UI
              Expand My Computer
              Expand AutoPlay
              Click Types
              UNcheck "Enable Autoplay for removable drives"
              Click Apply
              Click O.K.

              your external hard drive will STILL Autoplay, even after a re-boot.

              I suppose the Tweak Tool is divided up so that the section I looked at and modified is geared towards ENABLING a function - whereas the LIST I *should* have looked at is about SWITCHING THINGS OFF.

              I'm posting my mistake so that hopefully other people will avoid it.

              I do find it confusing that imy WRONG Tweak appears to have no effect.

              Is AutoPlay ever actually really necessary for anything ?

              If you have a CD or a DVD, could you not always CHOOSE to make it start by clicking the optical drive's icon ?

              Thanks again for all the help that you have provided. This site is brilliant. The direct links to the relevant pages for program downloads cut through so much time searching at Google or just trying to navigate through a software company's site.


              ADDITION : I just went to manually modify the AutoPlay settings on the Lenovo and this Systemax and can see that ALL of the drives - even the optical drives - have been deselected.

              So I take it that's what Panda Vaccine does when it "Vaccinates a Computer" rather than an external drive.


              « Last Edit: February 11, 2010, 12:48:08 PM by Tatterdemalion »

              evilfantasy

              • Malware Removal Specialist
              • Moderator


              • Genius
              • Calm like a bomb
              • Thanked: 493
              • Experience: Experienced
              • OS: Windows 11
              Re: Autorun Infections on USB Drives
              « Reply #57 on: February 11, 2010, 01:25:35 PM »
              There are some more solutions for disabling autoruns here. http://support.microsoft.com/kb/967715