Showing posts with label worm. Show all posts
Showing posts with label worm. Show all posts

Thursday, July 4, 2019

Malware Prevention: Autoit3 worms

Here is a script I wrote almost one year ago.  Purpose is to immunize (block) AutoIt3 worms that disguise as GoogleChrome, Firefox and Skype.  It's almost a year and I still encounter this on customers flash drives.

What it does is create four folders namely:

  • GoogleChrome
  • MozillaFirefox
  • Skypee
  • Skype

and locked them so the worm no longer have access to those folders.

Folder used by worm with denied Full control

Copy and paste the following to Notepad ans save as Immunize.bat
Change the Drive variable if you want to immunize your external/USB drives as well.

--------------------

@ECHO OFF

REM Replace Drive=*: with the appropriate drive letter

SET Drive=C:
%Drive%

CLS
ECHO Immunize against GoogleChrome, MozillaFirefox and Skype (AutoIt3 worms)
ECHO By WinXPert (7/09/2018)
ECHO https://www.facebook.com/groups/pinoytechrambo
ECHO https://www.facebook.com/groups/CTExperts.PH/
ECHO.
ECHO IMMUNIZING Drive %Drive%
ECHO.
PAUSE

MD "%Drive%"\GoogleChrome"
ATTRIB +h +s /s /d ""%Drive%"\GoogleChrome"
icacls ""%Drive%"\GoogleChrome" /inheritance:r /deny "Everyone:(OI)(CI)(F)" "ANONYMOUS LOGON:(OI)(CI)(F)"

MD ""%Drive%"\MozillaFirefox"
ATTRIB +h +s /s /d ""%Drive%"\MozillaFirefox"
icacls ""%Drive%"\MozillaFirefox" /inheritance:r /deny "Everyone:(OI)(CI)(F)" "ANONYMOUS LOGON:(OI)(CI)(F)"

MD ""%Drive%"\Skypee"
ATTRIB +h +s /s /d ""%Drive%"\Skypee"
icacls ""%Drive%"\Skypee" /inheritance:r /deny "Everyone:(OI)(CI)(F)" "ANONYMOUS LOGON:(OI)(CI)(F)"

MD ""%Drive%"\Skype"
ATTRIB +h +s /s /d ""%Drive%"\Skype"
icacls ""%Drive%"\Skype" /inheritance:r /deny "Everyone:(OI)(CI)(F)" "ANONYMOUS LOGON:(OI)(CI)(F)"

PAUSE

--------------------

Remember a byte of prevention is worth a megabyte of cure.



All content ("Information") contained in this report is the copyrighted work of WinXPert: Virus and Malware Removal.

The Information is provided on an "as is" basis. WinXPert disclaims all warranties, whether express or implied, to the maximum extent permitted by law, including the implied warranties that the Information is merchantable, of satisfactory quality, accurate, fit for a particular purpose or need, or non-infringing, unless such implied warranties are legally incapable of exclusion. Further, WinXPert does not warrant or make any representations regarding the use or the results of the use of the Information in terms of their correctness, accuracy, reliability, or otherwise. 
Copyright © 2019 WinXPert. All rights reserved. All other trademarks are the sole property of their respective owners.

To GOD be the glory!

Wednesday, May 8, 2019

Malware Removal 101: Worm (Files.bat)

I got this sample a few days ago from a customer's USB drive:

Virustotal


User's files and folders are replaced with shortcuts.  Files are hidden and moved to Files folder.

Manual Removal

Using System Explorer, terminate the running malware process.  If you have multiple running instances of the worm, select the parent process and End Process Tree instead.



Locate the files using CCleaner.  Select Start.lnk | Right click and click on File Directory Explore.


Delete all files including the parent folder.


 Using Explorer, delete at shortcut in your USB drive.


Unhiding the files.  You can use Attrib or Explorer.

  • Attrib
Launch CMD and type the following:

CD drive:
ATTRIB -S -H /S /D

Replace drive: with the corresponding drive assignment of your USB drive.  Ex.  F:

  • Explorer
At Folder Options enable Show hidden files, folders and drives

Navigate to Files folder

Move all files and folders to your root directory


Select all hidden folders and unhide using Properties



Delete Files folder



Back at System Explorer delete Start.lnk



Note:  If you have multiple instances of the malware running in memory, do not use TaskMan to terminate its process because there is a chance that your PC would reboot.  Use System Explorer instead.  Suspend all processes first then end them one by one.



POST:  Scan your system and USB drives with an updated Antivirus.






All content ("Information") contained in this report is the copyrighted work of WinXPert: Virus and Malware Removal.

The Information is provided on an "as is" basis. WinXPert disclaims all warranties, whether express or implied, to the maximum extent permitted by law, including the implied warranties that the Information is merchantable, of satisfactory quality, accurate, fit for a particular purpose or need, or non-infringing, unless such implied warranties are legally incapable of exclusion. Further, WinXPert does not warrant or make any representations regarding the use or the results of the use of the Information in terms of their correctness, accuracy, reliability, or otherwise. 
Copyright © 2019 WinXPert. All rights reserved. All other trademarks are the sole property of their respective owners.

To GOD be the glory!

Saturday, May 4, 2019

Malware Removal 101: Rotinom

Problem:  Drive C is running out of disk space every time you insert an external HDD or a USB drive?  Chances are you are infected with Rotinom.

Virustotal

What it does to your computer:


  • Starts with windows

  • Makes a copy of all files from USB drive to Rotinom folder on Drive C: thus reducing its free space.

  • Infects USB or external drives.  Hides all folders and replaces them with shortcuts.
Notice the difference in the icons.


Changes in the registry:

Key: HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\Shell Folders
Name: Startup
Value: C:\Users\admin\AppData\Local\Start

Key: HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\User Shell Folders
Name: Startup
Value: C:\Users\admin\AppData\Local\Start

Manual Removal Instruction:


  • Since TaskMan is not disabled, we can use it to terminate update.exe.

  • Navigate to "%LocalAppData%\Start" and delete update.exe
  • Search for Rotinom folder.  Easiest way to do that is search using Everything.  

  • Delete the folder.  Also delete its parent folder.  Empty you Recycle Bin



Cleaning USB and external drives:

  • Delete all files associated with Rotinom.  All *.exe files with folder icon and also the Usb 2.0 Driver folder.


POST:

  • Scan with an updated Antivirus/Antimalware.
  • Unhide files and folders at the CMD prompt.
        ATTRIB -S -H /S /D

  • Repair the registry.  Replace the value indicated in blue.

Key: HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\Shell Folders
Name: Startup
Value: %USERPROFILE%\AppData\Roaming\Microsoft\Windows\Start Menu

Key: HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\User Shell Folders
Name: Startup
Value: %USERPROFILE%\AppData\Roaming\Microsoft\Windows\Start Menu





All content ("Information") contained in this report is the copyrighted work of WinXPert: Virus and Malware Removal.

The Information is provided on an "as is" basis. WinXPert disclaims all warranties, whether express or implied, to the maximum extent permitted by law, including the implied warranties that the Information is merchantable, of satisfactory quality, accurate, fit for a particular purpose or need, or non-infringing, unless such implied warranties are legally incapable of exclusion. Further, WinXPert does not warrant or make any representations regarding the use or the results of the use of the Information in terms of their correctness, accuracy, reliability, or otherwise. 
Copyright © 2019 WinXPert. All rights reserved. All other trademarks are the sole property of their respective owners.

To GOD be the glory!

Saturday, September 3, 2016

How to remove ramnit



Type of file: exefile
Description: Random filename
Location: Startup Folder
Size: 101872 b
MD5: F3873258A4258A6761DC54D47463182F

What it does:

  • Starts with Windows
  • Infects exe, dll and html files
  • Worm spreads via the default web browser
  • Create 4 shortcuts on external drives
  • Create copies of itself at the RECYCLER folder on external drives

Manual removal instructions

These instructions are specific to this variant of Ramnit.


1.  Terminate the malware process using Taskman or Taskkill


    TASKKILL /F /IM FIREFOX.EXE*

* Replace filename with your default web browser


2.  Delete the worm located at the Startup folder.  Filename is random.exe.


3.  Delete all shortcuts and RECYCLER folder on external drives.



4.  Scan with an updated antivirus.




Note:  DO NOT SCAN while malware is active in memory.
          Do not use Smadav (Very low detection with high False Positive)


To GOD be the glory!


All content ("Information") contained in this report is the copyrighted work of WinXPert: Virus and Malware Removal.

The Information is provided on an "as is" basis. WinXPert disclaims all warranties, whether express or implied, to the maximum extent permitted by law, including the implied warranties that the Information is merchantable, of satisfactory quality, accurate, fit for a particular purpose or need, or non-infringing, unless such implied warranties are legally incapable of exclusion. Further, WinXPert does not warrant or make any representations regarding the use or the results of the use of the Information in terms of their correctness, accuracy, reliability, or otherwise.

Copyright © 2016 WinXPert. All rights reserved. All other trademarks are the sole property of their respective owners.