PDA

View Full Version : What is 999.vbs on a flash drive?


silverpaws006
08-27-2010, 04:18 PM
Okay umm, I need a little help.

There are two odd files in my flash drive.
Autorun.inf and 999.vbs

These two files seem to overwrite themselves continuously after a couple of seconds, because I can't delete them nor create my custom autorun.inf

I've attached the contents of both files as plain text here.
ESET and Malwarebytes don't detect it as a virus, but I'm suspicious of what it does. Please help, thanks in advance~

Spookster
08-27-2010, 06:29 PM
Okay umm, I need a little help.

There are two odd files in my flash drive.
Autorun.inf and 999.vbs

These two files seem to overwrite themselves continuously after a couple of seconds, because I can't delete them nor create my custom autorun.inf

I've attached the contents of both files as plain text here.
ESET and Malwarebytes don't detect it as a virus, but I'm suspicious of what it does. Please help, thanks in advance~


I would get rid of it or get a better antivirus/antimalmare software.

-- File: Autorun.inf.txt, malicious code name: Mal_Otorun2

effpeetee
08-27-2010, 06:58 PM
MS Security essentials found 199 VBS and alerted me even from the text file. Be careful!

Frank

Fou-Lu
08-27-2010, 07:19 PM
As spooks and frank mentioned, these are setting off all sorts of bells and whistles, so I have removed these from your post.
I'd boot your machine up in safe mode to do a full viral scan and anti-malware check. See if doing it in safe mode removes these from your machine (you mentioned that malwarebytes doesn't see a problem, though I find that malwarebytes in general is pretty good at spotting these).

silverpaws006
08-28-2010, 12:42 PM
Thanks everyone, I wasn't able to figure out heads or tails about that, but I did manage to figure out how to take it off.

First I made and ran this batch file (WinXP) silencing wscript.exe and cscript.exe and replacing them with notepad:


taskkill /F /IM wscript.exe
taskkill /F /IM cscript.exe

copy "c:\windows\system32\wscript.exe" "c:\windows\system32\wscript.txt"
copy "c:\windows\system32\cscript.exe" "c:\windows\system32\cscript.txt"
copy "c:\windows\system32\notepad.exe" "c:\windows\system32\wscript.exe"
copy "c:\windows\system32\notepad.exe" "c:\windows\system32\cscript.exe"


Now when I open my flash drive the code opens in notepad lol.

So I formatted my USB and it's fine now.
But idk what're the things it did to my registry O_o

oracleguy
08-28-2010, 06:34 PM
You might want to run a scan using better AV software on any machines you have plugged that drive into.

Fou-Lu
08-28-2010, 06:59 PM
Thats the problem yes. If you logon to your PC as a privileged user, who knows what kind of changes it has made (my user account is only a User, I elevate as necessary).
If the virus and malware still picks up nothing on your machine, I'd look at using hijackthis to make sure its not trying to execute something at boot. The application is not designed to find virus' or anything like that, but it sure is handy to see what is trying to run.

hitek
09-14-2010, 08:18 AM
There is not any attachment file. Please review your post again.

VIPStephan
09-14-2010, 08:54 AM
Read the other posts. Fou-Lu has removed the files for security reasons.

Tony M
09-21-2010, 12:38 AM
ESET and Malwarebytes don't detect it as a virus, but I'm suspicious of what it does.
I think You must always update Your AV programs and format the flash drive with suspicious files...:thumbsup: