Solved

Double clicking a mapped drive in Windows Explorer launches "information.vbs" script worm identified as VBS.Runauto

Posted on 2008-10-29
6
845 Views
Last Modified: 2013-12-09
One user running Windows XP SP3 with Symantec Antivirus Corporate Edition reported numerous detections and quarantines of the worm virus identified as VBS.Runauto.  I have scanned all workstations and server drives and removed multiple instances.

The user who has local admin priviliges on the PC, when double clicking a mapped network drive, would get no response, then seconds later Symantec would report VBS.Runauto.  The offending file is "information.vbs" and was then detected in the users home directory and on the local PC.

I then changed the users PC priviliges to "User" and this appears to prevent the propogation of the worm.

When the user now double clicks the mapped network drive a pop up appears called "Windows Script Host" and reports "Cannot find script file C:\windows.....etc\information.vbs"

What is causing this mapped drive to be hijacked? and how do I stop it?

Ed
0
Comment
Question by:Ed_B
  • 3
  • 3
6 Comments
 
LVL 1

Expert Comment

by:Blademonkey
ID: 22837425
i found this on da googletubes:

"Description:
VBS.Runauto is a malicious Visual Basic script that spread by copying itself in the root folder of compromised computer and removable media.
 
Technical Name: W32/VBS.RunAuto
 
Threat Level: Low
 
Type: Worm
 
Systems Affected: Windows All


VBS.Runauto removal procedure requires technical know-how on  computer troubleshooting. It is better to consult your LAN Administrator or Technical Persons to avoid additional damage on your computer if modifications on Services and Registry have to be done.
 
HOW TO REMOVE VBS.Runauto :
1. Temporarily Disable System Restore (Windows Me/XP). [how to]
2. Update the virus definitions.
3. Reboot computer in SafeMode [how to]
4. Run a full system scan and clean/delete all infected files
5. Delete any values added to the registry. [how to edit registry]
Navigate to and delete the following entries:
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\RunOnce\"autorun" = "autorun.exe"

Navigate to and restore registry entries to their original values, if necessary:
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon
\"Userinit" = "userinit.exe,autorun.bat"
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Advanced
\"ShowSuperHidden" = "0"
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Advanced
\"Hidden" = "2"
 
6. Exit registry editor and restart the computer.
7. In order to make sure that the threat is completely eliminated from your computer, carry out a full scan of your computer using AntiVirus and Antispyware Software. Another way to delete the virus using various Antivirus Program without the need to install can be done with Online Virus Scanner."

Source: http://www.precisesecurity.com/computer-virus/vbsra-mar0713.htm

I cut and pasted the text because there's alot of ads.  follow the steps and see if that helps.
0
 

Author Comment

by:Ed_B
ID: 22837507
Thanks for that. I had seen the worm description on the Symantec web however the registry entries aren't appearing as described.

My question relates to the hijacking of the mapped drive icons in windows explorer, which attempt to  launch a .vbs file.

Ed
0
 
LVL 1

Accepted Solution

by:
Blademonkey earned 500 total points
ID: 22837537
perhaps there's an autorun.inf or autorun.ini on that mapped drive/volume.  it may be hidden (by attribute or by windows explorer hidding system files).
0
Highfive Gives IT Their Time Back

Highfive is so simple that setting up every meeting room takes just minutes and every employee will be able to start or join a call from any room with ease. Never be called into a meeting just to get it started again. This is how video conferencing should work!

 
LVL 1

Expert Comment

by:Blademonkey
ID: 22837555
more specifically i think your "nodrivetypeautorun" setting is set to recognize autorun files on mapped network shares.

this is how this was enabled.  I hope this answers your question

http://articles.techrepublic.com.com/5100-22_11-5108199.html

0
 

Author Comment

by:Ed_B
ID: 22837814
Further examination has found that some shared drives have two files called information.vbs and autorun.inf

Autorun.inf contents shown below:

forgiveme
[autorun]
open=wscript.exe information.vbs
shell\open\Command=wscript.exe information.vbs
shell\find\Command=wscript.exe information.vbs
shell\open\default=1

Our virus scanner will detect and quarantine the files, however they keep reappearing.
How do I stop this?
0
 

Author Closing Comment

by:Ed_B
ID: 31511502
Thanks Blademonkey,  The autorun.inf file was the start of the problem. After investigating this further I now understand what was happening.
Many thanks,
Ed
0

Featured Post

What Is Threat Intelligence?

Threat intelligence is often discussed, but rarely understood. Starting with a precise definition, along with clear business goals, is essential.

Join & Write a Comment

The month of August was another action packed month for hackers and a security nightmare for many retailers and restaurant establishments. Some of the more notable data breach victims this past month included supermarket giants SUPERVALU and Alberts…
In every aspect, security is essential for your business, and for that matter you need to always keep an eye on it. The same can be said about your computer network system too. Your computer network is prone to various malware and security threats t…
Access reports are powerful and flexible. Learn how to create a query and then a grouped report using the wizard. Modify the report design after the wizard is done to make it look better. There will be another video to explain how to put the final p…
This demo shows you how to set up the containerized NetScaler CPX with NetScaler Management and Analytics System in a non-routable Mesos/Marathon environment for use with Micro-Services applications.

708 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question

Need Help in Real-Time?

Connect with top rated Experts

13 Experts available now in Live!

Get 1:1 Help Now