possible wscript on my computer (XP professional)

Hi there.I believe i have a certain virus that has been found on one of my usb devices . it is known for the appearance of the
wscript.exe window…

what should i do?

thanks in advance

Hi,

Until we check the system, please refrain from using USB

Please download Farbar Recovery Scan Tool by Farbar and save it to your desktop.

Note: You need to run the version compatibale with your system. If you are not sure which version applies to your system download both of them and try to run them.
Only one of them will run on your system, that will be the right version.

[*]Double-click to run it. When the tool opens click Yes to disclaimer.
[*]Under Optional Scan ensure “List BCD” and “Driver MD5” are ticked.
[*]Press Scan button.
[*]It will make a log (FRST.txt) in the same directory the tool is run. Please attach it to your reply.
[*]The first time the tool is run, it makes also another log (Addition.txt). Please attach it to your reply.

===========================================================

Please download aswMBR and save it to your desktop.

Double click aswMBR.exe to start the tool.

[*]Select Yes if prompted to download the Avast database.
[*]Click Scan
[*]Upon completion of the scan ( Scan finished successfully ) click Save log and save it to your desktop, and post that log in your next reply for review.
Note: do NOT attempt any Fix yet.

Here are logs. Thanks.

P.S. Mozemo i na srpskom :stuck_out_tongue:

1. Open notepad and copy/paste the text present inside the code box below.
To do this highlight the contents of the box and right click on it. Paste this into the open notepad.
NOTICE: This script was written specifically for this user, for use on that particular machine. Running this on another machine may cause damage to the operating system

Unlock: C:\Documents and Settings\User\Local Settings\Temp
HKLM\...\Run: [WinUsbDriver] - C:\Documents and Settings\User\Local Settings\Temp\WinUsbDriver.vbs [172340 2013-08-27] () <===== ATTENTION
C:\Documents and Settings\User\Local Settings\Temp\WinUsbDriver.vbs
HKCU\...\Run: [WinUsbDriver] - C:\Documents and Settings\User\Local Settings\Temp\WinUsbDriver.vbs [172340 2013-08-27] () <===== ATTENTION
SearchScopes: HKCU - {F4D03DC4-C794-4F89-A0DD-BB8100271228} URL = http://search.conduit.com/ResultsExt.aspx?q={searchTerms}&SearchSource=4&ctid=CT3289075&CUI=UN33766614151156620&UM=1
cmd: ipconfig /flushdns

2. Save notepad as fixlist.txt to your Desktop.
NOTE: => It’s important that both files, FRST and fixlist.txt are in the same location or the fix will not work.

3. Run FRST/FRST64 and press the Fix button just once and wait.
If the tool needed a restart please make sure you let the system to restart normally and let the tool completes its run after restart.

The tool will make a log on the Desktop (Fixlog.txt). Please attach it to your reply.
Note: If the tool warned you about the outdated version please download and run the updated version.

Then…

Re-run FRST, press Scan, and attach fresh report.

E, super sto mozemo na srpskom :slight_smile:
Prikacila sam fixlog i frst. Cekam dalja uputstva. Puno hvala!

Nismo uspeli da obrisemo crva, ako si koristila USB ponovo, izvadi ih i ne koristi dok ne zavrsimo.

Da probamo sa drugim alatom:

  1. Please download ComboFix by sUBs from here and save it to your Desktop.
    If you are unsure how ComboFix works please read this guide carefully.
    note: ComboFix must be downloaded to your Desktop.

  1. Temporarily disable your AntiVirus program, usually via a right click on the System Tray icon. They may interfere with Combofix.
    If you are unsure how to do this please read this or this Instruction.

Instructions how to disable avast:

[*]Right click on the avast! system tray icon (
http://www.mcshield.net/pg/images/avast5.png
) in the lower right corner of the screen and scroll up to avast! shield controls;
[*]In the menu that appears, choose Disable Permanently. When you are prompted to turn off security, click Yes.

Note: Do not forget to turn back on this option after the cleaning by choosing avast! shield controls > Enable all shield options.


  1. Run ComboFix. Click on I Agree!

ComboFix will check if there is a newer version of ComboFix available.
Click Yes if prompted to download.
ComboFix will display DISCLAIMER OF WARRANTY ON SOFTWARE.
Click Yes to allow ComboFix to continue.
If Recovery Console is not installed, ComboFix will offer download & installation.
Click Yes to allow ComboFix to install Recovery Console.
Note:Do not mouse-click Combofix’s window while it is running.
If you see a message like “Illegal operation attempted on a registry key that has been marked for deletion” just restart computer once more.


  1. When the tool is finished, it will produce a log report for you. (typical location: C:[b]ComboFix.txt[/b] )
    Attach log reports ( ComboFix.txt) back to topic.

Evo gotov je ComboFix log

Racunar je cist, jos da proverimo USB…

Posto si vec koristila MCShield, sad prikljuci jedan po jedan USB…

Nakon toga mi je potreban izvestaj

Start → All Programs → MCShield → Logs

Pa prikaci AllScans.txt

Pa jeste, prvo sam malo brljala - pokusavala da resim stvar sama :-[, a onda sam se predala i obratila za pomoc…
Nadam se da nisam napravila dodatne probleme?

U prilogu je poslednji log - to je mp3 plejer (za eksterni hard i fles je prijavio da su cisti)

Veoma sam zahvalna na pomoci!

Izvinjavam se, greskom sam prilozila pogresan fajl. Evo sada prilazem allscans.txt
Sve najbolje i jedno veliko hvala!

U redu, racunar je cist. Kazi mi kakvo je stanje?

Jos jedna stvar koju je potrebno da uradis:

Na tastaturi pritisni zajedno Windows taster (izmedju Ctrl i Alt) + R, a zatim kopiraj sledece i klikni OK.

%ALLUSERSPROFILE%\MCShield

Unutar foldera se nalazi folder Quarantine. Desni klik na taj folder, pa Send ToCompressed (zipped) folder. Unutar foldera ce se onda pojaviti arhiva. Kopiraj je na Desktop.

Potrebno je da je posaljes preko ovo linka:

http://www.mycity.rs/upload.php

Izaberes fajl sa Desktop-a i kliknes okaci.

Koliko sam stigla da isprobam, cini se da sve funkcionise dobro.
Ali imam mali problem sa poslednjom instrukcijom - prilozila sam print screen.
Probala sam da potrazim Quarantine preko Start - Search ali ni tako ga nema (prilazem i taj print screen).

Try at

%appdata%\MCShield

Isto

A da probas samo %allusersprofile% ili %appdata% ili %programdata% , pa pogledaj ima li MCShield folder i u okbiru njega Quarantine

Nigde ga nema… Sem kao na prilozenoj slici

Probacemo sutra kada cu ti dati i uputstvo za ciscenje koriscenih alata kada cemo i zavrsiti. Sada je kasno…

Vazi, “vidimo” se sutra :slight_smile:

Nema potrebe za ovim korakom sto smo pokusali pa nece, samo jos da ocistimo alate. Takodje imaj MCShield uvek instaliran ukoliko koristis USB Flash, sacuvace te ubuduce od ovakvih virusa.

Please download DelFix by “Xplode” to your Desktop.

Run the tool and check the following boxes below;

[] Remove disinfection tools
[
] Create registry backup
[*] Purge System Restore

Now click on “Run” button. Wait for the programme completes his work.
All the tools we used should be gone.
Tool will create and open an log report (DelFix.txt)
Note: The report will also be stored on C:\DelFix.txt

I don’t need DelFix log report.

Ovo je bilo lako! Steta sto nisam ranije znala za MCShield… Hvala na savetima i pomoci. Pozdrav :slight_smile: