Win32:Mutama, VBS:Malware-Gen, Win32:VB-UBR, new folders autogenerate

Running Win7 x64, Dell XPS i7@ 2GHz, 6GB RAM

I am in the process of consolidating all my files onto one external hard drive. During the transfer process, Avast found multiple sources of Win32:Mutama, VBS:Malware-Gen, Win32:VB-UBR, and a few autorun-gen@bhv. All instances were found and alerted ONLY during the transfer of files from one drive to another using a file sync program (Superflexible). Direct scans of any and all drives using Avast and MBAM are always negative for any malware (MBAM found one PDFcreator adware in Temp file). Scans of flash drives and external drives are negative.

Whenever I plug in a camera, flash drive, or external drive, a new folder autogenerates in the DCIM folder (or other) on the external drive. The folder is named after an old folder I created called “My Docs_DellD Backup”. The folder is empty and cannot be deleted as error messages report the file is under use. Even after I format the camera internal memory or drive, the “My Docs_DellD Backup” folder recreates immediately after I plug it in my computer USB port. All direct scans of the folder are negative.

This problem began after accessing files dumped from an external flash drive and transferring those files between other external drives. My computer is also running a bit sluggish, esp boot up.

Any help is greatly appreciated.

Logs attached:

Thanks in advance.
Don

Could you give me the full path of that folder and I will then use OTL to delete it

i.e. D:\dcim

It depends on the drive. I cannot find that folder on my C:\ drive anywhere. It appears on my flash drive, for example, at E:\My Docs_DellD Backup.

So it is actually on the flash drive as opposed to your hard drive

Well, I’m not sure.

It appears on every drive I plug into my computer USB. For example, if I format the drive on my Sony Camcorder, then connect it to the computer via usb, the “My Docs-DellD Backup” autocreates immediately. If I check the properties of that folder, it was created exactly when I first plugged it into the computer after the format. However, it remains on the drive after I unplug it. This happens no matter what kind of drive I plug in: flash, camera, SD, external hard drive, etc.

Therefore, I think the issue is on my computer,

I assume you have a dell system ?

Lets remove the mountpoints and see if that cures it, although I am not optimistic… I will also have a rummage around the dell site

Warning This fix is only relevant for this system and no other, using on another computer may cause problems

Be advised that when the fix commences it will shut down all running processes and you may lose the desktop and icons, they will return on reboot

Run OTL

[*]Under the Custom Scans/Fixes box at the bottom, paste in the following

https://dl.dropbox.com/u/73555776/OTL_Fix.GIF

:OTL O33 - MountPoints2\{f4411c83-f03a-11e0-9224-ac7289499f98}\Shell - "" = AutoRun O33 - MountPoints2\{f4411c83-f03a-11e0-9224-ac7289499f98}\Shell\AutoRun\command - "" = "F:\WD SmartWare.exe" autoplay=true

:Files
ipconfig /flushdns /c

:Commands
[purity]
[resethosts]
[emptytemp]
[CREATERESTOREPOINT]
[Reboot]


[*]Then click the Run Fix button at the top
[*]Let the program run unhindered, reboot the PC when it is done
[*]Open OTL again and click the Quick Scan button. Post the log it produces in your next reply.

Ok, Thanks. Yes, Dell XPS.

Q. Since you are accessing Drive F:\ which is an external drive, should I have this plugged in via usb when I run it?

Don

No it is just removing that directive from the registry

So when you insert the drive it will have no commands waiting

Scan Logs, as requested.

Could you check to see if that has cured it… Still rummaging around dell

It doesn’t appear on F:\ but does on other media and still can’t be deleted. I over a TB of data on that drive, but a search for the folder was negative.

Are these camera SD cards or USB sticks or both

2 USB sticks, A few SD cards, the camcorder which has an internal 64GB SS drive, and 2 other portable hard drives all have the unremovable folder.

OK bear with me and I will do some more digging

Of course. I appreciate the help.

As an interim measure you could run Panda Vaccinate on all cards and sticks … This will place a blocker on the autorun functions after removing any bad ones

http://www.pandasecurity.com/homeusers/downloads/usbvaccine/

Tried that. Doesn’t seem to work. I’ve narrowed down 2 folders (both empty) on my laptop C:/ drive that also cannot be deleted, possibly where the suspect program is located. Now all drives have the undeletable folders.

Could you give me the full paths of the Folders and I will use Avenger to delete them before windows loads

C:\Users\Deft\Documents\DellD FIles to Backup
E:\My Docs_ DellD Backup
F:\My Docs_ DellD Backup

etc…on every drive.

You will need to have the drives plugged in for the duration of this run

  1. Please download The Avenger by Swandog46 to your Desktop.

[*]Right click on the Avenger.zip folder and select “Extract All…”
[*] Follow the prompts and extract the avenger folder to your desktop

  1. Copy all the text contained in the code box below to your Clipboard by highlighting it and pressing (Ctrl+C):
Begin copying here:
Folders to delete:
C:\Users\Deft\Documents\DellD FIles to Backup
E:\My Docs_ DellD Backup
F:\My Docs_ DellD Backup

Note: the above code was created specifically for this user. If you are not this user, do NOT follow these directions as they could damage the workings of your system.

  1. Now, open the avenger folder and start The Avenger program by clicking on its icon.

https://dl.dropbox.com/u/73555776/Avenger%20icon.GIF

[*]Accept the disclaimer

https://dl.dropbox.com/u/73555776/Avenger%20disclaim.GIF

[*] Right click on the window under Input script here:, and select Paste.

https://dl.dropbox.com/u/73555776/Avenger%20run.GIF

[*] You can also click on this window and press (Ctrl+V) to paste the contents of the clipboard.
[*] Click on Execute

[*] Answer “Yes” twice when prompted.

  1. The Avenger will automatically do the following:

[*]It will Restart your computer. ( In cases where the code to execute contains “Drivers to Delete”, The Avenger will actually restart your system twice.)
[*]On reboot, it will briefly open a black command window on your desktop, this is normal.
[*]After the restart, it creates a log file that should open with the results of Avenger’s actions. This log file will be located at C:\avenger.txt
[*] The Avenger will also have backed up all the files, etc., that you asked it to delete, and will have zipped them and moved the zip archives to C:\avenger\backup.zip.

  1. Please copy/paste the content of c:\avenger.txt into your reply.