Windows 7 Forums
Welcome to Windows 7 Forums. Our forum is dedicated to helping you find support and solutions for any problems regarding your Windows 7 PC be it Dell, HP, Acer, Asus or a custom build. We also provide an extensive Windows 7 tutorial section that covers a wide range of tips and tricks.


Windows 7: Trojan-Downloader.Win32.VB.bbl


30 Sep 2009   #1

Windows 7 build 7600 64 bit
 
 
Trojan-Downloader.Win32.VB.bbl

I found this awesome virus "Trojan-Downloader.Win32.VB.bbl" and analyzed its behaviour in a VirtualBox and quickly found a weaknes
It is very hard to remove, it closes antivirus setups and then deletes them, closes all windows containg anything about antivirus tools (even if you google anything about it, it closes your browser)... AND it starts up in safemode too!
This post is only to ask for your opinion, a little bat file i created to remove it (and it works!).

Code:
@echo off
setlocal enabledelayedexpansion
set counter=1
cd %windir%\system32
if not exist "%windir%\system32\wins.exe" goto nothing:
:y
:yes

goto start
:counter

set /a counter=!counter!+1

:start
cls
echo Try %counter%
echo Killing processes...
start /MIN cmd.exe /c taskkill /im wins.exe /f
echo STOP!! please wait 5 seconds atleast before pressing any key && pause
taskkill /im lechuck.exe /f /t

echo Deleting files...
start /MIN cmd.exe /c del %windir%\system32\wins.exe /f /a
start /MIN cmd.exe /c del %windir%\system32\lechuck.exe /f /a
start /MIN cmd.exe /c del %windir%\system32\lechuck.hta /f /a
start /MIN cmd.exe /c del %windir%\system32\cmd.com /f /a
start /MIN cmd.exe /c del %windir%\regedit.com /f /a
start /MIN cmd.exe /c del %windir%\spolis.exe /f /a
start /MIN cmd.exe /c del %systemdrive%\p2p.exe /f /a
start /MIN cmd.exe /c del %systemdrive%\autorun.inf /a /f 

echo Fixing registry...
start /MIN cmd.exe /c reg add HKCR\exefile\shell\open\command /ve /t REG_SZ /d """"%%1""" %%*" /f
start /MIN cmd.exe /c reg add HKEY_CLASSES_ROOT\exefile\shell\open\command /ve /t REG_SZ /d """"%%1""" %%*" /f
start /MIN cmd.exe /c reg add HKEY_CLASSES_ROOT\batfile\shell\open\command /ve /t REG_SZ /d """"%%1""" %%*" /f
start /MIN cmd.exe /c reg add HKEY_CLASSES_ROOT\comfile\shell\open\command /ve /t REG_SZ /d """"%%1""" %%*" /f
start /MIN cmd.exe /c reg add HKEY_CLASSES_ROOT\cmdfile\shell\open\command /ve /t REG_SZ /d """"%%1""" %%*" /f
start /MIN cmd.exe /c reg add HKEY_CLASSES_ROOT\piffile\shell\open\command /ve /t REG_SZ /d """"%%1""" %%*" /f
start /MIN cmd.exe /c reg delete HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2 /f

echo Enabling Task Manager and Regedit again...
start /MIN cmd.exe /c Reg delete HKCU\Software\Microsoft\Windows\CurrentVersion\Policies\System /v DisableRegistryTools /f
start /MIN cmd.exe /c Reg Delete HKCU\Software\Microsoft\Windows\CurrentVersion\Policies\System /v DisableTaskMgr /f
start /MIN cmd.exe /c Reg Delete HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\system /v DisableTaskMgr /f

if %counter%==5 goto fail
if exist %windir%\system32\wins.exe goto counter
if not exist %windir%\system32\wins.exe goto done

:done
echo Done!
pause
exit

:nothing
echo You are not infected by LeChucK.exe
set /p choice=Would you like to clean the system anyways (Y/N)?
goto %choice%

:fail
echo Failed to remove LeChucK.exe 5 times, contact tech support :[
pause

:n
:no
exit
Edit:
I have the virus if anyone is interested in testing, but im not sure how...upload it or sumthing?

My System SpecsSystem Spec
.

30 Sep 2009   #2

Windows XP
 
 

upload it in an encrypted archive in an encrypted archive in an encrypted archive that each have different 31 character hex-decimal passwords that you provide

that should provide the rest of us enough protection
btw, what malicious activities does this virus conduct?
My System SpecsSystem Spec
01 Oct 2009   #3

Windows 7 build 7600 64 bit
 
 

Its supposed to download more malware! but i havent seen any of that yet...
My System SpecsSystem Spec
.


01 Oct 2009   #4

Windows XP
 
 

can you upload it? I'm interested in testing
My System SpecsSystem Spec
01 Oct 2009   #5

Windows 7 Ultimate x64 SP1
 
 

warning   Warning
No uploading or posting any malicious content on this site, period. And don't ask for it to be uploaded either. Failure to listen to this warning will result in a ban.
My System SpecsSystem Spec
Reply

 Trojan-Downloader.Win32.VB.bbl




Thread Tools



Similar help and support threads for2: Trojan-Downloader.Win32.VB.bbl
Thread Forum
ESET reports trojan in Orbit Downloader Security News
Trojan.Win32.Jorik.Midhos.axf System Security
Trojan:Win32/FakeSysdef System Security
Solved Trojan:Win32/Comroki!rts System Security
Hiloti Trojan downloader infection rates triple in UK Security News
Win32/Lethic is a trojan Security News
trojan downloader:win32/cutwail.ba HELP! System Security

Our Sites

Site Links

About Us

Find Us

Windows 7 Forums is an independent web site and has not been authorized, sponsored, or otherwise approved by Microsoft Corporation. "Windows 7" and related materials are trademarks of Microsoft Corp.

Designer Media Ltd

All times are GMT -5. The time now is 07:02 PM.
Twitter Facebook Google+



Windows 7 Forums

Seven Forums Android App Seven Forums IOS App
  

1 2 3 4 5 6 7 8 9 10 11 12 13 14 15 16 17 18 19 20 21 22 23 24 25 26 27 28 29 30 31 32 33