Trojan-Downloader.Win32.VB.bbl

Hakon

New member
Local time
8:25 PM
Messages
72
I found this awesome virus "Trojan-Downloader.Win32.VB.bbl" and analyzed its behaviour in a VirtualBox and quickly found a weaknes :p
It is very hard to remove, it closes antivirus setups and then deletes them, closes all windows containg anything about antivirus tools (even if you google anything about it, it closes your browser)... AND it starts up in safemode too!
This post is only to ask for your opinion, a little bat file i created to remove it (and it works!).

Code:
@echo off
setlocal enabledelayedexpansion
set counter=1
cd %windir%\system32
if not exist "%windir%\system32\wins.exe" goto nothing:
:y
:yes

goto start
:counter

set /a counter=!counter!+1

:start
cls
echo Try %counter%
echo Killing processes...
start /MIN cmd.exe /c taskkill /im wins.exe /f
echo STOP!! please wait 5 seconds atleast before pressing any key && pause
taskkill /im lechuck.exe /f /t

echo Deleting files...
start /MIN cmd.exe /c del %windir%\system32\wins.exe /f /a
start /MIN cmd.exe /c del %windir%\system32\lechuck.exe /f /a
start /MIN cmd.exe /c del %windir%\system32\lechuck.hta /f /a
start /MIN cmd.exe /c del %windir%\system32\cmd.com /f /a
start /MIN cmd.exe /c del %windir%\regedit.com /f /a
start /MIN cmd.exe /c del %windir%\spolis.exe /f /a
start /MIN cmd.exe /c del %systemdrive%\p2p.exe /f /a
start /MIN cmd.exe /c del %systemdrive%\autorun.inf /a /f 

echo Fixing registry...
start /MIN cmd.exe /c reg add HKCR\exefile\shell\open\command /ve /t REG_SZ /d """"%%1""" %%*" /f
start /MIN cmd.exe /c reg add HKEY_CLASSES_ROOT\exefile\shell\open\command /ve /t REG_SZ /d """"%%1""" %%*" /f
start /MIN cmd.exe /c reg add HKEY_CLASSES_ROOT\batfile\shell\open\command /ve /t REG_SZ /d """"%%1""" %%*" /f
start /MIN cmd.exe /c reg add HKEY_CLASSES_ROOT\comfile\shell\open\command /ve /t REG_SZ /d """"%%1""" %%*" /f
start /MIN cmd.exe /c reg add HKEY_CLASSES_ROOT\cmdfile\shell\open\command /ve /t REG_SZ /d """"%%1""" %%*" /f
start /MIN cmd.exe /c reg add HKEY_CLASSES_ROOT\piffile\shell\open\command /ve /t REG_SZ /d """"%%1""" %%*" /f
start /MIN cmd.exe /c reg delete HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2 /f

echo Enabling Task Manager and Regedit again...
start /MIN cmd.exe /c Reg delete HKCU\Software\Microsoft\Windows\CurrentVersion\Policies\System /v DisableRegistryTools /f
start /MIN cmd.exe /c Reg Delete HKCU\Software\Microsoft\Windows\CurrentVersion\Policies\System /v DisableTaskMgr /f
start /MIN cmd.exe /c Reg Delete HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\system /v DisableTaskMgr /f

if %counter%==5 goto fail
if exist %windir%\system32\wins.exe goto counter
if not exist %windir%\system32\wins.exe goto done

:done
echo Done!
pause
exit

:nothing
echo You are not infected by LeChucK.exe
set /p choice=Would you like to clean the system anyways (Y/N)?
goto %choice%

:fail
echo Failed to remove LeChucK.exe 5 times, contact tech support :[
pause

:n
:no
exit

Edit:
I have the virus if anyone is interested in testing, but im not sure how...upload it or sumthing?
 
Last edited:

My Computer My Computer

Computer Manufacturer/Model Number
Custom
OS
Windows 7 build 7600 64 bit
CPU
Phenom II X4 955 retail 3.2GHz
Motherboard
ASRock M3A790GXH/USB3 ATX AMD AMD3
Memory
4x GeiL 2GB Value PC3-10660 CL9 DC DDR3-1333, CL 9-9-9-28
Graphics Card(s)
PowerColor Radeon HD5850 PCS+ 1024MB, 256-bit GDDR5
Sound Card
Built in
Hard Drives
G.Skill Phoenix Pro 120GB SATA2 SSD Sandforce SF-120
Samsung Spinpoint 500GB SATA2 7200RPM
PSU
Tacens Radix III Smart 520W
upload it in an encrypted archive in an encrypted archive in an encrypted archive that each have different 31 character hex-decimal passwords that you provide

that should provide the rest of us enough protection
btw, what malicious activities does this virus conduct?
 

My Computer My Computer

OS
Windows XP
Its supposed to download more malware! but i havent seen any of that yet...
 

My Computer My Computer

Computer Manufacturer/Model Number
Custom
OS
Windows 7 build 7600 64 bit
CPU
Phenom II X4 955 retail 3.2GHz
Motherboard
ASRock M3A790GXH/USB3 ATX AMD AMD3
Memory
4x GeiL 2GB Value PC3-10660 CL9 DC DDR3-1333, CL 9-9-9-28
Graphics Card(s)
PowerColor Radeon HD5850 PCS+ 1024MB, 256-bit GDDR5
Sound Card
Built in
Hard Drives
G.Skill Phoenix Pro 120GB SATA2 SSD Sandforce SF-120
Samsung Spinpoint 500GB SATA2 7200RPM
PSU
Tacens Radix III Smart 520W
can you upload it? I'm interested in testing
 

My Computer My Computer

OS
Windows XP
   Warning
No uploading or posting any malicious content on this site, period. And don't ask for it to be uploaded either. Failure to listen to this warning will result in a ban.
 

My Computer My Computer

Computer type
PC/Desktop
Computer Manufacturer/Model Number
Airbot 2.0
OS
Windows 7 Ultimate x64 SP1
CPU
Core i7 920 (D0) @ 4Ghz, *26c idle *65c full load on air
Motherboard
Asus P6X58D Premium - Sata 6Gb/s - USB 3.0
Memory
12GB DDR3 Corsair Dominator -CMD12GX3M6A1600C8 at 1600MHz
Graphics Card(s)
Zotac Geforce GTX 770
Sound Card
ASUS Xonar D2X
Monitor(s) Displays
1 LG 24" Flatron W2453V-PF 1 Samsung 24" P2450H both 2ms RT
Screen Resolution
1920x1080@60hz
Hard Drives
1 Samsung 250GB 840 Evo SSD
1 OCZ Vertex2 180GB SSD
1 TB Samsung Spinpoint F1 7200RPM 32MB cache
2 500GB WD Caviar Blacks 7200RPM 32MB cache (WD5001AALS)

Pioneer DVD Burner DVR-S18M
PSU
Corsair HX1000W
Case
Cooler Master HAF 932
Cooling
Case Fans *3 230mm, *1 140mm/CPU - *Tuniq Tower 120 Extreme
Keyboard
Logitech Wireless MK700
Mouse
Logitech Wireless MK700
Internet Speed
DL 15 Mbps UL 0.98 Mbps
Antivirus
None
Browser
Firefox Nightly
Other Info
Processor-7.7 *RAM- 7.9 *Graphics-7.9 *Gaming Graphics- 7.9 *SSD- 7.8 W.E.I final score= 7.7
*Phone- LG Nexus 5
Back
Top