Malware

Translated from the Spanish original. Read in Spanish

Malicious programs? Malware? Why don’t I simply call this kind of program a virus? Well, the fact is that a virus is really just one particular class within a whole range of programs created for malicious purposes. To give you an idea, here are some of the different types of malware out there.

Viruses

Their goal is to infect other programs in order to run harmful instructions, and they rely on the user doing something.

Worms

Also designed to run harmful instructions, but with the difference that a worm spreads by itself, across a network.

Trojans

What sets this type of program apart is that it hides inside the code of a legitimate program, without infecting other programs.

Spyware

There’s a wide variety here, aimed at stealing information and monitoring the user

Adware

It’s used for advertising

Rogue security software

This kind of threat poses as a cleaning tool or antivirus, but it’s really a trap for the user: a program designed to infect the computer. For more information and details about the different varieties of this threat, see the following link

http://support.kaspersky.com/sp/viruses/rogue

Ransomware

Its goal is to encrypt a user’s important data and then demand payment in exchange for the password that unlocks it.

Today, however, malware is usually a mix of these different categories. Now let’s look at a particular and, at the same time, very common case. Many of you have probably already been infected through a USB stick. Below I’ll show you how the most common form of these programs works and how to prevent and/or manually clean up this malware. The modus operandi in these cases relies on an “Autorun.inf” file containing information about the malicious program that will run automatically when we plug the USB stick into the computer, double-click the drive in “My Computer” and/or browse the drive. One of the many versions, once run, sets the folders on the stick to “hidden” and “system” and, at the same time, creates fake versions of the folders that run the malware again. In many of these cases the user assumes their data has been deleted and gives it up for lost, but it’s still there.

So how do we open an infected USB stick, remove the virus and get to our files?

Based on the case I described above, first we need to disable the system feature that lets Autorun.inf code run automatically. For that, here’s a small file that changes the system settings automatically download . Just accept the prompts that appear when you run the file. Once that’s done, go to “My Computer” >> “Folder Options” >> “View”. There, turn on “Show hidden files and folders” and turn off “Hide protected operating system files” and “Hide extensions for known file types”. Then open the USB stick and delete the “Autorun.inf” file in the root of the device, along with any executable you don’t recognise. Finally, copy this file onto the USB stick and run it download . When it finishes, the folders and data will reappear and you can delete the rest of the files created by the virus (the fake folders).

Technical details of an Autorun.inf that launches a virus from a USB stick

[AutoRun]

;vribRlEcbtljhSjGRN

;WaBqIhbn

ShElL\oPen\command=dwvar.cmd

;ohcNfFVBUMKgSqxYVAcqxdPiox cKeYjvCHQcLcIhmjxwF

sHeLL\OpEn\defAUlT=1

;jqLJ ylGTV

SHELl\expLore\CoMMAnd=dwvar.cmd

;HEUcUcNysUoYbacSsInYxtbArenygqSgyYgtusqnvdrX

opEn = dwvar.cmd

;

shelL\AUtoplAY\coMmAnd=dwvar.cmd

;icnhbKEfNTAVEpVwntiLD

In blue we can see the code intended to confuse antivirus software

In red we can see the code that tells the system to run the malicious file in the situations I described above.

Technical details of the files that change the autorun policy and modify the attributes of the files on a USB stick

Zerogap.reg

Code:

Windows Registry Editor Version 5.00

[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\Explorer]

«NoDriveTypeAutoRun»=dword:000000FF

It sets the value 0xFF in the registry key, which means autorun is disabled on all drives.

Zero.cmd

Code:

@echo off

title=Cambiando atributos @ZeroGap

cls

cd

echo Un segundo, por favor.. el proceso puede demorar dependiendo la cantidad de archivos involucrados.

attrib /s /d -r -a -h -s

exit

It simply changes the attributes from cmd using the attrib command

Maximiliano Díaz Doglia

AI Platform Engineer & Full-Stack Developer
Building Enterprise Integrations & Automations