Worst Worm…

Ugggg…I just got my first USB stick worm and let me tell you….it SUCKED!!! This worm created or infected autorun.exe on my usb flash drive. Once you insert the USB stick into a PC it drops the files below into the following folders:

C:windowssystem32ftp32.dll

C:windowssystem32driversspools.exe (boy is that little .exe annoying)

C:Documents and Settingsuserctfmon.exe

Once these files are in place ANY exe takes about 5 minutes to execute because spools.exe runs at 100% cpu. If new media is inserted into the pc (like another flash drive) it will immediately become infected.

The PC I was working on had Avast 4.8. Avast 4.8 cleaned ctfmon constantly, but left spools.exe and ftp32.dll intact. I turned to my favorite…Spyware Doctor with AntiVirus to clean the entire infection (and my $30 usb stick which I just bought).

I suppose you could also clean this infection with a bootable antivirus disc, but I was too lazy :P

Be careful when sticking those USB flash drives into PC’s with inadequate anti-malware protection…you could get a nasty surprise.



, , , , , , , ,

  • Chris

    That’s why I *always* either hold down the SHIFT key or disable auto-run when inserting a USB drive.

  • malwarekilla

    Wow, I feel pretty stupid now…I had no idea that works! Thanks Chris!

  • David

    What happens when you download antivirus and spyware removal tools in safe-mode and they won’t load (also in safe-mode)? Lots of solutions on how to get rid of this pesky bug, but none seem to work with my machine. Any other suggestions? Thanks!

  • malwarekilla

    -Spyware Doctor with Antivirus runs in safe mode
    -malwarebytes runs in safe mode
    -superantispyware runs in safe mode

    if those still don’t work in safe mode then make a bootable cd and run antivirus from there

  • LinuxBox

    Here’s a handy tip. Get a write protect-able thumb drive. With the physical switch on the side. I couldn’t find one anywhere so this is what I did:

    Get an SD card. They all have the “lock” switch on the side.

    Next get a SD to USB converter.

    Done, now my stick never gets infected anymore. When I want to update the apps, I just flick the switch and copy like normal.

    • malwarekilla

      @LinuxBox – awesome tip man, thanks!


Remove-Malware Traffic Stats