It’s a recent worm having already infected scores of computers all around the world. It is also called Houdini.
Depending on the antivirus used, it is detected as :
It is spread through USB peripherals such as pendrives, external drives, but also smartphones or digital cameras through their memory cards.
Once the media is connected, for users, the contents appear normal. Here’s a view showing 2 photos and a MP3 audio-file :
But here is what the key really contains (which is “hidden” to users).
On the file on the right, we can notice a small arrow in the bottom left corner of the icon; it means this is a shortcut, and may be a sign of the infection
In 1, we can see the shortcuts (visible to users) and we may think they are real files; but in fact, these shortcuts, once clicked, will launch the infection (2) and then, open the original file (hidden to users).
You feel you have launched the file you wanted, and you won’t be aware the malware has been launched a few milli-seconds before.
YOU ARE CAUGHT!
The file is a VBS (Microsoft Visual Basic script).
This type of script is commonly used by managers
of operating systems and networks, to make small programs aiming at making repetitive tasks automatic.
Without entering technique too much,let’s say the malware is complexly encoded to camouflage itself, and so avoid detection by anti-virus.
it, then, will search for all removable peripherals, and infect them, thus, making new vectors of propagation.
The malware connects to the C&C server, to transmit some information :
The hacker, thus, will be able to take control of the “victim” computer to :
Update the malware (or delete it)
Install other malwares
He may also re-use the code, change it, enrich it
Here is a view of an ad for this type of malware :
Here is a view of a managing console (what the hacker can see on his scren) :
Even if the code is relatively simple, it is enough to corrupt the security of a whole organization, and retrieve personnal or confidential information from a great numberof people.
See this article : https://www.usb-antivirus.com/2014/03/infections-spreading-usb-peripherals/
In particular the passage : “How to avoid this type of infection
We recommend you, either firms, or particulars, to adopt a full antivirus protection like Bitdefender Internet Security.
It offers protection against most viruses and other internet dangers
Light, silent, and quick
It protects your on-line shopping, and make your digital identification safe
It informs you about your children’s activities, and provide filter tools if needed
It integrates a firewall to protect your internet connexion
Connect all your external data sources to your PC (Usb keys, external drives, etc…)
Donation is not compulsory, but is useful to go on developping the software, and meet the expense to maintain our website server.
Once you’ve made a choice, a report will open.
You can find a copy of this report on your desktop, and another at : C:UsbFixLogUsbFix [Clean 1] Your PC.txt
Copy/paste it on the board you’ve asked for help.
If you are not taken care, we invite you to create a subject on the forum of disinfection SosVirus
and to transmit the report for analysis.