Skype Logo
Buy Skype Credit · Help ·
  • Download
  • Use Skype
  • Business
  • Shop
  • Account
  • Home
  • Get Connected
  • Features
  • Mobile
  • Prices
  • Share
  • All

Skype Community

  • Skype Community
  • English
  • Windows


dsc027.scr virus explained -- including removal instructions

I was infected too (sigh), so I took a few hours to research the virus

Eyal
Regular member
Posts: 14

**


Disclaimer: I have cleaned up my own computer from the virus, and wrote down the instructions. I have not re-infected my computer in order to test these instructions are completely accurate, so it may be inaccurate in some way. Please write some feedback about whether it worked for you, and these instructions can be updated.

How to identify an infected computed:

1. Open the task manager (Ctrl+Shift+Escape should work, or Start->Run->taskman)
2. Look for wndrivsd32.exe: If it is running/in the list, you are infected.

How to fix/clean an infected computer:

1. Open the task manager (Ctrl+Shift+Escape should work, or Start->Run->taskman)

Inside Task Manager:
1.a. Select explorer.exe and use "End Task" (this will make the panel
and perhaps other things disappear)

1.b. Select wndrivsd32.exe and use "End Task" (this will kill the virus process)

1.c. Use File->New Task, and run "explorer" (this will restore things to normal).


2. Run regedit.exe (Note: If regedit dies/disappears after a few seconds, it means that you
haven't killed wndrivsd32.exe or explorer properly - repeat step 1, faster :-)

Inside the registry editor:
2.a. Go to HKEY_LOCAL_MACHINE->Software->Microsoft->Windows->Current Version->RunOnce
2.b. Delete the key in there that points to C:\Windows\System32\mshtmlsh32.exe

Then simply delete the files:
C:\Windows\System32\mshtmlsh32.exe
C:\Windows\System32\wndrivsd32.exe

And ofcourse, delete dsc027.scr whereever you put it.

Now replace C:\Window\System32\Drivers\etc\hosts with an empty file.

Now you should be clean. To verify this, you can reboot Windows, and
try to identify the virus process again, in the task manager.


Here's how the virus works:

www.fakme.org was appearantly taken over by virus maker to distribute
his virus. it redirects to either of http://www.bussines4me.net/dsc027.scr
or http://socsec.co.il/knopka/dsc027.scr to download the virus (DO NOT CLICK THE LINKS).
There may be more sites, but these are the ones I encountered.

The virus is a single executable (dsc027.scr is simply that executable).

The same executable is copied to several paths:

C:\Windows\System32\mshtmlsh32.exe (Marked as a "hidden" file, use show hidden files, or "dir /a" to see it)
C:\Windows\System32\wndrivsd32.exe

It installs a regsitry key: "Local Machine\Software\Microsoft\Windows\CurrentVersion\RunOnce" that runs C:\Windows\System32\mshtmlsh32.exe

Once that is run at boot time, it injects hostile code into the running explorer.exe which makes explorer.exe run wndrivsd32.exe periodically - it also holds it as an open file so it cannot be deleted easily. Either at boot time, or when run, it also overwrites C:\Windows\System32\Drivers\Etc\Hosts to contain wrong entries for various virus software update addresses, so that antivirus software updates will fail.
Mon Sep 10 2007, 13:21 · Reply · Quote and reply · Permalink · Top ·

Gioxx
New member
Posts: 3

*


Thanks a lot smile.png
I have two client (my friends) infected wink.png

This post has been edited by Gioxx: Mon Sep 10 2007, 14:06


--------------------
GxWare.org Research Lab c.e.o.
Mon Sep 10 2007, 14:05 · Reply · Quote and reply · Permalink · Top ·
Eyal
Regular member
Posts: 14

**


You're welcome!

The question is: Did the cleanup procedure work for you?

QUOTE(Gioxx @ Mon Sep 10 2007, 14:05) [snapback]439713[/snapback]

Thanks a lot smile.png
I have two client (my friends) infected wink.png

Mon Sep 10 2007, 14:08 · Reply · Quote and reply · Permalink · Top ·

TheUberOverlord
Advanced Member
Posts: 11,188

Group Icon


Official statement from Skype about this: http://heartbeat.skype.com/


--------------------
Get Free Software and Programming Tips and User Tricks For Skype
Now Monitor Your Subscription Usage In Real-Time!
Chat Language Translator For Skype - 43 Different Languages
How To Use Call Transfer With 4.x Skype Versions
52 Ways To Save NOW! With Skype Services
3rd Party Software Example for Skype - Includes ALL the source code
MyToGo For Skype - Use Skype services remotely from your phones
Save Skype Chat Messages To Text Files - Internet Explorer
Find Out If Someone Has Blocked You On Skype
Mon Sep 10 2007, 14:16 · Reply · Quote and reply · Permalink · Top ·

Gioxx
New member
Posts: 3

*


Thanks UberOverlord smile.png


--------------------
GxWare.org Research Lab c.e.o.
Mon Sep 10 2007, 14:39 · Reply · Quote and reply · Permalink · Top ·
prahaquiroga
New member
Posts: 1

*


QUOTE(Gioxx @ Mon Sep 10 2007, 14:39) [snapback]439746[/snapback]

Thanks UberOverlord smile.png

THANKS A LOT
Mon Sep 10 2007, 14:40 · Reply · Quote and reply · Permalink · Top ·

TheUberOverlord
Advanced Member
Posts: 11,188

Group Icon


There was a rumor going around saying that a program authorization was added for a program in the:

Tools -> Options -> Advanced -> Manage Other Programs Access To Skype

Is this True? and if so than these manual methods do not add a step to remove that authorization.


--------------------
Get Free Software and Programming Tips and User Tricks For Skype
Now Monitor Your Subscription Usage In Real-Time!
Chat Language Translator For Skype - 43 Different Languages
How To Use Call Transfer With 4.x Skype Versions
52 Ways To Save NOW! With Skype Services
3rd Party Software Example for Skype - Includes ALL the source code
MyToGo For Skype - Use Skype services remotely from your phones
Save Skype Chat Messages To Text Files - Internet Explorer
Find Out If Someone Has Blocked You On Skype
Mon Sep 10 2007, 14:49 · Reply · Quote and reply · Permalink · Top ·
Safferboy
New member
Posts: 1

*


Thanks Eyal,

This seems to have worked for me!

Much appreciated.
Mon Sep 10 2007, 15:00 · Reply · Quote and reply · Permalink · Top ·
Eyal
Regular member
Posts: 14

**


QUOTE(TheUberOverlord @ Mon Sep 10 2007, 14:49) [snapback]439751[/snapback]

There was a rumor going around saying that a program authorization was added for a program in the:

Tools -> Options -> Advanced -> Manage Other Programs Access To Skype

Is this True? and if so than these manual methods do not add a step to remove that authorization.


Yes, its true.
I have manually cleaned things up, and that entry was still in there. Do the automatic cleaners clean that up too?
Mon Sep 10 2007, 15:04 · Reply · Quote and reply · Permalink · Top ·
EDDIE CHAN
New member
Posts: 1

*


QUOTE(Gioxx @ Mon Sep 10 2007, 14:05) [snapback]439713[/snapback]

Thanks a lot smile.png
I have two client (my friends) infected wink.png


I was infected! Now had been removed.
Thanks Eyal smile.png
Mon Sep 10 2007, 15:10 · Reply · Quote and reply · Permalink · Top ·
nangniot
New member
Posts: 1

*


Thanks a lot EYAL, smile.png

you save my life with your message at 13:21.

I followed the instruction "how to fix ..." until operation 2 and stopped at the beginning of operation 2.a because I don't know what "registry editor" means in french, my mother language.
But anyway, everything is fixed and it works now as before the virus.
Thanks again

Pierre Nangniot
Mon Sep 10 2007, 16:19 · Reply · Quote and reply · Permalink · Top ·

TheUberOverlord
Advanced Member
Posts: 11,188

Group Icon


QUOTE(Eyal @ Mon Sep 10 2007, 09:04) [snapback]439755[/snapback]

Yes, its true.
I have manually cleaned things up, and that entry was still in there. Do the automatic cleaners clean that up too?


Good Question?

What are the entries you found there that need to be manually removed, please add those to your instructions ;-)


--------------------
Get Free Software and Programming Tips and User Tricks For Skype
Now Monitor Your Subscription Usage In Real-Time!
Chat Language Translator For Skype - 43 Different Languages
How To Use Call Transfer With 4.x Skype Versions
52 Ways To Save NOW! With Skype Services
3rd Party Software Example for Skype - Includes ALL the source code
MyToGo For Skype - Use Skype services remotely from your phones
Save Skype Chat Messages To Text Files - Internet Explorer
Find Out If Someone Has Blocked You On Skype
Mon Sep 10 2007, 16:25 · Reply · Quote and reply · Permalink · Top ·
paralax
New member
Posts: 1

*


Works fine. yes.png
I did it the usual (like above) way to remove worms and spyware.

Burn in hell worm coder. devil.png
Mon Sep 10 2007, 16:27 · Reply · Quote and reply · Permalink · Top ·

TheUberOverlord
Advanced Member
Posts: 11,188

Group Icon


QUOTE(paralax @ Mon Sep 10 2007, 10:27) [snapback]439793[/snapback]

Works fine. yes.png
I did it the usual (like above) way to remove worms and spyware.

Burn in hell worm coder. devil.png


Please be aware, you may addtionally need to check your approved programs that work with Skype:

Tools -> Options -> Advanced -> Manage Other Programs That Access Skype

If you see something that looks strange REMOVE it.


--------------------
Get Free Software and Programming Tips and User Tricks For Skype
Now Monitor Your Subscription Usage In Real-Time!
Chat Language Translator For Skype - 43 Different Languages
How To Use Call Transfer With 4.x Skype Versions
52 Ways To Save NOW! With Skype Services
3rd Party Software Example for Skype - Includes ALL the source code
MyToGo For Skype - Use Skype services remotely from your phones
Save Skype Chat Messages To Text Files - Internet Explorer
Find Out If Someone Has Blocked You On Skype
Mon Sep 10 2007, 16:29 · Reply · Quote and reply · Permalink · Top ·
henrykim
New member
Posts: 1

*


thks alot, i found out file wndrivs32.exe and tried to stop by using Task Manager but fail. I think this app was called by another program b/c it's come back 5s after I stop its task. Why can not scan file dsc027.scr by antivirus...?
Now all clear, thks
Mon Sep 10 2007, 17:21 · Reply · Quote and reply · Permalink · Top ·
Scythian
New member
Posts: 1

*


I have also found a file named game.exe in the root of my flash disk that was connected to a USB port at time of infection, as well as a hidden file zjbs.exe with a different date and time stamp. both these files appears to be the same as mshtmlsh32.exe or mshtmlsh32.exe. I expect that the virus looks for removable media and tries to make copys of itself onto the media.

Mon Sep 10 2007, 17:32 · Reply · Quote and reply · Permalink · Top ·

TheUberOverlord
Advanced Member
Posts: 11,188

Group Icon


QUOTE(Scythian @ Mon Sep 10 2007, 11:32) [snapback]439830[/snapback]

I have also found a file named game.exe in the root of my flash disk that was connected to a USB port at time of infection, as well as a hidden file zjbs.exe with a different date and time stamp. both these files appears to be the same as mshtmlsh32.exe or mshtmlsh32.exe. I expect that the virus looks for removable media and tries to make copys of itself onto the media.


Please be aware, you may addtionally need to check your approved programs that work with Skype:

Tools -> Options -> Advanced -> Manage Other Programs That Access Skype

If you see something that looks strange REMOVE it.




--------------------
Get Free Software and Programming Tips and User Tricks For Skype
Now Monitor Your Subscription Usage In Real-Time!
Chat Language Translator For Skype - 43 Different Languages
How To Use Call Transfer With 4.x Skype Versions
52 Ways To Save NOW! With Skype Services
3rd Party Software Example for Skype - Includes ALL the source code
MyToGo For Skype - Use Skype services remotely from your phones
Save Skype Chat Messages To Text Files - Internet Explorer
Find Out If Someone Has Blocked You On Skype
Mon Sep 10 2007, 17:37 · Reply · Quote and reply · Permalink · Top ·
jboo
New member
Posts: 1

*


I followed the instructions. Seemed to work, however...
I was not able to find these files:

mshtmlsh32.exe
dsc027.scr
mshtmldat32.exe
winlgcvers.exe
sdrivew32.exe

In fact, the only file I did find and delete was wndrivsd32.exe
also deleted the reg entry and the 'Manage Other Programs Access To Skype' entry

searched the entire hd for the other files (hidden and system) with no success.

so far so good. we will see if it acts up again.

Mon Sep 10 2007, 18:39 · Reply · Quote and reply · Permalink · Top ·
yehoshua
Regular member
Posts: 5

**


Toda, thanks a lot Eyal, this virus was sent to me by a friend, Skype sent it to a few friends of mine, but thanks to your instructions I could heal my computer. I had to read them of course on my 2nd computer, because on the infected one it was impossible to have Firefox!

Yehoshua

QUOTE(Eyal @ Mon Sep 10 2007, 13:21) [snapback]439683[/snapback]

Disclaimer: I have cleaned up my own computer from the virus, and wrote down the instructions. I have not re-infected my computer in order to test these instructions are completely accurate, so it may be inaccurate in some way. Please write some feedback about whether it worked for you, and these instructions can be updated.

How to identify an infected computed:

1. Open the task manager (Ctrl+Shift+Escape should work, or Start->Run->taskman)
2. Look for wndrivsd32.exe: If it is running/in the list, you are infected.

How to fix/clean an infected computer:

1. Open the task manager (Ctrl+Shift+Escape should work, or Start->Run->taskman)

Inside Task Manager:
1.a. Select explorer.exe and use "End Task" (this will make the panel
and perhaps other things disappear)

1.b. Select wndrivsd32.exe and use "End Task" (this will kill the virus process)

1.c. Use File->New Task, and run "explorer" (this will restore things to normal).
2. Run regedit.exe (Note: If regedit dies/disappears after a few seconds, it means that you
haven't killed wndrivsd32.exe or explorer properly - repeat step 1, faster :-)

Inside the registry editor:
2.a. Go to HKEY_LOCAL_MACHINE->Software->Microsoft->Windows->Current Version->RunOnce
2.b. Delete the key in there that points to C:\Windows\System32\mshtmlsh32.exe

Then simply delete the files:
C:\Windows\System32\mshtmlsh32.exe
C:\Windows\System32\wndrivsd32.exe

And ofcourse, delete dsc027.scr whereever you put it.

Now replace C:\Window\System32\Drivers\etc\hosts with an empty file.

Now you should be clean. To verify this, you can reboot Windows, and
try to identify the virus process again, in the task manager.
Here's how the virus works:

www.fakme.org was appearantly taken over by virus maker to distribute
his virus. it redirects to either of http://www.bussines4me.net/dsc027.scr
or http://socsec.co.il/knopka/dsc027.scr to download the virus (DO NOT CLICK THE LINKS).
There may be more sites, but these are the ones I encountered.

The virus is a single executable (dsc027.scr is simply that executable).

The same executable is copied to several paths:

C:\Windows\System32\mshtmlsh32.exe (Marked as a "hidden" file, use show hidden files, or "dir /a" to see it)
C:\Windows\System32\wndrivsd32.exe

It installs a regsitry key: "Local Machine\Software\Microsoft\Windows\CurrentVersion\RunOnce" that runs C:\Windows\System32\mshtmlsh32.exe

Once that is run at boot time, it injects hostile code into the running explorer.exe which makes explorer.exe run wndrivsd32.exe periodically - it also holds it as an open file so it cannot be deleted easily. Either at boot time, or when run, it also overwrites C:\Windows\System32\Drivers\Etc\Hosts to contain wrong entries for various virus software update addresses, so that antivirus software updates will fail.

Tue Sep 11 2007, 01:23 · Reply · Quote and reply · Permalink · Top ·
Eyal
Regular member
Posts: 14

**


You're welcome!

If you deleted the files, but did not perform step 2, you should be okay.
However, if you also skipped deleting the files, the virus will be back as soon as you reboot.

By "run regedit.exe" I simply meant that you should use: Start->Run, and type "regedit.exe".

QUOTE(yehoshua @ Tue Sep 11 2007, 01:23) [snapback]439994[/snapback]

Toda, thanks a lot Eyal, this virus was sent to me by a friend, Skype sent it to a few friends of mine, but thanks to your instructions I could heal my computer. I had to read them of course on my 2nd computer, because on the infected one it was impossible to have Firefox!

Yehoshua

Tue Sep 11 2007, 01:28 · Reply · Quote and reply · Permalink · Top ·
2 Pages 1 2 >
 
2 User(s) are reading this topic (2 Guests and 0 Anonymous Users)
0 Members:

Display Mode: Standard · Switch to: Linear+ · Switch to: Outline

Track this topic · Email this topic · Print this topic · Subscribe to this forum

Welcome guest Read a quick guide to using these community forums.

  • My area
  • Sign in
  • Related
  • Search
  • Community guidelines
  • User guides
  • Knowledgebase

Heartbeat Heartbeat See how our products are performing on the Heartbeat blog.

About us · News · Jobs · Prices · Security · Site map
Privacy policy · Legal · © 2009 Skype Limited