- Mar 8, 2013
- 22,627
As I already mentioned, I am member of MCShield developing team, so I decided to wrote an article about this program, and it's capabilities. I find out that you mentioned this tool through discussions, but I saw few incorrect statements (I ain't blame you), so I am here to correct it
I am member of AMF (Anti Malware Fighter) at Mycity.rs forum, and over the years there were a significant number of people that got infected with malware spreading via removable drives. Firsty bobby wrote an tool called USBNoRisk that was able to scan and remove malware traces on removable drives.
But we needed realtime protection, and this is how MCShield was born. Current version is 2.5.4.20, and new version is in beta testing.
You can find MCShield at this adress --> http://www.mcshield.net/
Now let's move on it's capabilities.
MCShield (You should not confuse it's name with mcshield module/driver from McAfee) is tool designed to prevent(remove) infections transmitted via removable drives. This means that when you plug-in usb into your computer, MCShield will automatically scan it and inform you whether drive is clean or infected/cleaned.
It's GUI is pretty simple and looks like this
http://img845.imageshack.us/img845/4167/capturexy.jpg
http://img850.imageshack.us/img850/2289/slikar.png
When you plug-in USB and it is scanned you get pop-up like this (saying it's clean)
http://img546.imageshack.us/img546/9484/slikab.png
Of course you can get the message that USB is infected and cleaned.
MCShield stores it's work withing log files. Logs are located at %programdata%\MCShield
You have two log types:
- allscans - contain all scans since the time program is installed
- lastscan - last scan
Example of the initial scan when computer starts:
Example of clean drive:
Example of infected drive (Virus:W32/Ramnit)
Another worm busted
And finally Stuxnet and Conficker
Stuxnet used Win32/CplLnk.A exploit, but got busted
As you can see scan time is very short, couple of seconds, but of course, it vary of number of files within USB.
Another feature is that MCShield gathers MD5, and shows it within log, so you can easily check MD5 on VirusTotal.
MCShield has ability to restore attributes, except that you need to manually tick option Always unhide items on flash driver within Scanner tab.
I am not going to compare other similar tools like Panda USB Vaccine or Bitdefende USB Immunizer, because these are just autorun blockers, and they couldn't match with MCShield, because they are not able to remove malware. MCShield has world class heuristics, and contain abilities to detect much more hidden malware.
That's just a short presentation, you can find more explanations on MCShield web adress.
If you need any question, I am here to answer.
Greetings
I am member of AMF (Anti Malware Fighter) at Mycity.rs forum, and over the years there were a significant number of people that got infected with malware spreading via removable drives. Firsty bobby wrote an tool called USBNoRisk that was able to scan and remove malware traces on removable drives.
But we needed realtime protection, and this is how MCShield was born. Current version is 2.5.4.20, and new version is in beta testing.
You can find MCShield at this adress --> http://www.mcshield.net/
Now let's move on it's capabilities.
MCShield (You should not confuse it's name with mcshield module/driver from McAfee) is tool designed to prevent(remove) infections transmitted via removable drives. This means that when you plug-in usb into your computer, MCShield will automatically scan it and inform you whether drive is clean or infected/cleaned.
It's GUI is pretty simple and looks like this
http://img845.imageshack.us/img845/4167/capturexy.jpg
http://img850.imageshack.us/img850/2289/slikar.png
When you plug-in USB and it is scanned you get pop-up like this (saying it's clean)
http://img546.imageshack.us/img546/9484/slikab.png
Of course you can get the message that USB is infected and cleaned.
MCShield stores it's work withing log files. Logs are located at %programdata%\MCShield
You have two log types:
- allscans - contain all scans since the time program is installed
- lastscan - last scan
Example of the initial scan when computer starts:
>>> MCShield ::Anti-Malware Tool:: v 2.6.3.21 / DB: 2013.4.7.1 / Windows 7 <<<
4/8/2013 1:18:11 PM > Drive C: - scan started (no label ~368 GB, NTFS HDD )...
=> The drive is clean.
4/8/2013 1:18:11 PM > Drive D: - scan started (Local Disk ~1863 GB, NTFS HDD )...
=> The drive is clean.
4/8/2013 1:18:12 PM > Drive E: - scan started (Windows 7 64-bit ~98 GB, NTFS HDD )...
=> The drive is clean.
4/8/2013 1:18:12 PM > Drive H: - scan started (no label ~1913 MB, FAT32 flash drive )...
=> The drive is clean.
Example of clean drive:
>>> MCShield ::Anti-Malware Tool:: v 2.6.3.21 / DB: 2013.4.7.1 / Windows 7 <<<
4/8/2013 2:59:09 PM > Drive H: - scan started (no label ~1913 MB, FAT32 flash drive )...
=> The drive is clean.
Example of infected drive (Virus:W32/Ramnit)
>>> MCShield ::Anti-Malware Tool:: v 2.6.3.21 / DB: 2013.3.31.3 / Windows 7 <<<
4/6/2013 4:18:06 PM > Drive H: - scan started (no label ~1913 MB, FAT32 flash drive )...
>>> H:\Copy of Shortcut to (1).lnk.vir - Malware > Deleted. (; MD5: unknown)
>>> H:\Copy of Shortcut to (2).lnk.vir - Malware > Deleted. (; MD5: unknown)
>>> H:\Copy of Shortcut to (3).lnk.vir - Malware > Deleted. (; MD5: unknown)
>>> H:\Copy of Shortcut to (4).lnk.vir - Malware > Deleted. (; MD5: unknown)
> H:\RECYCLER
> H:\RECYCLER\S-0-5-72-2868776140-8452855113-141528478-5743
> H:\RECYCLER\S-0-5-72-2868776140-8452855113-141528478-5743\KhbkJrVQ.exe (MD5: d41d8cd98f00b204e9800998ecf8427e)
> H:\RECYCLER\S-0-5-72-2868776140-8452855113-141528478-5743\ciMFWyqy.cpl (MD5: d41d8cd98f00b204e9800998ecf8427e)
> H:\RECYCLER\S-0-5-72-2868776140-8452855113-141528478-5743\UYTYReUW.exe (MD5: d41d8cd98f00b204e9800998ecf8427e)
> H:\RECYCLER\S-0-5-72-2868776140-8452855113-141528478-5743\yIjukoZb.cpl (MD5: d41d8cd98f00b204e9800998ecf8427e)
> H:\RECYCLER\S-0-5-72-2868776140-8452855113-141528478-5743\QuOLFhHT.exe (MD5: d41d8cd98f00b204e9800998ecf8427e)
> H:\RECYCLER\S-0-5-72-2868776140-8452855113-141528478-5743\YqdBTWFR.cpl (MD5: d41d8cd98f00b204e9800998ecf8427e)
> H:\RECYCLER\S-0-5-72-2868776140-8452855113-141528478-5743\mBRIcXMo.exe (MD5: d41d8cd98f00b204e9800998ecf8427e)
> H:\RECYCLER\S-0-5-72-2868776140-8452855113-141528478-5743\nxiLxJFM.cpl (MD5: d41d8cd98f00b204e9800998ecf8427e)
> H:\RECYCLER\S-0-5-72-2868776140-8452855113-141528478-5743\QGNqJmUm.exe (MD5: d41d8cd98f00b204e9800998ecf8427e)
> H:\RECYCLER\S-0-5-72-2868776140-8452855113-141528478-5743\rcVLMGDb.cpl (MD5: d41d8cd98f00b204e9800998ecf8427e)
> H:\RECYCLER\S-0-5-72-2868776140-8452855113-141528478-5743\TitbhEEV.exe (MD5: d41d8cd98f00b204e9800998ecf8427e)
> H:\RECYCLER\S-0-5-72-2868776140-8452855113-141528478-5743\DVGaGqTC.cpl (MD5: d41d8cd98f00b204e9800998ecf8427e)
> H:\RECYCLER\S-0-5-72-2868776140-8452855113-141528478-5743\IDOImjLK.exe (MD5: d41d8cd98f00b204e9800998ecf8427e)
> H:\RECYCLER\S-0-5-72-2868776140-8452855113-141528478-5743\BJcxKxxm.cpl (MD5: d41d8cd98f00b204e9800998ecf8427e)
> H:\RECYCLER\S-0-5-72-2868776140-8452855113-141528478-5743\koZDNMYw.exe (MD5: d41d8cd98f00b204e9800998ecf8427e)
> H:\RECYCLER\S-0-5-72-2868776140-8452855113-141528478-5743\SOwxlUDO.cpl (MD5: d41d8cd98f00b204e9800998ecf8427e)
> H:\RECYCLER\S-0-5-72-2868776140-8452855113-141528478-5743\xNCcVdqY.exe (MD5: d41d8cd98f00b204e9800998ecf8427e)
> H:\RECYCLER\S-0-5-72-2868776140-8452855113-141528478-5743\GBwvSQkv.cpl (MD5: d41d8cd98f00b204e9800998ecf8427e)
> H:\RECYCLER\S-0-5-72-2868776140-8452855113-141528478-5743\HnOZQEGw.exe (MD5: d41d8cd98f00b204e9800998ecf8427e)
> H:\RECYCLER\S-0-5-72-2868776140-8452855113-141528478-5743\wiGsVTMF.cpl (MD5: d41d8cd98f00b204e9800998ecf8427e)
> H:\RECYCLER\S-0-5-72-2868776140-8452855113-141528478-5743\OXZBUhVS.exe (MD5: d41d8cd98f00b204e9800998ecf8427e)
> H:\RECYCLER\S-0-5-72-2868776140-8452855113-141528478-5743\yDbFwECA.cpl (MD5: d41d8cd98f00b204e9800998ecf8427e)
> H:\RECYCLER\S-0-5-72-2868776140-8452855113-141528478-5743\MTwoUMcI.exe (MD5: d41d8cd98f00b204e9800998ecf8427e)
> H:\RECYCLER\S-0-5-72-2868776140-8452855113-141528478-5743\lgHMqKbc.cpl (MD5: d41d8cd98f00b204e9800998ecf8427e)
> H:\RECYCLER\S-0-5-72-2868776140-8452855113-141528478-5743\BRaLrUeC.exe (MD5: d41d8cd98f00b204e9800998ecf8427e)
> H:\RECYCLER\S-0-5-72-2868776140-8452855113-141528478-5743\YoSMfJqw.cpl (MD5: d41d8cd98f00b204e9800998ecf8427e)
> H:\RECYCLER\S-0-5-72-2868776140-8452855113-141528478-5743\ynGQSUeC.exe (MD5: d41d8cd98f00b204e9800998ecf8427e)
> H:\RECYCLER\S-0-5-72-2868776140-8452855113-141528478-5743\OFBsrOhm.cpl (MD5: d41d8cd98f00b204e9800998ecf8427e)
> H:\RECYCLER\S-0-5-72-2868776140-8452855113-141528478-5743\fxyZBsoM.exe (MD5: d41d8cd98f00b204e9800998ecf8427e)
> H:\RECYCLER\S-0-5-72-2868776140-8452855113-141528478-5743\HcvZuaaW.cpl (MD5: d41d8cd98f00b204e9800998ecf8427e)
>>> H:\Recycler - Malware (folder) > Deleted. (13.04.06. 16.18 Recycler.230506)
=> Malicious files : 34/34 deleted.
=> Malicious folders : 2/2 deleted.
____________________________________________
::::: Scan duration: 14sec :::::::::::::::::
____________________________________________
Another worm busted
>>> MCShield ::Anti-Malware Tool:: v 2.5.3.19 / DB: 2013.2.10.1 / NT6.1 <<<
2/10/2013 11:48:26 AM > Drive E: - scan started (no label ~1913 MB, FAT32 flash drive )...
>>> E:\muzika.lnk - Malware > Deleted. (13.02.10. 11.48 muzika.lnk.651013; MD5: cf79150f2c9cda8c0f7f439fa8e1de42)
>>> E:\RECYCLER\Desktop.ini - Malware > Deleted. (13.02.10. 11.48 Desktop.ini.958366; MD5: e783bdd20a976eaeaae1ff4624487420)
> E:\RECYCLER
> E:\RECYCLER\bcd8f464.exe (MD5: 6a119ebe709199c7c4b3b6766a38789c)
>>> E:\RECYCLER - Malware (folder) > Deleted. (13.02.10. 11.48 RECYCLER.892431)
> Resetting attributes: E:\muzika < Successful.
=> Malicious files : 3/3 deleted.
=> Malicious folders : 1/1 deleted.
=> Hidden folders : 1/1 unhidden.
____________________________________________
::::: Scan duration: 2sec ::::::::::::::::::
____________________________________________
And finally Stuxnet and Conficker
24.12.2010 17:41:32 > Scanning drive H: (NIKOOLA ~4 GB, FAT32 flash drive )...
> H:\RECYCLER
> H:\RECYCLER\S-5-3-42-2819952290-8240758988-879315005-3665
> H:\RECYCLER\S-5-3-42-2819952290-8240758988-879315005-3665\jwgkvsq.vmx (MD5: 3284fad8a6238205829d812a26a608ff)
>>> H:\recycler - Malware.Folder > Deleted. (10.12.24. 17.41 recycler.617306)
>>> H:\~WRL0001.tmp - Suspicious > Renamed. (MD5: 60819abb8eff2c7d66888e70e8e65604)
=> Malicious folders : 1/1 deleted.
=> Suspicious files : 1/1 renamed.
Stuxnet used Win32/CplLnk.A exploit, but got busted
As you can see scan time is very short, couple of seconds, but of course, it vary of number of files within USB.
Another feature is that MCShield gathers MD5, and shows it within log, so you can easily check MD5 on VirusTotal.
MCShield has ability to restore attributes, except that you need to manually tick option Always unhide items on flash driver within Scanner tab.
I am not going to compare other similar tools like Panda USB Vaccine or Bitdefende USB Immunizer, because these are just autorun blockers, and they couldn't match with MCShield, because they are not able to remove malware. MCShield has world class heuristics, and contain abilities to detect much more hidden malware.
That's just a short presentation, you can find more explanations on MCShield web adress.
If you need any question, I am here to answer.
Greetings