TwinHeadedEagle

Removal Expert
Staff member
Verified
As I already mentioned, I am member of MCShield developing team, so I decided to wrote an article about this program, and it's capabilities. I find out that you mentioned this tool through discussions, but I saw few incorrect statements (I ain't blame you), so I am here to correct it :)


I am member of AMF (Anti Malware Fighter) at Mycity.rs forum, and over the years there were a significant number of people that got infected with malware spreading via removable drives. Firsty bobby wrote an tool called USBNoRisk that was able to scan and remove malware traces on removable drives.

But we needed realtime protection, and this is how MCShield was born. Current version is 2.5.4.20, and new version is in beta testing.

You can find MCShield at this adress --> http://www.mcshield.net/

Now let's move on it's capabilities.

MCShield (You should not confuse it's name with mcshield module/driver from McAfee) is tool designed to prevent(remove) infections transmitted via removable drives. This means that when you plug-in usb into your computer, MCShield will automatically scan it and inform you whether drive is clean or infected/cleaned.

It's GUI is pretty simple and looks like this

http://img845.imageshack.us/img845/4167/capturexy.jpg
http://img850.imageshack.us/img850/2289/slikar.png

When you plug-in USB and it is scanned you get pop-up like this (saying it's clean)

http://img546.imageshack.us/img546/9484/slikab.png

Of course you can get the message that USB is infected and cleaned.

MCShield stores it's work withing log files. Logs are located at %programdata%\MCShield

You have two log types:
- allscans - contain all scans since the time program is installed
- lastscan - last scan :)

Example of the initial scan when computer starts:


>>> MCShield ::Anti-Malware Tool:: v 2.6.3.21 / DB: 2013.4.7.1 / Windows 7 <<<

4/8/2013 1:18:11 PM > Drive C: - scan started (no label ~368 GB, NTFS HDD )...


=> The drive is clean.

4/8/2013 1:18:11 PM > Drive D: - scan started (Local Disk ~1863 GB, NTFS HDD )...


=> The drive is clean.

4/8/2013 1:18:12 PM > Drive E: - scan started (Windows 7 64-bit ~98 GB, NTFS HDD )...


=> The drive is clean.

4/8/2013 1:18:12 PM > Drive H: - scan started (no label ~1913 MB, FAT32 flash drive )...


=> The drive is clean.


Example of clean drive:


>>> MCShield ::Anti-Malware Tool:: v 2.6.3.21 / DB: 2013.4.7.1 / Windows 7 <<<

4/8/2013 2:59:09 PM > Drive H: - scan started (no label ~1913 MB, FAT32 flash drive )...


=> The drive is clean.


Example of infected drive (Virus:W32/Ramnit)


>>> MCShield ::Anti-Malware Tool:: v 2.6.3.21 / DB: 2013.3.31.3 / Windows 7 <<<

4/6/2013 4:18:06 PM > Drive H: - scan started (no label ~1913 MB, FAT32 flash drive )...

>>> H:\Copy of Shortcut to (1).lnk.vir - Malware > Deleted. (; MD5: unknown)

>>> H:\Copy of Shortcut to (2).lnk.vir - Malware > Deleted. (; MD5: unknown)

>>> H:\Copy of Shortcut to (3).lnk.vir - Malware > Deleted. (; MD5: unknown)

>>> H:\Copy of Shortcut to (4).lnk.vir - Malware > Deleted. (; MD5: unknown)

> H:\RECYCLER
> H:\RECYCLER\S-0-5-72-2868776140-8452855113-141528478-5743
> H:\RECYCLER\S-0-5-72-2868776140-8452855113-141528478-5743\KhbkJrVQ.exe (MD5: d41d8cd98f00b204e9800998ecf8427e)
> H:\RECYCLER\S-0-5-72-2868776140-8452855113-141528478-5743\ciMFWyqy.cpl (MD5: d41d8cd98f00b204e9800998ecf8427e)
> H:\RECYCLER\S-0-5-72-2868776140-8452855113-141528478-5743\UYTYReUW.exe (MD5: d41d8cd98f00b204e9800998ecf8427e)
> H:\RECYCLER\S-0-5-72-2868776140-8452855113-141528478-5743\yIjukoZb.cpl (MD5: d41d8cd98f00b204e9800998ecf8427e)
> H:\RECYCLER\S-0-5-72-2868776140-8452855113-141528478-5743\QuOLFhHT.exe (MD5: d41d8cd98f00b204e9800998ecf8427e)
> H:\RECYCLER\S-0-5-72-2868776140-8452855113-141528478-5743\YqdBTWFR.cpl (MD5: d41d8cd98f00b204e9800998ecf8427e)
> H:\RECYCLER\S-0-5-72-2868776140-8452855113-141528478-5743\mBRIcXMo.exe (MD5: d41d8cd98f00b204e9800998ecf8427e)
> H:\RECYCLER\S-0-5-72-2868776140-8452855113-141528478-5743\nxiLxJFM.cpl (MD5: d41d8cd98f00b204e9800998ecf8427e)
> H:\RECYCLER\S-0-5-72-2868776140-8452855113-141528478-5743\QGNqJmUm.exe (MD5: d41d8cd98f00b204e9800998ecf8427e)
> H:\RECYCLER\S-0-5-72-2868776140-8452855113-141528478-5743\rcVLMGDb.cpl (MD5: d41d8cd98f00b204e9800998ecf8427e)
> H:\RECYCLER\S-0-5-72-2868776140-8452855113-141528478-5743\TitbhEEV.exe (MD5: d41d8cd98f00b204e9800998ecf8427e)
> H:\RECYCLER\S-0-5-72-2868776140-8452855113-141528478-5743\DVGaGqTC.cpl (MD5: d41d8cd98f00b204e9800998ecf8427e)
> H:\RECYCLER\S-0-5-72-2868776140-8452855113-141528478-5743\IDOImjLK.exe (MD5: d41d8cd98f00b204e9800998ecf8427e)
> H:\RECYCLER\S-0-5-72-2868776140-8452855113-141528478-5743\BJcxKxxm.cpl (MD5: d41d8cd98f00b204e9800998ecf8427e)
> H:\RECYCLER\S-0-5-72-2868776140-8452855113-141528478-5743\koZDNMYw.exe (MD5: d41d8cd98f00b204e9800998ecf8427e)
> H:\RECYCLER\S-0-5-72-2868776140-8452855113-141528478-5743\SOwxlUDO.cpl (MD5: d41d8cd98f00b204e9800998ecf8427e)
> H:\RECYCLER\S-0-5-72-2868776140-8452855113-141528478-5743\xNCcVdqY.exe (MD5: d41d8cd98f00b204e9800998ecf8427e)
> H:\RECYCLER\S-0-5-72-2868776140-8452855113-141528478-5743\GBwvSQkv.cpl (MD5: d41d8cd98f00b204e9800998ecf8427e)
> H:\RECYCLER\S-0-5-72-2868776140-8452855113-141528478-5743\HnOZQEGw.exe (MD5: d41d8cd98f00b204e9800998ecf8427e)
> H:\RECYCLER\S-0-5-72-2868776140-8452855113-141528478-5743\wiGsVTMF.cpl (MD5: d41d8cd98f00b204e9800998ecf8427e)
> H:\RECYCLER\S-0-5-72-2868776140-8452855113-141528478-5743\OXZBUhVS.exe (MD5: d41d8cd98f00b204e9800998ecf8427e)
> H:\RECYCLER\S-0-5-72-2868776140-8452855113-141528478-5743\yDbFwECA.cpl (MD5: d41d8cd98f00b204e9800998ecf8427e)
> H:\RECYCLER\S-0-5-72-2868776140-8452855113-141528478-5743\MTwoUMcI.exe (MD5: d41d8cd98f00b204e9800998ecf8427e)
> H:\RECYCLER\S-0-5-72-2868776140-8452855113-141528478-5743\lgHMqKbc.cpl (MD5: d41d8cd98f00b204e9800998ecf8427e)
> H:\RECYCLER\S-0-5-72-2868776140-8452855113-141528478-5743\BRaLrUeC.exe (MD5: d41d8cd98f00b204e9800998ecf8427e)
> H:\RECYCLER\S-0-5-72-2868776140-8452855113-141528478-5743\YoSMfJqw.cpl (MD5: d41d8cd98f00b204e9800998ecf8427e)
> H:\RECYCLER\S-0-5-72-2868776140-8452855113-141528478-5743\ynGQSUeC.exe (MD5: d41d8cd98f00b204e9800998ecf8427e)
> H:\RECYCLER\S-0-5-72-2868776140-8452855113-141528478-5743\OFBsrOhm.cpl (MD5: d41d8cd98f00b204e9800998ecf8427e)
> H:\RECYCLER\S-0-5-72-2868776140-8452855113-141528478-5743\fxyZBsoM.exe (MD5: d41d8cd98f00b204e9800998ecf8427e)
> H:\RECYCLER\S-0-5-72-2868776140-8452855113-141528478-5743\HcvZuaaW.cpl (MD5: d41d8cd98f00b204e9800998ecf8427e)

>>> H:\Recycler - Malware (folder) > Deleted. (13.04.06. 16.18 Recycler.230506)

=> Malicious files : 34/34 deleted.
=> Malicious folders : 2/2 deleted.

____________________________________________

::::: Scan duration: 14sec :::::::::::::::::
____________________________________________


Another worm busted :D


>>> MCShield ::Anti-Malware Tool:: v 2.5.3.19 / DB: 2013.2.10.1 / NT6.1 <<<

2/10/2013 11:48:26 AM > Drive E: - scan started (no label ~1913 MB, FAT32 flash drive )...

>>> E:\muzika.lnk - Malware > Deleted. (13.02.10. 11.48 muzika.lnk.651013; MD5: cf79150f2c9cda8c0f7f439fa8e1de42)

>>> E:\RECYCLER\Desktop.ini - Malware > Deleted. (13.02.10. 11.48 Desktop.ini.958366; MD5: e783bdd20a976eaeaae1ff4624487420)

> E:\RECYCLER
> E:\RECYCLER\bcd8f464.exe (MD5: 6a119ebe709199c7c4b3b6766a38789c)

>>> E:\RECYCLER - Malware (folder) > Deleted. (13.02.10. 11.48 RECYCLER.892431)

> Resetting attributes: E:\muzika < Successful.

=> Malicious files : 3/3 deleted.
=> Malicious folders : 1/1 deleted.
=> Hidden folders : 1/1 unhidden.

____________________________________________

::::: Scan duration: 2sec ::::::::::::::::::
____________________________________________


And finally Stuxnet and Conficker :p


24.12.2010 17:41:32 > Scanning drive H: (NIKOOLA ~4 GB, FAT32 flash drive )...

> H:\RECYCLER
> H:\RECYCLER\S-5-3-42-2819952290-8240758988-879315005-3665
> H:\RECYCLER\S-5-3-42-2819952290-8240758988-879315005-3665\jwgkvsq.vmx (MD5: 3284fad8a6238205829d812a26a608ff)

>>> H:\recycler - Malware.Folder > Deleted. (10.12.24. 17.41 recycler.617306)

>>> H:\~WRL0001.tmp - Suspicious > Renamed. (MD5: 60819abb8eff2c7d66888e70e8e65604)

=> Malicious folders : 1/1 deleted.
=> Suspicious files : 1/1 renamed.

Stuxnet used Win32/CplLnk.A exploit, but got busted :D


As you can see scan time is very short, couple of seconds, but of course, it vary of number of files within USB.

Another feature is that MCShield gathers MD5, and shows it within log, so you can easily check MD5 on VirusTotal.

MCShield has ability to restore attributes, except that you need to manually tick option Always unhide items on flash driver within Scanner tab.

I am not going to compare other similar tools like Panda USB Vaccine or Bitdefende USB Immunizer, because these are just autorun blockers, and they couldn't match with MCShield, because they are not able to remove malware. MCShield has world class heuristics, and contain abilities to detect much more hidden malware.

That's just a short presentation, you can find more explanations on MCShield web adress.

If you need any question, I am here to answer.

Greetings :)
 

Dacko

Level 2
RE: MCShield

Very good program. I use it since the first version. I am satisfied. From version to version is getting better and better.
 

jamescv7

Level 61
Trusted
Verified
RE: MCShield

Interesting program since even from most modern Windows OS have disabled autorun/autoplay good protection even in read/write. :)
 

TwinHeadedEagle

Removal Expert
Staff member
Verified
RE: MCShield

jamescv7 said:
Interesting program since even from most modern Windows OS have disabled autorun/autoplay good protection even in read/write. :)
Yes, but as I've said there are many more methods that malware use to trick user and infect the system.

MCShield is must have program, it is very light on resources, it's real time protection is only real time when you plug-in USB. Rest of the time MCShield "sleeps"...
 
Reactions: safe1st

jamescv7

Level 61
Trusted
Verified
RE: MCShield

So far only the first time operation tends to spike my CPU usage thus made it a bit slow but after everything is smooth which a + for that.

:)
 
D

Deleted member 178

RE: MCShield

just installed and trying it , disabled HDD scans (kept only USB), RAM usage is correct, around 15mb on my system.

McShield improved since last time i used it. Good job.

note: your website is flagged as "threat" by Webroot SA, i have to put it on the exclusions, you should tell Webroot, if not, you may loose lot of market shares.
 

rebel4life

Level 9
Verified
RE: MCShield

having problems with this website BD trafficlight is blocking it is this a real or a rogue software
 

TwinHeadedEagle

Removal Expert
Staff member
Verified
RE: MCShield

rebel4life said:
having problems with this website BD trafficlight is blocking it is this a real or a rogue software
You can be sure that this software and it's domen are 100% malware clean. After all, MCShield is made by experienced malware fighters :)

Detections are false positive.

What version of BD are you using?

Thanks for your feedback :)

EDIT: It's trafficlight :D
 

rebel4life

Level 9
Verified
RE: MCShield

bullguard would not install it it just deleted it from my computer and my download files too
 

rebel4life

Level 9
Verified
RE: MCShield

i installed it and had 3 warnings from bullguard and 2 warnings from mamutu and BD trafficlight blocked their site but i click to continue
 

TwinHeadedEagle

Removal Expert
Staff member
Verified
RE: MCShield

Reported to Bitdefender, cause bullguard uses BD engine...

Reported to emisoft last night, should be fixed till now...

New version coming these days... :)
 

jamescv7

Level 61
Trusted
Verified
RE: MCShield

I've installed the new version already which is 2.6.3.21 so far no problems but got only a minor issue.

As it sits in the taskbar when right click for the control panel nothing happened. (no appearance for control panel)

Instead I just searched the program name, pinned and open the control panel there.
 

TwinHeadedEagle

Removal Expert
Staff member
Verified
RE: MCShield

As you have seen, new version rolled out two days ago :)

Changelog:

Code:
v 2.6.3.21: 12th April 2013.

- updated all components to work with our new domain (www.mcshield.net);
- added detection for another variant of replicating worms;
- updated/improved detection/remediation of Win32.Gamarue;
- added Russian language (thanks to translator Covaliov Andrei Genadie).
Next relaese should probably have some new UI features, such as new version download progress :)


jamescv7 said:
I've installed the new version already which is 2.6.3.21 so far no problems but got only a minor issue.

As it sits in the taskbar when right click for the control panel nothing happened. (no appearance for control panel)

Instead I just searched the program name, pinned and open the control panel there.
I havent experienced this issue, right click shows corresponding menu. Do you still have this problem?
 

Similar Threads

Similar Threads