Jump to content

Build Theme!
  •  
  • Infected?

WE'RE SURE THAT YOU'LL LOVE US!

Hey there! :wub: Looks like you're enjoying the discussion, but you're not signed up for an account. When you create an account, we remember exactly what you've read, so you always come right back where you left off. You also get notifications, here and via email, whenever new posts are made. You can like posts to share the love. :D Join 93105 other members! Anybody can ask, anybody can answer. Consistently helpful members may be invited to become staff. Here's how it works. Virus cleanup? Start here -> Malware Removal Forum.

Try What the Tech -- It's free!


Photo

Nhatquanglan Infection from flash drive and ipod


  • This topic is locked This topic is locked
1 reply to this topic

#1 teppei

teppei

    New Member

  • New Member
  • Pip
  • 1 posts

Posted 11 October 2007 - 11:41 AM

EDIT: i was able to fix the problem... just a couple of things.. should i really have to make a new restore point? and why? and how does flash_disinfector work? everytime i run it, seems nothing happens. thanks for the reply.. u may as well close this topic right after. thanks.

Edited by teppei, 12 October 2007 - 12:30 PM.

    Advertisements

Register to Remove


#2 LDTate

LDTate

    Grand Poobah

  • Root Admin
  • 57,211 posts

Posted 13 October 2007 - 06:55 AM

EDIT: i was able to fix the problem...

just a couple of things.. should i really have to make a new restore point? and why?
and how does flash_disinfector work? everytime i run it, seems nothing happens.


thanks for the reply.. u may as well close this topic right after. thanks.

Yes, you need to create a new "clean" restore point. Bad and good files are in restore points. If you restore to a date that a infected file is, you'll load the infection again.


Okay, here's a brief descript of the worm:

It usually comes in through your removable drives - flash drives, cds, memory cards, usb disks.
When infected, it creates the following files:

* \Windows\System32\temp1.exe
* \Windows\System32\temp2.exe
* \Windows\xcopy.exe
* \Windows\Svchost.exe
* \Windows\Autorun.inf

Will also create these in the root every partition:

* \Autorun.inf
* \copy.exe
* \host.exe

Most of the time, your antivirus programs will detect & remove the infected files but that causes a minor side effect. Clicking on your drives would produce error messages about not being able to find "copy.exe"

flash_disinfector Will create a Autorun.inf folder on every drive including the flash drive,
Do Not remove the Autorun.inf folder. It will prevent the infection from creating a new Autorun.inf file.

The forum is run by volunteers who donate their time and expertise.

Want to help others? Join the ClassRoom and learn how.

Logs will be closed if you haven't replied within 3 days

 

If you would like to paypal.gif for the help you received.
 

Proud graduate of TC/WTT Classroom

 

Related Topics



0 user(s) are reading this topic

0 members, 0 guests, 0 anonymous users