A user inserted a USB flash drive into their PC and ran a file which they saw to have their user name on. Ie. daves photos. This initially opened some pop up screens, emptied the Recycle bin and ran what looked to be a VB script. It then began deleting files that they had access to accross the network including mapped drives. After the file has run it adds an entry to the start up config file called davesphotos.exe (takes on the user name of the PC it is installed on). An AOL 9.0 icon also appears on the desktop although information I have found on this does not indicate deletion of files.
This is the second time this has happened and each time the file has renamed itself to be the name of the user. Our anti virus did not in any way react to the file. I am unable to find any information on it.
Start Free Trial