Just curious if anyone else has been seeing this virus since I originally posted. It really turned out to be very nasty, posting questions about internet security, etc. The virus is well known and I believe part of Conflicker. Two things I didn't realize--one that it bypassed all the virus software we had--both Trend home and Trend enterprise--on machines that became infected. Second, how it was spread. I reformatted one machine, and within about 15 minutes the virus reappeared. The only thing I had done was put in a thumb drive with some files from the original machine. Nothing was executed, no documents were accessed, but the virus reappeared, even though the thumb drive scanned clean. Apparently thumbdrives will execute an autorun file when inserted, and it's difficult to turn this setting off in XP. Most people don't even realize that thumbdrives will auto execute something, so they haven't looked to turn that setting off. As soon as the thumb drive was inserted into the machine, boom the virus ran and reinfected the newly formatted machine. I had no idea anything had run, and it really fooled me. It's definitely something to be aware of and look out for!
Main Topics
Browse All Topics





by: vikingtechnologiesPosted on 2009-08-27 at 23:41:16ID: 25205414
You can modify the autorun.ini and delete the line that refers to bootex\thumbcache_131.exe and then the directory bootex. bootex\thumbcache_131.exe is definitely a virus.