Solved

W32/Generic!worm

Posted on 2007-03-24
3
1,984 Views
Last Modified: 2013-12-09
My Mcafee Detects the folowing virus for so many times but is only able to delete it but can't remove it from the system. Please tell me any free utility to remove it from my System

sal.xls.exe      W32/Generic!worm (Virus)
0
Comment
Question by:tsultan
  • 2
3 Comments
 
LVL 97

Accepted Solution

by:
war1 earned 500 total points
ID: 18787409
tsultan,

The worm may be in System Restore, so that is why you cannot delete it. Disable system restore.

This is Trend Micro description of the worm
http://www.trendmicro.com/vinfo/virusencyclo/default5.asp?VName=WORM_VB.CII

Here is how to remove it
http://www.trendmicro.com/vinfo/virusencyclo/default5.asp?VName=WORM%5FVB%2ECII&VSect=Sn
0
 
LVL 47

Expert Comment

by:rpggamergirl
ID: 18787595
That's called  "flashdrive' infection, in every root partition it creates the files below: You need to remove autorun.inf in every root partition, it's hidden, you can see it in DOS prompt.

* \Autorun.inf --> used to autorun the worm when the drive is accessed, so must be removed.
* \sal.xls.exe
*Windows\ufdata2000.log

I would suggest running "Flash_Disinfector.exe" not sure if "sal.xls.exe" variant is covered yet but the tool creates a bogus "autorun.inf" which would help prevent the worm from loading and spreading.

http://www.techsupportforum.com/sectools/sUBs/Flash_Disinfector.exe
According to the author, when flash_disinfector is run, it will create a bogus folder, autorun.inf in every partition. It wont stop the infected file from getting in, but it does prevent the loading point from getting created.


PrevX:(claims to remove it)
http://spywarefiles.prevx.com/RRDFGG29969813/SAL.XLS.EXE.html
0
 
LVL 97

Expert Comment

by:war1
ID: 18809816
tsultan, any update?
0

Featured Post

IT, Stop Being Called Into Every Meeting

Highfive is so simple that setting up every meeting room takes just minutes and every employee will be able to start or join a call from any room with ease. Never be called into a meeting just to get it started again. This is how video conferencing should work!

Join & Write a Comment

PREFACE The purpose of this guide is to explain what the SEPC Status Utility is and how it works. I have written the utility using AutoIt and have included the source code for your review. You are welcome to modify the code to your liking, but I wi…
HOW TO REMOTELY CLEAN MEROND.O WITH ESET SILENTLY PROBLEM       If you have the fortunate luck to contract the Merond.O virus on your network, it can be quite troublesome to remove as it propagates to network shares on your network. In my case, the …
This video gives you a great overview about bandwidth monitoring with SNMP and WMI with our network monitoring solution PRTG Network Monitor (https://www.paessler.com/prtg). If you're looking for how to monitor bandwidth using netflow or packet s…
You have products, that come in variants and want to set different prices for them? Watch this micro tutorial that describes how to configure prices for Magento super attributes. Assigning simple products to configurable: We assigned simple products…

747 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question

Need Help in Real-Time?

Connect with top rated Experts

12 Experts available now in Live!

Get 1:1 Help Now