Solved

user fell for a worm, opened an attachment that said video_fragment.zip

Posted on 2007-11-27
5
216 Views
Last Modified: 2013-11-22
I'm running a Symantec antivirus scan but I'm concerned because use is on an Exchange network.

What is the best way to get rid of this virus?
0
Comment
Question by:mrmyth
  • 3
  • 2
5 Comments
 
LVL 9

Accepted Solution

by:
the_b1ackfox earned 500 total points
ID: 20363817
Unplug the system from the network, reboot in safe mode & run your virus scans.  safe mode is entered by rebooting the system and pressing f8 right before you see the windows logo.
0
 
LVL 9

Expert Comment

by:the_b1ackfox
ID: 20363822
PS check out www.appriver.com  email filtering.  It will remove virus, spam and malware incoming and outgoing.  It is very reasonable.  I even get notices when the email is disrupted for any reason
0
 
LVL 1

Author Comment

by:mrmyth
ID: 20370855
I unplugged the system and ran norton antivirus in safe mode. It took almost all day. The virus still seems to be infecting the computer even though norton quarantined and deleted many files.
0
 
LVL 9

Assisted Solution

by:the_b1ackfox
the_b1ackfox earned 500 total points
ID: 20373058
Is Norton identifying the virus? if so what is the virus called, let me check out it's specs.   Another quick and dirty method, is to take the hardd rive out of the infected system, and connect it to another system.  At this point, I will usually switch up AV engines (Like use the free verion of AVG...)  Whatever you use, make sure it is up to date before you attach the infected harddrive to the system.   Run an AV sweep from the good system to cover the entireity of the infected harddrive.  

In this manner, Windows isn't holding onto the infected files.  If you do not have an additional system available to do this.  then we will need the name of the virus in order to do anything further.  Or is it malware?  (sometimes some av packages will note some malware, but do nothing other than report it... dumb huh?
0
 
LVL 1

Author Comment

by:mrmyth
ID: 20375659
I think I got the little bugger by running Norton Antivirus and then restoring the computer to a previous state before the infection.

From what I understand there was still something in the registry that makes it send out more of these viruses to people in the address book.


0

Featured Post

Networking for the Cloud Era

Join Microsoft and Riverbed for a discussion and demonstration of enhancements to SteelConnect:
-One-click orchestration and cloud connectivity in Azure environments
-Tight integration of SD-WAN and WAN optimization capabilities
-Scalability and resiliency equal to a data center

Question has a verified solution.

If you are experiencing a similar issue, please ask a related question

Suggested Solutions

Title # Comments Views Activity
Ransome Ware Question 10 160
Ransomware 9 97
Protecting a SKY 4.0 (Android) devise 15 141
EmsisoftAntiMalware is it trusted reliable 4 25
This article summarizes using a simple matrix to map the different type of phishing attempts and its targeted victims. It also run through many scam scheme scenario with "real" phished emails. There are safeguards highlighted to stay vigilance and h…
Getting hacked is no longer a matter or "if you get hacked" — the 2016 cyber threat landscape is now titled "when you get hacked." When it happens — will you be proactive, or reactive?
The goal of the tutorial is to teach the user how to select the video input device. Make sure you have an input device that in connected and work and recognized by Adobe Flash Media Live Encoder and select it in the “video input” menu.
The goal of the tutorial is to teach the user how to select which audio input to use. Once you have an audio input plugged into the laptop or computer, you will go into the audio input settings and choose which audio input you want to use.

820 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question