Link to home
Start Free TrialLog in
Avatar of Taqvi11
Taqvi11

asked on

Found.000\USB_Files.chk

I am facing some problem in my network becuse of some viruses. all foldersand thire child folders  in my server have some hidden and protected files named Found.000 and Autorun.inf. While if i open Autorun.inf it has text as following...
"[Autorun]
Explore=Found.000\USB_Files.chk
shellexecute=Found.000\USB_Files.chk
shell\Explore\command=Found.000\USB_Files.chk
Open=Found.000\USB_Files.chk
shell\Open\command=Found.000\USB_Files.chk"

So Please Help Me to solve this problem.
Avatar of rpggamergirl
rpggamergirl
Flag of Australia image


Hi Taqvi11,

What scanners have you tried using to remove the virus?

Try running these:
1.  Download Malwarebytes' Anti-Malware to your desktop, check for Updates before scanning.
http://www.malwarebytes.org/mbam.php

2.  DrWebCureIt:
http://www.freedrweb.com/cureit/

Let us know how you go.
Avatar of Taqvi11
Taqvi11

ASKER

I Have Tried these but failed. I have even deleted these files from one computer by booting system  with ERD. but when i logged in as normal mode it was still there. I think it creates some hidden processes but i am not sure about that. Please if someone has solution for that please help me. you can see these files after enabling three options under "FOLDER OPTION" as shown in attached picture number one and two.
1.JPG
2.JPG
ASKER CERTIFIED SOLUTION
Avatar of rpggamergirl
rpggamergirl
Flag of Australia image

Link to home
membership
This solution is only available to members.
To access this solution, you must be a member of Experts Exchange.
Start Free Trial
Avatar of Taqvi11

ASKER

hello rpggamergirl,

i have tried it. but it creates some other undeleteable folders. but when tried in other comuter it was not working. So it's fifty fifty. Please give 100% solution if you can. thank you.
I appriciate your help.
Thanks And Regards,
Taqvi.
Taqvi,

Flash_Disinfector does create autorun.inf folder but that folder is a harmless one, that's created to stop the spread of the infection.
Is that what you meant?

We've also expected you to attach the combofix log so we can check for any bad files that need to be removed using combofix script function.

You didn't have to close your question yet.