?
Solved

How do I get rid of "Alecks" virus

Posted on 2008-10-24
4
Medium Priority
?
404 Views
Last Modified: 2013-11-22
When I was backing up data from my office PCs (Windows Vista and XP Pro) to an external hard drive, I picked up the virus, "alecks". When I tried to read the data from my notebook, my AVG anti-virus identified several files on the root of the external drive as malicious and I "quarantined" the files as they could not be healed. Now I can't access the hard drive through the "open" or "explore" commands in explorer getting the message that the VB script is missing. When I right click on the external drive, I see Open (alecks). None of my other drives are affected.

How do I get rid of this virus/worm?

0
Comment
Question by:patyi888
[X]
Welcome to Experts Exchange

Add your voice to the tech community where 5M+ people just like you are talking about what matters.

  • Help others & share knowledge
  • Earn cash & points
  • Learn & ask questions
  • 2
  • 2
4 Comments
 
LVL 47

Accepted Solution

by:
rpggamergirl earned 2000 total points
ID: 22802364

Probably just the reg loading point that is left behind that needs to be removed, e.g.
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints\D]

Or, download ComboFix by sUBs and show us the log.
http://download.bleepingcomputer.com/sUBs/ComboFix.exe

You must download it to and run it from your Desktop
Now STOP all your monitoring programs (Antivirus/Antispyware, Guards and Shields) as they could easily interfere with ComboFix.
Double click combofix.exe & follow the prompts.
When finished, it will produce a log. Please save that log and attach it in your next reply by pasting it in the "Code Snippet" or "Attach File" window.
Re-enable all the programs that were disabled during the running of ComboFix..

Note:
Do not mouse-click combofix's window while it is running. That may cause it to stall.

CF disconnects your machine from the internet. The connection is automatically restored before CF completes its run. If CF runs into difficulty and terminates prematurely, the connection can be manually restored by restarting your machine.
0
 

Author Comment

by:patyi888
ID: 22803662
After running combofix, certain files were deleted including e:\autorun.inf. I can now open e: and when I right click on e: I don't see (alecks) next to the open and explore commands. A search of the registry does not show any "alecks" entries except for search because I had searched for alecks files on my computer.

It seems that my problem has been fixed by combofix's malware scanner.

Thanks


log.txt
0
 

Author Comment

by:patyi888
ID: 22806777
It appears that the malware scanner in combofix solved the problem by deleting e:\autorun.inf which is a hidden file on the infected external disk. To complete the cleaning, you can also delete the alecks registry entries in [HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints\] which combofix doesn't do.

0
 
LVL 47

Expert Comment

by:rpggamergirl
ID: 22811892
>>>you can also delete the alecks registry entries in [HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints\] which combofix doesn't do.<<<


Sorry for late reply.
Combofix has a script function that deletes file and reg entries in which we post back to the user after we've seen the log with bad entries, sorry.

Well done on deleting the bad reg entry.


To uninstall Combofix:
Go to Start > Run and copy and paste next command in the field:

ComboFix /u

The procedure will delete the following:
ComboFix and its associated files and folders.
VundoFix backups, if present
The C:\Deckard folder, if present
The C:_OtMoveIt folder, if present
Reset the clock settings.
Hide file extensions, if required.
Hide System/Hidden files, if required.
Set a new, clean Restore Point.
Thanks!
0

Featured Post

Hire Technology Freelancers with Gigs

Work with freelancers specializing in everything from database administration to programming, who have proven themselves as experts in their field. Hire the best, collaborate easily, pay securely, and get projects done right.

Question has a verified solution.

If you are experiencing a similar issue, please ask a related question

Have you ever tried to find someone you know on Facebook and searched to find more than one result with the same picture? Perhaps someone you know has told you that they have a 'facebook stalker' or someone who is 'posing as them' online and ta…
Ransomware continues to be a growing problem for both personal and business users alike and Antivirus companies are still struggling to find a reliable way to protect you from this dangerous threat.
Established in 1997, Technology Architects has become one of the most reputable technology solutions companies in the country. TA have been providing businesses with cost effective state-of-the-art solutions and unparalleled service that is designed…
Email security requires an ever evolving service that stays up to date with counter-evolving threats. The Email Laundry perform Research and Development to ensure their email security service evolves faster than cyber criminals. We apply our Threat…

718 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question