Link to home
Start Free TrialLog in
Avatar of patyi888
patyi888

asked on

How do I get rid of "Alecks" virus

When I was backing up data from my office PCs (Windows Vista and XP Pro) to an external hard drive, I picked up the virus, "alecks". When I tried to read the data from my notebook, my AVG anti-virus identified several files on the root of the external drive as malicious and I "quarantined" the files as they could not be healed. Now I can't access the hard drive through the "open" or "explore" commands in explorer getting the message that the VB script is missing. When I right click on the external drive, I see Open (alecks). None of my other drives are affected.

How do I get rid of this virus/worm?

ASKER CERTIFIED SOLUTION
Avatar of rpggamergirl
rpggamergirl
Flag of Australia image

Link to home
membership
This solution is only available to members.
To access this solution, you must be a member of Experts Exchange.
Start Free Trial
Avatar of patyi888
patyi888

ASKER

After running combofix, certain files were deleted including e:\autorun.inf. I can now open e: and when I right click on e: I don't see (alecks) next to the open and explore commands. A search of the registry does not show any "alecks" entries except for search because I had searched for alecks files on my computer.

It seems that my problem has been fixed by combofix's malware scanner.

Thanks


log.txt
It appears that the malware scanner in combofix solved the problem by deleting e:\autorun.inf which is a hidden file on the infected external disk. To complete the cleaning, you can also delete the alecks registry entries in [HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints\] which combofix doesn't do.

>>>you can also delete the alecks registry entries in [HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints\] which combofix doesn't do.<<<


Sorry for late reply.
Combofix has a script function that deletes file and reg entries in which we post back to the user after we've seen the log with bad entries, sorry.

Well done on deleting the bad reg entry.


To uninstall Combofix:
Go to Start > Run and copy and paste next command in the field:

ComboFix /u

The procedure will delete the following:
ComboFix and its associated files and folders.
VundoFix backups, if present
The C:\Deckard folder, if present
The C:_OtMoveIt folder, if present
Reset the clock settings.
Hide file extensions, if required.
Hide System/Hidden files, if required.
Set a new, clean Restore Point.
Thanks!