How do I get rid of "Alecks" virus

When I was backing up data from my office PCs (Windows Vista and XP Pro) to an external hard drive, I picked up the virus, "alecks". When I tried to read the data from my notebook, my AVG anti-virus identified several files on the root of the external drive as malicious and I "quarantined" the files as they could not be healed. Now I can't access the hard drive through the "open" or "explore" commands in explorer getting the message that the VB script is missing. When I right click on the external drive, I see Open (alecks). None of my other drives are affected.

How do I get rid of this virus/worm?

patyi888Asked:
Who is Participating?
 
rpggamergirlConnect With a Mentor Commented:

Probably just the reg loading point that is left behind that needs to be removed, e.g.
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints\D]

Or, download ComboFix by sUBs and show us the log.
http://download.bleepingcomputer.com/sUBs/ComboFix.exe

You must download it to and run it from your Desktop
Now STOP all your monitoring programs (Antivirus/Antispyware, Guards and Shields) as they could easily interfere with ComboFix.
Double click combofix.exe & follow the prompts.
When finished, it will produce a log. Please save that log and attach it in your next reply by pasting it in the "Code Snippet" or "Attach File" window.
Re-enable all the programs that were disabled during the running of ComboFix..

Note:
Do not mouse-click combofix's window while it is running. That may cause it to stall.

CF disconnects your machine from the internet. The connection is automatically restored before CF completes its run. If CF runs into difficulty and terminates prematurely, the connection can be manually restored by restarting your machine.
0
 
patyi888Author Commented:
After running combofix, certain files were deleted including e:\autorun.inf. I can now open e: and when I right click on e: I don't see (alecks) next to the open and explore commands. A search of the registry does not show any "alecks" entries except for search because I had searched for alecks files on my computer.

It seems that my problem has been fixed by combofix's malware scanner.

Thanks


log.txt
0
 
patyi888Author Commented:
It appears that the malware scanner in combofix solved the problem by deleting e:\autorun.inf which is a hidden file on the infected external disk. To complete the cleaning, you can also delete the alecks registry entries in [HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints\] which combofix doesn't do.

0
 
rpggamergirlCommented:
>>>you can also delete the alecks registry entries in [HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints\] which combofix doesn't do.<<<


Sorry for late reply.
Combofix has a script function that deletes file and reg entries in which we post back to the user after we've seen the log with bad entries, sorry.

Well done on deleting the bad reg entry.


To uninstall Combofix:
Go to Start > Run and copy and paste next command in the field:

ComboFix /u

The procedure will delete the following:
ComboFix and its associated files and folders.
VundoFix backups, if present
The C:\Deckard folder, if present
The C:_OtMoveIt folder, if present
Reset the clock settings.
Hide file extensions, if required.
Hide System/Hidden files, if required.
Set a new, clean Restore Point.
Thanks!
0
Question has a verified solution.

Are you are experiencing a similar issue? Get a personalized answer when you ask a related question.

Have a better answer? Share it in a comment.

All Courses

From novice to tech pro — start learning today.