How to Remove Ahsan and G.W.Bush virus

how can remove Ahsan virus?
RazbaanAsked:
Who is Participating?
I wear a lot of hats...

"The solutions and answers provided on Experts Exchange have been extremely helpful to me over the last few years. I wear a lot of hats - Developer, Database Administrator, Help Desk, etc., so I know a lot of things but not a lot about one thing. Experts Exchange gives me answers from people who do know a lot about one thing, in a easy to use platform." -Todd S.

Peter HartCommented:
this guy seems to have a solution...but I haven't tried it.
http://techspec-gec.blogspot.com/2008/05/i-caught-you-mr-ahsan-remove-ahsans.html
0
Mohamed OsamaSenior IT ConsultantCommented:
All solutions seem to direct to SDFix after the below solution

http://techspec-gec.blogspot.com/2008/05/i-caught-you-mr-ahsan-remove-ahsans.html

keep in mind all cleanup should be done in safe mode from a different user than the previously infected user, after cleanup of Ahsan , Combofix should be able to close this issue & remove the other one.

Good luck, as it seems like a nasty one.
0
rpggamergirlCommented:

Also called W32/Autorun.worm.ct
http://vil.nai.com/vil/content/v_144698.htm

If problem persists,
Flash_Disinfector might also help.
but Combofix is a good idea, you also need to attach the log to make sure there are no other bad files left.

IF you had run rootkit scanners e.g IceSword etc on this session, you must reboot first before running Combofix.

Please download ComboFix by sUBs:
http://download.bleepingcomputer.com/sUBs/ComboFix.exe

You must download it to and run it from your Desktop
Now STOP all your monitoring programs (Antivirus/Antispyware, Guards and Shields) as they could easily interfere with ComboFix.
Double click combofix.exe & follow the prompts.
When finished, it will produce a log. Please save that log and attach it in your next reply by pasting it in the "Code Snippet" or "Attach File" window.
Re-enable all the programs that were disabled during the running of ComboFix..

Note:
Do not mouse-click combofix's window while it is running. That may cause it to stall.
CF disconnects your machine from the internet. The connection is automatically restored before CF completes its run. If CF runs into difficulty and terminates prematurely, the connection can be manually restored by restarting your machine.
0

Experts Exchange Solution brought to you by

Your issues matter to us.

Facing a tech roadblock? Get the help and guidance you need from experienced professionals who care. Ask your question anytime, anywhere, with no hassle.

Start your 7-day free trial
It's more than this solution.Get answers and train to solve all your tech problems - anytime, anywhere.Try it for free Edge Out The Competitionfor your dream job with proven skills and certifications.Get started today Stand Outas the employee with proven skills.Start learning today for free Move Your Career Forwardwith certification training in the latest technologies.Start your trial today
Anti-Virus Apps

From novice to tech pro — start learning today.

Question has a verified solution.

Are you are experiencing a similar issue? Get a personalized answer when you ask a related question.

Have a better answer? Share it in a comment.