Go Premium for a chance to win a PS4. Enter to Win

x
?
Solved

hdav.exe and file.exe

Posted on 2009-05-14
2
Medium Priority
?
700 Views
Last Modified: 2013-12-09
Does anyone know anything about the virus that resides in the above files ?

I looks like once infected the PC creates an autorun.inf on the root of any connected drive, and also on the root of the same drive creates recycle bin folder named "drive"  containing file.exe which the autorun launches once initiated. Once run file.exe creates a new recycle bin folder named as a random SID  in c:recycler\ containing hdav.exe

Mcafee does not detect a virus after a full scan. There are lots of hits on google from companies selling other anti-virus or spyware products which I'd rather avoid.

Can anyone advise if they know this virus and how to clear it?
0
Comment
Question by:king_sguk
  • 2
2 Comments
 
LVL 8

Accepted Solution

by:
skywalker39 earned 1000 total points
ID: 24389276
Try using Spyware Doctor with AntiVirus http://www.pctools.com/spyware-doctor-antivirus/
Also try using Malwarebytes' Anti-Malware http://www.malwarebytes.org/mbam.php
Another is SuperAntiSpyware http://www.superantispyware.com/
Also try Combofix http://www.bleepingcomputer.com/combofix/how-to-use-combofix

Try running all of them in Safe Mode as well in Normal Mode except Combofix.
0
 
LVL 8

Expert Comment

by:skywalker39
ID: 24389285
Run Combofix only in Normal Mode not in Safe Mode.
0

Featured Post

When ransomware hits your clients, what do you do?

MSPs: Endpoint security isn’t enough to prevent ransomware.
As the impact and severity of crypto ransomware attacks has grown, Webroot has fought back, not just by building a next-gen endpoint solution capable of preventing ransomware attacks but also by being a thought leader.

Question has a verified solution.

If you are experiencing a similar issue, please ask a related question

No security measures warrant 100% as a "silver bullet". The truth is we also cannot assume anything but a defensive and vigilance posture. Adopt no trust by default and reveal in assumption. Only assume anonymity or invisibility in the reverse. Safe…
If you are like me and like multiple layers of protection, read on!
Established in 1997, Technology Architects has become one of the most reputable technology solutions companies in the country. TA have been providing businesses with cost effective state-of-the-art solutions and unparalleled service that is designed…
Email security requires an ever evolving service that stays up to date with counter-evolving threats. The Email Laundry perform Research and Development to ensure their email security service evolves faster than cyber criminals. We apply our Threat…

971 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question