Solved

hdav.exe and file.exe

Posted on 2009-05-14
2
685 Views
Last Modified: 2013-12-09
Does anyone know anything about the virus that resides in the above files ?

I looks like once infected the PC creates an autorun.inf on the root of any connected drive, and also on the root of the same drive creates recycle bin folder named "drive"  containing file.exe which the autorun launches once initiated. Once run file.exe creates a new recycle bin folder named as a random SID  in c:recycler\ containing hdav.exe

Mcafee does not detect a virus after a full scan. There are lots of hits on google from companies selling other anti-virus or spyware products which I'd rather avoid.

Can anyone advise if they know this virus and how to clear it?
0
Comment
Question by:king_sguk
  • 2
2 Comments
 
LVL 8

Accepted Solution

by:
skywalker39 earned 500 total points
ID: 24389276
Try using Spyware Doctor with AntiVirus http://www.pctools.com/spyware-doctor-antivirus/
Also try using Malwarebytes' Anti-Malware http://www.malwarebytes.org/mbam.php
Another is SuperAntiSpyware http://www.superantispyware.com/
Also try Combofix http://www.bleepingcomputer.com/combofix/how-to-use-combofix

Try running all of them in Safe Mode as well in Normal Mode except Combofix.
0
 
LVL 8

Expert Comment

by:skywalker39
ID: 24389285
Run Combofix only in Normal Mode not in Safe Mode.
0

Featured Post

How your wiki can always stay up-to-date

Quip doubles as a “living” wiki and a project management tool that evolves with your organization. As you finish projects in Quip, the work remains, easily accessible to all team members, new and old.
- Increase transparency
- Onboard new hires faster
- Access from mobile/offline

Join & Write a Comment

Suggested Solutions

This is a guide to the following problem (not exclusive but here) on Windows: Users need our support and we supporters often use global administrative accounts to do this. Using these accounts safely is a real challenge. Any admin who takes se…
Many of us in IT utilize a combination of roaming profiles and folder redirection to ensure user information carries over from one workstation to another; in my environment, it was to enable virtualization without needing a separate desktop for each…
This demo shows you how to set up the containerized NetScaler CPX with NetScaler Management and Analytics System in a non-routable Mesos/Marathon environment for use with Micro-Services applications.
When you create an app prototype with Adobe XD, you can insert system screens -- sharing or Control Center, for example -- with just a few clicks. This video shows you how. You can take the full course on Experts Exchange at http://bit.ly/XDcourse.

705 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question

Need Help in Real-Time?

Connect with top rated Experts

20 Experts available now in Live!

Get 1:1 Help Now