Link to home
Start Free TrialLog in
Avatar of jzacher
jzacher

asked on

Worm/Virus

Had a mass mailing virus hit our network, seems to be old, but Trend Micro is not pegging it off.
Subjects: "Jessica would like to be your friend" "Resume-thanks@google.com" ect
Can't find a tool to remove this.  Can anyone help?
Avatar of optoma
optoma
Flag of United States of America image

How many machines in question?

Try the 30day full trial of hitmanpro on them>will work alongside current av(cloud based on demand scanner)

http://www.surfright.nl/en/hitmanpro
ASKER CERTIFIED SOLUTION
Avatar of jzacher
jzacher

Link to home
membership
This solution is only available to members.
To access this solution, you must be a member of Experts Exchange.
Start Free Trial
No prob :)
Avatar of johnb6767
ThreatExpert Report: P2P-Worm.Win32.Agent.aak, Trojan.Mozipowp ...
http://www.threatexpert.com/report.aspx?md5=32e3a254ba8e8b8b2cd9ad042b548c84

If this is the one, you might have some cleanup to do..... Once a machine gets infected, it begins spamming as well....

Check your headers on teh emails to se if they are coming from the server, or another workstation.....
If you still have any problems Run combofix, make sure you read the tutorial.
http://www.bleepingcomputer.com/combofix/how-to-use-combofix
In addition to the other great suggestions posted; if they all fail, try creating a bootable antivirus CD. If that doesn't fix it, then you've got some serious problems. It's always good to keep on hand at anytime:
https://www.experts-exchange.com/questions/25347695/anti-infection-CD-solution.html 
https://www.experts-exchange.com/articles/Storage/Misc/Creating-a-bootable-CD-USB.html 
What I like is that there are just some pesky items that can't be removed while in Windows. I run from a bootable source first, then go into Windows and see what's left over and then deal with it after. The bootable CD sometimes will take care of 80-100% of the infected items; making it that much easier. Best of luck to you.