Solved

Folder Exe Virus : How to remove :

Posted on 2011-09-13
9
625 Views
Last Modified: 2013-12-09
My Lap top is infected by a virus which is making new files inside each folder having same
name as of folder ... Kindly help .. How to remove ... I  many anti virus including

Avira
Avast
Microsoft Security Essential

My Windows Xp is also updated  and genuine. .
0
Comment
Question by:Puneet Arora
9 Comments
 
LVL 17

Expert Comment

by:pjam
ID: 36528912
Try Microsoft Stnadalone Sweeper.  You create Windows type boot CD updated from Microsoft Security essentials.  You will need to make the CD on a clean comuter of course.  You can find it at:
http://connect.microsoft.com/systemsweeper
 
0
 
LVL 38

Assisted Solution

by:younghv
younghv earned 100 total points
ID: 36528928
I haven't seen 'folder replicating' malware for several years, but this may be a new variant.

Please take the time to describe the steps you have taken. Your comment indicates that you may have installed multiple AV programs on your computer - which is not something you should do:

 
[I  many anti virus including ]
[Avira ]
[Avast ]
[Microsoft Security Essential]

Open in new window


As a general recommendation, I suggest that you install and run RogueKiller, followed immediately by Malwarebytes - then post the logs that are generated for us to review.

Detailed instructions in this EE Article:
Rogue-Killer-What-a-great-name
0
 

Author Comment

by:Puneet Arora
ID: 36529103

    It is making file name same as the name of folder + adding  . exe   .. e.g If the folder name is

    Puneet .. this virus will make a file called Puneet.exe..


     
0
 
LVL 17

Expert Comment

by:Shanmuga Sundaram
ID: 36529119
Are Task Manager, Registry Editor, Folder Options, Run in start menu disabled in your computer?

0
Why You Should Analyze Threat Actor TTPs

After years of analyzing threat actor behavior, it’s become clear that at any given time there are specific tactics, techniques, and procedures (TTPs) that are particularly prevalent. By analyzing and understanding these TTPs, you can dramatically enhance your security program.

 
LVL 20

Assisted Solution

by:Hendrik Wiese
Hendrik Wiese earned 400 total points
ID: 36529126
We had the same issue not to long ago. Use the following application. It was the only app that scanned and removed the exe files:

Application Name: Dr.Web CureIt!®
Download Link: http://www.freedrweb.com/cureit/?lng=en
0
 

Author Comment

by:Puneet Arora
ID: 36534500
Task Manager, Registry Editor, Folder Options, Run in start menus are not  disabled ...


It is only making folderName.exe files in each folder ....rapidly
0
 
LVL 20

Assisted Solution

by:Hendrik Wiese
Hendrik Wiese earned 400 total points
ID: 36534516
puneetarora2000, honestly try my suggestion as this is the only application that worked for us.
0
 

Author Comment

by:Puneet Arora
ID: 36534526

Dear HendrikWiese:

I m allready running the scan ... I have downloaded the free version ... will it work ...
0
 
LVL 20

Accepted Solution

by:
Hendrik Wiese earned 400 total points
ID: 36534539
Yes the free version will work and removes the files. :)
0

Featured Post

Do You Know the 4 Main Threat Actor Types?

Do you know the main threat actor types? Most attackers fall into one of four categories, each with their own favored tactics, techniques, and procedures.

Join & Write a Comment

Suggested Solutions

These are on the increase and getting more common these days. Users who use the Google search engine may complain of having their search redirected to unwanted sites, regardless of what browser is used. This happens when the system is infected with…
Article by: btan
Provide an easy one stop to quickly get the relevant information on common asked question on Ransomware in Expert Exchange.
This tutorial demonstrates a quick way of adding group price to multiple Magento products.
You have products, that come in variants and want to set different prices for them? Watch this micro tutorial that describes how to configure prices for Magento super attributes. Assigning simple products to configurable: We assigned simple products…

747 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question

Need Help in Real-Time?

Connect with top rated Experts

11 Experts available now in Live!

Get 1:1 Help Now