Solved

How to get rid of this virus

Posted on 2011-09-23
13
1,647 Views
Last Modified: 2013-12-09
Hi in my school we recently get this virus that we are calling a porn virus cause when you plug in your flash drive you see all of your normal folders plus dulicate folders ending with .exe....

You also see some new folders named porn.exe etc...

i used mc afee and it fails to pick up this problem....how do i fix these flash drives???
0
Comment
Question by:slingingshot15
  • 4
  • 3
  • 2
  • +2
13 Comments
 
LVL 6

Expert Comment

by:Reubenwelsh
Comment Utility
is this a fully updated version of McAfee you are running? if not you need to run another antivirus till you actually find what it is. Without knowing what virus it is it is very hard to help you solve this issue.

Try downloading Avast or Microsoft Security Essentials, both are two very good antiviruses and see if they can find the virus.

Good luck!
0
 

Author Comment

by:slingingshot15
Comment Utility
yes it is an updated mcafee....
0
 
LVL 6

Expert Comment

by:Reubenwelsh
Comment Utility
Try with another antivirus then, preferably, boot the computer without any 3rd party software running but the antivirus and see if this helps. (run MSCONFIG and turn of all services exept the antivirus and see if that finds anything.
0
 
LVL 26

Expert Comment

by:Thomas Zucker-Scharff
Comment Utility
You should be using flash disinfector and usb-set.  This will disinfect your USB sticks and kill any autorun files that may be used as a vector.

Use Malwarebytes or Avast! to scan your computers.
0
 
LVL 29

Expert Comment

by:Sudeep Sharma
Comment Utility
I would recommend you to go through the articles from Younghv that would help you in getting rid of it completly. In short you would need to run Rogue Killer before MalwareBytes full system scan and post the logs here if the problem persists

http://www.experts-exchange.com/A_4922.html (Rogue-Killer-What-a-great-name)
http://www.experts-exchange.com/A_5124.html (Stop-the-Bleeding-First-Aid-for-Malware)
http://www.experts-exchange.com/A_1940.html (Basic Malware Troubleshooting)

I hope that would help.

Sudeep
0
 
LVL 29

Expert Comment

by:Sudeep Sharma
Comment Utility
Not to mention that you would also need to update the system with Microsoft windows update once you are finished cleaning the system.
0
What Security Threats Are You Missing?

Enhance your security with threat intelligence from the web. Get trending threat insights on hackers, exploits, and suspicious IP addresses delivered to your inbox with our free Cyber Daily.

 
LVL 47

Accepted Solution

by:
rpggamergirl earned 500 total points
Comment Utility
Run combofix, you need to disable Mcafee shield first so it won't eat combofix's files.


Please download ComboFix by sUBs:
http://download.bleepingcomputer.com/sUBs/ComboFix.exe

STOP all your monitoring programs (Antivirus/Antispyware, Guards and Shields) as they could easily interfere with ComboFix.
Double click combofix.exe & follow the prompts.
When finished, it will produce a log. Please save that log and attach it in your next reply.
Note:
Do not mouse-click combofix's window while it is running. That may cause it to stall.

ComboFix tutorial:
http://www.bleepingcomputer.com/combofix/how-to-use-combofix
0
 

Author Comment

by:slingingshot15
Comment Utility
this is the log file of combo fix
log.txt
0
 

Author Comment

by:slingingshot15
Comment Utility
also will this clean flash drives too?
0
 
LVL 47

Expert Comment

by:rpggamergirl
Comment Utility
CF had deleted some bad files there.
No it doesn't clean flashdrives, it only remove flash drive infections that are already in the system.

Try the flash_disinfector that tzucker posted, that removes flash drive infections also(hasn't been updated since combofix also started removing flashdrive infections) sUBs created both tools, other advantage of the Flash_disinfector is it will create bogus autorun.inf folder in each partition.
0
 

Author Comment

by:slingingshot15
Comment Utility
thanks a lot.....one other question....in our school all we have in terms of security is mc affee antivirus....

what do you all suggest? is that anti virus good enough or should we have other software on these machines
0
 
LVL 47

Expert Comment

by:rpggamergirl
Comment Utility
If McAfee is what's installed there now then I wouldn't suggest changing it till the subscription is due. Antiviruses are basically similar, some may have better detection than others but in terms of rogues none of them are effective.

If the McAfee installed is just an antivirus then you still need anti-malware unless it's a security suite.
The most effective anti-malware so far is MalwareBytes and it's cheap enough you can also get licenses for multiples machines.
http://www.malwarebytes.org/
0
 
LVL 26

Expert Comment

by:Thomas Zucker-Scharff
Comment Utility
I prefer ESET products myself.  I suggest to most users that they use ESET Smart Security.  Is is low maintenance, has a great admin interface, checks connected computers for windows updates as well as installing it's own firewall.  The updates are more frequent so they are smaller and in that way the ESET product takes up a lot less resources.

ESET http://www.eset.com/us/
0

Featured Post

Why You Should Analyze Threat Actor TTPs

After years of analyzing threat actor behavior, it’s become clear that at any given time there are specific tactics, techniques, and procedures (TTPs) that are particularly prevalent. By analyzing and understanding these TTPs, you can dramatically enhance your security program.

Join & Write a Comment

For those of you actively in the Malware fightling business, we now have available an amazing new tool in the malware wars (first recommended to me by rpggamergirl (http://www.experts-exchange.com/M_3598771.html), the Zone Advisor for the Virus and …
I recently had to create a utility which aim is to update McAfee's Virusscan and that had to be launched from a command line. I thought I’d share my experience with you. Why is it useful to be able to update an Antivirus from the command line?…
It is a freely distributed piece of software for such tasks as photo retouching, image composition and image authoring. It works on many operating systems, in many languages.
Internet Business Fax to Email Made Easy - With eFax Corporate (http://www.enterprise.efax.com), you'll receive a dedicated online fax number, which is used the same way as a typical analog fax number. You'll receive secure faxes in your email, fr…

772 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question

Need Help in Real-Time?

Connect with top rated Experts

12 Experts available now in Live!

Get 1:1 Help Now