Best way to remove Worm:Win32/Phorpiex.B
Posted on 2011-10-20
We are using Microsoft Forefront in our organisation, but one site is badly infected with Worm:Win32/Phorpiex.B and Forefront is not helping much. This is what a colleague sent me:
1. Last night, I left my machine scanning with FEP in Safe Mode – Unfortunately I couldn’t see the results as the machine was rebooted over night
2. Upon rebooting the machine in the Standard mode, FEP identifies a virus known as ‘Worm:Win32/Phorpiex.B ’, which I removed instead to disinfect or quarantine
3. I then scanned USB with FEP but it neither identified or removed the virus from it
4. I then used the tool ‘Virus Shortcut Remover’ to remove malicious application from the USB. Contrary to the previous behavior of this variant of virus, it has stopped repeating/coming back to USB. This result indicates that my computer is cleaned form virus or at least we can say that it is not affecting the USB disk drives any more.
A machine infected with ‘Worm:Win32/Phorpiex.B ’ gets slow but as such this virus doesn’t affect the data (files and folders). However it infects the USBs by changing the file type to Shortcut (.lnk) as well as hide files and folders inside it.
FEP doesn’t identify or remove the virus from USBs. This worm can be removed and the files and folder are restored by using the tool ‘Virus Shortcut Remover’.
FEP doesn’t identify or catch the virus on Full Scan in ladmin mode. It also doesn’t catch the virus in Safe Mode either.
However it is recommended to run a Full scan in Safe Mode. On next reboot in a standard mode, it is very likely that FEP would catch ‘Worm:Win32/Phorpiex.B’. It is recommend to remove the worm instead of disinfect or quarantine.
The main problem is that Forefront is not removing the virus from the USB drives.
The other problem is that I'm not sure if I trust the ‘Virus Shortcut Remover’ tool completely since there are few references to it in forums that I trust.
The microsoft website refers to this virus and it has been the Forefront defnitions for months - but it's still not cleaning it off USB drives.
What is the best thing to do next, please?