Aleks
asked on
Photo.scr
Evening. I have a server that got infected with the file "Photo.scr" and its copied itself to every folder and subfolder on my drive M.
I am trying instructions of what I can find online but with no luck. I can't even delete the file at all, says I don't have permissions to do so.
Has anyone had luck removing this virus ? Also another file seems to have copied itself all over named "info.zip" not sure if they are related.
Help is greatly appreciated.
I am trying instructions of what I can find online but with no luck. I can't even delete the file at all, says I don't have permissions to do so.
Has anyone had luck removing this virus ? Also another file seems to have copied itself all over named "info.zip" not sure if they are related.
Help is greatly appreciated.
SOLUTION
membership
This solution is only available to members.
To access this solution, you must be a member of Experts Exchange.
ASKER CERTIFIED SOLUTION
membership
This solution is only available to members.
To access this solution, you must be a member of Experts Exchange.
You can only get the data back by restoring it.
Run your own antivirus tool followed by Malwarebytes.
Run your own antivirus tool followed by Malwarebytes.
ASKER
Have you fixed this particular file with the recommended software ? "Spybot" ?
You cannot fix the files, just clean up the server.
ASKER
I want to REMOVE files (Photo.scr) not touch any of my clients files which are in the server. Reinstalling and losing data since last backup is not an option.
Those files are not part of your system so all files must be deleted.
Only good Antivirus/Antispy software can do it. Try MylwareBytes as well if you want but I did it one 2 years ago using Spybot
Only good Antivirus/Antispy software can do it. Try MylwareBytes as well if you want but I did it one 2 years ago using Spybot
You are going to discover that life has to have options.
ASKER
I dont mind paying for a good Malware. I do want the "Photo.scr" file deleted, but not all the other files I have in that drive.
Ill download Spybot but I understand you deleted a different malware and not this one in specific.
Ill download Spybot but I understand you deleted a different malware and not this one in specific.
ASKER
I am open to options and I will try the ones that don't affect my clients first.
Clean up your system, delete the photo.scr files and then check if other files are ok. They may or may not be.
ASKER
I can't delete photo.scr files manually, it won't let me. I will try malware software and see if that helps.
Spybot has good feature called Immunization.
Run it also to immunize your system
Run it also to immunize your system
You have a significant problem, have been hit with ransomware, and you probably will have to restore and recover from a good backup.
ASKER
I am running Norton Antivirus too and its showing that is sending the file to quarantine but not sure if just doing this will do.
ASKER
Between SpyBot and Norton it removed the files. Now we are trying to find out how the file got inside in the first place.
.scr is extension for screen saver.
Probably someone got it by email and open it.
Probably someone got it by email and open it.
ASKER
Seems it went through somehow by a web form on a site hosted in that server
ASKER