Link to home
Start Free TrialLog in
Avatar of Aleks
AleksFlag for United States of America

asked on

Photo.scr

Evening. I have a server that got infected with the file "Photo.scr" and its copied itself to every folder and subfolder on my drive M.
I am trying instructions of what I can find online but with no luck. I can't even delete the file at all, says I don't have permissions to do so.

Has anyone had luck removing this virus ?   Also another file seems to have copied itself all over named "info.zip"  not sure if they are related.

Help is greatly appreciated.
SOLUTION
Avatar of John
John
Flag of Canada image

Link to home
membership
This solution is only available to members.
To access this solution, you must be a member of Experts Exchange.
Start Free Trial
Avatar of Aleks

ASKER

I can't do that as clients upload files every day and if I did that files would be lost and data would be lost from clients. I need to somehow clean the malware from the server.
ASKER CERTIFIED SOLUTION
Avatar of Tom Cieslik
Tom Cieslik
Flag of United States of America image

Link to home
membership
This solution is only available to members.
To access this solution, you must be a member of Experts Exchange.
Start Free Trial
You can only get the data back by restoring it.

Run your own antivirus tool followed by Malwarebytes.
Avatar of Aleks

ASKER

Have you fixed this particular file with the recommended software ?  "Spybot" ?
You cannot fix the files, just clean up the server.
Avatar of Aleks

ASKER

I want to REMOVE files (Photo.scr) not touch any of my clients files which are in the server. Reinstalling and losing data since last backup is not an option.
Those files are not part of your system so all files must be deleted.
Only good Antivirus/Antispy software can do it. Try MylwareBytes as well if you want but I did it one 2 years ago using Spybot
You are going to discover that life has to have options.
Avatar of Aleks

ASKER

I dont mind paying for a good Malware. I do want the "Photo.scr" file deleted, but not all the other files I have in that drive.
Ill download Spybot but I understand you deleted a different malware and not this one in specific.
Avatar of Aleks

ASKER

I am open to options and I will try the ones that don't affect my clients first.
Clean up your system, delete the photo.scr files and then check if other files are ok. They may or may not be.
Avatar of Aleks

ASKER

I can't delete photo.scr files manually, it won't let me. I will try malware software and see if that helps.
Spybot has good feature called Immunization.
Run it also to immunize your system
You have a significant problem, have been hit with ransomware, and you probably will have to restore and recover from a good backup.
Avatar of Aleks

ASKER

I am running Norton Antivirus too and its showing that is sending the file to quarantine but not sure if just doing this will do.
Avatar of Aleks

ASKER

Between SpyBot and Norton it removed the files. Now we are trying to find out how the file got inside in the first place.
.scr is extension for screen saver.
Probably someone got it by email and open it.
Avatar of Aleks

ASKER

Seems it went through somehow by a web form on a site hosted in that server