Thursday, December 20, 2007

A virus has been spreading around and it cannot be detected by most commercial Antivirus such as Symantec, Eset Nod32 and Kaspersky.

Virus Information

Recycled --> Info.exe


How it propagates ?

When the user double clicks the infected drive, Info.exe in the recycled folder will be run via autorun.

Photobucket

File System Modifications

- %Windir%\Config\Svchost.exe (Virus.Win32.AutoRun.aim)
- %Windir%\Config\System.exe (Virus.Win32.AutoRun.aim)
- %Windir%\System.exe

Recycled & Autorun.inf created in every active drive.


Symptoms

- Unable to view "Hide protected operating system files (Recommended)"
- Probably transmits data over the network


Removal Instructions

1) Enter Task Manager, End process: System.exe
2) Download 7-zip from www.7-zip.org
3) Use 7-Zip to browse infected files in stated locations and delete them
4) Turn off System Restore
5) Run Virus Scan and remove all virus found

Alternative Removal Instruction (Advanced Users)

1) Enter Task Manager, End process: System.exe
2) Go to run, type Cmd
3) Type attrib -s -h C:\*.*
4) Delete Infected files in stated locations
5) Turn off System Restore
6) Run Virus Scan and remove all virus found
7) Run cmd and type attrib +s +h C:\*.*


@ ITSecure 2:36 PM

Disclaimer

CLICK HERE FOR DISCLAIMER

For more Information Contact ISAAC

Useful Links

  • Microsoft
  • AV Comparatives
  • Virus.gr
  • Virus Bulletin

  • Anti-Virus Solutions

  • VirusTotal Scanner
  • Nod32 AntiVirus
  • Symantec Antivirus
  • Grisoft AVG FREE
  • AVAST Home Edition FREE
  • Bitdefender FREE
  • Rising Antivirus FREE

  • FREE Anti-Spyware Softwares

  • Spybot S&D
  • Ad-Aware 2007
  • Spyware Terminator 2
  • SpyCatcher Express

  • FREE Firewalls

  • Comodo Firewall (Recommend)
  • Ashampoo Firewall
  • PC Tools Firewall
  • Outpost Firewall Free
  • ZoneAlarm Firewall

  • Zero Day Intrusion

  • Process Guard (Advanced User)

  • Computer Management (A-Z)

  • Abexo Registry Cleaner
  • Advanced WindowsCare
  • CCleaner
  • Eusing Registry Cleaner
  • Iobit SmartDefrag
  • Microsoft Tweak UI
  • Hoverdesk RegSeeker

  • Discussion Corner





    Memories

    December 2007
    January 2008
    February 2008
    March 2008
    April 2008
    May 2008
    August 2008

    Credits

    StoneSoft
    Helpdesk Technician Blog