BleepingComputer.com: AutoRun.B worm

Jump to content


Register a free account to unlock additional features at BleepingComputer.com
Welcome to BleepingComputer, a free community where people like yourself come together to discuss and learn how to use their computers. Using the site is easy and fun. As a guest, you can browse and view the various discussions in the forums, but can not create a new topic or reply to an existing one unless you are logged in. Other benefits of registering an account are subscribing to topics and forums, creating a blog, and having no ads shown anywhere on the site.

Click here to Register a free account now! or read our Welcome Guide to learn how to use this site.

Forum Rules

When posting your problem, do not run and post a ComboFix log. ComboFix is a tool that should only be run under the supervision of someone who has been trained in its use. Using it on your own can cause problems with your computer. Any posts containing CF Logs will be ignored.

To receive help, you should instead provide a detailed description of your problem, detailed word-for-word error messages that you are receiving, screenshots of strange behaviour, and your operating system. This information is much more useful to our helpers than a ComboFix log.


If you have not received help after three days, please post a link to your topic HERE.
Page 1 of 1
  • You cannot start a new topic
  • You cannot reply to this topic

AutoRun.B worm Help is needed

#1 User is offline   iwasstupid 

  • New Member
  • Pip
  • Find Topics
  • Group: Members
  • Posts: 1
  • Joined: 20-November 09

Posted 20 November 2009 - 08:00 AM

As the topic has suggested,its related to that dangerous Worm,its not my computer that has that,its my dad's company computer,and that worm is hidding my dad's files and disabled the com's Task Manager,Autorun and stuff,its night time here,i cant go to my dads company to check it out :flowers:.It happened today so i hope it wont be so serious...but i need help from those who know how to remove it :trumpet:.Please Help! :thumbsup:

Heres the link for the description of this Virus

Edit:It works on a WinXP OS and the virus was detected in the System32 folder(Test it out on my old com) and the com was infected due to the USB my dad use.

This post has been edited by iwasstupid: 20 November 2009 - 08:02 AM


#2 User is offline   garmanma 

  • Computer Masochist
  • PipPipPipPipPipPip
  • Find Topics
  • Group: Staff Emeritus
  • Posts: 27,809
  • Joined: 27-January 07
  • Location:Cleveland, Ohio

Posted 20 November 2009 - 11:25 AM

Welcome to BC
By your description it sounds like you have a very persistent rootkit infection
There is no easy way, no single application you can run to remove it
It must be done in our HJT forum using a variety of tools and custom batch scripts
There is a backlog and a wait time of close to a week and you would need access to his computer to do it
He would be better off to wipe it clean and reload the OS


Before he uses the flash drive again, hold down the shift key, insert the drive in your computer, and run this application

Flash_Disinfector.exe by sUBs and save it to your desktop.
  • Double-click Flash_Disinfector.exe to run it and follow any prompts that may appear.
  • The utility may ask you to insert your flash drive and/or other removable drives. Please do so and allow the utility to clean up those drives as well.
  • Hold down the Shift key when inserting the drive until Windows detects it to keep autorun.inf from executing if it is present.
  • Wait until it has finished scanning and then exit the program.
  • Reboot your computer when done.
Note: As part of its routine, Flash_Disinfector will create a hidden folder named autorun.inf in each partition and every USB drive that was plugged in when you ran it. Do not delete this folder...it will help protect your drives from future infection by keeping the autorun file from being installed on the root drive and running other malicious files.
Mark
Posted Image
why won't my laptop work?

Having grandkids is God's way of giving you a 2nd chance because you were too busy working your butt off the 1st time around
Do not send me PMs with problems that should be posted in the forums. Keep it in the forums, so everyone benefits
Become a BleepingComputer fan: Facebook and Twitter

Share this topic:


Page 1 of 1
  • You cannot start a new topic
  • You cannot reply to this topic

1 User(s) are reading this topic
0 members, 1 guests, 0 anonymous users