I'm new, therefore forgive my mistakes if any
My laptop at work was taken by a collegue of mine and returned with a virus/trojan that does:
- Fixes or generates a new autorun.inf in any USB-stick that is inserted to the PC.
- The autorun.inf has the following text:
- The filename inside the RECYCLER directory changes everytime the file is generated.
For my good luck, the McAfee antivirus detects and destroys the executable.
(The generated executable's size is 114688 bytes)
For my bad luck, The Antivirus tool does not find who is generating the trojan file when the disk-on-key is inserted.
For example, if I go to a different clean computer, format the disk-on-key, and then re-insert the clean disk-on-key on the laptop, the result is that the autorun.inf is generated together with the RECYCLER directory + trojan file which is catched by the antivirus...
The files ara also re-generated if they are deleted (after 10-30 secs)
Does anybody knows about this trojan/virus?...
Who is generating the file? (application/service/dll)?
How can I remove it?
Thanks in advance