craigg Posted March 5, 2009 Posted March 5, 2009 We have been unfortunate enough to come accross this virus. It seems to reside in some of our shared folders.... As far as anti virus goes we have got sophos, but even when we do a full system scan it seems to come back. I have read that it spreads through UNC paths and that there is a possibility that it might be on every client so just cleaning the server wont work. Anyone had this? or solved it?
Sophos-Support-5 Posted March 6, 2009 Posted March 6, 2009 We have been unfortunate enough to come accross this virus. We can sometimes class the autorun.inf file as part of a virus when we detect it's trying to call a viral file. The autorun.inf file on its own isn't harmful. Only that it's had its settings changed to load a virus that is (or was) on the removal device. What virus is actually being detected? 1
k-strider Posted March 6, 2009 Posted March 6, 2009 i've seen sophos pick this up when kids stick memory sticks into the machiens... since sophos emails me about the threats its detected and cleaned.... i guess the key is to use software restrictions policies to stop anything being executed from paths other than where you have "programs" that way it has less chance of getting in in the first place! 1
rdk Posted March 8, 2009 Posted March 8, 2009 Someone recommended "autorun eater" a few weeks agos if you do a search. I installed it and it works a treat on USB drives etc to stop it getting into your system in the first place.
mattx Posted March 8, 2009 Posted March 8, 2009 Someone recommended "autorun eater" a few weeks agos if you do a search. I installed it and it works a treat on USB drives etc to stop it getting into your system in the first place. Good tool to use - may add it to the Admin Bar at some point. Download Autorun Eater 2.3 - Scan and Remove Suspicious 'autorun.inf' Files Automatically! - Softpedia is the link. 3
ChrisH Posted March 8, 2009 Posted March 8, 2009 Our SRP stops this running for kids when they try and put it into one of our machines. I have found that our AV sometimes detects it and other times it doesn't. I can tell you for a fact the last one I had couldn't removed by Sophos or NOD. It was one that kept turning view hidden files off. Luckily my machine was dual boot with Ubuntu and clam seemed to nail it.
spchappell Posted March 8, 2009 Posted March 8, 2009 I wrote about our recent battle with the worm and our findings here. http://spchappell.blogspot.com Simon
Recommended Posts
Create an account or sign in to comment
You need to be a member in order to leave a comment
Create an account
Sign up for a new account in our community. It's easy!
Register a new accountSign in
Already have an account? Sign in here.
Sign In Now