Jump to content

Recommended Posts

Posted (edited)

We have a virus outbreak on our network. The virus in concern is Mal/AutoInf-A. The virus initially seems to have come via USB memory sticks. Mal/AutoInf-A then spreads to all mapped network drives, it drops "Troj/VB-CSA" and also creates a ctfmon.exe

Win32/FakeRecycled.A - CA

 

I have disabled the autorun on memory sticks and applied the Microsoft patch.

We have Sophos on the server and all client PC's and is fully up-to-date with daily scheduled scans.

However Sophos finds the virus and says it has deleted it on the server but then 30 seconds later finds the virus again.

The client PCs Sophos reports on daily scan "The attempt to delete the infected file H:autorun.inf failed the user dose not have the rights to perform the action on the infected file."

I have placed all the users in the Sophos Power user group.

 

It is the first year that we have used Sophos and I think it has been a real let down as we it should be blocking the virus or cleaning it up because we never had a virus problem with Symantec before.

 

Any advice would be appreciated on how to get rid of this virus?

 

Thanks

Edited by AM_LHS
Posted

Isolate the server first and look at cleaning it up totally then before you attempt to rejoin it to the network rebuild all infected workstations.

 

Check all the other servers in the domain also.

 

If this does not work then totally rebuilding the server + all workstations is the only other option open to you.

 

Fully empathise with you on this one. :( ;) :)

 

Good luck ;) :)

Posted
A bit late to say this I know, but why is autorun enabled, and why was the student able to the NastyVirus.exe file which the autorun was calling?
Posted

You might also want to have a read of this and use the registry key below to prevent re-infection.

 

Windows Registry Editor Version 5.00

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\IniFileMapping\Autorun.inf]
""="@SYS:DoesNotExist"

  • Thanks 1
Posted

This is probably slightly off topic, but i had this on a few memory sticks and i had it on my 1TB hard drive the other day.

 

So, i had a macbook in my office and i put my hard drive on there and it showed the auto.inf file and exe so i just deleted them and that got rid of the virus and my hard drive worked fine on a windows machine. i'm guessing if you put this on a linux box as well you would be able to do the same.

 

I know it dont solve the problem but it is a nice easy way to get rid of it. :)

 

James.

Posted

I made a program to get rid of it (the autorun.inf file). You can download it from filefront.

Version 1.0

[ame=http://files.filefront.com/Mal+AutoInf+A+VirusRemoverzip/;13092507;/fileinfo.html]Mal/AutoInf-A VirusRemover.zip Download File[/ame]

Version 2.0

[ame=http://files.filefront.com/Mal+AutoInf+A+VirusRemoverzip/;13762227;/fileinfo.html]Mal/AutoInf-A_VirusRemover.zip Download File[/ame]

 

It works by not deleting it, but by REPLACING the autorun file with another. Essentially, it makes an autorun file over the top of the autorun from the virus. Or, you could simply not download the program, and make your own blank autorun.inf, then copy and paste (or move) it to where the infected autorun.inf is. Deleting it didn't work for me either, but this did- on multiple computers at school and on a friend's flash drive.

 

Hope this helps.

Posted (edited)
Deleting it didn't work for me either, but this did- on multiple computers at school and on a friend's flash drive.

Did you have Autorun disabled for all devices before plugging any infected media into your system otherwise it plays with your system makes it call the program from the os so that it gets marked as being in use.

Edited by p858snake
Posted
Did you have Autorun disabled for all devices before plugging any infected media into your system otherwise it plays with your system makes it call the program from the os so that it gets marked as being in use.

 

Autorun was enabled.

  • 4 months later...
Posted
I made a program to get rid of it (the autorun.inf file). You can download it from filefront.

Version 1.0

Mal/AutoInf-A VirusRemover.zip Download File

Version 2.0

Mal/AutoInf-A_VirusRemover.zip Download File

 

It works by not deleting it, but by REPLACING the autorun file with another. Essentially, it makes an autorun file over the top of the autorun from the virus. Or, you could simply not download the program, and make your own blank autorun.inf, then copy and paste (or move) it to where the infected autorun.inf is. Deleting it didn't work for me either, but this did- on multiple computers at school and on a friend's flash drive.

 

Hope this helps.

 

I tried your secound software but it didnt let me to overright. givin a error message syin This file have been used by anotherprogram.?? help

Posted
If it's anything like the virus we had, the best option is to disable autorun entirely first e.g. using the method I posted above and then remove the Autorun.inf and associated .exe either automatically using anti-virus software or manually by deleting the files yourself.
Posted
If it's anything like the virus we had, the best option is to disable autorun entirely first e.g. using the method I posted above and then remove the Autorun.inf and associated .exe either automatically using anti-virus software or manually by deleting the files yourself.

 

This worked for me

Posted
Use group policy to disable Autorun network wide, thius will provent these Autorun virus's from spreading, and then you can nail them, if you have a tricky one, use the program Unlocker to remove locked files if in use.
Posted

Not had much experience configuring sophos but our network technician uses it here and you can force clients running the software to use specific settings using a policy, when they next connect contact the sophos server they pick up the settings and apply them, i think you can force the setting to delete the virus upon detection.

 

not sure if this helps....

Posted

With sophos you have to select ON WRITE in the policy as well, the stops the Virus on Write and not after its dropped on the machine when its being read.

 

The option your on about is "automatically clean up items that contain virus's/spyware"

 

Both of these are not on as default.

  • Thanks 1
Posted
With sophos you have to select ON WRITE in the policy as well, the stops the Virus on Write and not after its dropped on the machine when its being read.

 

The option your on about is "automatically clean up items that contain virus's/spyware"

 

Both of these are not on as default.

 

thats the bit i am talking about! thank you scorpio!

 

i remember seeing this on the client machines, and exactly how you have said these options are not turned on by default.

 

you can force these options from a policy in the enterprise console.

  • 4 months later...
Posted
We've got this now at home. As soon as you plug a memory stick a virus mal/autoinf-a is identified and cleaned up. However, when you put the stick in again the virus reappears. Narrowed it down to my son's laptop, but a full virus scan isn't showing anything on his laptop. Where do i look?

Create an account or sign in to comment

You need to be a member in order to leave a comment

Create an account

Sign up for a new account in our community. It's easy!

Register a new account

Sign in

Already have an account? Sign in here.

Sign In Now



×
×
  • Create New...