mhussain Posted May 24, 2010 Posted May 24, 2010 Hi people looking for some expert knowledge here on a Monday morning lol, I have had a memory stick given to me to saying it does not open, so when I checked the memory stick it appears as a folder and does not let you open the memory stick the way to get into the memory stick is to right click and explore it will write to the stick not a problem. So I went into hidden files and deleted the exe file but then I noticed another hidden folder called recycler. When I have deleted both files they seem to appear again very quickly and now 2 other members of staff have come to me with the same problem PLEASE HELP
localzuk Posted May 24, 2010 Posted May 24, 2010 Recycler is the recycle bin temporary file for the drive. The way to empty it is to empty the recycle bin.
mhussain Posted May 24, 2010 Author Posted May 24, 2010 but the exe file keeps on appearing any way of getting rid
TechSupp Posted May 24, 2010 Posted May 24, 2010 I had this the other week with staff sticks, deleted file you found (cant remember name) copy all files folder toa safe area, formatted stick, copied suff back. I know Sophos should have taken care of it but it was longer to do that than do the above method (and in the end Sophos did not seem to clear the problem anyway).
itguy22 Posted May 24, 2010 Posted May 24, 2010 Ok, We have had this problem and after a fair bit of investigating we have found out the problem, On your key you have the EXE the Recycler and and Autorun file, the autorun file is the one that is the biggist pain, this is becuase when the user trys to click on the memory key as normal the autorun file then runs the payload (exe) which infects the particular machine that the key is inserted in, this in turn infects every key that is put into the machine. We found that AVG a full scan on the PC and the Key cleans it up, although you will still have to delete the Autorun manually. run the scan on the computer first then on the key. To combat the problem from getting round the school we enabled removable device scan automaticly when a user plugs in the memory key so it removes it before it has chance to cause any trouble. Let me know if this works. 2
TechSupp Posted May 24, 2010 Posted May 24, 2010 Sure we have that checked but been a while since i delved into Sophos
mhussain Posted May 24, 2010 Author Posted May 24, 2010 (edited) cheer's it guy but we dont use AVG we tend to use McAffe, and this does not pick it up? Edited May 24, 2010 by mhussain
itguy22 Posted May 24, 2010 Posted May 24, 2010 Overall if you run AVG a fully updated version off 9(free) then that will clear it up. needs to be run on both the machine and key, also ask staff to do it on there home machines and any individual laptops that are in school. It does no real damage it is just an annoyance. Possible a Backdoor Bot
itguy22 Posted May 24, 2010 Posted May 24, 2010 cheer it guy but we dont use AVG we tend to use McAffe, and this does not pick it up? Sorry only just got your above post, we mainly use Symantec but we had to have a couple off test machines with AVG free on to clear up this problem. Seems it is a sneaky one.
computer_expert Posted May 24, 2010 Posted May 24, 2010 also don't forget that the free versions of security software are usually meant for personal home use, not for use in businesses/schools etc.
itguy22 Posted May 24, 2010 Posted May 24, 2010 also don't forget that the free versions of security software are usually meant for personal home use, not for use in businesses/schools etc. Very True, thats why we did it on test machines. It was not rolled out to the network.
Recommended Posts
Create an account or sign in to comment
You need to be a member in order to leave a comment
Create an account
Sign up for a new account in our community. It's easy!
Register a new accountSign in
Already have an account? Sign in here.
Sign In Now