flashdrive worm won't go away!

Discussion in 'Malware Help - MG (A Specialist Will Reply)' started by jeo, Nov 25, 2007.

  1. jeo

    jeo Private E-2

    Hi to anywone who could help me!
    I ran all the procedures on the read and run me first thread, except I wasn't able to run the getrunkeys and shownew because i'm a new user of Vistaand didn't know how to disable uac?
    I ran ccleaner and it cleaned up temp files cookies etc.
    I ran spybot and it only found attune which i immunized.
    anyway, I wasn't able to download counterspy but ran AVG free edition instead. It found some trojans and I wiped those, but didn't detect anything else until i ran test selected areas and scanned my flashdrive, and it found a worm named autorun.inf It attempted to heal it but said that error occured while healing. I ran the scan again and the worm was still there and I don't know how to get rid of it.
    Also, sometime between downloading ccleaner and the other stuff, 2 icons appeared on my desktop both named desktop.ini and when opened contained

    [.ShellClassInfo]
    LocalizedResourceName=@%SystemRoot%\system32\shell32.dll,-21769
    IconResource=%SystemRoot%\system32\imageres.dll,-183

    and

    [.ShellClassInfo]
    LocalizedResourceName=@%SystemRoot%\system32\shell32.dll,-21799

    I don't know what this means or where it came from. Is this connected with the worm or trojan? What should I do with it?

    Also, if the problem is the flashdrive, if I buy a new one and transferred files from the old infected flashdrive to the new flashdrive, will that get rid of the problem (no more worm or trojan in the new flashdrive and on my system?)

    I would really appreciate any help you can give me regarding this.

    Thanks!

    -Jeo
     
  2. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Welcome to Major Geeks!

    It is explained in the procedure. You should follow the new READ ME >>>> Read & RUN ME FIRST Before Asking for Support perhaps this version will be easier for you.

    We need all of the logs requested inorder to help you. Also you should start looking on all of your drives (including your flashdrive) for a file named autorun.inf and delete them.


    Nothing! They are normal. You just did not see them before because your did not have hidden files enabled.

    If you really have a trojan, you could inadvertantly copy the trojan from on drive to another. You also have the option of looking to see if the is formatting utility for your flashdrive.
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds