Findykill and autorun.inf

Discussion in 'Malware Help (A Specialist Will Reply)' started by banjobill, Nov 1, 2009.

  1. banjobill

    banjobill Private E-2

    First post. Win XP SP3, fully patched.

    Through my own stupidity I 'acquired' a bad worm.bagle infection (srosa/winupgro.exe). After several days, having restored the reg safeboot etc and thrown all sorts of malware weaponry at it I am almost there. The final assault was Norman 2009 which found stuff even Malwarebytes did not.

    The reason I am here is that in the maelstrom of rising panic I saw your thread on Findykill and ran that (- again, it removed some stuff). I removed the programme on completion.

    I think I am clear of the worm now, but every partition now has a 'zero byes, one folder' folder called autorun.inf containing a 'non-existent' file called 'lpt3.This folder was created by FindyKill', Hidden/archive. I have changed access permissions and all sorts of tricks, but they will not go away. Regedit shows no trace of the text or 'Findykill'.

    Is this a problem and what are the folders doing? Do you know how they are being created, and if a problem I woud appreciate removal advice.

    Thank you
     
  2. banjobill

    banjobill Private E-2

  3. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Welcome to Major Geeks!

    Yes you are correct. It was a folder created to block autorun worm infections.
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds