how do I detect and remove this virus/worm

Barfo

Lifer
Jan 4, 2005
27,539
212
106
A friend of mine told me he's sure his computer at work has a virus or worm infection but PC-Cilin doesn't detect it, and the only symptoms he could give was that it creates a lot of desktop.ini files and the mouse cursor jumps around the screen sometimes, he's not computer savvy and he's the sys admin in there (I know :p) so I'm going there tomorrow to try and help him save his job, any ideas? I think that determining what the problem is would be a good start, so what would be a good set of antivirus and diagnostics programs should I bring?
 

dBTelos

Golden Member
Apr 17, 2006
1,858
0
0
Download, Install, Update, and run in both reg. and safe mode all of the following:

Ewido Anti-MAlware
http://www.ewido.net/en/download/

Ewido Tutorial if you need it = http://rstones12.geekstogo.com/ewidosetup.htm

McAfee Stinger (Stand alone so no install or update)
http://vil.nai.com/vil/stinger/
Ad-Aware SE Personal
http://www.lavasoft.de/software/adaware/

Spybot S-D
http://www.spybot.info/en/download/index.html

If you don't have an A/V or use something crappy like Norton or McAfee Bloat-Ware then download *one* of the following:

Avast Home
http://www.avast.com/eng/download-avast-home.html

AntiVir
http://www.free-av.com/

AVG Free
http://free.grisoft.com/doc/2/lng/us/tpl/v5
 

mechBgon

Super Moderator<br>Elite Member
Oct 31, 1999
30,699
1
0
I can also suggest this routine: http://www.omnicast.net/~tmcfadden/scan.txt Before you run this, use F-Secure's BlackLight Beta to check for rootkits, and use the Rename option if any are found, then reboot to Safe Mode With Command Prompt to run the other scan as directed.

If you PM me the output from the C:\report.html file, I might have some insight on what's going on that allowed them to fall prey to it.

If you don't have an A/V or use something crappy like Norton or McAfee Bloat-Ware then download *one* of the following:
Have you tried McAfee's enterprise-level stuff? Also remember that AVG and AntiVir free versions aren't for business uses, don't want to get his friend in (more) trouble here :)
 

John

Moderator Emeritus<br>Elite Member
Oct 9, 1999
33,944
4
81
If you don't want to install utilities to clean the pc you can run online scans. First I'd recommend running a Panda Online scan, then run a Bitdefender Online scan for a second opinion. Both will detect and remove.

For a third opinion run a Kaspersky online scan since it will only detect and not remove.
 

Barfo

Lifer
Jan 4, 2005
27,539
212
106
Thanks guys :D I'll run the online scans first and then the apps, I'm hopeful that bunch will do :beer:
 

Barfo

Lifer
Jan 4, 2005
27,539
212
106
It was some sort of trojan and I think I got rid of it, thanks for the help :D