5 pts.
0
Q:
Memory Stick Virus
One of my friends' computer has believed to be infected by a virus. Whenever he put memory stick to the computer, following files appeared in the stick :

1)autorun.inf
2)squxe.exe
3)xnvjmz.exe

These files can be deleted manually.

But when he put that memory stick or other stick, the files appeared again in the stick.

It is assumed that the virus itself is hiding in the harddisk.

Please help me how to solve this virus problem.

P.S. he is using SAV

Awaiting your earliest replies.

kwinoo
ASKED: Feb 20 2009  8:17 AM GMT
_ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _
0
750 pts.
0
A:
 RATE THIS ANSWER
0
Click to Vote:
  •   0
  •  0
  • AddThis Social Bookmark Button
The standard response should be "make sure your virus definition files are up-to-date and scan your system". I imagine you tried that.

Yes, something on the harddisk that is not being detected as malicious. To narrow down what it may be, try Trend Micro's System Information Collector (SIC) utility.

Here’s an easy way to find suspicious files that you can give your antivirus vendor. You can detect that which they don’t detect. Use Trend Micro’s System Information Collector utility. See “Collecting malware samples and logs using the System Information Collector (SIC)” for download and usage instructions. (This particular page does not indicate that Windows Vista among the supported Operating Systems, although other references indicate that it is supported.) With this utility you will create a log file of system information and create a ZIP archive of suspicious files. Review the log file if you like, that’s optional. The important next step is to get the files that were archived to your antivirus vendor for review. The password for the ZIP file is “virus” (without the quotes).

Note that SIC doesn't remove the suspicious file, just helps you find it. You can use virustotal.com to confirm that yes, indeed, you have come across a file that your antivirus software is not detecting.

Removal will depend upon what is detected.
Last Answered: Feb 23 2009  11:29 PM GMT by Rklanke   750 pts.
Latest Contributors: Mshen   23525 pts., Technochic   40185 pts.
0
0
Discuss This Answer:
_ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _



0