Page 1 of 1

Define virus, please

Posted: Fri Sep 05, 2008 11:53 am
by Grand_Master
I found this on my USB-drive:

Code: Select all

[autorun]
open=RECYCLER\S-1-6-21-2434476501-1644491937-600003330-1213\autorunme.exe
icon=%SystemRoot%\system32\SHELL32.dll,4
action=Open folder to view files
shell\open=Open
shell\open\command=RECYCLER\S-1-6-21-2434476501-1644491937-600003330-1213\autorunme.exe
shell\open\default=1
It was a system file with the name autorun.inf

My anti-virus defined it as a trojan ("Trj/Autorun.YE"), and it recreate itself if I delete it.
In addition i found AUTORUNME.EXE-271E2F53.pf in C:\WINDOWS\prefetch

Anyone who knows how this trojan works or how I can delete it? I must admit that I don't really understand what's written in the .inf-file.

Re: Define virus, please

Posted: Fri Sep 05, 2008 12:33 pm
by Trogue
i had a similar problem with my old laptop it was in my temp each time i booted up it would recreate. what i done is got hijack this too delete it at boot then i done a search for all folders by that name in registry and using find i done a complete scan and then its just died :D that was a relief