Security [CENTRAL] Forum - SCforum.info
24. May 2012., 07:07:30 *
Welcome, Guest. Please login or register.

Login with username, password and session length

SCforum.info - Security [CENTRAL] Forum

↑ Grab this Headline Animator

Custom Search
News: For ultra cheap bullet proof vests, hard armor ballistic plates or for advice on body armor in general visit SafeGuardClothing.com
 
  Home Help Chess Links Login Register   *

SCforum.info


furniture store



Members
Total Members: 11258
Latest: donna717
Stats
Total Posts: 15637
Total Topics: 4337
Online Today: 2172
Online Ever: 51419
(01. January 2010., 10:27:49)

SCF UnSpam

Top Ten Antivirus Software

Friend of WOT


SCF Feedburner

SCF Facebook

SCF Twitter

Welcome to SCforum.info - Security [CENTRAL] Forum, a home of the SCF Community devoted to provide Computer related News, Alerts, Downloads and FREE Help in such a way that even the novice computer user can understand.

Getting started using our community is extremely easy, check the two steps below:

Step 1: Create an account by clicking here and wait for approval from Administrator. It's completely free with no hidden strings attached.

Step 2: If you have a computer problem and need some help, or just want to take part in opened discussions, simply browse Forum. Once you *Register an account, you can quickly post your questions and comments.

(*Registered Members get: free support, also, they can communicate privately with other members via PM, removal of this message, see fewer ads and much more...)






Pages: 1 2 »
  Print  
Author Topic: help wanted; PenDrive hidden file and shortcut folder problem  (Read 6451 times)
0 Members and 1 Guest are viewing this topic.
metalmunna
SCF Moderators
*****

KARMA: 16
Gender: Male
Age: N/A
Location: Dhaka
Posts: 79


Google Talk
WWW
« on: 03. May 2011., 19:22:00 »

hi guys,

fall on a trouble and the problem on the PenDrive only ..

whole the network is secured by McAfee Enterprise 8.8 VirusScan with latest update. on some client PC when attached a PenDrive those time all files gone hidden and some shortcut folder(my music, my documents .. etc) has been created automatically. VirusScan can't find any virus inside there. When take a look on the hidden files those time saw that some unknown Executable file inside there. If deleted that although not solved even added that Executable files on McAfee Unwanted files to deleted that when find inside the PC or PendDrive. But after sometime saw that problem isn't solved and the Executable files changed their own name and keep doing the same problem.

any help please? that's it and have a nice day guys ...
Logged

Munna
king@metalmunna.co.cc
My heart bleeds for none but my own!
http://www.metalmunna.co.cc
Security [CENTRAL] Forum - SCforum.info
« on: 03. May 2011., 19:22:00 »



 Logged
jheysen
SCF Moderator
*****

KARMA: 19
Gender: Male
Location: South America
Posts: 183


« Reply #1 on: 03. May 2011., 21:59:04 »

Well.. first thing is to disable autorun, then you might want to access the pendrive via system console.
there I suggest you to do a dir /a to see what's actually in there, after that proceed to delete unwanted files, starting by autorun.ini

Anyway, if you can create a compressed file with all of the pendrive's content, you can sumbit it to AVERT lab so they provide a extra.dat for you (wich can be deployed via ePO) and eventually will be included in a official DAT Release.
Logged
metalmunna
SCF Moderators
*****

KARMA: 16
Gender: Male
Age: N/A
Location: Dhaka
Posts: 79


Google Talk
WWW
« Reply #2 on: 03. May 2011., 23:39:11 »

Well.. first thing is to disable autorun, then you might want to access the pendrive via system console.
there I suggest you to do a dir /a to see what's actually in there, after that proceed to delete unwanted files, starting by autorun.ini

Anyway, if you can create a compressed file with all of the pendrive's content, you can sumbit it to AVERT lab so they provide a extra.dat for you (wich can be deployed via ePO) and eventually will be included in a official DAT Release.

thanks for the reply and i can delete all of them(included hidden executable files) but the problem is after sometime it will be created again with new file name(Example; before it was; abc.exe and when deleted that file after then it will be created with new file name like xyz.exe. as it can change it's own file name that's why not working if i added that on the unwanted programs Policies on McAfee Enterprise). so the source might be inside the PC but it can't make any trouble on PC, only doing that on the PenDrive. More even the user was logged in they haven't installation rights on the domain and on domain policy has blocked to install anything from the removable drive ...


Quote
(if you can create a compressed file with all of the pendrive's content, you can sumbit it to AVERT lab so they provide a extra.dat for you (wich can be deployed via ePO) and eventually will be included in a official DAT Release.)

note; can you please give me the mail address for this solution?
Logged

Munna
king@metalmunna.co.cc
My heart bleeds for none but my own!
http://www.metalmunna.co.cc
jheysen
SCF Moderator
*****

KARMA: 19
Gender: Male
Location: South America
Posts: 183


« Reply #3 on: 04. May 2011., 02:32:50 »

For submitting samples to AVERT..
http://service.mcafee.com/FAQDocument.aspx?id=TS100095
http://www.mcafee.com/us/mcafee-labs/resources/how-to-submit-sample.aspx

As for your problem, It looks like the case, that PC is infected, maybe it's a memory resident?
I don't know... but if you delete the files from linux maybe? (a live CD or something.. you can even use a Virtual Machine)
Logged
Samker
SCF Administrator
*****

KARMA: 86
Gender: Male
Location: Europe
Posts: 5078


Whatever doesn't kill us makes us stronger.

Google Talk
WWW
« Reply #4 on: 04. May 2011., 05:23:04 »


Hi MM, like "jheysen", I'm also 99% sure that this cause some nasty virus...  Undecided

Check this solution also:

Quote
1. If you did not format your flash drive, then check whether the files are not in hidden mode (Go to folder options-> view tab and uncheck the option of “Hide protected operating system files(Recommended)).

2. Click on "Start" -->Run-->type cmd and click on OK.

3. Enter this command: attrib -h -r -s /s /d g:\*.*

Note : Replace the letter g with your flash drive letter.

4. Now check for your files in Pen Drive.

5. After that, download the Malwarebytes' Anti-Malware and run Full scan: http://scforum.info/index.php/topic,2201.0.html



Finally check mentioned PC with some Online AV scanner: http://scforum.info/index.php/topic,734.0.html (my suggestion for this case is NOD32), also here is one great tool "Panda USB Vaccine": http://scforum.info/index.php/topic,4274.0.html


Hope some of this things will help you to resolve this problem??




Logged

metalmunna
SCF Moderators
*****

KARMA: 16
Gender: Male
Age: N/A
Location: Dhaka
Posts: 79


Google Talk
WWW
« Reply #5 on: 05. May 2011., 01:13:10 »

thank you guys for the help and will let you know the result later ... have a nice day to all of you ...
Logged

Munna
king@metalmunna.co.cc
My heart bleeds for none but my own!
http://www.metalmunna.co.cc
Samker
SCF Administrator
*****

KARMA: 86
Gender: Male
Location: Europe
Posts: 5078


Whatever doesn't kill us makes us stronger.

Google Talk
WWW
« Reply #6 on: 09. May 2011., 18:36:23 »

thank you guys for the help and will let you know the result later ... have a nice day to all of you ...

Any news about this case, MM??
Logged

metalmunna
SCF Moderators
*****

KARMA: 16
Gender: Male
Age: N/A
Location: Dhaka
Posts: 79


Google Talk
WWW
« Reply #7 on: 10. May 2011., 17:49:39 »

thank you guys for the help and will let you know the result later ... have a nice day to all of you ...

Any news about this case, MM??


Nothing new yet, as i told you that it's not my problem and on my network and system has no trouble like that. it's a friend's office network and that's a Govt. office and you know how lazy they are on their own trouble! still i didn't get that virus file which isn't detected by McAfee Enterprise(that's not fake coz i saw that too on their pen drive before), but they sent me some files yesterday but that's already protected by McAfee .. so waiting for the files which was cause of the Pen Drive ..
Logged

Munna
king@metalmunna.co.cc
My heart bleeds for none but my own!
http://www.metalmunna.co.cc
Samker
SCF Administrator
*****

KARMA: 86
Gender: Male
Location: Europe
Posts: 5078


Whatever doesn't kill us makes us stronger.

Google Talk
WWW
« Reply #8 on: 10. May 2011., 21:46:28 »

thank you guys for the help and will let you know the result later ... have a nice day to all of you ...

Any news about this case, MM??


... still i didn't get that virus file which isn't detected by McAfee Enterprise (that's not fake coz i saw that too on their pen drive before), but they sent me some files yesterday but that's already protected by McAfee .. so waiting for the files which was cause of the Pen Drive ..

Probably some "mistake" in ePO configuration... but we'll see.
Logged

jheysen
SCF Moderator
*****

KARMA: 19
Gender: Male
Location: South America
Posts: 183


« Reply #9 on: 11. May 2011., 00:56:16 »

Did somebody put exceptions for the pendrive or executable files in ePO?
Logged
Pages: 1 2 »
  Print  
 
Jump to:  

Enter your email address to receive daily email with 'SCforum.info - Security CENTRAL Forum' newest content:

Terms of Use | Privacy Policy | Advertising
Powered by MySQL Powered by PHP Powered by SMF | SMF © 2011, Simple Machines
TinyPortal © Bloc
Valid XHTML 1.0! Valid CSS!


Google visited last this page 19. May 2012., 11:40:33