Help - Search - Members
Full Version: PURE detects malware but doesn't remove it
Kaspersky Lab Forum > English User Forum > Virus-related issues
benbaaa
I'm stuck in a loop. unsure.gif

PURE says that Trojan.Win32.AutoRun.gen is detected on a flash drive in the file AUTORUN.INF.

Threats detected >
Malware >
Details >
Trojan.Win32.AutoRun.gen detected >
Fix >
Disinfection impossible >
Delete (recommended) >
Do you want to perform a special disinfection procedure? >
Yes, dininfect with reboot (recommended) >
PURE scans and reboots >
After reboot >
Threats detected >
Malware >
Details >
Trojan.Win32.AutoRun.gen detected >
Fix >


And so on. Don't know what to do next.

GSI Link
richbuff
Please post the full, complete detection details. Post screenshot of Reports > Detailed Report > Detected threats.
Right click the Detected bar, and select Path. Right click the Detected bar again and select File.
Then post the screenshot with columns widened to show full detected and name and object and path/location details.

How to take and post screenshot: PrtSc (Print screen) key (upper right part of keyboard)> open Paint (Start > All programs > Accessories) > Edit > Paste, File > Save as (jpeg or
png, Not bmp). When replying, Browse > click once to select file > Open > Upload > add reply.


benbaaa
I think this is what you asked for. h:\ is the flash drive.





I also did an AVZ thing which I've uploaded and attached.
richbuff
Run this script, instructions: http://forum.kaspersky.com/index.php?showt...mp;#entry678368 PC will reboot:
CODE
begin
SetAVZGuardStatus(True);
SearchRootkit(true, true);
QuarantineFile('H:\autorun.inf','');
DeleteFile('H:\autorun.inf');
BC_ImportAll;
ExecuteSysClean;
BC_Activate;
RebootWindows(true);
end.

After run script, scan again with PURE.
benbaaa
Tried all that. Ran the script, rebooted, scanned, rebooted into Safe Mode, scanned, rebooted. Same Threat detected. huh.gif

Just trying something else temporarily - moving my data to the desktop, formatting the flash drive, and moving the data back. (You can tell I'm not very technical, but I won't feel happy until I've tried it!)
benbaaa
Who da man?

biggrin.gif

(Although, PURE also shows autorun.inf in quarantine). But no pop-ups showing threats now. I think we won. Thanks for your help.
somy111
I have same issue with internet security 2012 ,each time scanning finding virus ,restarting and same loop is happening what should I do
virus : Trojan.win32.autorun.gen
also : worm.java.auotorun.c

amazing internet security is not able to disinfect the pc why???help pls
richbuff
Welcome. Please post the full, complete detection details. Post screenshot of Reports > Detailed Report > Detected threats.
Right click the Detected bar, and insure Path is selected. Right click the Detected bar again and insure File is selected.
Then post the screenshot with columns widened to show full detected and name and object and path/location details.

How to take and post screenshot: PrtSc (Print screen) key (upper right part of keyboard)> open Paint (Start > All programs > Accessories) > Edit > Paste, File > Save as (jpeg or
png, Not bmp). When replying, Browse > click once to select file > Open > Upload > add reply.
This is a "lo-fi" version of our main content. To view the full version with more information, formatting and images, please click here.
Invision Power Board © 2001-2014 Invision Power Services, Inc.