Help - Search - Members
Full Version: Cant we delete the Worm.Win32.Womble.d!!!! in Network
Kaspersky Lab Forum > English User Forum > Protection for Small and Medium Businesses
seenujanu
Hi Friends,

In our Office network was infected with Virus called Worm.Win32.Womble.d ...
i had scanned the Hard Disk (Network) with Kaspersky on 06/24/2008 from my system
Kaspersky founded some Virus which r give below. i have deleted the files which had shown to me.... But the Problem is it Regains the Virus ..same Issue ......
It just creats Duplicate files like My passwords.doc .exe

CODE
06/24/2008 08:02:42 PM    File \\backups1\Public\Seduction secrets.jpg: detected: Trojan program 'Exploit.Win32.IMG-WMF.y'.
06/24/2008 08:02:42 PM    File \\backups1\Public\Seduction secrets.jpg: is still infected, postponed.
06/24/2008 08:02:43 PM    File \\backups1\Public\MySexPicture.jpg: detected: Trojan program 'Exploit.Win32.IMG-WMF.y'.
06/24/2008 08:02:43 PM    File \\backups1\Public\MySexPicture.jpg: is still infected, postponed.
06/24/2008 08:02:50 PM    File \\backups1\Public\Seduction secrets.doc .exe: detected: virus 'Virus.Win32.Sality.q'.
06/24/2008 08:02:50 PM    File \\backups1\Public\Seduction secrets.doc .exe: is still infected, postponed.
06/24/2008 08:02:51 PM    File \\backups1\Public\My passwords.doc .exe: detected: virus 'Virus.Win32.Sality.q'.
06/24/2008 08:02:51 PM    File \\backups1\Public\My passwords.doc .exe: is still infected, postponed.
06/24/2008 08:11:15 PM    File \\backups1\SECOND WEEK\GoogleHack.jpg: detected: Trojan program 'Exploit.Win32.IMG-WMF.y'.
06/24/2008 08:11:15 PM    File \\backups1\SECOND WEEK\GoogleHack.jpg: is still infected, postponed.
06/24/2008 08:11:16 PM    File \\backups1\SECOND WEEK\me.jpg: detected: Trojan program 'Exploit.Win32.IMG-WMF.y'.
06/24/2008 08:11:17 PM    File \\backups1\SECOND WEEK\me.jpg: is still infected, postponed.
06/24/2008 08:11:19 PM    File \\backups1\SECOND WEEK\Seduction secrets.doc .exe: detected: virus 'Virus.Win32.Sality.q'.
06/24/2008 08:11:20 PM    File \\backups1\SECOND WEEK\Seduction secrets.doc .exe: is still infected, postponed.
06/24/2008 08:11:23 PM    File \\backups1\SECOND WEEK\Windows serial number.txt .exe: detected: virus 'Virus.Win32.Sality.q'.
06/24/2008 08:11:24 PM    File \\backups1\SECOND WEEK\Seduction secrets.doc .exe: detected: virus 'Virus.Win32.Sality.q'.
06/24/2008 08:11:24 PM    File \\backups1\SECOND WEEK\Windows serial number.txt .exe: detected: virus 'Virus.Win32.Sality.q'.
06/24/2008 08:11:25 PM    File \\backups1\SECOND WEEK\Windows serial number.txt .exe: is still infected, postponed.
06/24/2008 08:11:56 PM    File \\backups1\SECOND WEEK\Windows serial number.txt .exe: deleted.
06/24/2008 08:11:56 PM    File \\backups1\SECOND WEEK\Seduction secrets.doc .exe: deleted.


But i found in my sytem (F:\sathi\Me.jpg sathi is share folder in our Network) showing same Virus by Kaspersky and it has been deleted and ...
i have scanned the F: drive it doesnt show any thing ...
is this Virus Regains in my PC..
How can i delete this Permentely in the Network Also.
Is this efffecting to other PCs which r having the share Folders in network


CODE
06/26/2008 02:07:34 PM    File F:\sathi\Me.jpg cannot be deleted.
06/26/2008 02:07:25 PM    File F:\sathi\Me.jpg: deleted.
06/26/2008 02:06:27 PM    File F:\sathi\Me.jpg: detected: Trojan program 'Exploit.Win32.IMG-WMF.y'.
06/26/2008 02:06:59 PM    File F:\sathi\Me.jpg: detected: Trojan program 'Exploit.Win32.IMG-WMF.y'.
06/26/2008 03:21:29 PM    File F:\sathi\My passwords.doc .pif: deleted.
06/26/2008 03:21:26 PM    File F:\sathi\My passwords.doc .pif: detected: virus 'Email-Worm.Win32.Womble.d'.
06/26/2008 03:20:18 PM    File F:\sathi\My passwords.doc .pif: detected: virus 'Virus.Win32.Sality.q'.
06/26/2008 03:21:32 PM    File F:\sathi\OurNewHouse.jpg: deleted.
06/26/2008 03:21:29 PM    File F:\sathi\OurNewHouse.jpg: detected: Trojan program 'Exploit.Win32.IMG-WMF.y'.
06/26/2008 02:07:32 PM    File F:\sathi\Seduction secrets.doc .exe: deleted.
06/26/2008 02:06:27 PM    File F:\sathi\Seduction secrets.doc .exe: detected: virus 'Virus.Win32.Sality.q'.


Virus names r :

Exploit.Win32.IMG-WMF.y
Virus.Win32.Sality.q
Email-Worm.Win32.Womble.d

Would u please help me out of this........

Thanks in Advance

Seenujanu
Tybilly
Hello,

Please post a GetSystemInfo report of an infected computer.
This is a "lo-fi" version of our main content. To view the full version with more information, formatting and images, please click here.
Invision Power Board © 2001-2009 Invision Power Services, Inc.