In our Office network was infected with Virus called Worm.Win32.Womble.d ...
i had scanned the Hard Disk (Network) with Kaspersky on 06/24/2008 from my system
Kaspersky founded some Virus which r give below. i have deleted the files which had shown to me.... But the Problem is it Regains the Virus ..same Issue ......
It just creats Duplicate files like My passwords.doc .exe
CODE
06/24/2008 08:02:42 PM File \\backups1\Public\Seduction secrets.jpg: detected: Trojan program 'Exploit.Win32.IMG-WMF.y'.
06/24/2008 08:02:42 PM File \\backups1\Public\Seduction secrets.jpg: is still infected, postponed.
06/24/2008 08:02:43 PM File \\backups1\Public\MySexPicture.jpg: detected: Trojan program 'Exploit.Win32.IMG-WMF.y'.
06/24/2008 08:02:43 PM File \\backups1\Public\MySexPicture.jpg: is still infected, postponed.
06/24/2008 08:02:50 PM File \\backups1\Public\Seduction secrets.doc .exe: detected: virus 'Virus.Win32.Sality.q'.
06/24/2008 08:02:50 PM File \\backups1\Public\Seduction secrets.doc .exe: is still infected, postponed.
06/24/2008 08:02:51 PM File \\backups1\Public\My passwords.doc .exe: detected: virus 'Virus.Win32.Sality.q'.
06/24/2008 08:02:51 PM File \\backups1\Public\My passwords.doc .exe: is still infected, postponed.
06/24/2008 08:11:15 PM File \\backups1\SECOND WEEK\GoogleHack.jpg: detected: Trojan program 'Exploit.Win32.IMG-WMF.y'.
06/24/2008 08:11:15 PM File \\backups1\SECOND WEEK\GoogleHack.jpg: is still infected, postponed.
06/24/2008 08:11:16 PM File \\backups1\SECOND WEEK\me.jpg: detected: Trojan program 'Exploit.Win32.IMG-WMF.y'.
06/24/2008 08:11:17 PM File \\backups1\SECOND WEEK\me.jpg: is still infected, postponed.
06/24/2008 08:11:19 PM File \\backups1\SECOND WEEK\Seduction secrets.doc .exe: detected: virus 'Virus.Win32.Sality.q'.
06/24/2008 08:11:20 PM File \\backups1\SECOND WEEK\Seduction secrets.doc .exe: is still infected, postponed.
06/24/2008 08:11:23 PM File \\backups1\SECOND WEEK\Windows serial number.txt .exe: detected: virus 'Virus.Win32.Sality.q'.
06/24/2008 08:11:24 PM File \\backups1\SECOND WEEK\Seduction secrets.doc .exe: detected: virus 'Virus.Win32.Sality.q'.
06/24/2008 08:11:24 PM File \\backups1\SECOND WEEK\Windows serial number.txt .exe: detected: virus 'Virus.Win32.Sality.q'.
06/24/2008 08:11:25 PM File \\backups1\SECOND WEEK\Windows serial number.txt .exe: is still infected, postponed.
06/24/2008 08:11:56 PM File \\backups1\SECOND WEEK\Windows serial number.txt .exe: deleted.
06/24/2008 08:11:56 PM File \\backups1\SECOND WEEK\Seduction secrets.doc .exe: deleted.
06/24/2008 08:02:42 PM File \\backups1\Public\Seduction secrets.jpg: is still infected, postponed.
06/24/2008 08:02:43 PM File \\backups1\Public\MySexPicture.jpg: detected: Trojan program 'Exploit.Win32.IMG-WMF.y'.
06/24/2008 08:02:43 PM File \\backups1\Public\MySexPicture.jpg: is still infected, postponed.
06/24/2008 08:02:50 PM File \\backups1\Public\Seduction secrets.doc .exe: detected: virus 'Virus.Win32.Sality.q'.
06/24/2008 08:02:50 PM File \\backups1\Public\Seduction secrets.doc .exe: is still infected, postponed.
06/24/2008 08:02:51 PM File \\backups1\Public\My passwords.doc .exe: detected: virus 'Virus.Win32.Sality.q'.
06/24/2008 08:02:51 PM File \\backups1\Public\My passwords.doc .exe: is still infected, postponed.
06/24/2008 08:11:15 PM File \\backups1\SECOND WEEK\GoogleHack.jpg: detected: Trojan program 'Exploit.Win32.IMG-WMF.y'.
06/24/2008 08:11:15 PM File \\backups1\SECOND WEEK\GoogleHack.jpg: is still infected, postponed.
06/24/2008 08:11:16 PM File \\backups1\SECOND WEEK\me.jpg: detected: Trojan program 'Exploit.Win32.IMG-WMF.y'.
06/24/2008 08:11:17 PM File \\backups1\SECOND WEEK\me.jpg: is still infected, postponed.
06/24/2008 08:11:19 PM File \\backups1\SECOND WEEK\Seduction secrets.doc .exe: detected: virus 'Virus.Win32.Sality.q'.
06/24/2008 08:11:20 PM File \\backups1\SECOND WEEK\Seduction secrets.doc .exe: is still infected, postponed.
06/24/2008 08:11:23 PM File \\backups1\SECOND WEEK\Windows serial number.txt .exe: detected: virus 'Virus.Win32.Sality.q'.
06/24/2008 08:11:24 PM File \\backups1\SECOND WEEK\Seduction secrets.doc .exe: detected: virus 'Virus.Win32.Sality.q'.
06/24/2008 08:11:24 PM File \\backups1\SECOND WEEK\Windows serial number.txt .exe: detected: virus 'Virus.Win32.Sality.q'.
06/24/2008 08:11:25 PM File \\backups1\SECOND WEEK\Windows serial number.txt .exe: is still infected, postponed.
06/24/2008 08:11:56 PM File \\backups1\SECOND WEEK\Windows serial number.txt .exe: deleted.
06/24/2008 08:11:56 PM File \\backups1\SECOND WEEK\Seduction secrets.doc .exe: deleted.
But i found in my sytem (F:\sathi\Me.jpg sathi is share folder in our Network) showing same Virus by Kaspersky and it has been deleted and ...
i have scanned the F: drive it doesnt show any thing ...
is this Virus Regains in my PC..
How can i delete this Permentely in the Network Also.
Is this efffecting to other PCs which r having the share Folders in network
CODE
06/26/2008 02:07:34 PM File F:\sathi\Me.jpg cannot be deleted.
06/26/2008 02:07:25 PM File F:\sathi\Me.jpg: deleted.
06/26/2008 02:06:27 PM File F:\sathi\Me.jpg: detected: Trojan program 'Exploit.Win32.IMG-WMF.y'.
06/26/2008 02:06:59 PM File F:\sathi\Me.jpg: detected: Trojan program 'Exploit.Win32.IMG-WMF.y'.
06/26/2008 03:21:29 PM File F:\sathi\My passwords.doc .pif: deleted.
06/26/2008 03:21:26 PM File F:\sathi\My passwords.doc .pif: detected: virus 'Email-Worm.Win32.Womble.d'.
06/26/2008 03:20:18 PM File F:\sathi\My passwords.doc .pif: detected: virus 'Virus.Win32.Sality.q'.
06/26/2008 03:21:32 PM File F:\sathi\OurNewHouse.jpg: deleted.
06/26/2008 03:21:29 PM File F:\sathi\OurNewHouse.jpg: detected: Trojan program 'Exploit.Win32.IMG-WMF.y'.
06/26/2008 02:07:32 PM File F:\sathi\Seduction secrets.doc .exe: deleted.
06/26/2008 02:06:27 PM File F:\sathi\Seduction secrets.doc .exe: detected: virus 'Virus.Win32.Sality.q'.
06/26/2008 02:07:25 PM File F:\sathi\Me.jpg: deleted.
06/26/2008 02:06:27 PM File F:\sathi\Me.jpg: detected: Trojan program 'Exploit.Win32.IMG-WMF.y'.
06/26/2008 02:06:59 PM File F:\sathi\Me.jpg: detected: Trojan program 'Exploit.Win32.IMG-WMF.y'.
06/26/2008 03:21:29 PM File F:\sathi\My passwords.doc .pif: deleted.
06/26/2008 03:21:26 PM File F:\sathi\My passwords.doc .pif: detected: virus 'Email-Worm.Win32.Womble.d'.
06/26/2008 03:20:18 PM File F:\sathi\My passwords.doc .pif: detected: virus 'Virus.Win32.Sality.q'.
06/26/2008 03:21:32 PM File F:\sathi\OurNewHouse.jpg: deleted.
06/26/2008 03:21:29 PM File F:\sathi\OurNewHouse.jpg: detected: Trojan program 'Exploit.Win32.IMG-WMF.y'.
06/26/2008 02:07:32 PM File F:\sathi\Seduction secrets.doc .exe: deleted.
06/26/2008 02:06:27 PM File F:\sathi\Seduction secrets.doc .exe: detected: virus 'Virus.Win32.Sality.q'.
Virus names r :
Exploit.Win32.IMG-WMF.y
Virus.Win32.Sality.q
Email-Worm.Win32.Womble.d
Would u please help me out of this........
Thanks in Advance
Seenujanu