Another one Avast missed...

I have this one on both my laptop and desktop. The only way I know the virus is there is because after I delete the autorun.inf from my memory stick, it reappears in about 10 seconds. It also puts an executable in a folder called System on the memory stick.

I stuck the memory stick in a friend’s computer and Norton picked it up.

Here’s the link from VirusTotal.

http://www.virustotal.com/analisis/bf105159f83f982d0c9981298fbed1a7

Send the sample to virus@avast.com in a password-protected zip folder with Undetected Malware in subject and the password mentioned in the email body.

You need to update Avast to 4.8.1335.

Right click on the avast blue ball > click Update> click Program Update.

Unless you effectively immunize your USB sticks they are liable to reinfection.

  1. Flash Drive Disinfector
    Download Flash_Disinfector.exe by sUBs from >here< and save it to your desktop.
    [*] Double-click Flash_Disinfector.exe to run it and follow any prompts that may appear.[*] The utility may ask you to insert your flash drive and/or other removable drives including your mobile phone. Please do so and allow the utility to clean up those drives as well.[*] Wait until it has finished scanning and then exit the program.[*] Reboot your computer when done.
    Note: Flash_Disinfector will create a hidden folder named autorun.inf in each partition and every USB drive plugged in when you ran it. Don’t delete this folder…it will help protect your drives from future infection.

So what ever is reinfecting you usb stick is either on the stick or your system undetected/hidden.

So once you run the Flash_Disinfector on your system and then on individual usb sticks, we can uses some other tools to try and find the undetected/hidden element.

If you haven’t already got this software (freeware), download, install, update and run it, preferably in safe mode and report the findings (it should product a log file).

  1. SUPERantispyware On-Demand only in free version.
  2. MalwareBytes Anti-Malware, On-Demand only in free version http://download.bleepingcomputer.com/malwarebytes/mbam-setup.exe, right click on the link and select Save As or Save File (As depending on your browser), save it to a location where you can find it easily later.

Already up to date…