Hello All,
OS: XP Pro SP2
I found “autorun.inf” on my USD thumb drive. It appears to be different than other “autorun” viriuses / worms that I’ve researched.
I was not able to delete “autorun.inf”; it said “Cannot delete autorun: It is being used by another person or program. Close any programs that might be using the file and try again.”
I was not able to re-format the USB thumb drive; it said “Windows cannot format this drive. Quit any disk utilities or other programs that are using this drive, and make sure that no window is displaying the contents of the drive. Then try formatting again.”
I rebooted my machine into Ubuntu (I have dual operating systems, but I rarely use Ubuntu).
Plugged in USB drive.
Pop up message: “This medium contains software intended to be automatically started. Would you like to run it?” Of course I hit cancel.
I opened autorun.inf with the text editor. This is the contents:
[aUtoRun[
:0
[aUtoRUn
;jam3
OpEN=filesystem/pagefile.exe
:xm3d
ACtioN=Open
SHELL\\oPen\\\CoMMAnd=filesystem/pagefile.exe
SHEll\\eXpLorE\\cOMMand=filesystem/pagefile.exe
UseAUToPLAy=11m0yE5cY803Y803X4Mx+'I,0Q2ZUmXyM83tx9ceTA09H8W4u890e5
Using Ubunto I deleted autorun.inf without issue. It reappears when I plug the USB in when using XP Pro. It is somewhere on my HDD.
Avast boot time scan did not find anything.
Spybot did not find anything.
QUESTIONS:
The only “pagefile.exe” type file I could find was “PAGEFILE.EXE-1D5c4CC2.pf” in C:\WINDOWS\Prefetch. I do not know enough about OS’s to know if I should delete this file.
I do not know what “UseAUToPLAy=11m0yE5cY803Y803X4Mx+'I,0Q2ZUmXyM83tx9ceTA09H8W4u890e5” does.
Can someone help decipher the text file?
Where is the virus hiding on my HDD?
Thanks.