Looking for assistance deleting or bypassing fire\ice virus (The one which hides USB drive folders)

Leito360

New Member
Thread author
Nov 5, 2014
6
Hello.

I have the following questions regarding this malware.

Can it be deleted using USB antivirus like MX One?

I remember the file: X:\ice\fire\ccc.exe as a reference.

Can anyone provide me more info about this malware? or even a copy to test all in a safe environment?

Take into account that my idea is to use as little software as possible to delete it, and to do it manually if possible.
 

argus

Former MalwareTips Staff
Verified
Apr 24, 2014
3,395
Please download Farbar Recovery Scan Tool and save it to your Desktop.

Note: You need to run the version compatibale with your system. If you are not sure which version applies to your system download both of them and try to run them. Only one of them will run on your system, that will be the right version.

  • Right click on
    12579.gif
    to Run as Administrator
    (XP users click run after receipt of Windows Security Warning - Open File).
  • When the tool opens click Yes to disclaimer.
  • You will be presented with a window like below:
    FRSTconsole-2.jpg
  • Press Scan button.
  • It will produce a log called FRST.txt in the same directory the tool is run from.
  • The first time the tool is run it generates another log (Addition.txt - also located in the same directory as FRST.exe/FRST64.exe).
 

Leito360

New Member
Thread author
Nov 5, 2014
6
I don't know when I will have access to the infected computer again, but when I have, I will run the tool and upload the log.
 
Last edited:

Leito360

New Member
Thread author
Nov 5, 2014
6
Well, I couldn't make the scan yet... for now, I can give you an image of what my antivirus detected when I put the infected usb drive in my PC, also, I'll put the content of the autorun.inf below:

Link to the image: http://i.imgur.com/Mb43m0W.jpg

Code:
autorun]
[autorun[
[autorun]
open=ice\fire\traymgr.exe
icon=%SystemRoot%\system32\SHELL32.dll,4
action=Open folder to view files
UseAuTOPLAY=1
shell\\open\\command=ice\fire\traymgr.exe
shell\\Explore\\Command=ice\fire\traymgr.exe
 

About us

  • MalwareTips is a community-driven platform providing the latest information and resources on malware and cyber threats. Our team of experienced professionals and passionate volunteers work to keep the internet safe and secure. We provide accurate, up-to-date information and strive to build a strong and supportive community dedicated to cybersecurity.

User Menu

Follow us

Follow us on Facebook or Twitter to know first about the latest cybersecurity incidents and malware threats.

Top