C:\autorun.inf - Win32/AutoRun.Agent.BE worm - error while cleaning (Access denied)

Thread: C:\autorun.inf - Win32/AutoRun.Agent.BE worm - error while cleaning (Access denied)

  1. MB3000's Avatar

    MB3000 said:

    Help C:\autorun.inf - Win32/AutoRun.Agent.BE worm - error while cleaning (Access denied)

    Evening All,

    Wonder if anyone can help on the below...

    Tried to get a serial key but have ended up getting a virus. Tried to delete/clean with ESET but no joy.

    example pics below - 1st pic is ESET picking it up and the 2nd showing what happens when I try to clean or delete.

    [Only registered and activated users can see links. ]

    [Only registered and activated users can see links. ]

    PC now has the usual thing of IE now going to random pages after seaching on google/yahoo etc.
     
  2. Nibb's Avatar

    Nibb said:

    Default Re: C:\autorun.inf - Win32/AutoRun.Agent.BE worm - error while cleaning (Access denie

    Try Malawarebytes.
    "Where you are is what you eat. When I'm in London I'll have beans on toast for lunch. On holiday what? Tapas? Go on then I'll have a bit. You eat whatevers in that area"
    Karl Pilkington
     
  3. MB3000's Avatar

    MB3000 said:

    Default Re: C:\autorun.inf - Win32/AutoRun.Agent.BE worm - error while cleaning (Access denie

    Hey Nibb,

    Just downloaded and scanning now. so far found 2 objects sojust awaiting for it to finish.

    Thanks for the advice.
     
  4. MB3000's Avatar

    MB3000 said:

    Default Re: C:\autorun.inf - Win32/AutoRun.Agent.BE worm - error while cleaning (Access denie

    Right!

    Think I have sorted it all out. Ran Malwarebytes but also did a system restore to a couple of days ago and now seems to be ok.
     
  5. d3xt0r's Avatar

    d3xt0r said:

    Default Re: C:\autorun.inf - Win32/AutoRun.Agent.BE worm - error while cleaning (Access denie

    is C:\autorun.inf still on your HDD? If it wont let you delete it, restart your computer and run in safemode. It should delete in safe mode
     
  6. Over Carl's Avatar

    Over Carl said:

    Default Re: C:\autorun.inf - Win32/AutoRun.Agent.BE worm - error while cleaning (Access denie

    Any time I've ever had a pc infected, I always move all data I may want elsewhere before deleting and recreating partition then full format before starting to use again.

    Quite possibly ott for many instances, but imo well worth the time so at least you know your pc is 100% clean and any infections in future will be down to being reinfected, not due to old crap not properly cleaned.
     
  7. MB3000's Avatar

    MB3000 said:

    Default Re: C:\autorun.inf - Win32/AutoRun.Agent.BE worm - error while cleaning (Access denie

    It wasnt even showing anything program at all also checked hidden fies aswell. Since I did a restore all is working fine.

    Most notable thing was when searching on IE via google or yahoo it would open new tabs with search pages that sounded the same as the orginal website.
     
  8. d3xt0r's Avatar

    d3xt0r said:

    Default Re: C:\autorun.inf - Win32/AutoRun.Agent.BE worm - error while cleaning (Access denie

    Have you been having any trouble with flash drives?

    W32/AutoRun.Agent.BE.worm Normally infects all flash drives that get plugged in

    Also check Your Registry;

    HKLM\Software\Microsoft\Windows\CurrentVersion\Run\
    HKCU\Software\Microsoft\Windows\CurrentVersion\Run\

    For Autorun Processes
     
  9. MB3000's Avatar

    MB3000 said:

    Default Re: C:\autorun.inf - Win32/AutoRun.Agent.BE worm - error while cleaning (Access denie

    Quote Originally Posted by d3xt0r2005 View Post
    Have you been having any trouble with flash drives?

    W32/AutoRun.Agent.BE.worm Normally infects all flash drives that get plugged in

    Also check Your Registry;

    HKLMSoftwareMicrosoftWindowsCurrentVersionRun
    HKCUSoftwareMicrosoftWindowsCurrentVersionRun

    For Autorun Processes
    I have had my iPhone connected since and no probs. Came up with the normal AutoPlay options when first connected. (Does that count?)