I'm trying to remove a virus from my friend's PC. The virus is called qbqjralptr..vbs & I found it's a worm specified like USB – Dinihou – Houdini Worm.VBScript
It seemed easy to remove but I just was able to deactivate it, without removing.
It infects all USB keys connected to PC creating false links to all files contained into the key. They link to a hidden file on the key which is the virus.
Well, I found it's a process which check if a new key is connected and build virus links.
I tried to kill the process and it worked. It won't recreate itself and the key I connected didn't make any link anymore. I deleted all system registry keys which permitted the virus to start when the OS loaded.
I located it into the temp folder of the user, but when i checked into that folder i didn't find any file.
Windows suggests it is a file but dir command won't retrieve anything, so I can't delete it because of “file not found” message.
Do you know how can I proceed?
dirnot showing it, you might need to usedir /a:hswhich shows files with the hidden and system attributes. But I still recommend using an anti-virus program, and perhaps also something like Malwarebytes. – Andrew Morton Oct 04 '14 at 18:58