/build/static/layout/Breadcrumb_cap_w.png

How to remove img001 virus?

In our organization infrastructure which contains many VMware esx server machines and our physical workstations with workgroup connected instead of AD,
Has been attached with a virus img001.exe and I tried many options to clear it but it is coming back on next day once we connect to network.

It is having only issue with esx console machines.others are cleaned once we delete the appdata\nsminer folder.

Is there any way to clean them instead of reinstallation of OS.?

0 Comments   [ + ] Show comments

Answers (1)

Posted by: JoshRoss 6 years ago
Senior White Belt
0
Unfortunately, I don't know an easy and convenient way to clean that up. 

1. Find the running processes through task manager (Use right click context menu and locate the files where the virus resides) and kill it. As an alternative you can use RKill, to kill the majority of malicious tasks, including img001 and find the files manually.

2. After successfully killing the process, attempt to locate any files associated with what you found and proceed to remove them manually.

3. Check your installed applications and remove any ones you do not recognize.

4. Open up the registry editor and attempt to locate registry files associated with the virus.

Not much else you can do apart from a fresh install. Have you tried checking the source? Tracking if any queries have placed that download the files to computers? It could be a worm version of img001.
 
This website uses cookies. By continuing to use this site and/or clicking the "Accept" button you are providing consent Quest Software and its affiliates do NOT sell the Personal Data you provide to us either when you register on our websites or when you do business with us. For more information about our Privacy Policy and our data protection efforts, please visit GDPR-HQ