HELP: newHeur_PE virus/ how to clear

Discussion in 'ESET NOD32 Antivirus' started by animna, Nov 26, 2008.

Thread Status:
Not open for further replies.
  1. animna

    animna Registered Member

    Joined:
    Nov 26, 2008
    Posts:
    1
    Hi,

    In office , I acquired a virus undetectable to TrendMicro (antivirus used in office) named " newHeur_PE virus (as detected by Nod 32 2.7 in my home)and it was able to infect my external disk. I used NOD 32 to exterminate the virus in my USB howver some of the virus"file cannot be deleted as it is still running" (can't remember exact words but i think it is same effect".

    By the way, VIRUS behaviour is this:

    " it replicates folder i open and makes it a subfolder with same name adding the file extension ".exe"

    e.g.
    Folder I open: system 32
    Virus will create subfolder: system32.exe

    as I am a novice, can anyone give me some detailed instruction to clear the virus....


    Thanks in advance...

    animna
    phils.

    I am using a NOD 32 2.7
     
  2. Marcos

    Marcos Eset Staff Account

    Joined:
    Nov 22, 2002
    Posts:
    14,456
    I'd strongly recommend installing ESET NOD32 Antivirus, in your case v4 beta. V3 has better detection than v2 and v4 improves cleaning even furher which might help in your case.
     
  3. brwilkinson

    brwilkinson Registered Member

    Joined:
    Nov 26, 2008
    Posts:
    1
    I have a client with the same virus. At least that's what AVG & Spyware Terminator indicated after I installed them. Neither could remove it. I tried installing Spybot, but the virus blocked updating the program. The same happened when I installed a trial of NOD32. Without updates, I couldn't remove the virus. I could browse to any website I wanted, except sites that offer malware related tools. I ended up having to wipe/reinstall.

    Bruce
     
Thread Status:
Not open for further replies.
  1. This site uses cookies to help personalise content, tailor your experience and to keep you logged in if you register.
    By continuing to use this site, you are consenting to our use of cookies.