Endpoint Protection

 View Only
  • 1.  rejoice2009.exe?

    Posted Feb 27, 2010 04:05 PM
    Hi,
    I'm new to this forum, so I apologize for advance any ignorant mistakes.

    I only recently noticed a new file appear on my root directories (C:\, D:\, and E:\) called rejoice2009.exe and also an autorun.ini (with a suspiciously new creation date)
    I deleted these files, ran a liveupdate, and ran a fullscan of symantec 10.1.6.6

    The files no longer appear in my local hard drives, but every time I plug in an external drive (USB flash or SD card), the file is immediately copied onto them.  If i permanently delete them, but plug the devices back into my computer they will re-appear again.  The worm is clearly still on my computer, and I'm wondering if I need to do something other than run the full scan, there doesn't seem to be a lot of info on the web out there.

    thanks!
    -BigBossC


  • 2.  RE: rejoice2009.exe?

    Posted Feb 27, 2010 04:25 PM
    disable your autorun. might be getting copied from your usb. scan it once too.

    How to prevent a virus from spreading using the "AutoRun" feature


    http://service1.symantec.com/SUPPORT/ent-security.nsf/docid/2008032111570648 


  • 3.  RE: rejoice2009.exe?

    Posted Feb 28, 2010 01:47 AM
    Upload the rejoice2009.exe file to www.virustotal.com and see the result and submit the file to securityresponse team. symantec will release new defs this virus. for quick response call symantec customer care.