PDA

View Full Version : spyware worm


DEVIL808
November 25th 04, 12:25 AM
I HAVE THREE DIFERENT ANTI-VIRUS PROGRAMS, NORTONS ANTI-VIRUS 2002, SPYBOT-
SEARCH AND DESTROY, AND AD-AWARE SE PERSONAL. I AM TRYING TO GET RID OF A
SPYWARE W-32 WORM .(I THINK IT CALLED) CAN SOMEONE HELP ME GET RID OF IT FOR
FREE. MY COMPUTER IS REALLY SLOW AND MY CURSER KEEPS GOING NUT AND OPENING UP
THINGS I DON'T WANT IT TO.
HELP PLEASE

Rock
November 25th 04, 12:32 AM
DEVIL808 wrote:
> I HAVE THREE DIFERENT ANTI-VIRUS PROGRAMS, NORTONS ANTI-VIRUS 2002, SPYBOT-
> SEARCH AND DESTROY, AND AD-AWARE SE PERSONAL. I AM TRYING TO GET RID OF A
> SPYWARE W-32 WORM .(I THINK IT CALLED) CAN SOMEONE HELP ME GET RID OF IT FOR
> FREE. MY COMPUTER IS REALLY SLOW AND MY CURSER KEEPS GOING NUT AND OPENING UP
> THINGS I DON'T WANT IT TO.
> HELP PLEASE

First, please don't post in all caps. In internet useage that's
considered the equivalent of SHOUTING.

You need a newer AV engine. 2002 is getting old in the tooth. Whether
that will fix your problem I don't know, though.

Make sure you run those cleaners in safe mode.

For viruses, start with Trend Micro’s Sysclean. Download it and the
signature file. Turn off system restore, boot into safe mode and run
sysclean. Boot back into normal mode and run a full AV scan with your
normal AV program. Then turn system restore back on.

Trend Micro Sysclean
http://www.trendmicro.com/download/dcs.asp

Trend Micro Signature File
http://www.trendmicro.com/download/pattern.asp

You should also regularly run at least two of these online scans in
addition to your regular up to date AV program:

Online and Downloadable Virus Scanning:

Panda ActiveScan
http://www.pandasoftware.com/activescan/com/activescan_principal.htm

Bit Defender Online Virus Scan:
http://www.bitdefender.com/scan/license.php

Symantec Online Virus and Security Scan:
http://security.symantec.com/ssc/home.asp

TrendMicro:
http://housecall.trendmicro.com/housecall/start_corp.asp

McAfee Online Virus Scan:
http://www.mcafee.com/myapps/mfs/default.asp

RAV AntiVirus - Scan Online
http://www.ravantivirus.com/scan/

F-Secure:
http://support.f-secure.com/enu/home/ols.shtml

Lastly if those don't work download and run HijackThis. Post the log to
one of the specialty forums listed below, _not_ this one.

HijackThis
http://www.majorgeeks.com/download.php?det=3155

Forums to Interpret HijackThis Logs:

http://www.spywareinfo.com/forums/
http://forum.aumha.org/viewforum.php?f=30
http://forums.tomcoyote.org/
http://www.wilderssecurity.com/

After your system is clean use these programs to help keep it clean:

Spywareblaster
www.javacoolsoftware.com/sbdownload.html

Spywareguard
http://www.javacoolsoftware.com/sgdownload.html

IE-SPYAD
http://www.staff.uiuc.edu/~ehowes/resource.htm

Redhead
November 25th 04, 12:44 AM
Ewido is a wonderful freeware program that removes trojans, worms, key
loggers, spyware and such. They also have a premium "pay for" software
package. I run the freeware program. The difference is, the premium has a
background guard watching your system as you use your computer and it will
do auto updates for definitions. The freeware you have to click on update
and you have to click on scan to check your system. I can click! This
program is for XP and win 2000 only.

It is very thorough.
Ewido: http://www.ewido.net/en/

Redhead

"DEVIL808" > wrote in message
...
> I HAVE THREE DIFERENT ANTI-VIRUS PROGRAMS, NORTONS ANTI-VIRUS 2002,
SPYBOT-
> SEARCH AND DESTROY, AND AD-AWARE SE PERSONAL. I AM TRYING TO GET RID OF A
> SPYWARE W-32 WORM .(I THINK IT CALLED) CAN SOMEONE HELP ME GET RID OF IT
FOR
> FREE. MY COMPUTER IS REALLY SLOW AND MY CURSER KEEPS GOING NUT AND OPENING
UP
> THINGS I DON'T WANT IT TO.
> HELP PLEASE

Malke
November 25th 04, 12:44 AM
DEVIL808 wrote:

> I HAVE THREE DIFERENT ANTI-VIRUS PROGRAMS, NORTONS ANTI-VIRUS 2002,
> SPYBOT-
> SEARCH AND DESTROY, AND AD-AWARE SE PERSONAL. I AM TRYING TO GET RID
> OF A SPYWARE W-32 WORM .(I THINK IT CALLED) CAN SOMEONE HELP ME GET
> RID OF IT FOR FREE. MY COMPUTER IS REALLY SLOW AND MY CURSER KEEPS
> GOING NUT AND OPENING UP THINGS I DON'T WANT IT TO.
> HELP PLEASE

1. Please don't post in all capital letters - it is considered shouting
and rude, but even more important it makes your post hard to read.

2. NAV 2002 is really out of date. Are your virus definitions current?
Or did you let your subscription lapse?

3. Of the programs you listed above, only NAV is an antivirus. Spybot
and Ad-aware remove non-viral malware, not viruses.

4. Try running TrendMicro's Sysclean. You should disconnect the infected
machine from the Internet and any local network and not connect it
again until you know it is 100% virus and spyware-free. It is best
practice therefore to download Sysclean on an unconnected, known-clean
machine that has a cd burner. Here are instructions for Sysclean:

TrendMicro's Sysclean is an extensive antivirus tool which has the
advantage of not needing to be installed. It requires two parts - the
scanning engine and the virus pattern files.

1. Create a new folder on your Desktop or the C: drive named something
useful like "Sysclean".
2. Go here and download the two parts of the program to that folder:

http://www.trendmicro.com/download/dcs.asp - Sysclean
http://www.trendmicro.com/download/pattern.asp - virus pattern files

The pattern files will be zipped - extract them with your unzipper (like
WinZip) or if you have XP, you can just open the folder. You need to
put the extracted files in the Sysclean folder you made.

3. Restart your computer in Safe Mode. Get into Safe Mode by repeatedly
tapping the F8 key as the computer is starting up to get to the proper
menu.
4. Go to the Sysclean folder you made and double-click on sysclean.com.
Start the scan. After the scan is finished, look at the log. You may
need to make a note of where any viruses were found if they were not
able to be removed so you can manually delete them.

It is crucial that you run scans in Safe Mode. If you are unable to
clean your machine, take it to a good local computer repair shop (not a
BestBuy or CompUSA type of store) and have them do it for you.

Good luck,

Malke
--
MS-MVP Windows User/Shell
Elephant Boy Computers
www.elephantboycomputers.com
"Don't Panic"

Google