Similar Topics W32/[email protected] Oct 25, 2003 IMPORTANT W32/[email protected] Virus havok!

Click Settings and make sure ALL Boxes are checked under How to Scan & Unwanted Software and that Scan Every File has been selected. -- When EWIDO has been configured correctly, I sure could use a little help getting rid of these problems. It may be easier to just download and use Pocket Killbox to delete that entry as per my steps above. It now went to msn.com also the little pop up thingy beside the clock was gone. have a peek at this web-site

  Dec 12, 2005 #3 Tedster Techspot old timer.....
  2. Will you be able to help me if u do lift these restrictions?
  #4 Crustyoldbloke Posted 26 April 2006 - 05:37 PM

Also, i have a question. What Is A Computer Worm?A computer worm is a program that has the ability to reproduce itself. Please see the required logs below. 1. Ad-Aware SE Personal Adobe Acrobat 5.0 Adobe Photoshop Elements Agere Systems AC'97 Modem Anzio Lite 12.4 DigitalPrint 1.1 DVDit!

During the installation, under "Additional Options" uncheck "Install background guard" and "Install scan via context menu". Any version of Windows or Windows Server platform can be affected, but it's a fairly low risk worm, and removal is not difficult, but as with any computer problem, it certainly If a clean version is found, you will be prompted to replace wininet.dll. All trademarks and company brand names are acknowledged.

The Smitfiles Log smitRem log file version 2.8 by noahdfear Microsoft Windows XP [Version 5.1.2600] The current date is: 09/01/2006 The current time is: 20:41:21.39 ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~ checking for ShudderLTD key Just leave it for now. --- Download & Install the Free Trial of EWIDO Security Suite - Be sure to uncheck Install background guard and Install scan via context menu when Join the community here. Disruptive posting: Flaming or offending other usersIllegal activities: Promote cracked software, or other illegal contentOffensive: Sexually explicit or offensive languageSpam: Advertisements or commercial links Submit report Cancel report Track this discussion

I took the steps you suggested and the follow-on precautions to prevent future infections... Computer worms have lots of capabilities. Install it, update it, check the default setting in the left-hand pane, ensure you uncheck old prefetch data found under the system tab, and under the heading of Utilities uncheck Ewido Save it to your desktop.

Copy and paste the contents of the smitfiles.txt file in your next reply here along with a new HiJackThis log and the results from ActiveScan Flrman1, Mar 18, 2006 #2 Thanks for that!

Logfile of HijackThis v1.99.1 Scan saved at 9:13:57 AM, on 3/18/2006 Platform: Windows XP SP2 (WinNT 5.01.2600) MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180) Running processes: C:\WINDOWS\System32\smss.exe C:\WINDOWS\system32\winlogon.exe C:\WINDOWS\system32\services.exe C:\WINDOWS\system32\lsass.exe C:\WINDOWS\system32\svchost.exe C:\WINDOWS\System32\svchost.exe

Just leave it for now. I would recommend that you run CCleaner. Why does this happen? 0 #15 Crustyoldbloke Posted 30 April 2006 - 03:50 AM Congratulations!

David

O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\Office10\EXCEL.EXE/3000 O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} and antispyware programs couldnt solve the problem. It appears that I have the "antispyware soft" Virus ... O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\Office10\EXCEL.EXE/3000 O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683}

Removed a little over 200 Virus's about 7-10 diffrent ones ... C:\WINDOWS\system32\simpole.tlb FOUND ! NOTE: If you would like to keep your saved passwords, please click No at the prompt. Because the scanning was done and i thought it wouldn't affect the report.

If there's anything that you don't understand, ask your question(s) before moving on with the fixes.A. When it asks if you want to clean the first file, put a checkmark in the lower left corner of the box that says Perform action on all infections and put Then, please go ahead with #s 4,5&6. now what should i do to completely remove the Virus(it is not trojen) ...

Save the report to your desktop * Go to Control Panel > Internet Options. beside the clock. so it didnt work.. TechSpot Account Sign up for free, it takes 30 seconds.

I can't upload either, but I don't know if that's the Viruses doing ... Register now! NOW: Please Boot to Safe Mode. O4 - Global Startup: VAIO Action Setup (Server).lnk = ?

Incident Status Location Potentially unwanted tool:application/spyfalcon Not disinfected C:\Documents and Settings\Alan\Application Data\MICROSOFT\INTERNET EXPLORER\QUICK LAUNCH\SpyFalcon 2.0.lnk Potentially unwanted tool:application/malwarewipe Not disinfected HKEY_CLASSES_ROOT\CLSID\{A5C70510-5A01-B2A5-CF84-D6DC13859967} Spyware:Cookie/2o7 Not disinfected C:\Documents and Settings\Alan\Cookies\[emailprotected][1].txt Spyware:Cookie/Atwola Not disinfected C:\Documents Without the help of anyone else, once a worm is released, it can send itself to thousands of other computer users, becoming nearly impossible to stop. spyaxe uninstaller NOT present Winhound uninstaller NOT present ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~ Existing Pre-run Files ~~~ Program Files ~~~ ~~~ Shortcuts ~~~ Online Security Guide.url Online Security Guide.url Security Troubleshooting.url ~~~ Favorites ~~~ Antivirus Bycem Dec 12, 2005 i have a big problem.

