Re: agobot

From: deke (anonymous_at_discussions.microsoft.com)
Date: 12/19/03


Date: Fri, 19 Dec 2003 11:36:33 -0800


>-----Original Message-----
>You are confused - It's Trend's HouseCall, It's McAfee's
Stinger.
>
>As for the Registry - If you won't do it, take to a local
a service center. This is a Self
>Help forum. I can't reach out to your PC and make
modifications :-)
>
>Dave
>
>
>
>
>"deke" <anonymous@discussions.microsoft.com> wrote in
message
>news:00cd01c3c65f$fc4ddd60$a401280a@phx.gbl...
>>.
>| >McAffee's housecall, and TM's Stinger both found, but
>| could not remove worm. As previously mentioned, I am no
>| tech, and am terrified of editing the registry.
>
>
>.
>I'm not saying that I won't, just that I'm wary. At this
point, I have bought new McAfee basic AV software on CD,
and it would not install(or at least the scan console
would not start). I took your advice from another post
and tried it in safe mode. It is presently scanning.
Among other things, it has found one instance of
W32/Gaobot.worm.(g)en. The g in parenthesese could be a q,
I can't be sure, the name is underlined as a link,
obliterating the tail of the letter.
The file name is: C:\System Volume Information\_restore
{***}\RP10\A0005953,exe, where *** is a string of numbers,
digits, and dashes. I assume this to be a restore point,
which brings me to a problem(again). I cannot access
System Restore. When I try, I get an error message, and
there is no restore tab on the system properties box.
   I'm trying not to ramble, just don't know what is
important or not.
   One more thing, since this copy of McAfee was "off the
shelf" I feel that I probably need to update, but I can't
get on-line in safe mode.
   AV has finished scanning now, and has found another
instance of the same worm in
C:\WINDOWS\system 32\wincffg.exe
Both have been deleted by AV

 



Relevant Pages

  • Re: Help Restoring Registry
    ... I have not shut down and rebooted since I aborted the registry editing and tried to install the registry back up. ... > When System Restore opens, select the option to: Restore my computer to an earlier time. ... > booting into Safe Mode: Press the F8 key between powering on, ...
    (microsoft.public.windowsxp.general)
  • Re: Help Restoring Registry
    ... Go directly to System Restore. ... > I have not shut down and rebooted since I aborted the registry editing and tried to ... >> booting into Safe Mode: Press the F8 key between powering on, ...
    (microsoft.public.windowsxp.general)
  • Re: Strange language problem at bootup
    ... System Restore is more drastic that editing a registry ... See if fixing the pre-logon language resolves the problem. ...
    (microsoft.public.windowsxp.general)
  • Re: Corrupted Registry and Unable to Boot
    ... I exported the entire registry with regedit as a ... don't despair :-) If you had System Restore turned on you can ... The navigate to the folder System ...
    (microsoft.public.windowsxp.general)
  • Re: Restoring the registry
    ... > What exactly happens when you chose to restore the registry.. ... Several system hives, an all user hive, ... System Restore monitors changes to the portions of the registry that apply ...
    (microsoft.public.windowsxp.basics)