Re: AVG Virus program

From: Jack Nation (jnation_at_mchsi.com)
Date: 08/25/04


Date: Wed, 25 Aug 2004 14:42:43 -0500

Dave asked that I report on results after following the procedure he
outlined below.

I did download and run McAfee Stinger following all instructions. All went
well and my question is answered!

--
Thanks Sincerely,
Jack Nation http://www.cedarnet.org/jnation/
"David H. Lipman" <DLipman~nospam~@Verizon.Net> wrote in message
news:uAJ9k1iiEHA.2400@tk2msftngp13.phx.gbl...
> Obtain McAfee's virus and worm removal tool, Stinger:
http://vil.nai.com/vil/stinger/
>
> 1)    If you are using WinME or WinXP, disable System Restore
>             http://vil.nai.com/vil/SystemHelpDocs/DisableSysRestore.htm
> 2)     Reboot your PC into Safe Mode
> 3)     Using McAfee Stinger, perform a Full Scan of your platform and
clean/delete any
>             infectors found
> 4)     Restart your PC and perform a "final" Full Scan of your platform
> 5)     If you are using WinME or WinXP,Re-enable System Restore and
re-apply any
>             System Restore preferences, (e.g. HD space to use suggested
200 ~ 400MB),
>             reboot your PC.
> 6)     If you are using WinME or WinXP, create a new Restore point
> 7)     Please report back your results
>
> If the above does NOT find MyDoom then AVG is confirmed.  Just becuase a
file name,
> associated with an infector, is found it does not indicate it is indeed
infected.
>
>
> Dave
>
>
>
>
> "Jack Nation" <jnation@mchsi.com> wrote in message
> news:eJJCbwiiEHA.3288@TK2MSFTNGP10.phx.gbl...
> | I am using WindowsXP with Grisoft's AVG Virus program.  I am needing
help
> | understanding a note on the AVG website.  It say to delete a couple of
files
> | (services.exe & java.exe) if on the computer.  I have the files but AVG
does
> | not detect them as having a virus. (These two files are also on the
> | WindowsXP CD).
> |
> | Here is the website note:
> |
> | Quote:
> | I-Worm/Mydoom.O
> | Installation:
> | When the worm is launched it copies itself as services.exe in Windows
> | Directory. In the same directory it creates file java.exe (backdoor)
that it
> | registers as JavaVM in Run key in Windows registry. Worm also creates
> | HKLM\Software\Microsoft\Daemon and HKCU\Software\Microsoft\Daemon keys
in
> | Windows Registry.
> | Spreading: e-mail
> | Worm spreads by sending itself to e-mail addresses that are taken from
files
> | stored on infected computer harddrive.
> | Message:
> | Sender:
> | Sender address is random.
> | Subject and body are randomly generated from texts saved in virus body.
> | Name of attachment is random with one of the following extensions:
> | com
> | bat
> | cmd
> | exe
> | scr
> | pif
> | Removing:
> | Please delete infected files.
> | End quote.
> |
> | Should I delete these 2 files?
> | -- 
> | Sincerely,
> | Jack Nation
> |
> |
>
>


Relevant Pages

  • Re: CSRSS.EXE Virus That Wont Go Away
    ... It is a well established methodology to use the name of legitimate MS Windows Kernel files ... It was created by the infector. ... this being the CodeBlue worm. ... If SVCHOST.EXE is found in %windir% then there is a high chance of this being the Cozit ...
    (microsoft.public.windowsxp.general)
  • FW: Actions for the Blaster Worm - Special Edition, TechNet Flash
    ... Actions for the Blaster Worm - Special Edition, ... You are receiving this message because you are a Microsoft newsletter ... Presence of the file msblast.exe in the WINDOWS SYSTEM32 directory ... antivirus vendor and scan your machine. ...
    (Focus-Microsoft)
  • Re: Cant apply KB835732 on various Win2k systems
    ... So these machines have the Sasser worm? ... Microsoft has learned about a worm identified as "W32.Sasser.worm" that is ... Windows XP Professional ... > AnalyzePhaseOne: used 7691 ticks ...
    (microsoft.public.win2000.security)
  • Safeguard Your PC Against the Downadup Worm
    ... Safeguard Your PC Against the Downadup Worm ... How to protect your PC from the biggest worm in years. ... Security experts say it's the biggest worm attack in years, ... Windows that Microsoft Corp. patched nearly four months ago. ...
    (alt.comp.anti-virus)
  • [NEWS] A new Mass-Mailing and Backdoor Capable Worm Found in the Wild
    ... The worm uses the common auto-reply feature from an infected client to ... This directory varies with each version of Windows: ... It creates this registry entry to load the DLL file during startup: ... Message Body: Adult content!!! ...
    (Securiteam)