Re: JS.downloader.trojan & w32.netsky.p@mm!enc

From: David H. Lipman (DLipman~nospam~_at_Verizon.Net)
Date: 10/06/04


Date: Wed, 6 Oct 2004 16:24:45 -0400

1) Download the following three items...

         Trend Sysclean Package
         http://www.trendmicro.com/download/dcs.asp

         Latest Trend signature files.
         http://www.trendmicro.com/download/pattern.asp

         Adaware SE
         http://www.lavasoftusa.com/

Create a directory.
On drive "C:\"
(e.g., "c:\New Folder")
or the desktop
(e.g., "C:\Documents and Settings\lipman\Desktop\New Folder")

Download sysclean.com and place it in that directory.
Dowload the signature files (pattern files) by obtaining the ZIP file.
For example; lpt186.zip

Extract the contents of the ZIP file and place the contents in the same directory as
sysclean.com.

2) If you are using WinME or WinXP, disable System Restore
            http://vil.nai.com/vil/SystemHelpDocs/DisableSysRestore.htm
3) Reboot your PC into Safe Mode
4) Using both the Trend Sysclean utility and Adaware, perform a Full Scan of your
        platform and clean/delete any infectors/parasites found.
5) Restart your PC and perform a "final" Full Scan of your platform using both the
        Trend Sysclean utility and Adaware
6) If you are using WinME or WinXP,Re-enable System Restore and re-apply any
            System Restore preferences, (e.g. HD space to use suggested 400 ~ 600MB),
7) Reboot your PC.
8) If you are using WinME or WinXP, create a new Restore point
9) Please report back your results

Dave

"phildee" <phildee@discussions.microsoft.com> wrote in message
news:694ACAF3-88AD-4A8F-B979-C980FD276C0C@microsoft.com...
| Hi there
|
| I'm running symantec antivirus corporate edition and it keeps coming up with
| these 2 viruses, my virus defs are up to date and win updates and it will not
| delete these files or quarantine them. I have rebooted in safe made and ran
| a full scan and it comes back with nothing. I'm running windows 2000 small
| business server with an exchange drive (m:) some of the files come from there
| but some are on my c drive. When I go in to delete them manually they aren't
| there yet everyday just about they keep registering in symantec antivirus.
|
| Any help here would be appreciated!!



Relevant Pages

  • Re: what is fcfB.exe?
    ... Dump the contents of the IE Temporary Internet Folder cache ... Download Sysclean.com and place it in that directory. ... Reboot your PC into Safe Mode and shutdown as many applications as possible ... Re-enable System Restore and re-apply any System Restore preferences, ...
    (microsoft.public.windowsxp.general)
  • Re: mszx23.exe Trojan
    ... (e.g., "c:\New Folder") ... Download Sysclean.com and place it in that directory. ... If you are using WinME or WinXP, disable System Restore ... Reboot your PC into Safe Mode and shutdown as many applications as possible ...
    (microsoft.public.security.virus)
  • Re: System Freeze - 100% CPU Usage
    ... (e.g., "c:\New Folder") ... Download SYSCLEAN.COM and place it in that directory. ... Reboot your PC into Safe Mode and shutdown as many applications as possible ... Re-enable System Restore and re-apply any System Restore preferences, ...
    (microsoft.public.windowsxp.general)
  • Re: 100% CPU Usage
    ... folder probably caused by interference by an AV scan during the Update ... Stop and Disable Automatic Updates, ... Now Reboot Again. ... Go to http://wiki.djlizard.net/Dial-a-fix and download Dial-a-fix ...
    (microsoft.public.windowsupdate)
  • Re: rulechinbait.exe anybody?
    ... (e.g., "c:\New Folder") ... Download Sysclean.com and place it in that directory. ... Reboot your PC into Safe Mode and shutdown as many applications as possible ... Re-enable System Restore and re-apply any System Restore preferences, ...
    (microsoft.public.windowsxp.general)