Re: Netsky.Q and Dyfica viruses

From: David H. Lipman (DLipman~nospam~_at_Verizon.Net)
Date: 10/08/04


Date: Thu, 7 Oct 2004 20:37:18 -0400

1) Download the following three items...

         Trend Sysclean Package
         http://www.trendmicro.com/download/dcs.asp

         Latest Trend signature files.
         http://www.trendmicro.com/download/pattern.asp

         Adaware SE
         http://www.lavasoftusa.com/

Create a directory.
On drive "C:\"
(e.g., "c:\New Folder")
or the desktop
(e.g., "C:\Documents and Settings\lipman\Desktop\New Folder")

Download sysclean.com and place it in that directory.
Dowload the signature files (pattern files) by obtaining the ZIP file.
For example; lpt186.zip

Extract the contents of the ZIP file and place the contents in the same directory as
sysclean.com.

2) Update Adware with the latest definitions.
3) If you are using WinME or WinXP, disable System Restore
            http://vil.nai.com/vil/SystemHelpDocs/DisableSysRestore.htm
4) Reboot your PC into Safe Mode
5) Using both the Trend Sysclean utility and Adaware, perform a Full Scan of your
        platform and clean/delete any infectors/parasites found.
6) Restart your PC and perform a "final" Full Scan of your platform using both the
        Trend Sysclean utility and Adaware
7) If you are using WinME or WinXP,Re-enable System Restore and re-apply any
            System Restore preferences, (e.g. HD space to use suggested 400 ~ 600MB),
8) Reboot your PC.
9) If you are using WinME or WinXP, create a new Restore point
10) Please report back your results

Dave

"Dave Hanson" <anonymous@discussions.microsoft.com> wrote in message
news:037701c4accc$2ccec230$a501280a@phx.gbl...
| I have tried that approach, but the install stops about
| 2/3 of the way through with a runtime error in the
| Winsu.exe(?) program. I think that is the name of the
| program as I am no longer at her PC.
|
| Dave
| >-----Original Message-----
| >Reinstall the OS.
| >
| >Dave
| >
| >
| >
| >
| >
| >"Dave Hanson" <anonymous@discussions.microsoft.com> wrote
| in message
| >news:1e1901c4acc9$285660d0$a401280a@phx.gbl...
| >| I have a client who had these viruses on her Windows ME
| >| system. I was able to clean her PC, but have run into
| one
| >| major problem. When I run Windows Explorer, the only
| >| thing that appears on her C: drive are the files in her
| >| \My Documents folder. I cannot get to anything in the
| >| Control Pannel obviously either. I tried to run Windows
| >| in safe mode, but holding down on the Ctrl key and
| >| restarting won't allow me to do so. A number of Control
| >| Pannel functions (including Properties) are disabled,
| so I
| >| can't really make any changes here.
| >|
| >| Any help would really be appreciated.
| >|
| >| Dave
| >
| >
| >.
| >



Relevant Pages

  • Re: Home Page and cwshredder
    ... Download: CWShredder ... To rename: Right-click and select: Rename ... "Windows" and close RegLite. ... New> Folder ...
    (microsoft.public.windowsxp.general)
  • Re: the coolweb search file causding IE to revert to the about:blank page
    ... Download: CWShredder ... To rename: Right-click and select: Rename ... "Windows" and close RegLite. ... New> Folder ...
    (microsoft.public.windows.inetexplorer.ie6.browser)
  • Re: Cannot download files in IE6
    ... NIS 2006 personal firewall was disabled permanently and switching windows ... able to download files again. ... have a suggestion as to the best and least problematic internet security ... > Make sure that you can see hidden files (Folder Options> View) Then ...
    (microsoft.public.windows.inetexplorer.ie6.browser)
  • Re: ie explorer hangs up on shut down
    ... Download, install and run HiJackThis in "Safe Mode:" ... DO NOT install in your Desktop folder. ... WINDOWS XP SHUTDOWN & RESTART TROUBLESHOOTING ...
    (microsoft.public.windows.inetexplorer.ie6.browser)
  • Re: CWS searchx strain wont go away
    ... Download: CWShredder ... To rename: Right-click and select: Rename ... "Windows" and close RegLite. ... New> Folder ...
    (microsoft.public.security)

Quantcast