Re: help...fou or five virus's...confused...PC sick and dying

From: Shenan Stanley (news_helper_at_hushmail.com)
Date: 05/09/04


Date: Sun, 9 May 2004 15:28:57 -0500

confuzzled wrote:
> I have been battling a four virus's for a week or two. The virus's
> are W32.Netsky.C and W32.Beagle and at one point W32. Blaster.Worm
> and Trojan.Bookmark.Gen and Trojan.Mitgieder.F - I eventually got to
> pint were I could use Norton AntiVirus 2002 to work - and it found
> 11,536 infected file and it repaired two quarantined 11,433 and the
> rest it needs to delete. Unfortunately some of those files are
> C:\WINDOWS\winlogon.exe C:\WINDOWS\SYSTEM32\winproc.exe
> C:\WINDOWS\SYSTEM32\system.exe
> -ditto \drvsys.exe
> -ditto \drvsys.exeopen
> -ditto \drvsys.exeopenopen
>
> SHOULD I DELETE THEM? I have my Windows XP CD.
>
> PLEASE HELP - THANK YOU IN ADVANCE!!!!!!!!!!!!

Patch your PC with Windows Updates.

Clean it with an AntiVirus software and perhaps Removal Tools found at
Symantec:

Netsky:
http://securityresponse.symantec.com/avcenter/venc/data/w32.netsky@mm.removal.tool.html
Beagle:
http://securityresponse.symantec.com/avcenter/venc/data/w32.beagle@mm.removal.tool.html
Blaster:
http://securityresponse.symantec.com/avcenter/venc/data/w32.blaster.worm.removal.tool.html

Then clean up and secure that pc:

Please Notice that if you use AOL, you should at least upgrade to 9.0 or
greater before doing any of the fixes. I know you can get AOL 9.0 at almost
any convenience store, gas station, super market or other retail outlet in
the world, so this should not be a problem. Also, if you are using AOL 9.0,
you will not be able to perform the first step in this list. You should
look into another solution, such as ZoneAlarm, for a firewall.

Turn on that firewall...
http://www.microsoft.com/WindowsXP/home/using/howto/homenet/icf.asp

Make sure you have all the updates (critical) installed from:
http://windowsupdate.microsoft.com/
(Scan for updates, Review and Install)

Get rid of the spy/ad/mal-ware..
(Yes - using MORE than one of these..
I recommend at least the first three. Also..
UPDATE the definitions for them before using.)

 Spybot Search and Destroy
 http://www.safer-networking.net/

 Lavasoft AdAware
 http://www.lavasoft.de

 CWSShredder
 http://www.spywareinfo.com/~merijn/downloads.html

 Hijack This!
 http://mjc1.com/mirror/hjt/

 I also like "The Cleaner" and "SpywareBlaster" and "SpywareGuard".
  - http://www.moosoft.com/
  - http://www.javacoolsoftware.com/

The first is a PAY product, but useable for 30 days - it has found and
eliminated problems in the past the others did not. The latter two are
prevention mechanisms. SpywareBlaster is a FANTASTIC free product, I
suggest getting this after you cleanup and keeping it updated as well.

 Bazooka Adware and Spyware Scanner (Free!)
 http://kephyr.sureshot.xaviermedia.net/spywarescanner/

 ToolbarCop (Free!)
 http://www.mvps.org/sramesh2k/toolbarcop.htm

 Browser Security Tests
 http://www.jasons-toolbox.com/BrowserSecurity/

 And Assortment of Others:
 http://spywareinfo.com/

ALSO - Be sure to IMMUNIZE after you clean up. SpywareBlaster and Spybot
Search and destroy both have these features - use both!

After you cleanup your PC somewhat of spy/ad/mal-ware, verify your antivirus
software is updated and run a full scan of your computer. If you have no
antivirus software - get one NOW! Grisoft AntiVirus:
http://www.grisoft.com/us/us_dwnl_free.php

Empty your Temporary Internet Files and shrink the size it stores to about
80 to 120MB (seems to be an optimal size for the normal user)

 - Open ONE copy of Internet Explorer.
 - Select TOOLS -> Internet Options.
 - Under the General tab in the "Temporary Internet Files" section,
   do the following:
  - Click on "Delete Cookies" (click OK)
  - Click on "Settings" and change the
    "Amount of disk space to use:" to something between 80MB
    and 120MB. (Betting it is MUCH larger right now.)
  - Click OK.
  - Click on "Delete Files" and select to
    "Delete all offline contents" (the checkbox) and click
    OK. (If you had a LOT, this could take 2-10 minutes or
    more.)
- Once it is done, click OK, close Internet Explorer
- Re-open Internet Explorer.

Uninstall any software you do not use often/ever. (If you have something
installed but never use it, uninstall it.) If you go through Control
Panel -> Add/Remove Programs and see things you seldom if ever use, it is to
your advantage to remove it.

Also, if you are tired of Web Page Pop-Ups/Unders.. You could try the
Google Toolbar.
http://toolbar.google.com/

Stop loading applications at logon.. run MSCONFIG and look under the startup
tab for things you DON'T want to startup! Search the Internet with Google
to discover what things are safe to remove and what things may even be
malware infecting your computer.

Better control your email and lessen the amount of time you spend dealing
with SPAM:
 SpamBayes
 http://spambayes.sourceforge.net/
or
 Spamihilator.
 http://www.spamihilator.com

-- 
<- Shenan ->
-- 


Relevant Pages

  • Re: virus trouble, programs wont load
    ... You have not patched (or you did a repair installation and did not repatch) ... Make sure you have all the updates installed from: ... to have something running like antivirus software - and it prevents browser ... Empty your Temporary Internet Files and shrink the size it stores to about ...
    (microsoft.public.windowsxp.help_and_support)
  • Re: IE6 Homepage
    ... You may have spyware/adware infesting your machine, ... Make sure you have all the updates installed from: ... to have something running like antivirus software - and it prevents browser ... Empty your Temporary Internet Files and shrink the size it stores to about ...
    (microsoft.public.windows.inetexplorer.ie6.browser)
  • Re: CoolWebSearch Virus
    ... > I've been hearing a lot about the CoolWebSearch Virus on the Net. ... I don't see where any of the updates address this ... to have something running like antivirus software - and it prevents browser ... Empty your Temporary Internet Files and shrink the size it stores to about ...
    (microsoft.public.windowsxp.help_and_support)
  • Re: LSA Patch
    ... > window pops up there is another window that pops saying ... Know that even if you have the normal updates for Norton, ... to have something running like antivirus software - and it prevents browser ... Empty your Temporary Internet Files and shrink the size it stores to about ...
    (microsoft.public.windowsxp.perform_maintain)
  • Re: Norton Disk DR..Exclusive rights????
    ... > I am trying to run a Norton disk dr...everytime I run it ... to have something running like antivirus software - and it prevents browser ... Empty your Temporary Internet Files and shrink the size it stores to about ...
    (microsoft.public.windowsxp.security_admin)