1. You are viewing our forum as a guest. For full access please Register. WindowsBBS.com is completely free, paid for by advertisers and donations.

worm-spybot question

Discussion in 'Security and Privacy' started by bbob, 2004/01/22.

Thread Status:
Not open for further replies.
  1. 2004/01/22
    bbob

    bbob Inactive Thread Starter

    Joined:
    2002/03/19
    Messages:
    76
    Likes Received:
    0
    I have a worm/spybot on my computer that AVG continually removes. The only difference is that the last number changes.
    Can I locate the infected file and remove it with the information that AVG gives me? When I look for it I can't find it's location.

    I've included the report in the hopes that someone can help me.
    If you need more info ask and i'll do the best that I can.


    Testing C:\ serial 2456-1EF2
    Testing D:\ serial F074-F298
    D:\Documents and Settings\All Users.WINNT\Application Data\Microsoft\NETWORK\Downloader\QMGR0.DAT Cannot open; not checked!
    D:\Documents and Settings\All Users.WINNT\Application Data\Microsoft\NETWORK\Downloader\QMGR1.DAT Cannot open; not checked!
    D:\Documents and Settings\NetworkService.NT AUTHORITY\ntuser.dat.LOG Cannot open; not checked!
    D:\Documents and Settings\NetworkService.NT AUTHORITY\NTUSER.DAT Cannot open; not checked!
    D:\Documents and Settings\NetworkService.NT AUTHORITY\Local Settings\Application Data\Microsoft\WINDOWS\UsrClass.dat.LOG Cannot open; not checked!
    D:\Documents and Settings\NetworkService.NT AUTHORITY\Local Settings\Application Data\Microsoft\WINDOWS\USRCLASS.DAT Cannot open; not checked!
    D:\Documents and Settings\LocalService.NT AUTHORITY\ntuser.dat.LOG Cannot open; not checked!
    D:\Documents and Settings\LocalService.NT AUTHORITY\NTUSER.DAT Cannot open; not checked!
    D:\Documents and Settings\LocalService.NT AUTHORITY\Local Settings\Application Data\Microsoft\WINDOWS\UsrClass.dat.LOG Cannot open; not checked!
    D:\Documents and Settings\LocalService.NT AUTHORITY\Local Settings\Application Data\Microsoft\WINDOWS\USRCLASS.DAT Cannot open; not checked!
    D:\Documents and Settings\BOBS\NTUSER.DAT Cannot open; not checked!
    D:\Documents and Settings\BOBS\NTUSER.DAT.LOG Cannot open; not checked!
    D:\Documents and Settings\BOBS\Local Settings\Application Data\Microsoft\WINDOWS\USRCLASS.DAT Cannot open; not checked!
    D:\Documents and Settings\BOBS\Local Settings\Application Data\Microsoft\WINDOWS\UsrClass.dat.LOG Cannot open; not checked!
    D:\System Volume Information\_restore{C9F75713-B641-41FB-95DD-0FB93089CE47}\RP556\A0134233.EXE repaired
    D:\System Volume Information\_restore{C9F75713-B641-41FB-95DD-0FB93089CE47}\RP556\A0134234.EXE repaired
    D:\System Volume Information\_restore{C9F75713-B641-41FB-95DD-0FB93089CE47}\RP556\A0134235.EXE repaired
    D:\System Volume Information\_restore{C9F75713-B641-41FB-95DD-0FB93089CE47}\RP556\A0134236.EXE repaired
    D:\System Volume Information\_restore{C9F75713-B641-41FB-95DD-0FB93089CE47}\RP556\A0134237.EXE repaired
    D:\System Volume Information\_restore{C9F75713-B641-41FB-95DD-0FB93089CE47}\RP556\A0134238.EXE repaired
    D:\System Volume Information\_restore{C9F75713-B641-41FB-95DD-0FB93089CE47}\RP556\A0134239.EXE repaired
    D:\WINNT\SYSTEM32\CONFIG\SYSTEM.LOG Cannot open; not checked!
    Testing F:\ serial 2C6D-AD09

    Test finished, duration 00:48:46.3 s
    245282 objects tested, 7 found infected

    Thanks in advance.
     
    bbob,
    #1
  2. 2004/01/22
    markp62

    markp62 Geek Member Alumni

    Joined:
    2002/05/01
    Messages:
    4,012
    Likes Received:
    16
    Disable System Restore, reboot, then enable it and reboot. Your system keeps pulling it out of there, this will get rid of it.
     

  3. to hide this advert.

  4. 2004/01/22
    bbob

    bbob Inactive Thread Starter

    Joined:
    2002/03/19
    Messages:
    76
    Likes Received:
    0
    in the process of doing it now.

    thank you.


    it appears that was all that needed to be done.:D
     
    Last edited: 2004/01/23
    bbob,
    #3
  5. 2004/02/05
    bbob

    bbob Inactive Thread Starter

    Joined:
    2002/03/19
    Messages:
    76
    Likes Received:
    0
    these files r back again. Is there a way to permanantly remove them?
     
    bbob,
    #4
  6. 2004/02/05
    noahdfear

    noahdfear Inactive

    Joined:
    2003/04/06
    Messages:
    12,178
    Likes Received:
    15
    If infected files are getting back into system restore after disabling it and rebooting, then your system is still infected or reinfected. Do this online scan. Then update AVG, disable system restore and reboot, then run AVG. When it's done, re-enable system restore.
     
  7. 2004/02/06
    bbob

    bbob Inactive Thread Starter

    Joined:
    2002/03/19
    Messages:
    76
    Likes Received:
    0
    i've completed the process. when I did the online scan it listed some files. It did not remove them or/and I could'nt print them. When I ran AVG it did not find any virus's. I guess i'll just see what happens. If I need to do anything else let me know.

    thanks :)

    I am going to use the autoclean setting, which I may not of had on.
     
    Last edited: 2004/02/06
    bbob,
    #6
  8. 2004/02/07
    markp62

    markp62 Geek Member Alumni

    Joined:
    2002/05/01
    Messages:
    4,012
    Likes Received:
    16
    You might want to check the scan settings for AVG. By default it does not scan all files, usually document & sheets, program files. The online does all files by default.
     
Thread Status:
Not open for further replies.

Share This Page

  1. This site uses cookies to help personalise content, tailor your experience and to keep you logged in if you register.
    By continuing to use this site, you are consenting to our use of cookies.