1. You are viewing our forum as a guest. For full access please Register. WindowsBBS.com is completely free, paid for by advertisers and donations.

W32.Ganda.A@mm.enc

Discussion in 'Security and Privacy' started by Christer, 2003/05/28.

Thread Status:
Not open for further replies.
  1. 2003/05/28
    Christer

    Christer Geek Member Staff Thread Starter

    Joined:
    2002/12/17
    Messages:
    6,585
    Likes Received:
    74
    Hi all!

    Had a phone call from a friend who has been hit by this virus.
    He has the latest definitions update from Symantec and the virus is listed in his known virus list.

    The NAV log says that two files had been infected and automatically deleted.

    A virus scan turns up nice and clean.

    However, he can no longer connect to the internet. He is on a dial up modem.

    Is there a connection between the virus and his unability to get online or is this coincidence?

    Thanks for Your time,
    Christer
     
    Last edited: 2003/05/28
  2. 2003/05/28
    aleekat

    aleekat Inactive

    Joined:
    2002/01/07
    Messages:
    902
    Likes Received:
    0
    Did he do this?

    NOTE: As mentioned in step 3 of the Technical Description, the worm infects the .exe and .scr files. These files cannot be repaired and must be deleted. Restore the files that you deleted from a clean backup or re-install the file's software.

    Here's the link.
     

  3. to hide this advert.

  4. 2003/05/28
    Christer

    Christer Geek Member Staff Thread Starter

    Joined:
    2002/12/17
    Messages:
    6,585
    Likes Received:
    74
    Hi aleekat,
    thanks for Your reply!

    I searched the Symantec site for "W32.Ganda.A@mm.enc" which provided far less information than for W32.Ganda.A@mm.

    I´m pretty sure that he has done nothing but he told me that the NAV log listed the deleted files.
    He has no backup but I guess that the deleted files can be extracted from the Win2k CD. (I wish I knew how!)

    I´ll meet with him tomorrow and see what can be done.

    Christer
     
    Last edited: 2003/05/28
  5. 2003/05/28
    aleekat

    aleekat Inactive

    Joined:
    2002/01/07
    Messages:
    902
    Likes Received:
    0
    I would create a new dialup first. But from Symantec, his modem software could have been affected.

    I just re-read your original post. If he had his virus defs up to date. This virus was around 19 Mar. Norton would have found the virus in his email and deleted the affected email files. So, therefore, he never got infected. I would get more specifics from him exactly the sequence of events.
     
  6. 2003/05/29
    Christer

    Christer Geek Member Staff Thread Starter

    Joined:
    2002/12/17
    Messages:
    6,585
    Likes Received:
    74
    I´ve had a look at the computer.

    The virus was caught by NAV and the files deleted were the actual virus trying to copy itself to two locations. Thus the computer wasn´t infected.

    When my friend saw the NAV activity he physically disconnected from the internet, pulled the plug. This is probably why he couldn´t reconnect to the internet.

    Yesterday, on the phone, I told him to restart the computer and he said he did but actually didn´t. He hibernated the computer and woke it up again.

    After a proper shut-off and re-start everything worked.

    He confessed to never having shut off properly, always using hibernation. He now understands the difference.

    Thanks for Your assistance,
    Christer
     
  7. 2003/05/29
    aleekat

    aleekat Inactive

    Joined:
    2002/01/07
    Messages:
    902
    Likes Received:
    0
    Glad it was a simple fix.
     
  8. 2003/05/29
    Christer

    Christer Geek Member Staff Thread Starter

    Joined:
    2002/12/17
    Messages:
    6,585
    Likes Received:
    74
    First of all, when I re-read my own post this "sounded" wacky:

    Of course, he re-connected the plug ...... :D ...... before trying!

    I don´t know how it´s possible but he knows even less about computers than I do so, he was very relieved that it wasn´t a serious situation.

    Christer
     
Thread Status:
Not open for further replies.

Share This Page

  1. This site uses cookies to help personalise content, tailor your experience and to keep you logged in if you register.
    By continuing to use this site, you are consenting to our use of cookies.