1. You are viewing our forum as a guest. For full access please Register. WindowsBBS.com is completely free, paid for by advertisers and donations.

w32/MYDOOM

Discussion in 'Security and Privacy' started by Bimmer Guy, 2004/01/29.

Thread Status:
Not open for further replies.
  1. 2004/01/29
    Bimmer Guy

    Bimmer Guy Well-Known Member Thread Starter

    Joined:
    2002/04/01
    Messages:
    328
    Likes Received:
    0
    Hello, Like a dummy I opened an attachment. Just for the heck of it I ran this new STINGER program. It found 10 versions of it. AVG and Norton don't see it to remove it. How can I remove it? I don't wanna infect everyone on my address book:(
    Thanks
     
  2. 2004/01/29
    reboot

    reboot Inactive

    Joined:
    2002/01/07
    Messages:
    831
    Likes Received:
    0

  3. to hide this advert.

  4. 2004/01/29
    Bimmer Guy

    Bimmer Guy Well-Known Member Thread Starter

    Joined:
    2002/04/01
    Messages:
    328
    Likes Received:
    0
    Thanks Reboot No viruses found!!!!!!!!!!!!!:D
     
  5. 2004/01/29
    aleekat

    aleekat Inactive

    Joined:
    2002/01/07
    Messages:
    902
    Likes Received:
    0
    Just for the heck of it I ran this new STINGER program. It found 10 versions of it. AVG and Norton don't see it to remove it.

    10 versions of what? MyDoom? Try to update your Norton's virus definitions. If you can't, then you got the new variant. Look down a couple posts for info.
     
  6. 2004/01/31
    Bimmer Guy

    Bimmer Guy Well-Known Member Thread Starter

    Joined:
    2002/04/01
    Messages:
    328
    Likes Received:
    0
    Thanks aleekat: 10 versions of w32/MYDOOM.a@mm in my Netscape trash was found by Stinger. I found in other posts some links to remove all the junk.

    Thanks guys
     
  7. 2004/02/02
    Bimmer Guy

    Bimmer Guy Well-Known Member Thread Starter

    Joined:
    2002/04/01
    Messages:
    328
    Likes Received:
    0
    Virus??

    I just ran that Stinger proram from Mcafee that they released 1/28/04. It says I have the W32/Dumaru@mm 2 times. So I went to Symantic and found their W32/Dumaru@mm fix tool. It says I have NO such virus. Who do I believe???

    Thanks Marty

    Btw, I'm running AVG antivirus. Fully up to date and it finds nothing wrong either??:confused:
     
  8. 2004/02/02
    goddez1

    goddez1 Inactive

    Joined:
    2002/01/12
    Messages:
    2,975
    Likes Received:
    49
    If in doubt walk through the manual cleanups. Look for files and regkeys mentioned.

    Perhaps you have quarantined files by Norton that mcaffee is detecting as viral.

    OR maybe this log file flips mcaffee out, as mentioned in the link provided:

    Creates %Windir%\winload.log, which is a log file. The worm uses this file to store the stolen email addresses.

    NOTE: This file is not viral by itself, and therefore, Symantec antivirus products do not detect this file. Manually delete it if your system is infected with this worm.
     
    Last edited: 2004/02/02
  9. 2004/02/03
    Bimmer Guy

    Bimmer Guy Well-Known Member Thread Starter

    Joined:
    2002/04/01
    Messages:
    328
    Likes Received:
    0
    Thanks for replying goddez1, beyond using a removal tool for viruses I have no idea how to remove them. Basicly I don't follow what you said.

    Marty
     
  10. 2004/02/03
    Bimmer Guy

    Bimmer Guy Well-Known Member Thread Starter

    Joined:
    2002/04/01
    Messages:
    328
    Likes Received:
    0
    From Symantec: a.Click Start, and then click Run. (The Run dialog box appears.)
    b.Type regedit

    Then click OK. (The Registry Editor opens.)

    c.Navigate to the key:

    HKEY_LOCAL_MACHINE SOFTWARE \ Microsoft \ Windows \ CurrentVersion \ Run

    d.In the right pane, delete the value:

    "load32 "= "%Windir%\load32.exe "

    e.Exit the Registry Editor.
    Nothing was there
     
  11. 2004/02/03
    aleekat

    aleekat Inactive

    Joined:
    2002/01/07
    Messages:
    902
    Likes Received:
    0
    Isn't this your second post the this "Stinger" found something, but others did not? Why not try an online scan. Housecall
     
  12. 2004/02/03
    markp62

    markp62 Geek Member Alumni

    Joined:
    2002/05/01
    Messages:
    4,012
    Likes Received:
    16
    I merged the two threads.
    You haven't mentioned the OS, but is it possible these are found in the Restore folder?
    I would disable System Restore, reboot, then enable it, if your OS has this.
     
  13. 2004/02/05
    Bimmer Guy

    Bimmer Guy Well-Known Member Thread Starter

    Joined:
    2002/04/01
    Messages:
    328
    Likes Received:
    0
    Hello markp62: I have win 98. It does'nt have
    that disable System Restore option right? House call would'nt run on my Netscape 4.79. I ran it on IE 6 and it says no viruses. Maybe thats it, I hope.

    Marty
     
  14. 2004/02/07
    markp62

    markp62 Geek Member Alumni

    Joined:
    2002/05/01
    Messages:
    4,012
    Likes Received:
    16
    No, 98 does not have System Restore. I would go with the opinion of Housecall. Some AV programs do make what is called a false positive, that is why more than one scan is good.
     
Thread Status:
Not open for further replies.

Share This Page

  1. This site uses cookies to help personalise content, tailor your experience and to keep you logged in if you register.
    By continuing to use this site, you are consenting to our use of cookies.