new msn virus? help!

R

Roger Wilco

Peter said:
i cant resist asking how come i never got a virus and have no firewall
and no active on line virus schecker and i use yahoo chat msn
messenger chat and aol chat and used to use mirc?

Ummm, because you have an on demand scanner and use best practices?

Without a scanner at all, how would you know if you never got one or
not? Even with one, they are not conclusive.
 
A

aazar

Has anyone found a solution? I have tried SYSCLEAN, STINGER, Norton's
SERFLOG removal tool, I have tried renaming taskmanager, regedit and
running them under new name, I have also tried downloading other
regedit programs, ALL TO NO AVAIL it won't let me download any of the
free anti-virus programmes either. Please don't plug your anti-virus
program or website. Need a removal tool that works.
 
K

kurt wismer

aazar said:
Has anyone found a solution? I have tried SYSCLEAN, STINGER, Norton's
SERFLOG removal tool, I have tried renaming taskmanager, regedit and
running them under new name, I have also tried downloading other
regedit programs, ALL TO NO AVAIL it won't let me download any of the
free anti-virus programmes either. Please don't plug your anti-virus
program or website. Need a removal tool that works.

you need to download from a clean machine, not the compromised one...

and if the serflog (sp?) removal tool doesn't work then there's a good
chance you don't have that particular virus...

you are pretty much stuck - you need an anti-virus to tell you what
virus you have before you can go looking for a removal tool... that
means you're going to have to download an anti-virus that can detect it...
 
A

aazar

Doh!
I know what I have, it''s W/32-Sumom and the serflog removal is
useless, I think a new variant came out on Friday which is worse that
the earlier version.
 
S

SLP

aazar said:
Doh!
I know what I have, it''s W/32-Sumom and the serflog removal is
useless, I think a new variant came out on Friday which is worse that
the earlier version.

I was able to run Win Patrol on an infected machine, which allowed me to
kill the mscv.com and other relevant processes. This allowed Regedit,
Msconfig and Hijack this, etc to be run normally in Safe Mode.

Installing Antivir from http://www.free-av.com/ cleared up the remaining
infected files, but I still had to manually undo the registry changes the
virus made.
See here for the list of changes:

http://securityresponse.symantec.com/avcenter/venc/data/w32.serflog.c.html

SLP
 
I

Ian JP Kenefick

Has anyone found a solution? I have tried SYSCLEAN, STINGER, Norton's
SERFLOG removal tool, I have tried renaming taskmanager, regedit and
running them under new name, I have also tried downloading other
regedit programs, ALL TO NO AVAIL it won't let me download any of the
free anti-virus programmes either. Please don't plug your anti-virus
program or website. Need a removal tool that works.

A removal tool was published to detect and remove this. Details and
link on my site.
--

Regards,
Ian Kenefick
Got a virus?
Go to www.ik-cs.com > 'Got a virus?'
 
A

aazar

Thanks but I have tried the Norton serflog removal utitlity and
although it runs it has *no* effect on this variant. I will try your
other suggestion.
 
A

aazar

I have been to your site and I could not find it, please identify the
direct link if you are telling the truth.
 
I

Ian JP Kenefick

I have been to your site and I could not find it, please identify the
direct link if you are telling the truth.

Its on the front page!
[20-Mar-2005] Serflog.C (aka Fatso.c and Sumom.c) removal utility
available
--

Regards,
Ian Kenefick
Got a virus?
Go to www.ik-cs.com > 'Got a virus?'
 
A

aazar

Doh! I said in earlier posts none of these tools work on the latest
variant.
Ian said:
I have been to your site and I could not find it, please identify the
direct link if you are telling the truth.

Its on the front page!
[20-Mar-2005] Serflog.C (aka Fatso.c and Sumom.c) removal utility
available
--

Regards,
Ian Kenefick
Got a virus?
Go to www.ik-cs.com > 'Got a virus?'
 
I

Ian JP Kenefick

Doh! I said in earlier posts none of these tools work on the latest
variant.

My bad. Trend sysclean detects and removes the latest variant
according to their website.
--

Regards,
Ian Kenefick
Got a virus?
Go to www.ik-cs.com > 'Got a virus?'
 

Ask a Question

Want to reply to this thread or ask your own question?

You'll need to choose a username for the site, which only take a couple of moments. After that, you can post your question and our members will help you out.

Ask a Question

Similar Threads


Top