worm removal tools ?

N

Norvin Gordon

Running XP and it seems that my computer has been invaded with 'sasser
B', W32.korgo.V, worm/padobot.S and worm/padobot.V.
Question is which tool to download that will do the job of detecting and
removing and even prevent future invasion.
I am running NAV 04' under auto and AVG7 in the manual mode weekly.
TIA
Norvin in tropical Minnesota (+2F)
 
D

David H. Lipman

1) Download the following three items...

McAfee Stinger
http://vil.nai.com/vil/stinger/

Trend Sysclean Package
http://www.trendmicro.com/download/dcs.asp

Latest Trend signature files.
http://www.trendmicro.com/download/pattern.asp

Create a directory.
On drive "C:\"
(e.g., "c:\New Folder")
or the desktop
(e.g., "C:\Documents and Settings\lipman\Desktop\New Folder")

Download SYSCLEAN.COM and place it in that directory.
Download the signature files (pattern files) by obtaining the ZIP file.
For example; lpt333.zip

Extract the contents of the ZIP file and place the contents in the same directory as
SYSCLEAN.COM.

2) If you are using WinME or WinXP, disable System Restore
http://vil.nai.com/vil/SystemHelpDocs/DisableSysRestore.htm
3) Reboot your PC into Safe Mode and shutdown as many applications as possible
4) Using both the Trend Sysclean utility and Stinger, perform a Full Scan of your
platform and clean/delete any infectors found
5) Restart your PC and perform a "final" Full Scan of your platform using both.
6) If you are using WinME or WinXP, Re-enable System Restore and re-apply any
System Restore preferences, (e.g. HD space to use suggested 400 ~ 600MB),
7) Reboot your PC.
8) If you are using WinME or WinXP, create a new Restore point


* * * Please report back your results * * *

--
Dave
http://www.claymania.com/removal-trojan-adware.html





| Running XP and it seems that my computer has been invaded with 'sasser
| B', W32.korgo.V, worm/padobot.S and worm/padobot.V.
| Question is which tool to download that will do the job of detecting and
| removing and even prevent future invasion.
| I am running NAV 04' under auto and AVG7 in the manual mode weekly.
| TIA
| Norvin in tropical Minnesota (+2F)
|
 
N

Norvin

David said:
1) Download the following three items...

McAfee Stinger
http://vil.nai.com/vil/stinger/

Trend Sysclean Package
http://www.trendmicro.com/download/dcs.asp

Latest Trend signature files.
http://www.trendmicro.com/download/pattern.asp

Create a directory.
On drive "C:\"
(e.g., "c:\New Folder")
or the desktop
(e.g., "C:\Documents and Settings\lipman\Desktop\New Folder")

Download SYSCLEAN.COM and place it in that directory.
Download the signature files (pattern files) by obtaining the ZIP file.
For example; lpt333.zip

Extract the contents of the ZIP file and place the contents in the same directory as
SYSCLEAN.COM.

2) If you are using WinME or WinXP, disable System Restore
http://vil.nai.com/vil/SystemHelpDocs/DisableSysRestore.htm
3) Reboot your PC into Safe Mode and shutdown as many applications as possible
4) Using both the Trend Sysclean utility and Stinger, perform a Full Scan of your
platform and clean/delete any infectors found
5) Restart your PC and perform a "final" Full Scan of your platform using both.
6) If you are using WinME or WinXP, Re-enable System Restore and re-apply any
System Restore preferences, (e.g. HD space to use suggested 400 ~ 600MB),
7) Reboot your PC.
8) If you are using WinME or WinXP, create a new Restore point


* * * Please report back your results * * *

--
Dave
http://www.claymania.com/removal-trojan-adware.html





| Running XP and it seems that my computer has been invaded with 'sasser
| B', W32.korgo.V, worm/padobot.S and worm/padobot.V.
| Question is which tool to download that will do the job of detecting and
| removing and even prevent future invasion.
| I am running NAV 04' under auto and AVG7 in the manual mode weekly.
| TIA
| Norvin in tropical Minnesota (+2F)
|
Dave, my system seems to be running much better and Spybot and Adaware
are running clear and free. Thanks, Norvin
 
D

David H. Lipman

Great ! --
That is good to hear !

--
Dave




| David H. Lipman wrote:
| > 1) Download the following three items...
| >
| > McAfee Stinger
| > http://vil.nai.com/vil/stinger/
| >
| > Trend Sysclean Package
| > http://www.trendmicro.com/download/dcs.asp
| >
| > Latest Trend signature files.
| > http://www.trendmicro.com/download/pattern.asp
| >
| > Create a directory.
| > On drive "C:\"
| > (e.g., "c:\New Folder")
| > or the desktop
| > (e.g., "C:\Documents and Settings\lipman\Desktop\New Folder")
| >
| > Download SYSCLEAN.COM and place it in that directory.
| > Download the signature files (pattern files) by obtaining the ZIP file.
| > For example; lpt333.zip
| >
| > Extract the contents of the ZIP file and place the contents in the same directory as
| > SYSCLEAN.COM.
| >
| > 2) If you are using WinME or WinXP, disable System Restore
| > http://vil.nai.com/vil/SystemHelpDocs/DisableSysRestore.htm
| > 3) Reboot your PC into Safe Mode and shutdown as many applications as possible
| > 4) Using both the Trend Sysclean utility and Stinger, perform a Full Scan of your
| > platform and clean/delete any infectors found
| > 5) Restart your PC and perform a "final" Full Scan of your platform using both.
| > 6) If you are using WinME or WinXP, Re-enable System Restore and re-apply any
| > System Restore preferences, (e.g. HD space to use suggested 400 ~ 600MB),
| > 7) Reboot your PC.
| > 8) If you are using WinME or WinXP, create a new Restore point
| >
| >
| > * * * Please report back your results * * *
| >
| > --
| > Dave
| > http://www.claymania.com/removal-trojan-adware.html
| >
| >
| >
| >
| >
| > | > | Running XP and it seems that my computer has been invaded with 'sasser
| > | B', W32.korgo.V, worm/padobot.S and worm/padobot.V.
| > | Question is which tool to download that will do the job of detecting and
| > | removing and even prevent future invasion.
| > | I am running NAV 04' under auto and AVG7 in the manual mode weekly.
| > | TIA
| > | Norvin in tropical Minnesota (+2F)
| > |
| >
| >
| Dave, my system seems to be running much better and Spybot and Adaware
| are running clear and free. Thanks, Norvin
 
P

Peter Seiler

David H. Lipman - 10.01.2005 05:37 :
Great ! --
That is good to hear !

me too!

--
Dave




| David H. Lipman wrote:
| > 1) Download the following three items...
| >
| > McAfee Stinger
| > http://vil.nai.com/vil/stinger/
| >
| > Trend Sysclean Package
| > http://www.trendmicro.com/download/dcs.asp
| >
| > Latest Trend signature files.
| > http://www.trendmicro.com/download/pattern.asp
| >
| > Create a directory.
| > On drive "C:\"
| > (e.g., "c:\New Folder")
| > or the desktop
| > (e.g., "C:\Documents and Settings\lipman\Desktop\New Folder")
| >
| > Download SYSCLEAN.COM and place it in that directory.
| > Download the signature files (pattern files) by obtaining the ZIP file.
| > For example; lpt333.zip
| >
| > Extract the contents of the ZIP file and place the contents in the
same directory as
| > SYSCLEAN.COM.
| >
| > 2) If you are using WinME or WinXP, disable System Restore
| > http://vil.nai.com/vil/SystemHelpDocs/DisableSysRestore.htm
| > 3) Reboot your PC into Safe Mode and shutdown as many
applications as possible
| > 4) Using both the Trend Sysclean utility and Stinger, perform a
Full Scan of your
| > platform and clean/delete any infectors found
| > 5) Restart your PC and perform a "final" Full Scan of your
platform using both.
| > 6) If you are using WinME or WinXP, Re-enable System Restore and
re-apply any
| > System Restore preferences, (e.g. HD space to use suggested
400 ~ 600MB),
| > 7) Reboot your PC.
| > 8) If you are using WinME or WinXP, create a new Restore point
| >
| >
| > * * * Please report back your results * * *
| >
| > --
| > Dave
| > http://www.claymania.com/removal-trojan-adware.html
| >
| >
| >
| >
| >
| > | > | Running XP and it seems that my computer has been invaded with 'sasser
| > | B', W32.korgo.V, worm/padobot.S and worm/padobot.V.
| > | Question is which tool to download that will do the job of
detecting and
| > | removing and even prevent future invasion.
| > | I am running NAV 04' under auto and AVG7 in the manual mode weekly.
| > | TIA
| > | Norvin in tropical Minnesota (+2F)
| > |
| >
| >
| Dave, my system seems to be running much better and Spybot and Adaware
| are running clear and free. Thanks, Norvin
 

Ask a Question

Want to reply to this thread or ask your own question?

You'll need to choose a username for the site, which only take a couple of moments. After that, you can post your question and our members will help you out.

Ask a Question

Top