also @ TechSpot: Disable Windows automatic check for solutions after a program crashes
Welcome to the TechSpot OpenBoards. Please read the FAQ if you have any questions. Login to participate.

Go Back   TechSpot OpenBoards > Operating Systems & Software > Virus & Malware removal

WORM victim!

Closed Thread
Bookmark Thread Tools
  #1  
Old 09-14-2005
Newcomer, in training
 
Member since: Sep 2005, 2 posts
WORM victim!

Hi everyone. I am in severe panic mode here:

Trend Micro's PC-Cillin discovered 'WORM_SDBOT.BUY" yesterday completely out of the blue. It can be found in c:\windows\system32\msconfig32.exe I looked there and it will not show up.

It lets me know that I have it, but gives me no option to clean/remove/quarantine for some reason. Also, now suddenly the taskmanager and msconfig will only appear for a split second and vanish.

One other problem that has just started so I assume is somehow related; is my internet connection is constantly being interrupted and disconnected. It could be coincidence but at this point I believe there is something evil happening. (I am on dial-up.)

Edit: I almost forgot to mention that I am using XP Home SP1a

Thanks a lot for your time, I am very appreciative!

Last edited by mgodin; 09-14-2005 at 02:41 AM..
  #2  
Old 09-14-2005
DonNagual's Avatar
TechSpot Evangelist
 
Location: Canada
Member since: Apr 2004, 3,483 posts
Hmmm. Symantec's online database doesn't have an exact match, but comes up with THIS .

Try running this online check on your system, and let us know what it comes up with: http://housecall.trendmicro.com/hous...start_corp.asp

Once you get rid of that worm probably best to run through all of this HERE as well to clean your system up.

It takes time to go through all the steps, but it works. After you are finished, you should also post your hijackthis log file here for someone to take a look at and make sure you got all the junk out.

Instructions on how to post your hijackthis file are HERE

And for GAWD's sake, upgrade to SP2! :bounce:

Last edited by DonNagual; 09-14-2005 at 03:10 AM..
To remove this ad, sign in. To register for a new account, click here.
  
  #3  
Old 09-14-2005
Newcomer, in training
 
Member since: Sep 2005, 2 posts
Thanks for the reply, I will do that online test in a moment.

Like I said though, I'm on dial-up (I'm a km out of range to get broadband) and SP2 is pretty big isn't it? Thats pretty much a no-go for me.

I am so bummed about this.
  #4  
Old 09-14-2005
TechSpot Evangelist
 
Location: has left the building
Member since: Aug 2003, 8,160 posts
XP SP2 comes on a FREE CD that you can order from M$, or borrow a copy from a friend.
  #5  
Old 09-14-2005
Newcomer, in training
 
Location: Wakefield, UK
Member since: Sep 2005, 30 posts
check out bazzoka spyware remover from download.com
you have to do it manually but it never fails.

on a personal note: dont install SP2, it sodomized my computer! i lost 250Gigs worth of movies, music and personal files and now i cant even access my HD to reinstall XP.
  #6  
Old 09-14-2005
Vigilante's Avatar
TechSpot Paladin
 
Location: Arizona, USA
Member since: Dec 2004, 2,120 posts
Galaxy, your SP2 experience is hardly the norm. If it was, Microsoft would have proven the extent of their quality department.

My advice on SP2 is, install it on a fresh load of Windows. Or if you are 100% sure you have NO spyware and viruses and anything else that shouldn't be there. A fresh load works best.
It's to late for updates now, though, you need to be clean first!
  #7  
Old 09-21-2005
tomrca's Avatar
TechSpot Addict
 
Location: sunderland, tyne and wear
Member since: Jun 2005, 1,050 posts
perhaps you could try another anti-virus prog because your case seems to be a 1% problem.
try ewido. it worked for me. hope you are not using norton, it doesn't work
Closed Thread

Tip: Download Advanced SystemCare 3 Freeware - 1 Click A Day to Clean, Repair, Protect & Optimize your PC.

Thread Tools


Similar Topics
Topic Category Replies Last Post
Sasser worm uses new LSASS vulnerability Old Frontpage News & Comments 3 05-05-2004 09:32 AM
Worm Authors Exchange Taunting Messages News and Links from Around the Web 0 03-12-2004 10:56 AM
Blaster worm "B" Strain News and Links from Around the Web 0 08-14-2003 05:09 AM
Hacker code could unleash Windows worm News and Links from Around the Web 1 07-26-2003 04:32 AM
SQL Slammer Worm Spread Worldwide in 10 Minutes Old Frontpage News & Comments 4 02-07-2003 05:36 AM


All times are GMT -4. The time now is 09:10 AM.