|
TheShroomHermit
Divine Hermit of the Everything
Registered: 02/19/02
Posts: 7,575
Loc: border of Canada and Mexi...
Last seen: 9 months, 11 days
|
The computer worm that wouldn't die...
#2350042 - 02/18/04 12:19 PM (20 years, 1 month ago) |
|
|
My wonderful girlfreind, who is a computer support worker for a major US campus, downloaded a virus through Winmx. She used f-secure to remove the program. After she left, it came back! I've removed this thing about a dozen times since yesturday, and it doesn't show signs of stopping. http://uk.trendmicro-europe.com/enterprise/security_info/ve_detail.php?Vname=WORM_BEREB.B&VSect=T This thing apparently opens a backdoor to my computer, and so now I'm thinking that the virus scan just didn't detect this vunverability. And that a hacker is putting the virus onto my computer through the hole over and over again.
How do I stop this thing? My girlfreind won't help because she thinks that she got rid of the virus and it's my own stupid fault. For now, I'll be running Fsecure over and over again. PS: It tampered with DOS, when I run IPCONFIG it immidiatly closes.
|
Mitchnast
Toadmonger
Registered: 10/27/99
Posts: 8,656
Loc: Okanagan
Last seen: 5 days, 6 hours
|
Re: The computer worm that wouldn't die... [Re: TheShroomHermit]
#2350109 - 02/18/04 12:33 PM (20 years, 1 month ago) |
|
|
you probably have a program in your startup that DLs and runs the virus. not a virus itself, probably worse
that or its a tricky program that spawns its own viral files which your scan deletes, then regenerates them. but id say most likely it is hidden in the code of a more vital program, probably put there by a viral program (that respawns for automatic distribution to your contact list through your e-mail server, and is no longer treatable. time to reformat.
the same probably goes for evrone on your contact list without a firewall.
|
recalcitrant
My Own God
Registered: 04/20/02
Posts: 2,927
Loc: Canada West
Last seen: 7 years, 10 months
|
Re: The computer worm that wouldn't die... [Re: TheShroomHermit]
#2350320 - 02/18/04 01:10 PM (20 years, 1 month ago) |
|
|
Does the virus appear every time you start your computer?
-------------------- We have to answer our own prayers
|
TheShroomHermit
Divine Hermit of the Everything
Registered: 02/19/02
Posts: 7,575
Loc: border of Canada and Mexi...
Last seen: 9 months, 11 days
|
Re: The computer worm that wouldn't die... [Re: recalcitrant]
#2350515 - 02/18/04 01:50 PM (20 years, 1 month ago) |
|
|
It was supposed to do that, but I edited the list of programs that start upon load. The virus is not in full effect, it no longer has it's own folder with 269 copies of itself with interesting names and being shared by Winmx. However, I will run the virus scan and get nothing, and then run it again and an infected file called "restore002022929202229292 etc" on the C drive. I am guessing that this is a file that is supposed to undue the damage that my virus scanner had caused it. I've disinfected it a bunch of times, and I'm now trying to figure out how it's getting there over and over again.
|
nofind_um
Explorer ofEarth
Registered: 06/30/03
Posts: 933
Loc: At work, at school, at my...
|
Re: The computer worm that wouldn't die... [Re: recalcitrant]
#2350564 - 02/18/04 02:00 PM (20 years, 1 month ago) |
|
|
first you need to disconnect from any type of LAN or inernet connection. Next depends on the O/S?? If it's windows ME or XP turn off system restore. Next run the removal tool. Next run your anti virus. Next run your anti spyware(adaware/spybot s&d). Next run a trojan removal tool. I always restart after each and every scan. Now run everything again. Connect to the LAN or internet connection. Pray it's gone. Rin through the removal process again. If not post back here, I'll figure something out.... NFum... Make sure you terminate the processes... First otherwise they remain in memory... Are you following the removal procedure step by step....????
-------------------- My hunting partner is gone, I miss her so!
Edited by nofind_um (02/18/04 02:03 PM)
|
Mitchnast
Toadmonger
Registered: 10/27/99
Posts: 8,656
Loc: Okanagan
Last seen: 5 days, 6 hours
|
Re: The computer worm that wouldn't die... [Re: nofind_um]
#2351049 - 02/18/04 03:34 PM (20 years, 1 month ago) |
|
|
its going to do a "updating system configuration. this may take a few minutes, please wait." after that ^^^^^^ and it will take 10 min to HALF HOUR , let it go.
|
|