Jump to content


Photo

Virus Help Please


  • Please log in to reply
17 replies to this topic

#1 dec

dec
  • Members
  • 371 posts

Posted 01 October 2004 - 09:45 PM

i got this Virus called I-Worm/mabuta i ran virus scan it cant get rid of it, im on win 98 if it helps. please tell me if there is anything that could get rid of it Except from formatting my C drive *looks at Cule*
Roses are red
Violets are blue
In Soviet Russia
Poem write you!


Belzabar in-game

#2 alone

alone
  • Members
  • 2261 posts

Posted 01 October 2004 - 09:51 PM

Kick it real hard. If the worm's still there, pour water over to bring it to the surface, then simply pick it up.


Keep trying various different virus scanners (I mean AVg/Norton/McAfee (sp?), and any other free ones you can find), otherwise. Wait for someone smarter than me.
"Entertain yourself with my nightmares."
- AfterAll

Bunny!

#3 dec

dec
  • Members
  • 371 posts

Posted 01 October 2004 - 09:57 PM

anyone wanna link me to scanner downloads
Roses are red
Violets are blue
In Soviet Russia
Poem write you!


Belzabar in-game

#4 Charon

Charon
  • Members
  • 617 posts

Posted 01 October 2004 - 10:24 PM

AVG free version
McAfee Trial
Norton Antivirus 2005 Free TrialWare
Panda ActiveScan
Stop Sign
Trend Micro

Please note- I take NO responsibility if any of these make your system worse.
"Words are, of course, the most powerful drug used by mankind." --Rudyard Kipling

#5 dec

dec
  • Members
  • 371 posts

Posted 01 October 2004 - 10:52 PM

ok i'll blame alone
Roses are red
Violets are blue
In Soviet Russia
Poem write you!


Belzabar in-game

#6 Akira

Akira
  • Members
  • 101 posts

Posted 01 October 2004 - 10:53 PM

Hmm, according to what I have read, this worm blocks access attempts by anti-virus software, meaning that only specially designed tools will be able to remove it, by re-writing BAT files and the such.

Anyway, I'm sure a bit of quick searching will give you results, however I won't give you any recommendations, just try them if you want to risk it =).

You may want to think about updating from 98 as well, seeing as it will be pretty much decommisioned as of next year or so.

Edited by Akira, 01 October 2004 - 10:55 PM.

You have to forget about what other people say, when you're supposed to die, or when you're supposed to be loving. You have to forget about all these things. You have to go on and be crazy. Craziness is like heaven.

#7 alone

alone
  • Members
  • 2261 posts

Posted 01 October 2004 - 10:55 PM

I believe Norton do specific solutions for some virus', but you may need their paid-for software...?!
"Entertain yourself with my nightmares."
- AfterAll

Bunny!

#8 dec

dec
  • Members
  • 371 posts

Posted 01 October 2004 - 10:58 PM

i got some intructions to do something along the lines of what akira said but it didnt work
Roses are red
Violets are blue
In Soviet Russia
Poem write you!


Belzabar in-game

#9 Cule

Cule
  • Members
  • 762 posts

Posted 02 October 2004 - 12:04 AM

Format the bastage i say :P

#10 2Pac

2Pac
  • Members
  • 78 posts

Posted 02 October 2004 - 06:08 AM

I'm with Cule on this one, reformat it is only choice you got, if that makes it worse blame it on cule and sue him for alot of money.
Thúg LíFè

#11 Lady_Maha

Lady_Maha
  • Members
  • 479 posts

Posted 02 October 2004 - 07:23 AM

Why take drastic measures? Follow instructions on here: http://securityrespo...w32.mota.a.html

Important part is to delete the value "winupd" = "RUNDLL32.EXE %Windir%\<random value>.dll,_mainRD" from the registry key HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run after running a virus scan and removing the actual worm.

To fix the registry:

Click Start > Run.
Type regedit

Then click OK.


Navigate to the key:

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run


In the right pane, delete the value:

"winupd" = "RUNDLL32.EXE %Windir%\<random value>.dll,_mainRD"


Exit the Registry Editor.
Social Engineering Specialist - Because there is no patch for human stupidity

#12 jurian

jurian

    YAY! Less Lag!

  • Members
  • 1505 posts

Posted 02 October 2004 - 07:29 AM

if what maha said dun work then just google something like "remove 9insert worm name here)"
Even in death my hate will go on

#13 dec

dec
  • Members
  • 371 posts

Posted 02 October 2004 - 11:23 AM

well idid what maha said before posting on here but ill try that again just incase.

EDIT: nope i cant find the file in there so i must have delted it :S

Edited by dec, 02 October 2004 - 11:33 AM.

Roses are red
Violets are blue
In Soviet Russia
Poem write you!


Belzabar in-game

#14 sayadin

sayadin
  • Members
  • 248 posts

Posted 04 October 2004 - 01:23 PM

hmm... you can formatt or you can get a magnet and put it next to the tower... that should bring everything back into its place, if that doesn't work then give it a lil voltage to the cpu... if all else fails draw a big circle over the tower and slam your head in the circle continously until it works.
The Greater the Difficulty, the More the Glory in Surmounting it. -Epicurus

#15 Thrice

Thrice
  • Members
  • 148 posts

Posted 11 October 2004 - 09:48 PM

hmm... you can formatt or you can get a magnet and put it next to the tower... that should bring everything back into its place, if that doesn't work then give it a lil voltage to the cpu... if all else fails draw a big circle over the tower and slam your head in the circle continously until it works.

That made me laugh! lol

#16 jurian

jurian

    YAY! Less Lag!

  • Members
  • 1505 posts

Posted 12 October 2004 - 11:40 AM

you have no sense of humor :P
Even in death my hate will go on

#17 sayadin

sayadin
  • Members
  • 248 posts

Posted 12 October 2004 - 01:26 PM

true, but i probaly did make you smile :P
The Greater the Difficulty, the More the Glory in Surmounting it. -Epicurus

#18 jurian

jurian

    YAY! Less Lag!

  • Members
  • 1505 posts

Posted 12 October 2004 - 01:36 PM

nah takes alot more to make me smile :P
Even in death my hate will go on




0 user(s) are reading this topic

0 members, 0 guests, 0 anonymous users