Computing.Net > Forums > Security and Virus > Annoying virus or worm

Annoying virus or worm

Reply to Message Icon

Original Message
Name: doreencares
Date: October 5, 2003 at 23:42:18 Pacific
Subject: Annoying virus or worm
OS: Windows XP
CPU/Ram: AMD 1200
Comment:

After mass infection of viruses and whatever (Jeefo the main infection)and reformatting of hard drive as well as FDISK /MBR to gain access to drive, still had to reformat a couple of times as XP became corrupted or wouldn't boot. I have 2 256 SDRAM sticks, one of which has now been left out and (touch wood) PC seems to work perfectly fine. If a virus or worm is present in memory which is the best utility to flush it out? Tried something to test it for the Jeefo worm but nothing was detected. Any advice greatly appreciated. Mick


Report Offensive Message For Removal

Response Number 1
Name: capt
Date: October 6, 2003 at 07:59:26 Pacific
Subject: Annoying virus or worm
Reply: (edit)

Try http://f-prot.com/index.html F-prot for dos is the best virus program for cleaning a bios infection, and it is free. Their antivirus program is also very good and reasonably priced too. Yyou could try it for a free trial. Are you sure the loss of memory was not a coincidence. Have you reset the cmos jumper to clear the bios? Have you checked to make sure the ram is secure in their slots? Have you checked the ram's performance by using a memory performance scan from PC Pitstop or used a memory program like Doc Memory?


Report Offensive Follow Up For Removal

Response Number 2
Name: dorencares
Date: October 6, 2003 at 10:37:25 Pacific
Subject: Annoying virus or worm
Reply: (edit)

Many thanks for reply and link. I tried the CMOS jumper as well as removing the battery on the motherboard. One thing i did notice was on Yahoo where i went to delete some read mail but it came back 3 fold so some bug or whatever in Yahoo? The virus or whatever usually strikes within 24 hours. But as you mentioned the memory stick could be a coincidence.


Report Offensive Follow Up For Removal

Response Number 3
Name: blender
Date: October 6, 2003 at 13:18:14 Pacific
Subject: Annoying virus or worm
Reply: (edit)

In most cases removing a memory resident virus requires you to totally power down the pc for at least 30 seconds including pulling the plug if you have some sort of ups backup. (I leave it off for couple min.)
That will clear the memory...then boot to safe mode to run the removal tool or the antivirus program to clean it. Most viruses/trojans/worms won't load in safe mode since windows will only load the bare minimum of drivers and processes so there isn't a pile of stuff running in the background when trying diagnose or repair whatever problem you have.

Where does your antivirus program keep detecting this virus?
After formatting and reinstalling your o/s and other applications...you were reinfected? Any chance one of your cd's or floppy's used to reload everything infected?
Do you have online storage space such as "my briefcase" on yahoo? Not probable but is possible you are reinfecting yourself from there...
I imagine you do...but you have set up your antivirus to "auto protect" all the time? And is up to date?
Are you running a firewall? Some of the internet worms running around can get in if you dont have a firewall( blaster worm is an example)
XP's firewall is "alright" for keeping out unwanted incomming traffic but doesn't monitor outgoing traffic.
A 3rd party firewall such as Sygate or Zone Alarm will monitor outgoing trafic as well. You will get an alert asking for permission to allow/disallow whatever application wants internet access, which will give you a clue as to how you are getting the infection. Depending on what you are doing at the time of the alert should narrow down the possible source of where the infection is comming from.
Hope something is of use here.
Good luck


Report Offensive Follow Up For Removal

Response Number 4
Name: doreencares
Date: October 6, 2003 at 14:11:00 Pacific
Subject: Annoying virus or worm
Reply: (edit)

Thanks for detailed advice, blender. Antivirus programmes, stinger,Norton and a couple of others haven't detected a thing past week even before reformatting twice. Now trying Avast. With the memory sticks both were in place around a day before boot problems then after 2nd reformat tried about a day with only one of the memory sticks in. within 24 hours of both being used again more boot problems. Four days with one memory stick and no trouble (famous last words??) Yahoo was normal e-mail account usage, 10 letters that were deleted came back as 30 unread. Not sure what happened there. Zone alarm is a terrific piece of software which has stopped a great number of intrusions.


Report Offensive Follow Up For Removal







Use following form to reply to current message:

   Name: From My Computing.Net Settings
 E-Mail: From My Computing.Net Settings

Subject: Annoying virus or worm

Comments:

 


  Homepage URL (*): 
Homepage Title (*): 
         Image URL: 
 
Data Recovery Software