Thread: Worm
View Single Post
  #2 (permalink)  
Old January 10th, 2006
sonnet sonnet is offline
Enthusiast
 
Join Date: December 7th, 2002
Posts: 35
sonnet is flying high
Default

Hi; I can't read Dutch but I will do my best.

I think you are saying you have a worm gotten through Limewire or Peer to Peer P2P File Sharing.

If you go to www.thetechguide.com they can help but it is English.

You would

1. Download a program called "Hijack this" from http://www.spywareinfo.com/~merijn/downloads.html
Also please read How to post a Hijackthis log You want to follow the instructions there and make your first Hijackthis log before you begin to delete the viruses, worms, spyware. Your first Hijackthis log needs to show your system the way it is now.

If you can find someone to interpret English for you, go to www.thetechguide and ask for help.

If not, try to find someone who speaks both English and Dutch to help you with the following. It may get rid of some of your problem.

When I ask you to download a zip file, make sure you choose SAVE TO DISK rather than Open
Can you open "MyComputer"
Double click to open Local Disk C: drive
Right click an empty spot and left click NEW>>Folder
A new folder will be placed in the C: folder , name it BFU
So you now have C:\BFU

2. Download and save p2pnetwork.zip
Then UNZIP it to the BFU Folder so you now have p2pnetwork.bfu extracted

3. Download and save and then UNZIP to the BFU folder
BFU.zip
So you now have BFU.exe extracted

4. ==Download and Install this small program
to help clean your temp folders,cookies, etc...
Windows Cleanup! 4.0
Don't run it yet

5. There may be a other file virus/removal utilities for your specific situation (based on your original hijack this! log); check with the folks at www.thetechguide.com; also you would want them to check your before-and-after Hijack this! logs. They are experts at helping people with malware get rid of it for free; and they are very good.

6. ==Download and then Install
Ewido Security Suite (Ewido Malware Suite)

When installing, under "Additional Options" Uncheck "Install background guard" and "Install scan via context menu".

From the main ewido screen, click on Update in the left menu, then click the Start update button.
After the update finishes (the status bar at the bottom will display "Update successful")
Close out Ewido for now, we'll need it later
If for some reason the Updater won't work can you manually download the
Updates from this link after you have Ewido installedhttp://www.ewido.net/en/download/updates/

Please save these instructions to a Notepad file and save it to your Desktop for reference
or Print them out!

Also remember if you really want to do this right and remove the exact virus/trojan/worm/spyware that is causing your problem, go see to www.thetechguide.com/forum and post in the Tech support forum.

RESTART your Computer into SAFE MODE
You can do this by tapping the F8 key as the system is restarting, just before Windows loads
Choose Safe mode from the startup menu and hit Enter

In safe mode

Open the BFU folder
Double click to run BFU.exe
Use the "Open Script file" button (the folder icon next to Scriptfile to execute)
Navigate to p2pnetwork.bfu in the BFU folder
Right click p2pnetwork.bfu and choose Select
In Brute Force Uninstaller select Execute
Let it finish then Exit

==Open Cleanup! by double-clicking the icon on your desktop (or from the Start > All Programs menu).
Set the program up as follows:
Click "Options..."
Move the arrow down to "Custom CleanUp!"
Put a check next to the following (Make sure nothing else is checked!):

* Empty Recycle Bins
* Delete Cookies
* Delete Prefetch files
* Cleanup! All Users

Click OK
Press the CleanUp! button to start the program.
When it's done, decline to log off or restart the computer

==Open Ewido Security Suite
Click on the Scanner button on the left menu (it is the third button down if your Safe Mode doesn't show the buttons)
Select Complete System Scan
*If Ewido finds something it will prompt you with "Infected Object found"
Ensure the following are Selected
*1. Perform Action = Remove
*2. Create Encrypted Backup in Quarantine (Recommended)
*3. Perform action with all infections

Then click OK
When Ewido has finished its scan click the "Save Report" button
Save the report to desktop
Exit Ewido
NOTE: When Ewido is running, don't open any other Windows

Reboot back to Normal mode

Back in Windows, to do this right, you would need to contact the people at www.thetechguide.com and post a few logs so they can tell you if your system is clean; this is why I recommend you start with them at the beginning. Much better to let the experts analyze the final logs and tell you whether you are "clean." I am no expert; I only ran into the same problem myself, but there are many viruses out there, so I would let them help if you can find someone to interpret for you.

The techs at www.techguide.com will want to see logs of the following (and anything else they ask for):

1. Scan and save logfile with Hijackthis again, post a fresh log
2. Post the Whole contents of Ewido's report

Don't post it here as I cannot help you determine if your system is clean! I am no expert; I cannot interpret the logs for you to tell you if your system is clean; only a tech support board that uses Hijack this could do that.

Good luck.
__________________
Currently sticking with an older version of Limewire Pro 4.8.1, which has proven more stable

PowerMac G4 933 with ISP Brighthouse/Roadrunner broadband 15/2 connection running Mac OS X 10.2.8

~~~~~~~~

Details of my computer (firewall, RAM, hard disk), network set-up, country, and all can be found here: http://limewiresettings.jottit.com/
Reply With Quote