Forum Moderators: open

Message Too Old, No Replies

My first virus...

Any help would make me very happy

         

edit_g

2:21 pm on May 21, 2004 (gmt 0)

WebmasterWorld Senior Member 10+ Year Member



I've got my first virus. I've never had a problem with them before, but somehow I have ended up with this one. :(

WUAMGRD.EXE is the problem file - it seems to shut down my PC whenever it feels like it (if I don't have my firewall activated). My virus program can't seem to move it into a safe folder and I can't delete it. It lives in c:/windows/system32/. It is some sort of trojan - It isn't actually affecting me because it can't get past my software firewall (zonealarm pro) but I badly want to get rid of it...

I'm using AVG anti-virus and if anybody can help there's a beer (or 16) in it for you at the pubcon after London...

crashomon

2:30 pm on May 21, 2004 (gmt 0)

10+ Year Member



How about running stinger.exe from a floppy? I have found it to be a nice addition to the other 'full featured' programs.

do a google for stinger.exe and download it from the first link: vil.nai.com/vil/stinger/

Good luck!

Patrick Elward
(thanks for the beer offer, but I'm stateside until July)

Receptional Andy

2:41 pm on May 21, 2004 (gmt 0)



The general method for removing this type of thing is to kill the process (using the task manager or something like process explorer - www.sysinternals.com/ntw2k/freeware/procexp.shtml ) then delete the file in question.

You also need to check your registry entries for places that the worm may have set to run at startup.

Lastly, you need to make sure you have taken steps to prevent reinfection - AVG doesn't really cut it, but the fact you got this in the first place would point at some changes needed to your PC security ;)

edit_g

2:48 pm on May 21, 2004 (gmt 0)

WebmasterWorld Senior Member 10+ Year Member



Stinger sorted it, thanks guys. :)

(AVG, I guess you get what you pay for, Receptional Andy - I'm off to purchase norton...)

[edited by: edit_g at 2:49 pm (utc) on May 21, 2004]

Sanenet

2:49 pm on May 21, 2004 (gmt 0)

WebmasterWorld Senior Member 10+ Year Member



Try the Mcafee "Free Scan" utility, might get rid of it.

Also look into the virus libraries online, see if they come up with removal instructions.

ukgimp

2:54 pm on May 21, 2004 (gmt 0)

edit_g

2:57 pm on May 21, 2004 (gmt 0)

WebmasterWorld Senior Member 10+ Year Member



For the first time I'm seriously considering one of the linux installs... RedHat looks good. :)

Macguru

3:01 pm on May 21, 2004 (gmt 0)

WebmasterWorld Senior Member 10+ Year Member



Thanks ukgimp!

I missed this one. Another great ressource flagged.