HELP!
#1
Scooby Regular
Thread Starter
Join Date: Oct 2001
Posts: 11,403
Likes: 0
Received 0 Likes
on
0 Posts
AVG picked up that I have sobig.f and couldn't quarantine it, so I ran the Symantec Removal Tool and it said I didn't have it on my computer.
Have run AVG again and it says I DO
What the **** do I do now. Am really stressed and panicing like hell
Have run AVG again and it says I DO
What the **** do I do now. Am really stressed and panicing like hell
#3
Scooby Regular
Thread Starter
Join Date: Oct 2001
Posts: 11,403
Likes: 0
Received 0 Likes
on
0 Posts
Have just ran an online scan from TrendMicro and that has picked it up as well [img]images/smilies/mad.gif[/img]
Can only deduce that Symantec/Norton must be crap!!!
Can only deduce that Symantec/Norton must be crap!!!
#5
Scooby Regular
Thread Starter
Join Date: Oct 2001
Posts: 11,403
Likes: 0
Received 0 Likes
on
0 Posts
My problem is not detecting it....it's how to fecking get rid of it - how the **** I got it I haven't a clue, as it's NOT been via an email - says it's \temp\movie0045.pif...which makes it even more confusing because I haven't seen any movies or popups
Trending Topics
#8
Scooby Regular
Thread Starter
Join Date: Oct 2001
Posts: 11,403
Likes: 0
Received 0 Likes
on
0 Posts
Oh ****...went to delete it and this message came up
Unable to clean the file 'C :\ Documents and Settings\Windows\Local Settings\Temp\movie0045.pif because it is currently in use
What now? I am getting decidedly distraught
Unable to clean the file 'C :\ Documents and Settings\Windows\Local Settings\Temp\movie0045.pif because it is currently in use
What now? I am getting decidedly distraught
#9
try this
Manual Removal Instructions
To remove this virus "by hand", follow these steps:
- Win9x/ME - Reboot the system into Safe Mode (hit the F8 key as soon as the Starting Windows text is displayed, choose Safe Mode.
- WinNT/2K/XP - Terminate the process WINPPR32.EXE
Delete the following files from your WINDOWS directory (typically c:\windows or c:\winnt)
WINPPR32.EXE
WINSTT32.DAT
Edit the registry
Delete the "TrayX" value from
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\
Windows\CurrentVersion\Run
HKEY_CURRENT_USERS\SOFTWARE\Microsoft\
Windows\CurrentVersion\Run
Manual Removal Instructions
To remove this virus "by hand", follow these steps:
- Win9x/ME - Reboot the system into Safe Mode (hit the F8 key as soon as the Starting Windows text is displayed, choose Safe Mode.
- WinNT/2K/XP - Terminate the process WINPPR32.EXE
Delete the following files from your WINDOWS directory (typically c:\windows or c:\winnt)
WINPPR32.EXE
WINSTT32.DAT
Edit the registry
Delete the "TrayX" value from
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\
Windows\CurrentVersion\Run
HKEY_CURRENT_USERS\SOFTWARE\Microsoft\
Windows\CurrentVersion\Run
#10
Scooby Regular
Thread Starter
Join Date: Oct 2001
Posts: 11,403
Likes: 0
Received 0 Likes
on
0 Posts
- WinNT/2K/XP - Terminate the process WINPPR32.EXE
But a search I did, threw up movie0045.pif as a shortcut to MS-DOS. I haven't opened any emails that have had attachments for the last 2-3 days - so can anyone throw any light on how on earth it got in my PC?
#14
Scooby Regular
Thread Starter
Join Date: Oct 2001
Posts: 11,403
Likes: 0
Received 0 Likes
on
0 Posts
Nick when the search threw up movie0045.pif as a shortcut to MS-DOS I deleted it and also deleted it from the Recycle Bin. I have run 2 more scans on AVG and each one has showed the PC as clean and virus free now
I am still confused as to how I got the virus, as I can honestly say I haven't opened any emails with attachments. I ran AVG last night about 9pm [altho it is set to autoscan every morning] and it was clear then. Yet when it had run autoscan this morning at 7.00am it found the sobig.f virus Also, I didn't receive any emails after 5.30pm yesterday afternoon!
[Edited by Redkop - 8/21/2003 5:08:35 PM]
I am still confused as to how I got the virus, as I can honestly say I haven't opened any emails with attachments. I ran AVG last night about 9pm [altho it is set to autoscan every morning] and it was clear then. Yet when it had run autoscan this morning at 7.00am it found the sobig.f virus Also, I didn't receive any emails after 5.30pm yesterday afternoon!
[Edited by Redkop - 8/21/2003 5:08:35 PM]
#15
It could have been a false alarm ?
Depending on how you recieve emails also you may not of opened the email but using pre-view pane etc can excute the .exe anyway
It seems pretty odd I must admit
Cheers Nick
Depending on how you recieve emails also you may not of opened the email but using pre-view pane etc can excute the .exe anyway
It seems pretty odd I must admit
Cheers Nick