Notices
Computer & Technology Related Post here for help and discussion of computing and related technology. Internet, TVs, phones, consoles, computers, tablets and any other gadgets.

VIRUS HELP NEEDED PLEASE

Thread Tools
 
Search this Thread
 
Old 28 July 2004, 11:08 AM
  #1  
Fulham71
Scooby Regular
Thread Starter
 
Fulham71's Avatar
 
Join Date: Jan 2002
Posts: 7,922
Likes: 0
Received 0 Likes on 0 Posts
Default VIRUS HELP NEEDED PLEASE

I am getting a virus w32.randex.gen

I am unable to clear it with Norton

Please can anyone advise how to remove it

Cheers
Paul
Old 28 July 2004, 11:24 AM
  #2  
Figment
Scooby Regular
 
Figment's Avatar
 
Join Date: Jul 2001
Location: deep inside your imagination
Posts: 24,057
Likes: 0
Received 0 Likes on 0 Posts
Default

http://www.sophos.com/virusinfo/****...32randexg.html
Old 28 July 2004, 04:49 PM
  #3  
Fulham71
Scooby Regular
Thread Starter
 
Fulham71's Avatar
 
Join Date: Jan 2002
Posts: 7,922
Likes: 0
Received 0 Likes on 0 Posts
Default

Thanks mate
Tried the following :-

Please follow the instructions for removing worms.

Check your administrator passwords and review network security.

You will also need to edit the following registry entries, if they are present. Please read the warning about editing the registry.

At the taskbar, click Start|Run. Type 'Regedit' and press Return. The registry editor opens.

Before you edit the registry, you should make a backup. On the 'Registry' menu, click 'Export Registry File'. In the 'Export range' panel, click 'All', then save your registry as Backup.

Locate the HKEY_LOCAL_MACHINE entries:

HKLM\Software\Microsoft\Windows\CurrentVersion\Run \
Microsoft Network Daemon for Win32 = ntd32.exe

HKLM\Software\Microsoft\Windows\CurrentVersion\Run Services\
Microsoft Network Daemon for Win32 = ntd32.exe

and delete them if they exist.

Close the registry editor.


BUT NOTHING WAS THERE !
Old 28 July 2004, 05:05 PM
  #4  
Figment
Scooby Regular
 
Figment's Avatar
 
Join Date: Jul 2001
Location: deep inside your imagination
Posts: 24,057
Likes: 0
Received 0 Likes on 0 Posts
Default

Do a search of your machine for ntd32.exe and delete it if it exists (Cannot delete if it is currently running, in which case CTRL-ALT-DEL to bring up the list of running apps, look for ntd32.exe in the lists and if found close it / end process then delete it (exact way to stop it depends on operating system))

If not found, do another scan with Norton and post the message it displays when it finds the worm.
Old 03 August 2004, 01:54 PM
  #5  
Fulham71
Scooby Regular
Thread Starter
 
Fulham71's Avatar
 
Join Date: Jan 2002
Posts: 7,922
Likes: 0
Received 0 Likes on 0 Posts
Default

still cant remove it
Search found nothing !
Norton finds it but it keeps reappearing !
Old 03 August 2004, 01:57 PM
  #6  
Fulham71
Scooby Regular
Thread Starter
 
Fulham71's Avatar
 
Join Date: Jan 2002
Posts: 7,922
Likes: 0
Received 0 Likes on 0 Posts
Default

how do i do that please ?
Old 03 August 2004, 02:10 PM
  #7  
Fulham71
Scooby Regular
Thread Starter
 
Fulham71's Avatar
 
Join Date: Jan 2002
Posts: 7,922
Likes: 0
Received 0 Likes on 0 Posts
Default

thanks for that but not sure how to do it on W 2000
I now have a trojan dropper too !!!!
Old 03 August 2004, 02:17 PM
  #8  
ChrisB
Moderator
 
ChrisB's Avatar
 
Join Date: Dec 1998
Location: Staffs
Posts: 23,573
Likes: 0
Received 0 Likes on 0 Posts
Default

Windows 2000 doesn't have System Restore
Old 03 August 2004, 02:20 PM
  #9  
Fulham71
Scooby Regular
Thread Starter
 
Fulham71's Avatar
 
Join Date: Jan 2002
Posts: 7,922
Likes: 0
Received 0 Likes on 0 Posts
Default

Old 03 August 2004, 02:34 PM
  #10  
JackClark
Scooby Senior
 
JackClark's Avatar
 
Join Date: Dec 2000
Location: Overdosed on LCD
Posts: 20,852
Received 51 Likes on 34 Posts
Default

Run this http://uk.mcafee.com/root/mfs/default.asp?cid=9575 and let me know the result.
Old 03 August 2004, 04:14 PM
  #11  
Fulham71
Scooby Regular
Thread Starter
 
Fulham71's Avatar
 
Join Date: Jan 2002
Posts: 7,922
Likes: 0
Received 0 Likes on 0 Posts
Default

Thanks Jack
it found the following !

C:\WINNT\system32\bot.exe W32/Sdbot.worm.gen.q
C:\WINNT\system32\cvcse.exe W32/Sdbot.worm.gen.b
C:\WINNT\system32\cvvcsr.exe W32/Sdbot.worm.gen.b
C:\WINNT\system32\cvvcsr.exe Proxy-FBSR.gen
C:\WINNT\system32\fdfsr.exe W32/Sdbot.worm.gen.b
C:\WINNT\system32\fds.exe Proxy-FBSR.gen
C:\WINNT\system32\landisc.exe W32/Sdbot.worm.gen.h
C:\WINNT\system32\msgfix.exe W32/Sdbot.worm.gen.i
C:\WINNT\system32\msnsrv.exe BackDoor-RQ
C:\WINNT\system32\ntsys32.exe W32/Sdbot.worm.gen
C:\WINNT\system32\outlook.exe Exploit-Mydoom
C:\WINNT\system32\svchostn.exe W32/Sdbot.worm.gen
C:\WINNT\system32\temp IRC/Flood.dk
C:\WINNT\system32\wnt.exe W32/Sdbot.worm.gen.q
Old 03 August 2004, 05:07 PM
  #12  
JackClark
Scooby Senior
 
JackClark's Avatar
 
Join Date: Dec 2000
Location: Overdosed on LCD
Posts: 20,852
Received 51 Likes on 34 Posts
Default

Nice

There's a trial of our command line scanner available here which will deal with those puppys. If that's too much of a pain to run I can send you a free McAfee trial. but that will remove Norton.
Old 04 August 2004, 09:34 AM
  #13  
Fulham71
Scooby Regular
Thread Starter
 
Fulham71's Avatar
 
Join Date: Jan 2002
Posts: 7,922
Likes: 0
Received 0 Likes on 0 Posts
Default

Jack I paid for McAfee & deleted Norton
However I think the virus I have is hidden in Outlook express
everytime i use outlook expresss i get virus warnings
i then scan the drives but when i reuse outlook express i get error messages
w31.netsky.peml!exe

I have tried stinger to get rid but still no joy

PLEASE HELP !!!!
Old 04 August 2004, 10:13 AM
  #14  
JackClark
Scooby Senior
 
JackClark's Avatar
 
Join Date: Dec 2000
Location: Overdosed on LCD
Posts: 20,852
Received 51 Likes on 34 Posts
Default

If it's in outlook then can't you find the message and delete it? Make sure you're fully up to date with Windows Update first.
Old 04 August 2004, 10:17 AM
  #15  
Fulham71
Scooby Regular
Thread Starter
 
Fulham71's Avatar
 
Join Date: Jan 2002
Posts: 7,922
Likes: 0
Received 0 Likes on 0 Posts
Default

My windows update is up to date
not sure where to go now & what to do ?
Old 04 August 2004, 10:27 AM
  #16  
JackClark
Scooby Senior
 
JackClark's Avatar
 
Join Date: Dec 2000
Location: Overdosed on LCD
Posts: 20,852
Received 51 Likes on 34 Posts
Default

>not sure where to go now & what to do ?

Have you looked for the email?
Old 04 August 2004, 01:44 PM
  #17  
Fulham71
Scooby Regular
Thread Starter
 
Fulham71's Avatar
 
Join Date: Jan 2002
Posts: 7,922
Likes: 0
Received 0 Likes on 0 Posts
Default

yes cant find the email
Old 04 August 2004, 02:26 PM
  #18  
JackClark
Scooby Senior
 
JackClark's Avatar
 
Join Date: Dec 2000
Location: Overdosed on LCD
Posts: 20,852
Received 51 Likes on 34 Posts
Default

Does the message you get contain a location??
Related Topics
Thread
Thread Starter
Forum
Replies
Last Post
MH-Racing
Subaru Parts
18
18 October 2015 04:49 PM
taylor85
Wanted
2
13 September 2015 04:57 PM
AzzDSM
Engine Management and ECU Remapping
4
13 September 2015 03:59 PM
robbie1988
Wanted
2
13 September 2015 09:25 AM
Scooby-Doo 2
Wheels And Tyres For Sale
1
09 September 2015 06:51 PM



Quick Reply: VIRUS HELP NEEDED PLEASE



All times are GMT +1. The time now is 02:22 PM.