anyone know to ge this out of a xp home system?

Re: net-worm win 32 theals.b by Malke

Malke
Sun May 27 09:01:32 CDT 2007

jaz wrote:
> anyone know to ge this out of a xp home system?

Go through these general malware removal steps systematically -
http://www.elephantboycomputers.com/page2.html#Removing_Malware

Include scanning with either Sysclean or Multi_AV, plus AVG Anti-Spyware
(formerly Ewido - http://www.ewido.net/en/) and follow instructions to
do all scans in Safe Mode.

When all else fails, run HijackThis and post your log in one of the
specialty forums listed at the link above (not here, please).

Standard caveat: If the procedures look too complex - and there is no
shame in admitting this isn't your cup of tea - take the machine to a
professional computer repair shop (not your local version of
BigStoreUSA). Please be aware that not all local shops are skilled at
removing malware and even if they are, your computer may be so infested
that Windows will need to be clean-installed. Have all your data backed
up before you take the machine into a shop.


Malke
--
Elephant Boy Computers
www.elephantboycomputers.com
"Don't Panic!"
MS-MVP Windows - Shell/User

Re: net-worm win 32 theals.b by David

David
Sun May 27 11:19:11 CDT 2007

From: "jaz" <jaz@discussions.microsoft.com>

| anyone know to ge this out of a xp home system?

How do you know you have this ?
What software declared the plaform is infected with this Internet worm ?

--
Dave
http://www.claymania.com/removal-trojan-adware.html
http://www.ik-cs.com/got-a-virus.htm



Re: net-worm win 32 theals.b by jaz

jaz
Sun May 27 18:44:01 CDT 2007

a 2 suared

"David H. Lipman" wrote:

> From: "jaz" <jaz@discussions.microsoft.com>
>
> | anyone know to ge this out of a xp home system?
>
> How do you know you have this ?
> What software declared the plaform is infected with this Internet worm ?
>
> --
> Dave
> http://www.claymania.com/removal-trojan-adware.html
> http://www.ik-cs.com/got-a-virus.htm
>
>
>

Re: net-worm win 32 theals.b by David

David
Sun May 27 19:35:33 CDT 2007

From: "jaz" <jaz@discussions.microsoft.com>

| a 2 suared
|

You mean Emisoft's A2 [ http://www.emsisoft.com ] ?


Download MULTI_AV.EXE from the URL --
http://www.pctipp.ch/downloads/dl/35905.asp

To use this utility, perform the following...
Execute; Multi_AV.exe { Note: You must use the default folder C:\AV-CLS }
Choose; Unzip
Choose; Close

Execute; C:\AV-CLS\StartMenu.BAT
{ or Double-click on 'Start Menu' in C:\AV-CLS }

NOTE: You may have to disable your software FireWall or allow WGET.EXE to go through your
FireWall to allow it to download the needed AV vendor related files.

C:\AV-CLS\StartMenu.BAT -- { or Double-click on 'Start Menu' in C:\AV-CLS}
This will bring up the initial menu of choices and should be executed in Normal Mode.
This way all the components can be downloaded from each AV vendor's web site.
The choices are; Sophos, Trend, McAfee, Kaspersky, Exit this menu and Reboot the PC.

You can choose to go to each menu item and just download the needed files or you can
download the files and perform a scan in Normal Mode. Once you have downloaded the files
needed for each scanner you want to use, you should reboot the PC into Safe Mode [F8 key
during boot] and re-run the menu again and choose which scanner you want to run in Safe
Mode. It is suggested to run the scanners in both Safe Mode and Normal Mode.

When the menu is displayed hitting 'H' or 'h' will bring up a more comprehensive PDF help
file.

Additional Instructions:
http://pcdid.com/Multi_AV.htm


* * * Please report back your results * * *



--
Dave
http://www.claymania.com/removal-trojan-adware.html
http://www.ik-cs.com/got-a-virus.htm



Re: net-worm win 32 theals.b by jaz

jaz
Mon May 28 02:56:01 CDT 2007

yes, that is the one.

"David H. Lipman" wrote:

> From: "jaz" <jaz@discussions.microsoft.com>
>
> | a 2 suared
> |
>
> You mean Emisoft's A2 [ http://www.emsisoft.com ] ?
>
>
> Download MULTI_AV.EXE from the URL --
> http://www.pctipp.ch/downloads/dl/35905.asp
>
> To use this utility, perform the following...
> Execute; Multi_AV.exe { Note: You must use the default folder C:\AV-CLS }
> Choose; Unzip
> Choose; Close
>
> Execute; C:\AV-CLS\StartMenu.BAT
> { or Double-click on 'Start Menu' in C:\AV-CLS }
>
> NOTE: You may have to disable your software FireWall or allow WGET.EXE to go through your
> FireWall to allow it to download the needed AV vendor related files.
>
> C:\AV-CLS\StartMenu.BAT -- { or Double-click on 'Start Menu' in C:\AV-CLS}
> This will bring up the initial menu of choices and should be executed in Normal Mode.
> This way all the components can be downloaded from each AV vendor's web site.
> The choices are; Sophos, Trend, McAfee, Kaspersky, Exit this menu and Reboot the PC.
>
> You can choose to go to each menu item and just download the needed files or you can
> download the files and perform a scan in Normal Mode. Once you have downloaded the files
> needed for each scanner you want to use, you should reboot the PC into Safe Mode [F8 key
> during boot] and re-run the menu again and choose which scanner you want to run in Safe
> Mode. It is suggested to run the scanners in both Safe Mode and Normal Mode.
>
> When the menu is displayed hitting 'H' or 'h' will bring up a more comprehensive PDF help
> file.
>
> Additional Instructions:
> http://pcdid.com/Multi_AV.htm
>
>
> * * * Please report back your results * * *
>
>
>
> --
> Dave
> http://www.claymania.com/removal-trojan-adware.html
> http://www.ik-cs.com/got-a-virus.htm
>
>
>

Re: net-worm win 32 theals.b by jaz

jaz
Mon May 28 04:54:00 CDT 2007

, i went to safe mode and ran spy sweeper, ad-aware, spybot, all came up
clean. avg antimalware won't run in safe mode. ewido used to. miss that
program.
running avg anti root kit now.
have a couple of others to run then i will go follow the rest of yall's
instructions.
i do practice safe hex. don't do porn, or open anything i don't know.
i email the person sending it to make they did send it.
because some programs will spoof a email address.
don't use IE, am very careful when i do surf the net.
not careful enough, so it seems.
actually, that system is only turned on once a week for a bout a hour. i
update everything, do my deal, then run the programs. i have zone alarm and
avast.
only avast and spysweeper run in real time, the rest are used as stand
alones. disabled the real time settings on them.
spybot found something called net-intergretion (?), then a squared found
what it called that worm.
that system has not been on the net since.
there are things i do that this sytem can't do as yet. once i get it all
straight.
i will wipe xp off the other box.
do appreciate yall's help.
i am always telling folks to bookmark this site.
i lurk here alot and run random programs that are posted, when i read about
what others have been infected
with , just to be sure mine didn't have it.

"jaz" wrote:

> yes, that is the one.
>
> "David H. Lipman" wrote:
>
> > From: "jaz" <jaz@discussions.microsoft.com>
> >
> > | a 2 suared
> > |
> >
> > You mean Emisoft's A2 [ http://www.emsisoft.com ] ?
> >
> >
> > Download MULTI_AV.EXE from the URL --
> > http://www.pctipp.ch/downloads/dl/35905.asp
> >
> > To use this utility, perform the following...
> > Execute; Multi_AV.exe { Note: You must use the default folder C:\AV-CLS }
> > Choose; Unzip
> > Choose; Close
> >
> > Execute; C:\AV-CLS\StartMenu.BAT
> > { or Double-click on 'Start Menu' in C:\AV-CLS }
> >
> > NOTE: You may have to disable your software FireWall or allow WGET.EXE to go through your
> > FireWall to allow it to download the needed AV vendor related files.
> >
> > C:\AV-CLS\StartMenu.BAT -- { or Double-click on 'Start Menu' in C:\AV-CLS}
> > This will bring up the initial menu of choices and should be executed in Normal Mode.
> > This way all the components can be downloaded from each AV vendor's web site.
> > The choices are; Sophos, Trend, McAfee, Kaspersky, Exit this menu and Reboot the PC.
> >
> > You can choose to go to each menu item and just download the needed files or you can
> > download the files and perform a scan in Normal Mode. Once you have downloaded the files
> > needed for each scanner you want to use, you should reboot the PC into Safe Mode [F8 key
> > during boot] and re-run the menu again and choose which scanner you want to run in Safe
> > Mode. It is suggested to run the scanners in both Safe Mode and Normal Mode.
> >
> > When the menu is displayed hitting 'H' or 'h' will bring up a more comprehensive PDF help
> > file.
> >
> > Additional Instructions:
> > http://pcdid.com/Multi_AV.htm
> >
> >
> > * * * Please report back your results * * *
> >
> >
> >
> > --
> > Dave
> > http://www.claymania.com/removal-trojan-adware.html
> > http://www.ik-cs.com/got-a-virus.htm
> >
> >
> >

Re: net-worm win 32 theals.b by PA

PA
Mon May 28 09:23:38 CDT 2007

Something's definitely wrong: AVG Anti-Spyware /should/ run in Safe Mode.
--
~PA Bear

jaz wrote:
> , i went to safe mode and ran spy sweeper, ad-aware, spybot, all came up
> clean. avg antimalware won't run in safe mode. ewido used to. miss that
> program.
> running avg anti root kit now.
> have a couple of others to run then i will go follow the rest of yall's
> instructions.
> i do practice safe hex. don't do porn, or open anything i don't know.
> i email the person sending it to make they did send it.
> because some programs will spoof a email address.
> don't use IE, am very careful when i do surf the net.
> not careful enough, so it seems.
> actually, that system is only turned on once a week for a bout a hour. i
> update everything, do my deal, then run the programs. i have zone alarm
> and
> avast.
> only avast and spysweeper run in real time, the rest are used as stand
> alones. disabled the real time settings on them.
> spybot found something called net-intergretion (?), then a squared found
> what it called that worm.
> that system has not been on the net since.
> there are things i do that this sytem can't do as yet. once i get it all
> straight.
> i will wipe xp off the other box.
> do appreciate yall's help.
> i am always telling folks to bookmark this site.
> i lurk here alot and run random programs that are posted, when i read
> about
> what others have been infected
> with , just to be sure mine didn't have it.
>
> "jaz" wrote:
>
>> yes, that is the one.
>>
>> "David H. Lipman" wrote:
>>
>>> From: "jaz" <jaz@discussions.microsoft.com>
>>>
>>>> a 2 suared
>>>>
>>>
>>> You mean Emisoft's A2 [ http://www.emsisoft.com ] ?
>>>
>>>
>>> Download MULTI_AV.EXE from the URL --
>>> http://www.pctipp.ch/downloads/dl/35905.asp
>>>
>>> To use this utility, perform the following...
>>> Execute; Multi_AV.exe { Note: You must use the default folder
>>> C:\AV-CLS }
>>> Choose; Unzip
>>> Choose; Close
>>>
>>> Execute; C:\AV-CLS\StartMenu.BAT
>>> { or Double-click on 'Start Menu' in C:\AV-CLS }
>>>
>>> NOTE: You may have to disable your software FireWall or allow WGET.EXE
>>> to
>>> go through your FireWall to allow it to download the needed AV vendor
>>> related files.
>>>
>>> C:\AV-CLS\StartMenu.BAT -- { or Double-click on 'Start Menu' in
>>> C:\AV-CLS}
>>> This will bring up the initial menu of choices and should be executed in
>>> Normal Mode. This way all the components can be downloaded from each AV
>>> vendor's web site.
>>> The choices are; Sophos, Trend, McAfee, Kaspersky, Exit this menu and
>>> Reboot the PC.
>>>
>>> You can choose to go to each menu item and just download the needed
>>> files
>>> or you can download the files and perform a scan in Normal Mode. Once
>>> you
>>> have downloaded the files needed for each scanner you want to use, you
>>> should reboot the PC into Safe Mode [F8 key during boot] and re-run the
>>> menu again and choose which scanner you want to run in Safe Mode. It is
>>> suggested to run the scanners in both Safe Mode and Normal Mode.
>>>
>>> When the menu is displayed hitting 'H' or 'h' will bring up a more
>>> comprehensive PDF help file.
>>>
>>> Additional Instructions:
>>> http://pcdid.com/Multi_AV.htm
>>>
>>>
>>> * * * Please report back your results * * *
>>>
>>>
>>>
>>> --
>>> Dave
>>> http://www.claymania.com/removal-trojan-adware.html
>>> http://www.ik-cs.com/got-a-virus.htm


Re: net-worm win 32 theals.b by jen

jen
Mon May 28 12:44:52 CDT 2007

"jaz" <jaz@discussions.microsoft.com> wrote in message
news:D6A2589D-D1B5-4CC8-93E6-50E57636252E@microsoft.com...
>, i went to safe mode and ran spy sweeper, ad-aware, spybot, all came
>up
> clean. avg antimalware won't run in safe mode. ewido used to. miss
> that
> program.
> running avg anti root kit now.
> have a couple of others to run then i will go follow the rest of
> yall's
> instructions.
> i do practice safe hex. don't do porn, or open anything i don't know.
> i email the person sending it to make they did send it.
> because some programs will spoof a email address.
> don't use IE, am very careful when i do surf the net.
> not careful enough, so it seems.
> actually, that system is only turned on once a week for a bout a hour.
> i
> update everything, do my deal, then run the programs. i have zone
> alarm and
> avast.
> only avast and spysweeper run in real time, the rest are used as stand
> alones. disabled the real time settings on them.
> spybot found something called net-intergretion (?), then a squared
> found
> what it called that worm.
> that system has not been on the net since.
> there are things i do that this sytem can't do as yet. once i get it
> all
> straight.
> i will wipe xp off the other box.
> do appreciate yall's help.
> i am always telling folks to bookmark this site.
> i lurk here alot and run random programs that are posted, when i read
> about
> what others have been infected
> with , just to be sure mine didn't have it.

False positive. See:
http://forum.emsisoft.com/Default.aspx?g=posts&m=11189

-jen



Re: net-worm win 32 theals.b by jaz

jaz
Mon May 28 16:21:00 CDT 2007

oh man, that's a relief.

thanks jen.



"jen" wrote:

> "jaz" <jaz@discussions.microsoft.com> wrote in message
> news:D6A2589D-D1B5-4CC8-93E6-50E57636252E@microsoft.com...
> >, i went to safe mode and ran spy sweeper, ad-aware, spybot, all came
> >up
> > clean. avg antimalware won't run in safe mode. ewido used to. miss
> > that
> > program.
> > running avg anti root kit now.
> > have a couple of others to run then i will go follow the rest of
> > yall's
> > instructions.
> > i do practice safe hex. don't do porn, or open anything i don't know.
> > i email the person sending it to make they did send it.
> > because some programs will spoof a email address.
> > don't use IE, am very careful when i do surf the net.
> > not careful enough, so it seems.
> > actually, that system is only turned on once a week for a bout a hour.
> > i
> > update everything, do my deal, then run the programs. i have zone
> > alarm and
> > avast.
> > only avast and spysweeper run in real time, the rest are used as stand
> > alones. disabled the real time settings on them.
> > spybot found something called net-intergretion (?), then a squared
> > found
> > what it called that worm.
> > that system has not been on the net since.
> > there are things i do that this sytem can't do as yet. once i get it
> > all
> > straight.
> > i will wipe xp off the other box.
> > do appreciate yall's help.
> > i am always telling folks to bookmark this site.
> > i lurk here alot and run random programs that are posted, when i read
> > about
> > what others have been infected
> > with , just to be sure mine didn't have it.
>
> False positive. See:
> http://forum.emsisoft.com/Default.aspx?g=posts&m=11189
>
> -jen
>
>
>

Re: net-worm win 32 theals.b by jen

jen
Mon May 28 16:59:52 CDT 2007

"jaz" <jaz@discussions.microsoft.com> wrote in message
news:FBBAE0C6-AF0A-44C1-BCC0-7D90E0DD2E29@microsoft.com...
> oh man, that's a relief.
> thanks jen.

You're very welcome, jaz :)

-jen