Worm/Virus Help!!

Status
Not open for further replies.

zildjianchris

In Runtime
Messages
157
I cant seem to find the folder in which this worm is in. Vet found it but wont delete it, and yes I have set vet to delete infected files. Please help.
 

Attachments

  • untitled3.zip
    59.8 KB · Views: 6
1. To disable System Restore (Windows Me/XP)
If you are running Windows Me or Windows XP, we recommend that you temporarily turn off System Restore. Windows Me/XP uses this feature, which is enabled by default, to restore the files on your computer in case they become damaged. If a virus, worm, or Trojan infects a computer, System Restore may back up the virus, worm, or Trojan on the computer.

Windows prevents outside programs, including antivirus programs, from modifying System Restore. Therefore, antivirus programs or tools cannot remove threats in the System Restore folder. As a result, System Restore has the potential of restoring an infected file on your computer, even after you have cleaned the infected files from all the other locations.

Also, a virus scan may detect a threat in the System Restore folder even though you have removed the threat.

4. To delete the value from the registry
Important: Symantec strongly recommends that you back up the registry before making any changes to it. Incorrect changes to the registry can result in permanent data loss or corrupted files. Modify the specified subkeys only. For instructions refer to the document: How to make a backup of the Windows registry.

Click Start > Run.
Type regedit
Click OK.

Note: If the registry editor fails to open the threat may have modified the registry to prevent access to the registry editor. Security Response has developed a tool to resolve this problem. Download and run this tool, and then continue with the removal.


Navigate to the subkey:

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run


In the right pane, delete the value:

"winupdates" = "%ProgramFiles%\winupdates\winupdates.exe /auto"


Exit the Registry Editor.
 
I've already got system restore disabled. And also that wasn't in the specified location in the registry. Any other suggestions?
 
Did you try Microsofts AS? Also, run Hijack this and post a log. Run your spyware scans in safemode.
 
Tried both, but not in safe mode. What button do I press for safe mode when booting again. Been so long since I've have to.
 
Don't worry now. I've deleted it. Vet wasn't completely up to date. So I updated it and ran a search, and it found it and deleted this time. Thanks for your help anyway.
 
Status
Not open for further replies.
Back
Top Bottom