Got a virus - Need help fast!
Results 1 to 15 of 15

Thread: Got a virus - Need help fast!

  1. #1
    Registered User
    Join Date
    Jun 2001
    Posts
    1,822

    Post Got a virus - Need help fast!

    My anti virus found JOKE_WINAVOID.A in my PC yesterday and all programs I started started as if it was the first time I started it and went threw the initial setup (as if all registry entries were gone, but they seemed to still be there when i looked in regedit).

    I shut down my PC and I don't want to turn it back on so the virus doesnt do anymore damage.

    Also, my backup software stopped working 2 months ago so I dont have a recent backup. What I thought of doing was get a new 30GB drive (I have 26GB to backup) copy my important files to it, format the old one and restore the files, then return the drive for my money back.

    Is there another way of fixing my PC?

    Thanks
    "[...] drug companies are killing far more Americans than all terrorists, murderers and criminals combined [...]" - NewsTarget.com

  2. #2
    Registered User *SlyVenom*'s Avatar
    Join Date
    Oct 2001
    Posts
    1,034

    Post

    JOKE_WINAVOID.A
    <a href="http://www.antivirus.com/vinfo/virusencyclo/default5.asp?VName=JOKE_WINAVOID.A" target="_blank">http://www.antivirus.com/vinfo/virusencyclo/default5.asp?VName=JOKE_WINAVOID.A</a>

    In the wild: No
    Payload 1: Displays Message
    Detection available: October 8, 2001
    Detected by pattern file#: 152 or 952
    (note about pattern numbering)
    Detected by scan engine#: 5.170
    Language:
    English
    Platform: Windows
    Encrypted: No
    Size of virus: 272,128 Bytes

    Details:
    When executed, this Joke program displays a dialog box with graphics of 3 beer bottles. The dialog box contains a title as follows:

    “How drunk are you ?” <“Click here to close this program”>

    When the user follows the instruction on the window to close the program, the dialog box literally moves over the screen to avoid being closed. When the user hits the Enter key, or the Spacebar, or gets the dialog box cornered on one side of the screen and clicks it, the program terminates.


    Description created: October 12, 2001
    Description updated: October 12, 2001

  3. #3
    Registered User
    Join Date
    Jun 2001
    Posts
    1,822

    Post

    Anyway I do have a virus since all my registry settings have dissapeared so I got a new hard drive so I can restore my files and I'll return the drive after.

  4. #4
    Registered User
    Join Date
    Jun 2001
    Posts
    1,822

    Post

    I have WORM_SIRCAM.A

    What does this virus do? Is it safe to restore my files or can they be infected?

  5. #5
    Registered User *SlyVenom*'s Avatar
    Join Date
    Oct 2001
    Posts
    1,034

    Post

    [quote]Originally posted by ClickHere2Surf.com:
    <strong>I have WORM_SIRCAM.A

    What does this virus do? Is it safe to restore my files or can they be infected?</strong><hr></blockquote>

    <a href="http://www.trendmicro.dk/vinfo/virusencyclo/default5.asp?VName=WORM_SIRCAM.A" target="_blank">http://www.trendmicro.dk/vinfo/virusencyclo/default5.asp?VName=WORM_SIRCAM.A</a>

    WORM_SIRCAM.A
    Risk rating:
    Virus type: Worm
    Destructive: Yes

    Aliases:
    SCAM.A, TROJ_SCAM.A, W32.Sircam.Worm@mm

    Description:
    This Worm is a high-level program created in Delphi that propagates via email using SMTP commands. It sends copies of itself to all addresses listed in an infected user's address book and in temporary Internet cached files. It arrives with a random subject line, and an attachment by the same name.

    This Worm also propagates via shared network drives.

    Solution:
    To automatically remove the Worm using the fix tool:

    Download the fix tool and run the file. It will scan Drive C:\ and subfolders.
    If a Worm is detected, it prompts you to delete the file or not.
    The tool will also restore the registry entries modified by the Trojan.
    Edit AUTOEXEC.BAT.
    Delete @win \recycled\SIRC32.EXE.
    Restart your computer.

  6. #6
    Registered User
    Join Date
    Jun 2001
    Posts
    1,822

    Post

    Since I have this virus, my cable modem stopped working and I have to connect at 56k. Is there a way to get the network working again? There arent any problems in device manager and the connection status with the cable modem is "Connected, Speed 10.0Mbps".

    So why isnt my cable modem working? I'd like to download a large file (500MB) before formating but this would take years at 56k!

    Also, now I get lots of errors when I start windows and lots of programs arent working, is it possible I have a new unknown virus that the virus scanner doesn't know of?

    Would restoring my files from the backup restore the virus?

    Thanks
    "[...] drug companies are killing far more Americans than all terrorists, murderers and criminals combined [...]" - NewsTarget.com

  7. #7
    Registered User *SlyVenom*'s Avatar
    Join Date
    Oct 2001
    Posts
    1,034

    Post

    What virus scanner do you use? and when is the last time it was updated?

  8. #8
    Registered User DiR[ëctory]'s Avatar
    Join Date
    Nov 2001
    Location
    third house on the right
    Posts
    1,060

    Post

    Is there really any important files on your computer? It sounds as though you may have a mess. I would suggest just formatting and reinstalling if you aren't going to lose anything much. Just a thought.

  9. #9
    Registered User
    Join Date
    Jun 2001
    Posts
    1,822

    Post

    OK, i found the problem with the cable modem, I forgot to reset it after i switched it back to my desktop from my handheld PC.

    I did backup my 27GB of important files to the new hard drive I got, I'll format and re-install Windows, then restore from the new drive and return it for my money back (has a 30 day satisfaction garantee, I'll say I bought it because I thought it would make a big speed increase from my old drive but I didnt see a big difference in performance ).

    Thanks

  10. #10
    Registered User Niclo Iste's Avatar
    Join Date
    Oct 2007
    Location
    Pgh, PA
    Posts
    2,051

    Talking

    Try Trend Micro out for their housecall online virus scan or use NOD32 online scan by ESET. Once you get the virus out I suggest updating your systems protection and get NOD32, if you cannot afford that 2 free decent virus scans are AVG and Bit Defender.



    By the way yes I know this is an ancient thread and there is no reason to reply to it. I did this because I said I would in that last 7 year old post that was replied to. So we'll see how long my hobby of answering posts from 5+ years ago lasts.
    One Script to rule them all.
    One Script to find them.
    One Script to bring them all,
    and clean up after itself.

  11. #11
    Driver Terrier NooNoo's Avatar
    Join Date
    Dec 2000
    Location
    UK
    Posts
    31,824
    Niclo, of all the member's threads to resurrect, you would pick a troublemaker...

  12. #12
    Registered User MobilePCPhysician's Avatar
    Join Date
    Jan 2002
    Location
    Cleveland, Oh
    Posts
    2,381
    [quote=Niclo Iste] Once you get the virus out I suggest updating your systems protection and get NOD32, if you cannot afford that 2 free decent virus scans are AVG and Bit Defender.quote]

    He would buy the NOD 32, use it, then return it.....

  13. #13
    Registered User Niclo Iste's Avatar
    Join Date
    Oct 2007
    Location
    Pgh, PA
    Posts
    2,051
    Quote Originally Posted by NooNoo
    Niclo, of all the member's threads to resurrect, you would pick a troublemaker...
    Such sweet irony that to be troublesome I choose a troublemakers thread to dig up. Sounds like he was a stellar type of guy from the feedback you both gave.

  14. #14
    Driver Terrier NooNoo's Avatar
    Join Date
    Dec 2000
    Location
    UK
    Posts
    31,824
    Have a laugh, do a search for his posts.... but keep your comments to yourself and let sleeping dogs lie.

  15. #15
    Registered User slgrieb's Avatar
    Join Date
    Feb 2003
    Posts
    4,103
    "Alas! Poor Yorick! I knew him, Horatio. A fellow of infinite problems! A thousand times he hath asked me to bear him on my back. And now, how abhorred is he!"

Bookmarks

Posting Permissions

  • You may not post new threads
  • You may not post replies
  • You may not post attachments
  • You may not edit your posts
  •