View Full Version : win32usb virus help
gazmate
January 25th, 2005, 10:32 AM
I got a virus on my computer and its attached its self to my win32usb.exe file.
I can t quarantine, delete or rename, and my anti virus software, just keeps finding it every two seconds, its getting quite annoying!
Anyone know how to get rid or delete it!!!!
Please Help :mad:
Conan
January 25th, 2005, 10:46 AM
What anti-virus are you using? I suggest to use the Free version of Avast:
http://www.avast.com/eng/avast_4_home.html
gazmate
January 25th, 2005, 10:52 AM
nod32!! It works really well, A to well as its starting to annoy me!
and the virus is called wootbot
Conan
January 25th, 2005, 10:58 AM
nod32!! It works really well, A to well as its starting to annoy me!
and the virus is called wootbot
NOD 32 is great at identifying viruses but it's really lousy in removing them. I've used NOD before and this is it's weakness.
gazmate
January 25th, 2005, 10:59 AM
cool! Well ive just installed the one from the link you gave me! ill let u no if it works!
Curio
January 25th, 2005, 11:05 AM
Sounds like u got a worm most likely SpyBot worm, you can try an online scan from panda http://www.pandasoftware.co.uk/. There doesn't appear to be a standalone removal tool for it. Many firms also offer trialware which will remove the virus - what AV are you using (Norton) and when did you update the definitions?
gazmate
January 25th, 2005, 11:28 AM
Sounds like u got a worm most likely SpyBot worm, you can try an online scan from panda http://www.pandasoftware.co.uk/. There doesn't appear to be a standalone removal tool for it. Many firms also offer trialware which will remove the virus - what AV are you using (Norton) and when did you update the definitions?
Nod32 is the antivirus im using
FastGame
January 25th, 2005, 11:51 AM
Check these two out also
http://securityresponse.symantec.com/avcenter/venc/data/w32.spybot.dhv.html
And
http://securityresponse.symantec.com/avcenter/venc/data/w32.spybot.dhv.html
Get rid of wootbot http://www.f-secure.com/v-descs/wootbot.shtml#disinf
Did you try a boot scan or Safe Mode scan ?
Curio
January 25th, 2005, 17:50 PM
Yes sorry - it looks like keyboard telepathy, I remember thinking 'Norton' but I don't remember typing it. Anyway if you can do a panda activescan it should cure your PC alternately you can kill the win32usb.exe file yourself and remove the run registry keys (see below). If it is identified as wootbot/forbot rather than spybot worm take a look here http://castlecops.com/startuplist-5875.html and here http://www.sophos.com/virusinfo/analyses/w32forbotbq.html .
Remove the file by whichever method you choose, get this http://www.techzonez.com/forums/attachment.php?attachmentid=1294 rename the extension from .txt to .reg and run it - it will remove many possible malware startup entries from your registry including the one for win32usb.exe.
|
|