Black Worm Message?

Black Worm Message?

Secure Home | Search | About
 Microsoft Antivirus Discussions    Post an article   get this group's latest topics as an RSS feed add this group's latest topics to your My MSN content add this group's latest topics to your My Yahoo content add this group's latest topics to your Google content
Subject Author Date
Black Worm Message? pc student 02-27-2006
Posted by =?Utf-8?B?cGMgc3R1ZGVudA==?= on February 27, 2006, 12:05 pm
If you were  Registered and logged in, you could reply and use other advanced thread options
I keep getting this message:
Security breach by Blackworm Virus. To prevent futher Melware infictions
download .......

Posted by =?Utf-8?B?cGMgc3R1ZGVudA==?= on February 27, 2006, 12:17 pm
If you were  Registered and logged in, you could reply and use other advanced thread options


"pc student" wrote:

> I keep getting this message:
> Security breach by Blackworm Virus. To prevent futher Melware infictions
> download .......


Sorry I have run Norton antivirus 2006 full and quick scan and it found one
spyware and another threat and quarantined it and deleted it then I also
rebooted today and I got the same message again. It is about to drive me
crazy!

Posted by =?Utf-8?B?UGFuZGFfbWFu?= on February 27, 2006, 12:32 pm
If you were  Registered and logged in, you could reply and use other advanced thread options
First , I advise you to scan with Panda Software's free Active Scan (where
you check for ALL kind of security threats)
http://www.activescan.com

When the scan is ready , you view a report and then you are allowed to save
the report on your hard-drive.Please save the report on the Desktop,for
example , the open it (it is Notepad txt file) and post the report here so I
(and everyone else) can see what you have exactly.

Then , you can start performing the malware removal instructions in my
web-site:
http://pandaman.hit.bg

Learn how to protect your PC:
http://www.microsoft.com/protect


Panda_man
--
Prevention is always better than cure !
Panda TruPrevent - the most intelligent technology to combat unknown malware
http://www.pandasoftware.com
http://pandaman.hit.bg



"pc student" wrote:

>
>
> "pc student" wrote:
>
> > I keep getting this message:
> > Security breach by Blackworm Virus. To prevent futher Melware infictions
> > download .......
>
>
> Sorry I have run Norton antivirus 2006 full and quick scan and it found one
> spyware and another threat and quarantined it and deleted it then I also
> rebooted today and I got the same message again. It is about to drive me
> crazy!

Posted by =?Utf-8?B?cGMgc3R1ZGVudA==?= on February 28, 2006, 5:17 pm
If you were  Registered and logged in, you could reply and use other advanced thread options
I am running this panda software right now and it shows that I have 87
possible problems. HELP!!! Ok and I have norton running ...


Potentially unwanted tool:application/winantivirus2006
Not disinfected C:\PROGRAM FILES\COMMON FILES\WinAntiVirus
Pro 2006


Adware:adware/savenow
Not disinfected Windows Registry



Potentially unwanted tool:application/myway
Not disinfected
HKEY_CLASSES_ROOT\MYWAYSEARCHASSISTANTDE.AUXILIARY


Spyware:Cookie/24/7 Realmedia
Not disinfected C:\Documents and Settings\Dawn
Baldwin\Cookies\dawn baldwin@247realmedia[1].txt


Spyware:Cookie/Atlas DMT
Not disinfected C:\Documents and Settings\Dawn
Baldwin\Cookies\dawn baldwin@atdmt[2].txt


Spyware:Cookie/Bluestreak
Not disinfected C:\Documents and Settings\Dawn
Baldwin\Cookies\dawn baldwin@bluestreak[1].txt


Spyware:Cookie/bravenetA
Not disinfected C:\Documents and Settings\Dawn
Baldwin\Cookies\dawn baldwin@bravenet[2].txt


Spyware:Cookie/Bs.serving-sys
Not disinfected C:\Documents and Settings\Dawn
Baldwin\Cookies\dawn baldwin@bs.serving-sys[2].txt


Spyware:Cookie/BurstNet
Not disinfected C:\Documents and Settings\Dawn
Baldwin\Cookies\dawn baldwin@burstnet[2].txt

Spyware:Cookie/DomainSponsor
Not disinfected C:\Documents and Settings\Dawn
Baldwin\Cookies\dawn baldwin@landing.domainsponsor[1].txt


Spyware:Cookie/FastClick
Not disinfected C:\Documents and Settings\Dawn
Baldwin\Cookies\dawn baldwin@media.fastclick[2].txt


Spyware:Cookie/Mediaplex
Not disinfected C:\Documents and Settings\Dawn
Baldwin\Cookies\dawn baldwin@mediaplex[2].txt


Spyware:Cookie/Overture
Not disinfected C:\Documents and Settings\Dawn
Baldwin\Cookies\dawn baldwin@overture[1].txt


Spyware:Cookie/Overture
Not disinfected C:\Documents and Settings\Dawn
Baldwin\Cookies\dawn baldwin@perf.overture[1].txt


Spyware:Cookie/QuestionMarket
Not disinfected C:\Documents and Settings\Dawn
Baldwin\Cookies\dawn baldwin@questionmarket[2].txt


Spyware:Cookie/WUpd
Not disinfected C:\Documents and Settings\Dawn
Baldwin\Cookies\dawn baldwin@revenue[1].txt


Spyware:Cookie/Searchportal
Not disinfected C:\Documents and Settings\Dawn
Baldwin\Cookies\dawn baldwin@searchportal.information[1].txt


Spyware:Cookie/Seeq
Not disinfected C:\Documents and Settings\Dawn
Baldwin\Cookies\dawn baldwin@seeq[1].txt


Spyware:Cookie/Serving-sys
Not disinfected C:\Documents and Settings\Dawn
Baldwin\Cookies\dawn baldwin@serving-sys[2].txt


Spyware:Cookie/onestat.com
Not disinfected C:\Documents and Settings\Dawn
Baldwin\Cookies\dawn baldwin@stat.onestat[2].txt


Spyware:Cookie/Statcounter
Not disinfected C:\Documents and Settings\Dawn
Baldwin\Cookies\dawn baldwin@statcounter[1].txt


Spyware:Cookie/Reliablestats
Not disinfected C:\Documents and Settings\Dawn
Baldwin\Cookies\dawn baldwin@stats1.reliablestats[1].txt


Spyware:Cookie/WebtrendsLive
Not disinfected C:\Documents and Settings\Dawn
Baldwin\Cookies\dawn baldwin@statse.webtrendslive[2].txt


Spyware:Cookie/Target
Not disinfected C:\Documents and Settings\Dawn
Baldwin\Cookies\dawn baldwin@target[2].txt


Spyware:Cookie/Valueclick
Not disinfected C:\Documents and Settings\Dawn
Baldwin\Cookies\dawn baldwin@valueclick[1].txt


Spyware:Cookie/WinFixer
Not disinfected C:\Documents and Settings\Dawn
Baldwin\Cookies\dawn baldwin@winfixer[1].txt


Spyware:Cookie/Affiliate fuel
Not disinfected C:\Documents and Settings\Dawn
Baldwin\Cookies\dawn baldwin@www.affiliatefuel[1].txt


Spyware:Cookie/BurstBeacon
Not disinfected C:\Documents and Settings\Dawn
Baldwin\Cookies\dawn baldwin@www.burstbeacon[2].txt


Spyware:Cookie/Seeq
Not disinfected C:\Documents and Settings\Dawn
Baldwin\Cookies\dawn baldwin@www48.seeq[1].txt


Spyware:Cookie/Zedo
Not disinfected C:\Documents and Settings\Dawn
Baldwin\Cookies\dawn baldwin@zedo[1].txt


Spyware:Cookie/24/7 Realmedia
Not disinfected C:\Documents and Settings\Dawn
Baldwin\Cookies\dawn baldwin@247realmedia[1].txt


Spyware:Cookie/2o7.net
Not disinfected C:\Documents and Settings\Dawn
Baldwin\Cookies\dawn baldwin@2o7[2].txt


Spyware:Cookie/PointRoll
Not disinfected C:\Documents and Settings\Dawn
Baldwin\Cookies\dawn baldwin@ads.pointroll[1].txt


Spyware:Cookie/adultfriendfinder
Not disinfected C:\Documents and Settings\Dawn
Baldwin\Cookies\dawn baldwin@adultfriendfinder[2].txt


Spyware:Cookie/Advertising
Not disinfected C:\Documents and Settings\Dawn
Baldwin\Cookies\dawn baldwin@advertising[2].txt


Spyware:Cookie/Falkag
Not disinfected C:\Documents and Settings\Dawn
Baldwin\Cookies\dawn baldwin@as-us.falkag[1].txt


Spyware:Cookie/Falkag
Not disinfected C:\Documents and Settings\Dawn
Baldwin\Cookies\dawn baldwin@as1.falkag[2].txt


Spyware:Cookie/Atlas DMT
Not disinfected C:\Documents and Settings\Dawn
Baldwin\Cookies\dawn baldwin@atdmt[2].txt


Spyware:Cookie/Bluestreak
Not disinfected C:\Documents and Settings\Dawn
Baldwin\Cookies\dawn baldwin@bluestreak[1].txt


Spyware:Cookie/bravenetA
Not disinfected C:\Documents and Settings\Dawn
Baldwin\Cookies\dawn baldwin@bravenet[2].txt


Spyware:Cookie/Bs.serving-sys
Not disinfected C:\Documents and Settings\Dawn
Baldwin\Cookies\dawn baldwin@bs.serving-sys[2].txt


Spyware:Cookie/BurstNet
Not disinfected C:\Documents and Settings\Dawn
Baldwin\Cookies\dawn baldwin@burstnet[2].txt


Spyware:Cookie/Enhance
Not disinfected C:\Documents and Settings\Dawn
Baldwin\Cookies\dawn baldwin@c.enhance[1].txt


Spyware:Cookie/CentrPort
Not disinfected C:\Documents and Settings\Dawn
Baldwin\Cookies\dawn baldwin@centrport[1].txt


Spyware:Cookie/Hitslink
Not disinfected C:\Documents and Settings\Dawn
Baldwin\Cookies\dawn baldwin@counter.hitslink[2].txt


Spyware:Cookie/cs.sexcounter
Not disinfected C:\Documents and Settings\Dawn
Baldwin\Cookies\dawn baldwin@cs.sexcounter[2].txt


Spyware:Cookie/360i
Not disinfected C:\Documents and Settings\Dawn
Baldwin\Cookies\dawn baldwin@ct.360i[1].txt


Spyware:Cookie/did-it
Not disinfected C:\Documents and Settings\Dawn
Baldwin\Cookies\dawn baldwin@did-it[1].txt


Spyware:Cookie/Doubleclick
Not disinfected C:\Documents and Settings\Dawn
Baldwin\Cookies\dawn baldwin@doubleclick[2].txt


Spyware:Cookie/Entrepreneur
Not disinfected C:\Documents and Settings\Dawn
Baldwin\Cookies\dawn baldwin@entrepreneur[1].txt


Spyware:Cookie/FastClick
Not disinfected C:\Documents and Settings\Dawn
Baldwin\Cookies\dawn baldwin@fastclick[1].txt


Spyware:Cookie/DomainSponsor
Not disinfected C:\Documents and Settings\Dawn
Baldwin\Cookies\dawn baldwin@landing.domainsponsor[1].txt


Spyware:Cookie/FastClick
Not disinfected C:\Documents and Settings\Dawn
Baldwin\Cookies\dawn baldwin@media.fastclick[2].txt


Spyware:Cookie/Mediaplex
Not disinfected C:\Documents and Settings\Dawn
Baldwin\Cookies\dawn baldwin@mediaplex[2].txt


Spyware:Cookie/Overture
Not disinfected C:\Documents and Settings\Dawn
Baldwin\Cookies\dawn baldwin@overture[1].txt


Spyware:Cookie/Overture
Not disinfected C:\Documents and Settings\Dawn
Baldwin\Cookies\dawn baldwin@perf.overture[1].txt


Spyware:Cookie/QuestionMarket
Not disinfected C:\Documents and Settings\Dawn
Baldwin\Cookies\dawn baldwin@questionmarket[2].txt


Spyware:Cookie/WUpd
Not disinfected C:\Documents and Settings\Dawn
Baldwin\Cookies\dawn baldwin@revenue[1].txt


Spyware:Cookie/Searchportal
Not disinfected C:\Documents and Settings\Dawn
Baldwin\Cookies\dawn baldwin@searchportal.information[1].txt


Spyware:Cookie/Seeq
Not disinfected C:\Documents and Settings\Dawn
Baldwin\Cookies\dawn baldwin@seeq[1].txt


Spyware:Cookie/Serving-sys
Not disinfected C:\Documents and Settings\Dawn
Baldwin\Cookies\dawn baldwin@serving-sys[2].txt


Spyware:Cookie/onestat.com
Not disinfected C:\Documents and Settings\Dawn
Baldwin\Cookies\dawn baldwin@stat.onestat[2].txt


Spyware:Cookie/Statcounter
Not disinfected C:\Documents and Settings\Dawn
Baldwin\Cookies\dawn baldwin@statcounter[1].txt


Spyware:Cookie/Reliablestats
Not disinfected C:\Documents and Settings\Dawn
Baldwin\Cookies\dawn baldwin@stats1.reliablestats[1].txt


Spyware:Cookie/WebtrendsLive
Not disinfected C:\Documents and Settings\Dawn
Baldwin\Cookies\dawn baldwin@statse.webtrendslive[2].txt


Spyware:Cookie/Target
Not disinfected C:\Documents and Settings\Dawn
Baldwin\Cookies\dawn baldwin@target[2].txt


Spyware:Cookie/Valueclick
Not disinfected C:\Documents and Settings\Dawn
Baldwin\Cookies\dawn baldwin@valueclick[1].txt


Spyware:Cookie/WinFixer
Not disinfected C:\Documents and Settings\Dawn
Baldwin\Cookies\dawn baldwin@winfixer[1].txt


Spyware:Cookie/Affiliate fuel
Not disinfected C:\Documents and Settings\Dawn
Baldwin\Cookies\dawn baldwin@www.affiliatefuel[1].txt



Adware:Adware/ClockSync
Not disinfected C:\Documents and Settings\Dawn Baldwin\Local
Settings\Temp\VVSNInst.exe


Potentially unwanted tool:Application/ErrorSafe
Not disinfected C:\Documents and Settings\Dawn Baldwin\Local
Settings\Temporary Internet
Files\Content.IE5KX37UAD\WinAntiVirusPro2006ScannerInstall[1].exe


Potentially unwanted tool:Application/Winfixer2005
Not disinfected C:\Documents and Settings\Dawn Baldwin\Local
Settings\Temporary Internet
Files\Content.IE5\WP2ZS1QZ\WinFixer2006FreeInstall[1].exe


Potentially unwanted tool:Application/Winantivirus2006
Not disinfected C:\Program Files\Common Files\WinAntiVirus
Pro 2006\WapCHK.dll


Potentially unwanted tool:Application/Winantivirus2006
Not disinfected C:\Program Files\Common Files\WinFixer
2006\pcheck.dll


Spyware:Spyware/Virtumonde
Not disinfected C:\WINDOWS\system32\pmnnk.dll





Posted by David H. Lipman on February 28, 2006, 5:35 pm
If you were  Registered and logged in, you could reply and use other advanced thread options

| I am running this panda software right now and it shows that I have 87
| possible problems. HELP!!! Ok and I have norton running ...
|
| Potentially unwanted tool:application/winantivirus2006
| Not disinfected C:\PROGRAM FILES\COMMON FILES\WinAntiVirus
| Pro 2006
|
| Adware:adware/savenow
| Not disinfected Windows Registry
|
| Potentially unwanted tool:application/myway
| Not disinfected
| HKEY_CLASSES_ROOT\MYWAYSEARCHASSISTANTDE.AUXILIARY
|

< snip >

|
| Adware:Adware/ClockSync
| Not disinfected C:\Documents and Settings\Dawn Baldwin\Local
| Settings\Temp\VVSNInst.exe
|
| Potentially unwanted tool:Application/ErrorSafe
| Not disinfected C:\Documents and Settings\Dawn Baldwin\Local
| Settings\Temporary Internet
| Files\Content.IE5KX37UAD\WinAntiVirusPro2006ScannerInstall[1].exe
|
| Potentially unwanted tool:Application/Winfixer2005
| Not disinfected C:\Documents and Settings\Dawn Baldwin\Local
| Settings\Temporary Internet
| Files\Content.IE5\WP2ZS1QZ\WinFixer2006FreeInstall[1].exe
|
| Potentially unwanted tool:Application/Winantivirus2006
| Not disinfected C:\Program Files\Common Files\WinAntiVirus
| Pro 2006\WapCHK.dll
|
| Potentially unwanted tool:Application/Winantivirus2006
| Not disinfected C:\Program Files\Common Files\WinFixer
2006\pcheck.dll
|
| Spyware:Spyware/Virtumonde
| Not disinfected C:\WINDOWS\system32\pmnnk.dll
|

Most of what was fopund were cookies which are NOT a problem. However you did
have
"WinAntiVirus Pro" which is a is a Rogue anti spyware application and is NOT
safe to use.
Please check with Syware Warrior when checking out any anti spyware
appplications. You will
find WinAntiSpyware and WinAntiVirus listed as Rogues on Spyware Warrior.
http://www.spywarewarrior.com/rogue_anti-spyware.htm

It should be removed ASAP !

It also shows the Winfixer and Vundo/Virtumonde. WinFixer is another rogue
antospyware
application on SyWare Warrior and is auto installed my certain downloader
Trojans.

The following set of instructions can be used to clean your PC...



Two phase answer...

Perform Part 1 then perform Part 2

It is suggested that you execute each tool in Normal Mode then in Safe Mode.

If you are using any version of Sun Java that is prior to JRE Version 5.0,
then you are strongly urged to remove any/all versions that are prior to JRE
Version 5.0. There are vulnerabilities in them and they are actively being
exploited.
It is possible that is how you got infected with malware.

Therefore, it is highly suggested that if there are any prior versions of Sun
Java
to Version 5 on the PC that they be removed and Sun Java JRE Version 5.0 Update 6
be installed ASAP.

http://www.java.com/en/download/manual.jsp



Part 1
------------
Download Adware-Virtumundo Removal Tool --
http://secured2k.home.comcast.net/tools/VirtumundoBeGone.exe

Information on the Adware-Virtumundo Removal Tool:
http://forums.mcafeehelp.com/viewtopic.php?t=57049

Part 2
------------
Download WinFixerFix.exe from the URL --
http://www.ik-cs.com/programs/virtools/WinFixerFix.exe

Execute; WinFixerFix.exe { Note: You must accept the default of C:\McAfee }
Choose; Unzip
Choose; Close

NOTE: You may have to disable your software FireWall or allow WGET.EXE to go
through your
FireWall to enable WGET.EXE to download the needed McAfee related files.

Execute; c:\mcafee\clean.bat
{ or Double-click on 'Clean Link' in c:\mcafee }

A final report in HTML format called C:\mcafee\Normal_ScanReport.HTML or
C:\mcafee\Safe_ScanReport.HTML will be generated. At the end of the scan, it
will be
displayed in your browser (Opera, FireFox or Internet Explorer). However, if
you are using
WinXP, Win2K or Win2003 your system will be left in a state where you will have
to manually
shutdown/reboot the PC. On Win9x/ME platforms the report will not be shown in
your bowser
but your PC will automatically be shutdown. It is suggested that you move the
report out of
c:\mcafee before performing another scan.

It would be best to scan in both Safe Mode and in Normal Mode and save a copy of
the HTML
report for each session.

Please Copy and Paste the contents of the HTML Log files;
C:\mcafee\Normal_ScanReport.HTML & C:\mcafee\Safe_ScanReport.HTML in your reply.

* * * Please report back your results * * *



--
Dave
http://www.claymania.com/removal-trojan-adware.html
http://www.ik-cs.com/got-a-virus.htm



Similar ThreadsPosted
kamsutra virus ,[black worm, my wife] February 3, 2006, 12:02 pm
Worm VB.AS Aliases W32.Alcra.B and W32/Alcan.worm!p2p July 18, 2005, 8:37 am
Blinking cursor on black screen January 30, 2007, 6:18 pm
Virus Makes Monitor Go Black Upon Detection July 20, 2006, 12:06 pm
Black Paper about MPS Technology - Anti Malware technique February 14, 2008, 9:39 am
WORM/DELF.FPV - new worm?? January 14, 2008, 6:58 am
virus message August 20, 2006, 5:09 am
Pop Up Registry Error Message November 9, 2005, 7:38 pm
Re: error message 0x8DDD0018 - need help November 29, 2005, 2:12 am
fake spyware message February 18, 2006, 7:49 pm

The site map in XML format XML site map

Contact Us | Privacy Policy