Page 1 of 1

help virus experts

Posted: Tue Jul 15, 2003 1:15 am
by grumpy 1
Im having a hell of a ttime getting rid of a virus of opaserve from a windows me machine
Ive have found filles called brasil.pif and marco .scr deleted as many keys as i could find from the registry
I deleted system restore all together because that just kept sticking the viruses back
Initially pc cillin wont let me install it because it warns me of a virus so i have to clean it up
I install pc-cillin and update it and its cllear uninstall pc-cillin and put norton 2003 on and update it and it says its clear
Restart the computer and still all clear as soon as i connect to the internet i get a virus warning of a virus in c cdrive opa serve brasil.pif scrnsvr .exe within minutes of being connected to the net they re back
I read that there can be a ini file that connects to a web site that rebuilds the virus but im dammed if i can find it

Man this is driving me bonkers

Cheers

Posted: Tue Jul 15, 2003 1:24 am
by blade
Looks like a nasty one.

A lot on it here:
http://securityresponse.symantec.com/av ... .worm.html

Scroll down for removal instructions and removal tool:
http://securityresponse.symantec.com/av ... .tool.html

This patch is suppose to prevent future infections:
http://www.microsoft.com/technet/securi ... 00-072.asp

Good luck. :)

Post back if that helps or not.



Free online virus scan:
http://housecall.trendmicro.com/

Posted: Tue Jul 15, 2003 7:24 am
by FlyingPenguin
ALWAYS read the security bulletin on a virus. Just cleaning and deleting a reference in the startup registry won't do. Many of the new ones (like this one) back themselves up and restore themselves from a safe place when you reboot.

When it's a complex virus there's usually a free removal tool available (like this one). Follow the instructions with the removal tool explicitly - in the case of ME and XP you must disable System Restore before using the tool for example, and most of these viruses will restore themselves from network shared so you usually need to disconnect the computer from the network.

virus

Posted: Tue Jul 15, 2003 9:18 pm
by grumpy 1
I have followed symantec s removal advice i can clean the thing up the way they explain and use there removal tool but when i go back on the net bam it reinfesyts the computer
From what i understand there is a file that connects to a opaserve server and when you go online it makes it trigger again but im dammed if i can find such a file

Grrr