AIM Virus/Worm Help

Discussion in 'Software' started by ANHEDONIC, Mar 10, 2004.

  1. ANHEDONIC

    ANHEDONIC Will Title For Food

    my roommate got this virus via clicking on someone's AOL Instant Messenger Profile... i need a removal tool or manual removal instructions... Symantec's website only seems to have instructions for Norton AV users... any help is greatly appreciated....

    he's using Windows XP btw. thanks

    he's scanning his comp with his PC Cillin Anti-virus right now...

    also, this is NOT realphx, talkstocks, buddypicture, or the Osama WORM
     
    Last edited: Mar 10, 2004
  2. chi

    chi Private E-2

    try going to 'twocows' and downloading 'stinger'
     
  3. ANHEDONIC

    ANHEDONIC Will Title For Food

    thx for the link xflat but the scan did not find the virus
     
  4. Kodo

    Kodo SNATCHSQUATCH

    Chi, welcome to Major Geeks..

    www.majorgeeks.com has a gigantically enormous file section. Please check there first for files before sending people off to other websites.

    Thank you :)
     
  5. ANHEDONIC

    ANHEDONIC Will Title For Food

    btw fellas i'm not 100% sure this is the virus he has... but the file he downloaded was labeled:

    webcam.scr

    i tried googling it but it comes up listed under many different virus/worm names...
     
  6. ANHEDONIC

    ANHEDONIC Will Title For Food

    xflat he uses PC Cillin anti-virus... he did a full system scan and it found nothing... but his computer is definetely infected with something... his AOL Instant Messenger automatically puts up an away message for him that links to the download site for "webcam.src" which is hosted on an Angelfires account (odd)...

    when i google "webcam.src" i get links related to other virii/trojans but nothign that specifically mentions the file name... he's running stinger and trying this Bazooka spyware scanner right now... i will let u guys know if it finds anything...

    appreciate the insight though

    (btw, i'm only inquiring about this for him because he does not have a MG account and i seem to know the ropes around here a little better so i'm trying to help him out)

    also, he cannot get into Regedit or Ctrl-Alt-Dlt, so i'm having him boot into Safe Mode
     
    Last edited: Mar 10, 2004
  7. ANHEDONIC

    ANHEDONIC Will Title For Food

    xflat could you PM me the links to those forums where the problem was described because i'm not seeing them...

    i'm having him download and run Spybot right now... he already has Ad-Aware with the latest updates...
     
  8. ANHEDONIC

    ANHEDONIC Will Title For Food

    okay he updated and ran spybot search and destroy, it found 33 items and fixed them all, and the problem still persists...

    xflat i'm aware of the talkstocks, realphx, and buddypicture worms... this is definetely NOT it...

    the file was called webcam.src, and if he's not in safe mode, it prevents him from using Ctrl-Alt-Dlt to look at his running processes, and also prevents him from getting into regedit
     
  9. ANHEDONIC

    ANHEDONIC Will Title For Food

    true it's possible it was hosted on someone else's site as the website was an angelfires account... PC Cillin found nothing, that house cleaner found nothing, Ad-Aware did not find the 32 items that Spybot found and cleaned, i'll have him uninstall and reinstall AOL Instant Messenger right now...


    problem still persists :mad:
     
    Last edited: Mar 10, 2004
  10. Mr.Wolf

    Mr.Wolf Private First Class

    i had the link to the damn solution but i cant find it
    gimme a few
     
  11. Mr.Wolf

    Mr.Wolf Private First Class

  12. ANHEDONIC

    ANHEDONIC Will Title For Food

    appreciate the link Wolf, but i'm not sure this is related to realphx or any of those worms that add links to your profiles... this worm or whatever it is automatically puts up an away message for you and even tries to take action when you're exited out of AIM...

    although it's very possible that this is some variant of the realphx, talkstocks, buddypicture worm... i'm hoping as more people get infected with this a removal took or removal instructions will surface on the web....
     
  13. Mr.Wolf

    Mr.Wolf Private First Class

    alright sorry for the bum link.
    If i hear anything (which i do often) ill tell you
     
  14. KegMan51

    KegMan51 Private E-2

    The worm that is doing this is called w32.spybot.if By running the free virus/remover program Panda ActiveScan, it should find the worm and then remove it for you
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds