Assistance please?

Discussion in 'Malware Help - MG (A Specialist Will Reply)' started by theyellowdart, May 17, 2004.

  1. theyellowdart

    theyellowdart Private E-2

    Can anyone assist me with removal of a worm called "ronoper"? I found a way to rid of it from my registry, however, when I looked on my registry, it was not there. I know it is there, because my virus scan picks it up, but can not seem to completely rid of it. I am having quite the difficult time here and would really appreciate assistance.

    I downloaded and used the program Hijack this, however, I dont' know what to delete or not, and didn't see a thread/forum on this subject.

    Thank you.
     
  2. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    HiJaak This is not for virus removal. Which OS are you running and what is the name of your virus scan program? You could try downloading and running Avast from here: http://www.majorgeeks.com/download1968.html

    Checkout this info from Symantec: http://securityresponse.symantec.com/avcenter/venc/data/w32.ronoper.worm.html
     
  3. theyellowdart

    theyellowdart Private E-2

    My OS is Windows XP Pro. and my virus scan is unfortunately McAfee Pro 7.5
     
  4. Major Attitude

    Major Attitude Co-Owner MajorGeeks.Com Staff Member

    Would not stay connected to the net too much longer:

    W32.Ronoper.Worm will try to terminate the processes of several antivirus programs. It also sends user information such as you user name, nickname, password, and IP address to a specified Web site. W32.Ronoper.Worm is written in Delphi and uses ICQ to spread.

    Try a small removal tool maybe like Mcaffee Stinger in our anti virus section. I think what chaslang was trying to point out is the instructions, most importantly, is your Mcafee up to date with its virus definitions? Mcaffees page reads the same, update definitions, disable system restore:

    http://vil.nai.com/vil/content/v_100675.htm
     
  5. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    That's exactly what I was trying to do Major. And now since we know that McAfee is the virus scanner and you have given the link to McAfee's page, theyellowdart should see that the minimum virus definitions required is 4266 which is quite old (meaning this is a relatively old virus).

    Yellowdart, What definitions version were you running.
     
  6. Major Attitude

    Major Attitude Co-Owner MajorGeeks.Com Staff Member

    Agreed! Problem is a lot of people get these 90 day subscriptions and think they have free antivirus and are protected, so it never hurts, like now, to remind people, your antivirus is only as good as its updates and thats what they charge you for every year on average. I have seen anti virus programs YEARS out of date!
     
  7. theyellowdart

    theyellowdart Private E-2

    I have an updated virus scan, It updates itself almost daily, until It started showing this worm was active. I've used the symantec security response page and couldn't find it in the registry. I have used that online scan as well as a few other ones and it still has not detected it.

    Also, due to the fact that this is my first time on this site, I don't know where your 'anti-virus' section is. and I've looked for it. I'm not familar with every thread/message here so could you please link me to it?

    I'm having a really hard time getting rid of it and I want to make starting my Operating system over again the last and final card I have left.

    Thank you for your assistance.
     
  8. kevin18328

    kevin18328 Private E-2

    try rebooting in safe mode and then doing a virus scan.
     
  9. theyellowdart

    theyellowdart Private E-2

    I have already done a dos safe mode virus scan as well as the stinger scan. NOthing :( :( :(


    OKay, thanks.. I honestly though :( am having a really hard time..
     
  10. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    You previously said you are using McAfee. What is your scan engine version and what virus definitions version do you have?

    By the way WinXP safe mode is not dos safe mode, it is windows safe mode. Are you sure you booted to safe mode and performed a full system (scan all files) scan?
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds