Results 1 to 3 of 3

Thread: Advice needed re polymorphic worm

  1. #1
    Member Member Mumu Champion Prodigal's Avatar
    Join Date
    Oct 2002
    Location
    UK
    Posts
    578

    Default Advice needed re polymorphic worm

    Hi, was wondering if anyone could help please, I have a "exinjs" polymorphic worm on my PC & although I can block it from using my net access I can't find anything to get rid of it without fear or wrecking Windows.

    Can anyone please advise if there is a virus scanner that can rip this things still beating heart from my PC without killing my system?

    Tried Pest Patrol, PC-Cillin, McAffe, AdAware, Zone Alarm Pro.

  2. #2

    Default Re: Advice needed re polymorphic worm

    Quote Originally Posted by Prodigal
    Hi, was wondering if anyone could help please, I have a "exinjs" polymorphic worm on my PC & although I can block it from using my net access I can't find anything to get rid of it without fear or wrecking Windows.

    Can anyone please advise if there is a virus scanner that can rip this things still beating heart from my PC without killing my system?

    Tried Pest Patrol, PC-Cillin, McAffe, AdAware, Zone Alarm Pro.
    I'm pretty sure CCleaner gets rid of exinjs. Download it from here, install it and run a full scan and fix all problems: http://www.ccleaner.com/download/

    If that doesn't work then I'm sure we can clean it up using Hijack this and some other methods.

    Regardless of whether it works or not you'll still need to download HijackThis from here so that I can check that the malware has been completely removed (ignore the commerical ads on the site):

    http://www.majorgeeks.com/download3155.html

    Extract HijackThis.exe to C:\Hijackthisxyz\

    Rename HijackThis.exe to Hijackthis1991.exe

    Run HijackThis and do a full scan and save a log. Post up the full log here, don't do anything yet. Please IGNORE any advice from other posters as to what to delete or remove. You can seriously mess up your system by deleting the wrong thing from HijackThis. HijackThis is not an anti-spyware scanner. Not everything in your log is spyware, some things are critical, so you need to be careful and not delete anything until it's been positively identified.

    Do this after you have tried to fix the problem with CCleaner

    Good luck with that.

    Manco

    Edit: If CCleaner doesn't work for you, remove PCcillin, Mcafee and Pest Patrol and install the programs on this page: https://forums.totalwar.org/vb/showp...2&postcount=21

    Run full scans with those programs, after updating them, and fix all problems. If that fails try the manual method:

    Spoiler Alert, click show to read: 
    Run HijackThis and search the log for these two entries:

    O4 - HKLM \. \ Run: [.nvsvc] C:\WINDOWS\system\smss.exe /w

    O23 - Service: Windows Log - Unknown to owner - C:\WINDOWS\system32\nvsvcd.exe
    Start -> run -> "services.msc" and click in OK.

    look in the services for "Windows Log", right click -> Properties, Startup type Disabled, and Stop it.

    Open HijackThis and click Misc Tools -> Delete an NT service.

    Delete: "Windows Log" and OK, DO NOT RESTART.

    Reboot into safe mode, (hit F8 repeatedly just before WinXP starts to boot and browse to "C:\WINDOWS\system\" and delete "smss.exe"

    Browse to "C:\WINDOWS\system32\" delete "nvsvcd.exe"

    Scan with the HijackThis again fix, the above quoted problems.

    Close HijackThis and run CCleaner again. This will remove temp files left behind by the malware.

    Restart normally. Run HijackThis again and post up the log file here.
    Last edited by caravel; 12-05-2006 at 16:51.
    “The majestic equality of the laws prohibits the rich and the poor alike from sleeping under bridges, begging in the streets and stealing bread.” - Anatole France

    "The law is like a spider’s web. The small are caught, and the great tear it up.” - Anacharsis

  3. #3
    The very model of a modern Moderator Xiahou's Avatar
    Join Date
    Aug 2002
    Location
    in the cloud.
    Posts
    9,007

    Default Re: Advice needed re polymorphic worm

    Try SwatIT. As I've said, I had luck with it before- but haven't used it in quite awhile.
    "Don't believe everything you read online."
    -Abraham Lincoln

Bookmarks

Posting Permissions

  • You may not post new threads
  • You may not post replies
  • You may not post attachments
  • You may not edit your posts
  •  
Single Sign On provided by vBSSO