Author Topic: Eeeks! Should I Be Concerned?  (Read 2998 times)

0 Members and 1 Guest are viewing this topic.

as400

  • Guest
Eeeks! Should I Be Concerned?
« on: October 12, 2004, 01:45:40 PM »
PC seems to have been losing its connection A LOT recently, have a 2mb ADSL with Nildram, the orange dot in taskbar says connected but any page I go to is 'not available'.

Scanned with Avast but found nothing, scanned with Trends free on line service and it found

WORM AGOBOT.XM in  E/WIN/SYS32/UPC32.EXE

not removalable!

Is this causing my loss of connection issues every 40 min utes and PC lock ups?...any clues on how to rid the nasty worm and why doesnt Avast pick it up?!! :-[

Offline RejZoR

  • Polymorphic Sheep
  • Serious Graphoman
  • *****
  • Posts: 9406
  • We are supersheep, resistance is futile!
    • RejZoR's Flock of Sheep
Re:Eeeks! Should I Be Concerned?
« Reply #1 on: October 12, 2004, 01:54:22 PM »
Recently there has been many Agobot variants so its posible that avast! misses certain one. I recommend you to manually delete the file in Safe-Mode. Id also like you to send the copy of sample to avast! virus gurus, so they'll add it to definitions.
Visit my webpage Angry Sheep Blog

as400

  • Guest
Re:Eeeks! Should I Be Concerned?
« Reply #2 on: October 12, 2004, 01:56:23 PM »
OK  remove it yes, good, but Trend said it wasn't removable?..how do I remove it in 'safe mode'?...excuse my dumbness!...and then how do I send it to Avast?...isn't that dodgy?

Cheers!... :-\
« Last Edit: October 12, 2004, 02:01:17 PM by as400 »

Offline Eddy

  • Avast Evangelist
  • Maybe Bot
  • ***
  • Posts: 31079
  • Watching (over?) you
    • Malware removal, Biljart and other things.
Re:Eeeks! Should I Be Concerned?
« Reply #3 on: October 12, 2004, 03:08:11 PM »
- Boot in safe mode
- Put the file in a password protected zip
- send it to virus@avast.com (mention in the mail you think it is infected and the password)
- Delete both the original as well as the zip from your system
- Reboot

It is reported as "not removable" because it is in use. Safe mode only loads things really needed for the system to work at a minumum, so that file shouldn't be in use and you can delete it.
« Last Edit: October 12, 2004, 03:12:49 PM by Eddy »