Calum wrote:
> I think the problem is to do with a file called mypic.scr I was sent
> via MSN Messenger. I accepted it before knowing what it was and this
> must have caused all the trouble.
>
> I have done a bit of research and this mypic.scr is linked to the
> W32.Yaha worm. So I downloaded the tool to fix it but it failed to
> find the worm on my computer. I don't know what to do now as all the
> symptoms of this worm are there (XP firewall, Task Manager, regedit,
> System Restore, command prompt all disabled), but it says that I
> don't have this worm!
>
> Can anyone suggest what else I can do???
Don't you have a full-featured antivirus installed? Apparently not, or
if you do perhaps it is an older version and the subscription has
expired. The W32.Yaha worm is old and there are many new worms out,
including the MSN messenger worm. The tool you downloaded is specific
and won't clean anything but the old worm it was written to remove.
If my assumptions about your antivirus status are correct, start
cleaning up with TrendMicro's Sysclean after deleting all Temporary and
Temporary Internet files:
TrendMicro's Sysclean is an extensive antivirus tool which has the
advantage of not needing to be installed. It requires two parts - the
scanning engine and the virus pattern files.
1. Create a new folder on your Desktop or the C: drive named something
useful like "Sysclean".
2. Go here and download the two parts of the program to that folder:
<a rel="nofollow" style='text-decoration: none;' href="http://www.trendmicro.com/download/dcs.asp" target="_blank">http://www.trendmicro.com/download/dcs.asp</a> - Sysclean
<a rel="nofollow" style='text-decoration: none;' href="http://www.trendmicro.com/download/pattern.asp" target="_blank">http://www.trendmicro.com/download/pattern.asp</a> - virus pattern files
The pattern files will be zipped - extract them with your unzipper (like
WinZip) or if you have XP, you can just open the folder. You need to
put the extracted files in the Sysclean folder you made.
3. Restart your computer in Safe Mode. Get into Safe Mode by repeatedly
tapping the F8 key as the computer is starting up to get to the proper
menu.
4. Go to the Sysclean folder you made and double-click on sysclean.com.
Start the scan. After the scan is finished, look at the log. You may
need to make a note of where any viruses were found if they were not
able to be removed so you can manually delete them.
After your scan with Sysclean, get a full-featured av, install it,
update it, and do a thorough scan in Safe Mode. And practice Safe Hex
in the future.
Malke
--
MS MVP - Windows Shell/User
Elephant Boy Computers
<a rel="nofollow" style='text-decoration: none;' href="http://www.elephantboycomputers.com" target="_blank">www.elephantboycomputers.com</a>
"Don't Panic!"
>> Stay informed about: Cannot enable firewall!