Question about Acer TravelMate 2300 Notebook

2 Answers

Worm Autolt Super AnitSpyware and AVG only detect the infected files and delete it. The original worm still remains. Everytime i run AntiSpyware and AVG,they detect files but are undable to delete the worm causing this.Please help!

Posted by on

2 Answers

  • Level 2:

    An expert who has achieved level 2 by getting 100 points

    MVP:

    An expert that got 5 achievements.

    Novelist:

    An expert who has written 50 answers of more than 400 characters.

    Scholar:

    An expert who has written 20 answers of more than 400 characters.

  • Expert
  • 151 Answers

Spyware removal utility of the spyware remover tools is the best effective and only viable solution to get rid o the deadly spywares. Spywares are malicious programs that are spread through the freeware and shareware programs and through peer to peer file transfers. Spywares are hidden in these apparently harmless and attractive free downloads. When you download and install these programs the spywares are also installed in your computer. As the spywares are different from the computer viruses they are not even detected by anti virus software and the user is not even aware of the spyware in his or her computer.

Posted on Jan 20, 2012

  • Level 2:

    An expert who has achieved level 2 by getting 100 points

    Hot-Shot:

    An expert who has answered 20 questions.

    Corporal:

    An expert that has over 10 points.

    Mayor:

    An expert whose answer got voted for 2 times.

  • Expert
  • 51 Answers

Take the backup.Format the "c" drive.Load os and install a legal copy of antivirus with anti spyware.update regularly.

Posted on Jul 08, 2008

1 Suggested Answer

6ya6ya
  • 2 Answers

SOURCE: I have freestanding Series 8 dishwasher. Lately during the filling cycle water hammer is occurring. How can this be resolved

Hi,
a 6ya expert can help you resolve that issue over the phone in a minute or two.
best thing about this new service is that you are never placed on hold and get to talk to real repairmen in the US.
the service is completely free and covers almost anything you can think of (from cars to computers, handyman, and even drones).
click here to download the app (for users in the US for now) and get all the help you need.
goodluck!

Posted on Jan 02, 2017

Add Your Answer

Uploading: 0%

my-video-file.mp4

Complete. Click "Add" to insert your video. Add

×

Loading...
Loading...

Related Questions:

1 Answer

There are two folder namely desktop.ini, desktop.ini automatically appeared in the desktop. I scan my computer using Microsoft security Analysis but these folders are not moved or deleted from the desktop....


This must be a worm that replicates files/folders. As we all know, desktop.ini is not a folder, it's a system file which can be opened with Notepad.

What antivirus were you using to scan your computer? This worm/s can be easily detected and deleted/repaired by avg free (click here to download avg free). [open the link and click green "Download" button]

Download and install the Avg Free. Run a full system scan and check the result. That will fix the issue related to your desktop.ini folder etc..etc..

If you need further help, let me know.

Good luck.

Thanks for using FixYa.

Sep 22, 2010 | HP Computers & Internet

2 Answers

Laptop infected with worm? Help


No virus checker catches them all, and frankly, Norton 360 is pretty weak. Try running AVG, which is downloadable and free.

Dec 28, 2009 | HP Compaq Presario v3000z Notebook

1 Answer

I can't logon my toshiba portege m400 - s5032x a error message shows up saying Isass.exe application error the application failed to initialize properly (0xc0000005). Click on ok to terminate the...


Your system is infected by Sasser worm.The Sasser worm infects machines via network connections. It can attack entire networks of computers or one single computer connected to the Internet. The worm exploits a known windows vulnerability that is easily patched, however few systems seem to have this patch installed. It attacks Windows 2000 and Windows XP machines along with Windows NT and Windows Server 2003.


The patch from Microsoft known as the MS04-011 Security Update fixes the following vulnerabilities:
LSASS Vulnerability 
LDAP Vulnerability 
PCT Vulnerability 
Winlogon Vulnerability 
Metafile Vulnerability 
Help and Support Center Vulnerability 
Utility Manager Vulnerability 
Windows Management Vulnerability 
Local Descriptor Table Vulnerability 
H.323 Vulnerability 
Virtual DOS Machine Vulnerability 
Negotiate SSP Vulnerability 
SSL Vulnerability 
ASN.1 “Double-Free” Vulnerability 

Download the Windows patches for this vulnerability.Here is the link below:

http://www.microsoft.com/technet/security/bulletin/ms04-011.mspx



How Can I Remove the Sasser worm?

Follow these steps in removing the Sasser worm.

1) Disconnect your computer from the local area network or Internet

2) Terminate the running program
Open the Windows Task Manager by either pressing CTRL+ALT+DEL, selecting the Processes tab or selecting Task Manager and then the process tab on WinNT/2000/XP machines.
Locate one of the following programs (depending on variation), click on it and End Task or End Process

avserve.exe
avserve2.exe
skynetave.exe
any process running with the "_up.exe" suffix
Close Task Manager

3) Activate the Windows XP Firewall (if running Windows XP) or another firewall to prevent the worm from shutting your system down while downloading the patches. To activate the Windows XP firewall, follow these steps.
Click on Start, Control Panel
Double-click on Networking and Internet Connections, then click on Network Connnections
Right-click on the connection you use to access the Internet and choose Properties
Click on the Advanced Tab and check the box
"Protect my computer and network by limiting or preventing access to this computer from the Internet"
Click OK and close out of the Network and Control Panel

4) Remove the Registry entries
Click on Start, Run, Regedit
In the left panel go to 

HKEY_LOCAL_MACHINE>Software>Microsoft>Windows>Current Version>Run
In the right panel, right-click and delete the following entry

"avserve.exe"="%Windir%\avserve.exe"
"avserve2.exe"="%Windir%\avserve2.exe"
"skynetave.exe"= "%Windows%\skynetave.exe"
Close the Registry Editor

5) Delete the infected files (for Windows ME and XP remember to turn off System Restore before searching for and deleting these files to remove infected backed up files as well)
Click Start, point to Find or Search, and then click Files or Folders.
Make sure that "Look in" is set to (C:\WINDOWS).
In the "Named" or "Search for..." box, type, or copy and paste, the file names:

avserve.exe
avserve2.exe
skynetave.exe
C:\win2.log
Click Find Now or Search Now.
Delete the displayed files.
Empty the Recycle bin

6) Reboot the computer and update your antivirus software, and run a thorough virus scan using your favorite antivirus program.

For Automatic Removal of Sasser, download the Symantec removal tool, you'll still need to download the patches above and install them, however this removal tool will stop the Sasser worm from running, remove the items in the registry, and delete the infected files.

Dec 27, 2009 | Toshiba Portege M400-S5032X Tablet PC

2 Answers

Net-worm.win32.kido.ih virus free removal required


Have you tried AVG antivirus webpage? They have a free version of their software, 100% usable at :

http://download.cnet.com/AVG-Anti-Virus-Free-Edition/3000-2239_4-10320142.html?part=dl-10044820&subj=dl&tag=button&cdlPid=11014801

Per their website, there is the following info on your worm:
The first version of this virus which is recognized by AVG as Downadup (alternativelly I-Worm.Generic) has been detected at the end of November / begining of December, 2008. Currently there are over 300 unique versions of this virus. AVG detects and protects against all known variants of the worm.
Hope it takes care of it. If not let me know and I'll help you with fixing it so AVG does its job.

Oct 09, 2009 | Computers & Internet

1 Answer

Worm.win32.autorun.blw virus appear in my system i already use kesper sky, but not solved. please advise a solution. thanx


When the executable is run on the victim's machine, the worm copies itself to the following locations:
  • %Application Data%\remove.exe (Copy of itself)
  • %Application Data%\autorun.inf
Where %Application Data% = c:\Documents and Settings\All Users\Application Data
Autorun.inf has following command
Exp: [autorun]
shellExecute=remove.exe
The worm adds a Run entry in registry so that it executes itself at every startup:
  • HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run
    "(Default)" = "%Application Data%\remove.exe"
Symptoms -
  • Presence of above mentioned files.
  • Presence of registry entries mentioned above.
Method of Infection Method of Infection - This worm spreads by using autorun.inf on shared drives and removable devices.
Removal - A combination of the latest DATs and the Engine will be able to detect and remove this threat. AVERT recommends users not to trust seemingly familiar or safe file icons, particularly when received via P2P clients, IRC, email or other media where users can share files.


Thanks for using fixya..

Sep 14, 2009 | Computers & Internet

1 Answer

Avg update failed earlier today and then had issue w/ avg so looking at solutions I uninstalled avg, adware anniversity sw usede agv remover and that didn't help. So I keeping getting one the the 3 files...


You may want to look into this. This may be your issue with AVG anti virus. The Conficker worm mostly spreads across networks. If it finds a vulnerable computer, it turns off the automatic backup service, deletes previous restore points, disables many security services, blocks access to a number of security web sites and opens infected machines to receive additional programs from the malware’s creator. The worm then tries to spread itself to other computers on the same network.

Apr 05, 2009 | Computers & Internet

2 Answers

Something is changing icons shape and left double click does work


It seems like a worm more or less a along vir detail below - you wlll have to scan and remove it using a good antivirus program:
Virus Profile: W32/Xiaoho.worm Name: W32/Xiaoho.worm Risk Assessment - Home Users: Low-Profiled - Corporate Users: Low-Profiled Date Discovered: 8/1/2007 Date Added: 8/1/2007 Origin: N/A Length: Varies Type: Virus SubType: Worm DAT Required: 5088
Virus Characteristics -- Update August 18, 2007 --
The risk assessment of this threat has been updated to Low-Profiled due to media attention at:
http://shanghaiist.com/2007/08/17/vicious_new_chi.php
To receive an extra.dat file for this threat please visit: https://www.webimmune.net/extra/getextra.aspx
This detection is for a worm which tries to copy itself to removable drives. It will destroy systems it's used on by infecting all .exe files and changing their icons to the Chinese character HAO.
Upon execution, the worm drops a copy of itself into the Windows System folder:
  • %SysDir%\exloroe.exe
The worm creates the following registry keys to activate itself:
  • HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Active Setup\Installed Components\{H9I12RB03-AB-B70-7-11d2-9CBD-0O00FS7AH6-9E2121BHJLK}\: "ïµí³éèöã"
  • HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Active Setup\Installed Components\{H9I12RB03-AB-B70-7-11d2-9CBD-0O00FS7AH6-9E2121BHJLK}\stubpath: "%SystemRoot%\system32\exloroe.exe"
It spreads by dropping files named autorun.inf and xiaohao.exe on removable drives and setting file attributes as hidden.
The worm infects .exe files by overwriting them or corrupting them beyond repair. This changes their icon to Chinese word HAO.
ico142876.jpg and changes active window title as "X14o-H4o":

Apr 21, 2008 | Computers & Internet

6 Answers

How can i remove virus worm/autoit permanently


its simple guys..!!!
if it asks for permission to access outlook..don't permit it because it is a smart virus and is going to spread it to all the people on your contact list...!!!
simply open task manager and end process tree of KHATRA.exe , gHost.exe , xplorer.exe and OUTLOOK.exe seperately...!!
then run your anti virus or download one if you don't have one..!!!
run a complete computer scan in detail..!!
then delete all files which are infected by the virus because the results contain only duplicate files which are created by the virus

Feb 04, 2008 | Acer TravelMate 2300 Notebook

1 Answer

A Virus problem


Turn off system restore and try running AVG in safe mode as this stops any trojans from running, hence stopping any removal of the file. When the trojan has been deleted turn system restore back on.

Sep 21, 2007 | Symantec Norton AntiVirus 2004 - (Open...

Not finding what you are looking for?
Computers & Internet Logo

Related Topics:

206 people viewed this question

Ask a Question

Usually answered in minutes!

Top Acer Computers & Internet Experts

Les Dickinson
Les Dickinson

Level 3 Expert

18386 Answers

Mohammed Ebrahim M
Mohammed Ebrahim M

Level 3 Expert

586 Answers

Steve Sweetleaf
Steve Sweetleaf

Level 3 Expert

1144 Answers

Are you an Acer Computer and Internet Expert? Answer questions, earn points and help others

Answer questions

Manuals & User Guides

Loading...