PDA

View Full Version : Damn Viruses.


Andy Murray
27-Jan-2004, 12:54 PM
I've got Win32/Shimg.Worm virus

Any ideas?

YODA
27-Jan-2004, 04:15 PM
Shimg is an alias for the MyDoom worm.

Here you go

http://www.sophos.com/support/disinfection/mydooma.html

Saz
27-Jan-2004, 04:22 PM
Another one? Blimey Andy...

If you need help, holler.

Andy Murray
27-Jan-2004, 04:23 PM
Hmm, say's I'm not infected

Ghost Frog
27-Jan-2004, 04:24 PM
Oh yeah, we've had those coming in droves today. Damn those ignorant customers of ours!!

Saz
27-Jan-2004, 04:28 PM
Originally posted by Andy Murray
Hmm, say's I'm not infected

You follow the instructions properly? Sometimes with those you need to boot into Safe Mode :D

What/who told you the virus was on your system? Some AV's can trigger false positives on certain files.

Andy Murray
27-Jan-2004, 05:52 PM
Got loads of emails from various peoples AV software quoting the virus.

Still haven't found safe mode either.

Saz
27-Jan-2004, 06:04 PM
Don't know why Safe Mode's not working for you. Is there an option in the shut down menu to boot into Safe Mode?

Shim/MyDoom is very new (and potentially high risk), its only been in the wild for 24 hours at the most as I understand. It spreads via email and kazaa. Its got a Keylogger too, so you may want to change vital passwords. It also has its own SMTP server, which in English, means it can make the email look like it came from anywhere, so you may not have it at all, it may just be stealing your address.

The main problem is, because its so new, AV's are having trouble picking it up. Update your AV software, even if you have, try again.

Try checking this page out too, it has some removal instructions. http://us.mcafee.com/virusInfo/default.asp?id=description&virus_k=100983#removal_instructions

YODA
27-Jan-2004, 08:40 PM
I use Sophos and they released their ide for it at lunchtime today!

Saz
27-Jan-2004, 08:43 PM
Apparently some of them are still on it! I don't see why really, its just a typical mass mailing variant of almost every other virus thats been released. I would think the main vendors would have it covered by now.