Thank you for being a valued part of the CNET community. As of December 1, 2020, the forums are in read-only format. In early 2021, CNET Forums will no longer be available. We are grateful for the participation and advice you have provided to one another over the years.

Thanks,

CNET Support

General discussion

W32 Spybot Worm

Dec 4, 2003 1:28PM PST

HELP ME!!

W32 SpyBot Worm ... detected and deleted by Norton 2003

file name open_me.exe

Problem... AND ITS A BIG ONE

this virus had been plauging me for 3 weeks .. then I got mad and tried to rid my self of it

so I got more pissed and FORMATTED MY COMPUTER

sure enough after getting all my basics installed I setup my DSL

not 20 mins later norton said the spybot was BACK

help me out

please

savvy

Mystery

(send mail to the_mr_mystery@hotmail.com (subject VIRUS HELP)) thanks

Discussion is locked

- Collapse -
Re:W32 Spybot Worm
Dec 4, 2003 11:30PM PST

Are you using KaZaa or IRC??

W32.Spybot.Worm
Discovered on: April 16, 2003
Last Updated on: October 08, 2003 01:46:53 PM

W32.Spybot.Worm is a detection for a family of worms that spreads using KaZaA file-sharing and mIRC. This worm can also spread to computers infected with common Backdoor Trojan Horses.

W32.Spybot.Worm can perform different backdoor-type functions by connecting to a configurable IRC server and joining a specific channel to listen for instructions.

Note: The October 8, 2003 virus definitions contain a modified W32.Spybot.Worm detection which accounts for a minor variation discovered on October 7, 2003.


Also Known As: Worm.P2P.SpyBot.gen [KAV], W32/Spybot-Fam [Sophos], W32/Spybot.worm.gen [McAfee], WORM_SPYBOT.GEN [Trend], Win32.Spybot.gen [CA]

Type: Worm

Removal instructions here:

http://securityresponse.symantec.com/avcenter/venc/data/w32.spybot.worm.html

- Collapse -
Re:W32 Spybot Worm
Dec 5, 2003 5:50AM PST

Themr,

Things like...the operating system, processor speed, etc. are sure helpful

After cleaning the machine with the info from Marianna's post above, there are some other steps that you can take that should help:

First, if you aren't running on a LAN (network), then you don't need to have a network service called "File and Printer Sharing" installed. It allows the "hole" whereby the infected files are being transferred to your computer. If you are on a LAN, then you need to create a password for your shared drives. If you are not on a network, please uninstall "File and Printer Sharing" like this:

Windows 9.x/ME: Click on Start-Settings-Control Panel, double click on the "Network" icon. When that loads, on the "Configuration" tab, look in the white network components section and click once on the "File and Printer Sharing for Microsoft Networks" to highlight it, then click on the "Remove" button and follow the prompts to remove the service.

Windows 2000/XP: Click on Start-Settings-Control Panel, (or Start-Control Panel in XP), then double click on the "Networks and Dial Up Connections" icon, then find your type of connection type being used currently, either "Local Area Network" or "Dial-Up", then RIGHT click on it, choose "Properties". You should then be able to see the network components that are installed on the computer. If "File and Printer Sharing for Microsoft networks" is listed, click once on it to highlight it, then click on the "remove" button.

Next, download, install and run the free spyware removal tool below:

?Spybot Search & Destroy? Spyware Removal Tool