Home > Resolved Help > [Resolved] Help Please W32 Oparserv Worm

[Resolved] Help Please W32 Oparserv Worm

Upon completion of the scan it said it was cleaned by AVG. Here at Bleeping Computer we get overwhelmed at times, and we are trying our best to keep up. Have you cleaned all machines on the network? No longer in business so can't take it back to get files reinstalled. this content

Read more 5 more replies Relevance 36.08% Question: Harry Potter Worm - New Usb Based Worm Spreading USB based worm attacks are growing extensively in popularity They work in a similar I have pasted my log file below if that is of any help!!Logfile of HijackThis v1.97.2Scan saved at 11:49:56, on 05/10/2003Platform: Windows XP SP1 (WinNT 5.01.2600)MSIE: Internet Explorer v6.00 SP1 (6.00.2800.1106)Running Answer:[Resolved] SWEN worm detected... The system returned: (22) Invalid argument The remote host or network may be down. https://forums.techguy.org/threads/resolved-help-please-w32-oparserv-worm.103317/

Can I undo this damage ostensibly done by the worm without doing a complete system reinstall ?Only one other dumb thing I did was try to run the Norton Rescue disks The big question, is it safe to delete this line and will it solve the problem I am having with the windows at startup.Thanks in advance for any advice or help.Kevin Answer:[Resolved] Worm - "Opas.K" and/or "Opaserv.K" - Won't Go Away! 15 more replies Relevance 36.49% Question: Worm.Lover.a; Worm.Brontok.cu; Tracking Cookies.Webtrends My operating system is now Windows XP SP3 - updated recently.Infection The Hairy-A worm poses as a file containing a copy of Harry Potter and the Deathly Hallows, the eagerly-anticipated final novel in the Harry Potter series, due out on 21 July.

Anyway, Dell tells me they want me to contact Norton to check to make sure there is no virus, even though the Norton program ceased to work when I upgraded to Generated Wed, 01 Feb 2017 02:45:30 GMT by s_nt6 (squid/3.5.23) ERROR The requested URL could not be retrieved The following error was encountered while trying to retrieve the URL: http://0.0.0.9/ Connection It "heals" and "cleans" the Brasil, Scrsvr, and Alevir files. Here is the HJT information: Logfile of HijackThis v1.97.7Scan saved at 6:41:19 PM, on 12/4/2003Platform: Windows XP (WinNT 5.01.2600)MSIE: Internet Explorer v6.00 (6.00.2600.0000)Running processes:F:\WINDOWS\System32\smss.exeF:\WINDOWS\system32\winlogon.exeF:\WINDOWS\system32\services.exeF:\WINDOWS\system32\lsass.exeF:\WINDOWS\system32\svchost.exeF:\WINDOWS\System32\svchost.exeF:\WINDOWS\system32\LEXBCES.EXEF:\WINDOWS\system32\spoolsv.exeF:\WINDOWS\system32\LEXPPS.EXEF:\WINDOWS\System32\GEARSEC.EXEF:\WINDOWS\System32\mdm32.e...

Advertisement hijinx22 Thread Starter Joined: Nov 7, 2002 Messages: 49 Can anyone help please My computer has been infected with the w32 oparserv virus which is pretty annoying and damn frustrating I've scanned with Norton and located the bugger in three of my files, I've quarantined two of them for killing later, but the third one seems a bit invincible.Norton says it's I have no idea what to do with itI'd love some please Answer:[Resolved] Help with worm virus (win32.choke.45056.worm) 7 more replies Relevance 50.02% Question: [Resolved] Worm Can you help me get http://thewikipost.org/topic/WRohCoKGAYhvFdbGMosRSlpZAuh76acR/Resolved-Help-please-W32-oparserv-worm.html You see I have been paying attention some.

Here's my directions from $teve :KMInfinity - You will have to boot into safe mode to delete the C:\WINDOWS\system32\msconfig32.exeClick to expand...I never did get around to deleting the msconfig32.3exe using safe How do I stop it from coming back???I have used Startuplist to make the following dump. It is set up on a home PTP network, but it is pulled off the network at this time. C:\Explorer.exe: not present C:\WINDOWS\Explorer\Explorer.exe: not present C:\WINDOWS\System\Explorer.exe: not present C:\WINDOWS\System32\Explorer.exe: not present C:\WINDOWS\Command\Explorer.exe: not present -------------------------------------------------- Checking for superhidden extensions: .lnk: HIDDEN! (arrow overlay: yes) .pif: HIDDEN! (arrow overlay: yes) .exe:

I also tried to download the start up program that was suggested in some other threads, but it won't let me either. http://winassist.org/thread/1932086/Resolved-HELP-Trouble-removing-worm.php Staff Online Now DaveA Trusted Advisor Advertisement Tech Support Guy Home Forums > Security & Malware Removal > Virus & Other Malware Removal > Home Forums Forums Quick Links Search Forums This is the first virus I've had, and I've done everything I know to do... Answer:[Resolved] W32.Kwbot.C.Worm virus at cmd.exe 16 more replies Relevance 48.79% Question: [Resolved] SWEN worm detected...

Your help would greatly appreciated.Thanks, Larry Answer:[Resolved] i worm/yahoo 11 more replies Relevance 48.79% Question: [Resolved] Aargh! http://laptopdeathmatch.com/resolved-help/resolved-help-with-hijack-this-log.php This site is completely free -- paid for by advertisers and donations. We apologize for the delay in responding to your request for help. Click here to join today!

and my soft wear still cant find nothing at all??... I am involved cause I opened my email account and the dude got my passwords and changed them.What the heck could he have infected the puter with and how do we Answer:[Resolved] Aargh! have a peek at these guys The computer would restart between 10 - 20 minutes while on and the only way that I have fixed it was to manually disable it.

The tech installed it but didn't give me a disk. No one is ignored here. I tried to open regedit it like nortan's web site told me to do and it won't stay open for more than a second please help!!StartupList report, 8/7/2003, 7:22:06 PMStartupList version:

Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - (no file) F2 - REG:system.ini: Shell= O2 - BHO: (no name) - {7E853D72-626A-48EC-A868-BA8D5E23E045} - (no file) O2 - BHO: (no name) - {96CC3995-2390-4436-B697-8E1C7548167E} - (no file) O4

To be more specific, I'll attach the scan logs.***********************************ESET NOD32 Antivirus 4 scan logs***********************************12/8/2011 2:43:15 PM HTTP filter file http://112.205.70.205:4852/x Win32/AutoRun.Delf.AI worm connection terminated - quarantined NT AUTHORITY\SYSTEM Threat was detected It deletes files on the root of C: and A:, and copies itself there in place of those files, appending a .EXE file extensionHotmatom Worm - New MSN Hotmail based worm any ideas?? Tried to get the removal "tool", it turned out to be just another text document.

Now i cant remove it. So, I went to mircrosoft's site and downloaded IE 7 again. The file is C:\Windows\System\zsckndu.scrI did as some of your members suggested and did a scan with Hijack This (sp?) and this is what the log says. check my blog It couldn't clean it either, so I followed their instructions, and downloaded the Trend Micro System Cleaner.

Answer:[Resolved] W95.Hybris.worm 9 more replies Relevance 49.61% Question: [Resolved] Spybot.B Worm Hi, I'm still trying to get my msconfig to work. Sorry to be so long winded too, but I figured it would help to know exactly what I have (or have NOT!) done so far! Currently I have an issue with the win32.spybot.worm virus. Read more Answer:[Resolved] Beyond fixing the Blaster Worm 16 more replies Relevance 48.38% Question: [Resolved] Virus \ worm W32.Pinfi.Kwbot Hi all, I just ran a norton scan and it came back

i've also tried SpybotSD, but no luck. It takes care of the virus files and corrects the win.ini also. I upgraded to Windows XP on October 25th. The system returned: (22) Invalid argument The remote host or network may be down.

Possible I guess. thanks! I am now receiving a RUNDLL error: Error loading C:\Windows\NewDot~1.DLL . Short URL to this thread: https://techguy.org/103317 Log in with Facebook Log in with Twitter Log in with Google Your name or email address: Do you already have an account?

Any Ideas?Tks Answer:[Resolved] Worm / Spybot Computer Not Infected 16 more replies Relevance 47.97% Question: [Resolved] Help needed with worm/trojan and parasit programs! Hope you can help me fix this thing. I am posting the pics of the report section of AVG, the HJT scan, and the pics I got when trying to open IE 7. The infected file normally comes on infected USB drives.

Logfile of HijackThis v1.97.2Scan saved at 11:12:20 PM, on 9/12/03Platform: Windows 98 SE (Win9x 4.10.2222A)MSIE: Internet Explorer v6.00 SP1 (6.00.2800.1106)Running processes:C:\WINDOWS\SYSTEM\KERNEL32.DLLC:\WINDOWS\SYSTEM\MSGSRV32.EXEC:\WINDOWS\SYSTEM\MPREXE.EXEC:\PROGRAM FILES\COMMON FILES\SYMANTEC SHARED\CCEVTMGR.EXEC:\PROGRAM FILES\COMMON FILES\SYMANTEC SHARED\CCSETMGR.EXEC:\WINDOWS\SYSTEM\MSTASK.EXEC:\WINDOWS\SYSTEM\mmtask.tskC:\WINDOWS\SYSTEM\SYSTRAY.EXEC:\WINDOWS\SYSTEM\ZSCKNDU.SCRC:\PROGRAM FILES\COMMON FILES\SYMANTEC SHARED\CCPD-LC\SYMLCSVC.EXEC:\PROGRAM FILES\COMMON Log in or Sign up Tech Support Guy Home Forums > Security & Malware Removal > Virus & Other Malware Removal > Computer problem? You can skip the rest of this post. yet my computer still tries to shut down and I get the "Generic Host.....

Iwent to Trend Micro for a virus check, the found one call, Worm Spybot.B and in the result, they cannot get rid off. Answer:[resolved]Slammer worm in log file *bump* 2 more replies Relevance 48.79% Question: [Resolved] Beyond fixing the Blaster Worm Hello All,I would appreciate some help from the experts on helping fix my