Democratic Underground Latest Greatest Lobby Journals Search Options Help Login
Google

HELP!!!!!! Virus: I love you my sweet sexy poooooh..........

Printer-friendly format Printer-friendly format
Printer-friendly format Email this thread to a friend
Printer-friendly format Bookmark this thread
This topic is archived.
Home » Discuss » The DU Lounge Donate to DU
 
aquart Donating Member (1000+ posts) Send PM | Profile | Ignore Sat Sep-18-04 01:02 AM
Original message
HELP!!!!!! Virus: I love you my sweet sexy poooooh..........
Anybody heard of this monster? I went to dinner, left my pc on, came back and found Norton Antivirus hysterically running a scan, begging me to delete some files which couldn't be quarantined, which I did. Then it told me I was still infected. I ran Update, installed new definitions (not that new, I only installed Antivirus 2002 two days ago)and rebooted. Oh, dear.

The first thing that was destroyed was my access to Norton Antivirus itself. This thing seems to have a special hatred for all my Symantec products. (Not unlike my feelings, just now.)

Anyway, the screensaver this disease gives me is light blue with I love you, my sweet sexy poooooh........ running across the screen. Anyone know what to do about it? I see reformatting in my future, don't I?

I know it's still doing damage, because it was running my hard drive like mad a while ago.

HELP!!!!!
Printer Friendly | Permalink |  | Top
will work 4 food Donating Member (184 posts) Send PM | Profile | Ignore Sat Sep-18-04 01:21 AM
Response to Original message
1. You must
unplug your computer immediately, take it outside away from the house (at least 30 feet). This is an exploding virus. Be berry careful. :argh:
Printer Friendly | Permalink |  | Top
 
4morewars Donating Member (1000+ posts) Send PM | Profile | Ignore Sat Sep-18-04 01:23 AM
Response to Original message
2. You have Yaha !
Or more precisely; W32.Yaha.AB@mm A nasty little trojan worm. The good news is:It can be fixed !!! It is not doing anymore "damage" (it sounds like it has already done it's damage) as you said, but it is a busy little fucker. No need to reformat, you should be able to handle the repair (I'm assuming,since you know how to reformat, you know a few things about "puters?) Go here and follow the instructions :

http://securityresponse.symantec.com/avcenter/venc/data/w32.yaha.ab@mm.html

Make some coffee, good luck !!!

PS: Ever heard of LINUX ?
Printer Friendly | Permalink |  | Top
 
aquart Donating Member (1000+ posts) Send PM | Profile | Ignore Sat Sep-18-04 02:24 AM
Response to Reply #2
5. Linux requires more knowledge than I yet have.
Printer Friendly | Permalink |  | Top
 
4morewars Donating Member (1000+ posts) Send PM | Profile | Ignore Sat Sep-18-04 02:44 AM
Response to Reply #5
8. LINUX is easier than you think !
The latest releases are more user friendly than in the past. But you can think about that tomorrow, right now you have other problems !!
Printer Friendly | Permalink |  | Top
 
aquart Donating Member (1000+ posts) Send PM | Profile | Ignore Sat Sep-18-04 02:25 AM
Response to Reply #2
6. Question?
This thing disabled Norton Antivirus. And Live Update. And Crash Guard. It won't load and it won't uninstall. Will the security response repair that damage?
Printer Friendly | Permalink |  | Top
 
aquart Donating Member (1000+ posts) Send PM | Profile | Ignore Sat Sep-18-04 02:37 AM
Response to Reply #6
7. I already screwed up.
The first thing I did when I got back online was download the intelligent updater stuff and install it. They CAUTION NOT to install it.

I'm screwed, right?
Printer Friendly | Permalink |  | Top
 
4morewars Donating Member (1000+ posts) Send PM | Profile | Ignore Sat Sep-18-04 02:50 AM
Response to Reply #7
9. No, you are not done yet !
This is what you need to do:
1. Download the updated virus definitions using the Intelligent Updater, but do not install them.
2. Restart the computer in Safe mode.
3. Copy the Regedit.exe file to Regedit.com.
4. Edit the registry and reverse the changes that the worm made.
5. Restart the computer in Normal mode.
6. Start your Symantec antivirus software. If it does not properly start or function, re-install it.
7. Install the Intelligent Updater virus definitions that you downloaded earlier.
8. Run a full system scan and delete the files that are detected as W32.Yaha.AB@mm and Keylogger.Trojan.


The security response will not do it for you, you have to do it manually. Near the bottom of the page you will find detailed instructions. Here is the link again:

http://securityresponse.symantec.com/avcenter/venc/data/w32.yaha.ab@mm.html
Printer Friendly | Permalink |  | Top
 
aquart Donating Member (1000+ posts) Send PM | Profile | Ignore Sat Sep-18-04 03:04 AM
Response to Reply #9
10. But...but...I INSTALLED when they told me NOT to. With a CAUTION.
I'm over there right now, copying everything by hand since I also can't use my printer which is a whole other installation problem.

Has anyone ever introduced a trouble free pc into their home? This one is second hand and there wasn't a clean install. I like some of the software I don't have disks to, so I didn't reformat. I may go insane over this.

BTW, I didn't thank you for your help: THANK YOU!!!!!!!!!!!!!
Printer Friendly | Permalink |  | Top
 
4morewars Donating Member (1000+ posts) Send PM | Profile | Ignore Sat Sep-18-04 03:23 AM
Response to Reply #10
11. Hey , you're welcome !
No problem, I have been down this road MANY times ! I know I could fix this for you in about 30 minutes, but you WILL learn from this, LOL !
I trust you will be MUCH more cautious in the future. Regarding that, pay attention to the section entitled "reccomendations" where they list "best practices"

To answer your question,"Has anyone ever introduced a trouble free pc into their home?"
YES ! MAC and LINUX are immune to this crap(with one or two MINOR exceptions, which have already been addressed)

PS: Luckily for you I have chronic insomnia ! I am in Michigan and I will be willing to talk you through this on the phone later today(saturday) if you run into any problems, but right now I think I will try to get some sleep, Peace, JOE
Printer Friendly | Permalink |  | Top
 
aquart Donating Member (1000+ posts) Send PM | Profile | Ignore Sat Sep-18-04 03:38 AM
Response to Reply #11
12. Sleep. Me, too.
I've copied the instructions, but I don't think you can talk me thru in safe mode. Thank you so much, though. I was in shock earlier. Now, just exhausted.

And if I ever, ever meet the little prick who did this..........

No jury would convict me.
Printer Friendly | Permalink |  | Top
 
aquart Donating Member (1000+ posts) Send PM | Profile | Ignore Sat Sep-18-04 10:44 AM
Response to Reply #11
13. You would talk to me on phone? That's so kind.
This afternoon I think I am going to risk getting stranded uptown by subway flooding and go for poll watcher training at Columbia.

But I wrote your DU id name on top of the Symantec instructions and you can expect to hear from me again.

Cripes, I just remembered I can't get email. The monster removed my Send Receive. Weird. Weird and evil. But I'll check back here for messages.
Printer Friendly | Permalink |  | Top
 
4morewars Donating Member (1000+ posts) Send PM | Profile | Ignore Sat Sep-18-04 12:20 PM
Response to Reply #13
14. You are from NYC ?????!!!!
I am from NYC too !! Born and raised there (and, later, the 'burbs) God, I miss ny, the ocean !!!, GOOD pizza !! Chinatown !!!! The subway is flooded? damn, that's nasty. Glad to hear you are going to be a poll watcher !!! I have been working with the Kerry campaigh here in Michigan, and I have met both Kerry and Edwards !!!
Anyway, we can use the PM function here on this board if we have to, I'm sure we can fix your 'puter !
Peace, JOE
Printer Friendly | Permalink |  | Top
 
ofrfxsk Donating Member (817 posts) Send PM | Profile | Ignore Sat Sep-18-04 01:33 AM
Response to Original message
3. A cold shower?
I dunno.
Printer Friendly | Permalink |  | Top
 
aquart Donating Member (1000+ posts) Send PM | Profile | Ignore Sat Sep-18-04 02:23 AM
Response to Reply #3
4. Welcome to DU.
Building up your post count?

Looking forward to seeing what else you have to say.
Printer Friendly | Permalink |  | Top
 
DU AdBot (1000+ posts) Click to send private message to this author Click to view 
this author's profile Click to add 
this author to your buddy list Click to add 
this author to your Ignore list Fri Apr 19th 2024, 06:30 AM
Response to Original message
Advertisements [?]
 Top

Home » Discuss » The DU Lounge Donate to DU

Powered by DCForum+ Version 1.1 Copyright 1997-2002 DCScripts.com
Software has been extensively modified by the DU administrators


Important Notices: By participating on this discussion board, visitors agree to abide by the rules outlined on our Rules page. Messages posted on the Democratic Underground Discussion Forums are the opinions of the individuals who post them, and do not necessarily represent the opinions of Democratic Underground, LLC.

Home  |  Discussion Forums  |  Journals |  Store  |  Donate

About DU  |  Contact Us  |  Privacy Policy

Got a message for Democratic Underground? Click here to send us a message.

© 2001 - 2011 Democratic Underground, LLC