xstash
asked on
WORM.WIN32.LADEX
NEED TO GET RID OF WORM.WIN32.LADEX. NORTON CAN'T FIND AND DESTROY
Also check using these online scanners
online virus scanner:
---------------------
http://housecall.trendmicro.com/
http://security.symantec.com/
http://www.pandasoftware.com/activescan/com/activescan_principal.htm
http://www.pcpitstop.com/antivirus/default.asp
online virus scanner:
---------------------
http://housecall.trendmicro.com/
http://security.symantec.com/
http://www.pandasoftware.com/activescan/com/activescan_principal.htm
http://www.pcpitstop.com/antivirus/default.asp
Hi xstash,
Have you followed Norton guide to removal:
http://www.symantec.com/avcenter/venc/data/w32.dalbug.worm.html
Have you followed Norton guide to removal:
http://www.symantec.com/avcenter/venc/data/w32.dalbug.worm.html
sunray_2003,
Ba hum bug, you beat me to it, same link too! ;-)
Ba hum bug, you beat me to it, same link too! ;-)
What90,
> Ba hum bug, you beat me to it, same link too!
Not a problem
> Ba hum bug, you beat me to it, same link too!
Not a problem
Protect your pc in the future with a firewall...
Getting a personal Firewall
http://www.zensecurity.co.uk/default.asp?URL=personal
Download the free version of Sygate personal firewall
http://smb.sygate.com/support/documents/spf/default.htm
http://smb.sygate.com/download/download.php?pid=spf
Download the free version of ZoneAlarm firewall
http://www.zonelabs.com/store/content/company/zap_za_grid.jsp?lid=ho_za
Comparative reviews of personal firewall software:
http://www.firewallguide.com/software.htm
Firewall Product Selector - Choose yourself which one to compare
http://www.spirit.com/cgi-new/report.pl?dbase=fw&function=view
Getting a personal Firewall
http://www.zensecurity.co.uk/default.asp?URL=personal
Download the free version of Sygate personal firewall
http://smb.sygate.com/support/documents/spf/default.htm
http://smb.sygate.com/download/download.php?pid=spf
Download the free version of ZoneAlarm firewall
http://www.zonelabs.com/store/content/company/zap_za_grid.jsp?lid=ho_za
Comparative reviews of personal firewall software:
http://www.firewallguide.com/software.htm
Firewall Product Selector - Choose yourself which one to compare
http://www.spirit.com/cgi-new/report.pl?dbase=fw&function=view
Also protect your pc against spyware
Spybot:
http://security.kolla.de/index.php
Ad-aware Standard Edition is THE award winning, free*, multicomponent adware detection and removal utility:
http://www.lavasoft.de/software/adaware/
SpyFerret detects & removes spyware
http://www.onlinepcfix.com/spyware/spyware.htm
Bazooka Adware and Spyware Scanner v1.13.01
http://www.kephyr.com/spywarescanner/
Automatic check of your browser for parasites, adware and spyware
http://www.doxdesk.com/parasite/
Spybot:
http://security.kolla.de/index.php
Ad-aware Standard Edition is THE award winning, free*, multicomponent adware detection and removal utility:
http://www.lavasoft.de/software/adaware/
SpyFerret detects & removes spyware
http://www.onlinepcfix.com/spyware/spyware.htm
Bazooka Adware and Spyware Scanner v1.13.01
http://www.kephyr.com/spywarescanner/
Automatic check of your browser for parasites, adware and spyware
http://www.doxdesk.com/parasite/
ASKER
All solutions recommended were tried before I came to experts exchange. I can't remove symantec sugested files.
I need something new.
I need something new.
According to your question , you have said that Norton cannot find.
Is it finding the files now ?
what happens after you try using the removal instructions given in the link ? After rebooting the machine are the files still present or are the files being shown as virus by norton ..
May be that virus has disabled norton from removing them .. Could be the case. What you can do is try removing norton completely from the system, reinstall it and check if it would work
http://service1.symantec.com/SUPPORT/nav.nsf/docid/2001092114452606
What OS are you in ?
Can you not go directly to that file and delete it ?
Is it finding the files now ?
what happens after you try using the removal instructions given in the link ? After rebooting the machine are the files still present or are the files being shown as virus by norton ..
May be that virus has disabled norton from removing them .. Could be the case. What you can do is try removing norton completely from the system, reinstall it and check if it would work
http://service1.symantec.com/SUPPORT/nav.nsf/docid/2001092114452606
What OS are you in ?
Can you not go directly to that file and delete it ?
ASKER
ANSWER:
I HAVE RUN NORTON AND IT DOES NOT IDENTIFY LMHSVC.EXE, SMSS.EXE, LADY.EXE, CSRSS.EXE AS A TROJAN OR VIRUS.
I HAVE FOLLOWED SYMANTEC SECURITY RESPONSE AND RE-BOOTED IN SAFE MODE WITH SYSTEM RESTORE OFF.
SMSS AND CSRSS DO NOT PERMIT "ENDING PROCESS" IN TASK MANAGER. PROIROTY IS NORMAL AND HIGH RESPECTIVELY AND CAN NOT BE CHANGED.
RENAMING THRU DOS (OR WINDOWS) OR CHANGING ATTRIBUTES EITHER IS NOT PERMITTED OR RESULTED IN A NEW FILE BEING CREATED IN 30 SECONDS.
ACCORDING TO SYMANTIC THIS BUGGER MESSES WITH THE REGISTRY AND DELETES ITSELF IF IT SEES REGEDIT RUNNING
ONCE REGEDIT IS CLOSED IT GOES BACK IN AND RECREATES THE REGISTRY ENTRIES AGAIN.
THERE IS MORE INFO ON SYMANTEC'S SITE UNDER W32.DALBUG.WORM.
YOU CAN TRULY GO MAD.
I HAVE RUN NORTON AND IT DOES NOT IDENTIFY LMHSVC.EXE, SMSS.EXE, LADY.EXE, CSRSS.EXE AS A TROJAN OR VIRUS.
I HAVE FOLLOWED SYMANTEC SECURITY RESPONSE AND RE-BOOTED IN SAFE MODE WITH SYSTEM RESTORE OFF.
SMSS AND CSRSS DO NOT PERMIT "ENDING PROCESS" IN TASK MANAGER. PROIROTY IS NORMAL AND HIGH RESPECTIVELY AND CAN NOT BE CHANGED.
RENAMING THRU DOS (OR WINDOWS) OR CHANGING ATTRIBUTES EITHER IS NOT PERMITTED OR RESULTED IN A NEW FILE BEING CREATED IN 30 SECONDS.
ACCORDING TO SYMANTIC THIS BUGGER MESSES WITH THE REGISTRY AND DELETES ITSELF IF IT SEES REGEDIT RUNNING
ONCE REGEDIT IS CLOSED IT GOES BACK IN AND RECREATES THE REGISTRY ENTRIES AGAIN.
THERE IS MORE INFO ON SYMANTEC'S SITE UNDER W32.DALBUG.WORM.
YOU CAN TRULY GO MAD.
ASKER CERTIFIED SOLUTION
membership
This solution is only available to members.
To access this solution, you must be a member of Experts Exchange.
SOLUTION
membership
This solution is only available to members.
To access this solution, you must be a member of Experts Exchange.
> WORM.WIN32.LADEX
possibly you are having this worm which is also knows as ladex
check the removal instructions here
http://www.symantec.com/avcenter/venc/data/w32.dalbug.worm.html
Thanks