PDA

View Full Version : [Sumom A spyware -- can't get rid of]



lewis90
2008-11-16, 03:00
Hi,

I have the following problem --

I have fully run Spybot, and have seemed to eliminate all other spyware that was on my computer, except 1 -- a Sumom A entry, that Spybot says it
can't get rid of, but that maybe if I restarted my computer, it could remove it then.

The effect seems to be, that unlike all the other spyware I have gotten on my computer, this Sumom A entry, is not at present being eliminated by my Spybot.

Is it possible to help me to get rid of this last spyware ?

drragostea
2008-11-16, 05:08
This is a worm. Can you run Spybot-Search&Destroy in Safe Mode?

Do you have any other anti-malware/virus programs that you can run?

lewis90
2008-11-17, 09:15
Hi,

[1.]
Oh my goodness !!!! You say it's a worm !
Is it damaging my computer ?
Should I be very worried about this ?
My computer has seemed to have been going fine mostly.

[2.]
I don't know how to run Spybot in Safe Mode.
Could you please give me steps, in order to do it ?

Would doing that work ?

[3.]
No I don't think I have any other programs that I can run, for this.
(If I should try this option, could you also give me steps to follow,
so that I can do it ? I had tried other programs though, and they didn't work
on my computer. My preference, would be to stick with Spybot,
as I seem to have got it to run on my computer, whereas I haven't been so successful with other programs).
It seems that Spybot picked it up, but can't get rid of it.

lewis90
2008-11-17, 09:24
I do have a running copy of Norton Antivirus 2002.

drragostea
2008-11-18, 04:53
lewis, this is some serious stuff. You're running a version of Norton that is way to dated to even be serious, even though you may have the latest definition updates, the program updates are in the dumps.

I'm not even sure if running Spybot in Safe Mode will purge this threat completely. A worm is malware, something that hides in your machine. It could either collect data and/or destroy files at the same time. To run in Safe Mode you'll have to tap F8 (Function 8) during Bootup. The instant you hear the computer start up (before the bootscreen with the Windows logo) you'll have to tap F8.

You can have a specialist purge this threat. Follow the directions below:
-
Consider posting in the Malware Removal (http://forums.spybot.info/forumdisplay.php?f=22) forum and having someone take a look at your system.

If you decide to have an experienced malware removal specialist assist you, please follow the procedure in this link to run scans and produce a HijackThis log:

"BEFORE you POST"(READ this Procedure BEFORE Requesting Assistance) (http://forums.spybot.info/showthread.php?t=288).

-

tashi
2008-11-18, 05:24
Hello lewis90,

Is this your Win98 computer? I'm asking because the malware forum analysts may be reluctant to take on those older machines. The Operating System is no longer supported by Microsoft and therefore cannot be updated, leaving them open to reinfection.

Either way could you try running Spybot-S&D in safe mode first please and let us know how it goes. :)

In safe mode, you have access to only basic files and drivers. When the machine is operating in normal mode all processes are running.
Scanning with Spybot-S&D in safe mode allows the program to try and remove items that keep reappearing after a scan, despite having been 'fixed'.

Windows XP.
Reboot your computer into SafeMode by doing the following:

Restart your computer
After hearing your computer beep once during startup, but before the Windows icon appears, begin tapping F8.
Instead of Windows loading as normal, a menu should appear.
Select the first option, to run Windows in Safe Mode.


How to Start a Windows 98-Based Computer in Safe Mode
http://support.microsoft.com/kb/180902

Open Spybot-S&D while still in safe mode.

Close all browsers, check for problems and fix everything found in red
Repeat until no more items are found in red
Close Spybot-S&D
Reboot back into Windows

lewis90
2008-11-21, 15:17
Hi Tashi,

Sorry, I didn't see your post, until after I had posted a new post in a new thread --

http://forums.spybot.info/showthread.php?p=255263#post255263

Sorry about that.

My other post, also did ask, about well, do I actually have to worry about
this infection, because my computer seems to be going just fine.
For example, is it something -- the Sumom A -- that might be damaging my computer ?

I can try the safe mode thing.

I did post some other questions in my other thread, that perhaps you
might answer, if that's ok to ask ?

drragostea
2008-11-21, 23:39
For example, is it something -- the Sumom A -- that might be damaging my computer ?
The worm could be hidden.
Your questions will be answered in the Malware Removal Forums.
Good luck.

tashi
2008-11-22, 00:24
Hello lewis90, :)

I have closed your topic in the malware removal forum.

Please start a new one there producing the HJT log with a link back to this topic, if it is needed after running Spybot-S&D in safe mode.

"BEFORE you POST"(READ this Procedure BEFORE Requesting Assistance) (http://forums.spybot.info/showthread.php?t=288)

Cheers.

Edit.
Anti virus program topic
http://forums.spybot.info/showthread.php?t=9289 (http://forums.spybot.info/showthread.php?t=9289)

So how did I get infected in the first place? (http://forums.spybot.info/showthread.php?t=279)