Re: I got a virus in about an hour after a format
Now days, you cannot just reformat, then go on the internet to get the
latest MS Patches, Anti-Virus upgrades, etc. unless you are behind a
firewall, Sygate personal firewall or zonealarm, (both have free versions
that work) that should be the first program (Software firewall) to install
after reformating and prior to going on the net, if you have no hardware
firewall to hide behind. My two cents
"Tony" <lkjlkj@l;lkjlk.com> wrote in message
news:c9eq91$ja1$1@titan.btinternet.com...
>I went throught the gates of hell trying to reinstall my PC.
>
> Every time I put a new system in, a worm came when I tried to upgrade my
> system on line, even from the MS site and from the Norton site.
>
> Eventually, I had to go to a friend's place and upgrade there, he had
> firewall..
>
>
> Hard lesson learned!
>
>
>
> "Elbow" <elbowSPAM@gol.com> wrote in message
> news:2hnp0tFf6toeU1@uni-berlin.de...
>> I had just formatted my drive and hadnt installed my firewall and virus
>> software just yet, I went on the web to get some tips etc and after I
>> installed my firewall I got a file called wuam.exe trying to connect to
> the
>> internet, naturally I blocked it until i could find out what it was.
>> I installed my virus software AVG, rebooted and got an alarm. Virus
>> wuam.exe detected . So I scanned and found it in the System32 folder, I
> had
>> to put in the virus vault.
>>
>> Ive noticed in my startup that its listed as
>> Microsoft Update Time wuam.exe
>> Ive unchecked it so it doesnt start.
>> Just letting others know in case you do a format and dont add your
> security
>> proggies asap. DO them FIRST!!
>> This is the first detected virus I have had in about 2 yrs.
>>
>> here is a log if it helps you to help me or vice a versa
>>
>>
>> Results of Complete Test, date and time 27/05/2004 20:49:21 :
>>
>> Testing C:\ serial C:\Documents and Settings\ELBOW\NTUSER.DAT Cannot
>> open;
>> not checked!
>> C:\Documents and Settings\ELBOW\ntuser.dat.LOG Cannot open; not checked!
>> C:\Documents and Settings\ELBOW\Local Settings\Application
>> Data\Microsoft\WINDOWS\USRCLASS.DAT Cannot open; not checked!
>> C:\Documents and Settings\ELBOW\Local Settings\Application
>> Data\Microsoft\WINDOWS\UsrClass.dat.LOG Cannot open; not checked!
>> C:\Documents and Settings\LocalService\NTUSER.DAT Cannot open; not
> checked!
>> C:\Documents and Settings\LocalService\ntuser.dat.LOG Cannot open; not
>> checked!
>> C:\Documents and Settings\LocalService\Local Settings\Application
>> Data\Microsoft\WINDOWS\USRCLASS.DAT Cannot open; not checked!
>> C:\Documents and Settings\LocalService\Local Settings\Application
>> Data\Microsoft\WINDOWS\UsrClass.dat.LOG Cannot open; not checked!
>> C:\Documents and Settings\NetworkService\NTUSER.DAT Cannot open; not
>> checked!
>> C:\Documents and Settings\NetworkService\ntuser.dat.LOG Cannot open; not
>> checked!
>> C:\Documents and Settings\NetworkService\Local Settings\Application
>> Data\Microsoft\WINDOWS\USRCLASS.DAT Cannot open; not checked!
>> C:\Documents and Settings\NetworkService\Local Settings\Application
>> Data\Microsoft\WINDOWS\UsrClass.dat.LOG Cannot open; not checked!
>> C:\WINDOWS\SYSTEM32\WUAM.EXE Virus identified Worm/Spybot.17.BQ
>> C:\WINDOWS\SYSTEM32\CONFIG\SYSTEM.LOG Cannot open; not checked!
>> Testing D:\ volume Programmes Testing E:\ volume AQS Shares
>> Testing F:\ volume Media + New Stuff serial Testing G:\ volume AQS Shares
> 2
>> Test finished, duration 00:29:27.0 s
>> 18486 objects tested, 1 found infected
>>
>>
>
>
Fnews-brouse 1.9(20180406) -- by Mizuno, MWE <mwe@ccsf.jp>
GnuPG Key ID = ECC8A735
GnuPG Key fingerprint = 9BE6 B9E9 55A5 A499 CD51 946E 9BDC 7870 ECC8 A735