Tek-Tips is the largest IT community on the Internet today!

Members share and learn making Tek-Tips Forums the best source of peer-reviewed technical information on the Internet!

  • Congratulations gkittelson on being selected by the Tek-Tips community for having the most helpful posts in the forums last week. Way to Go!

Computer has a worm that Norton's AV is not detecting.

Status
Not open for further replies.

slg2005

IS-IT--Management
Jun 16, 2005
1
US
Hi-

My computer has a worm and has been sending out the same set of old messages a few times per year. I am running Nortons Antivirus software w/current virus definitions and have done a full system scan w/nothing detected.

In the past, it would send out one copy of each message; we recently got cable internet access and when the worm activated itself it to sent out the same set over and over. Not sure where to start. Please help.

Thanks.
 
I would start by installing a firewall like Zonealarm as this will prevent anything connecting to the net without your permission, it will also give you a clue what is trying to connect.

Norton may be damaged so i'd be tempted to take advantage of Trends free online scan.


Process explorer is worth trying as well, it will tell you what processes are running and what files they are using.


Also AdAware is well worth trying as it might be a Spyware prog of some sort and so Norton won't flag this as a virus.


They are all free and worth trying.

Hope that gets you started.
 
The other thing to question is -- are you sure the machine is infected? How do you know that?

Spoofed (faked) email sender (From:) addresses aren't a definate indication that your machine is infected.

Nearly all viruses send emails using an address they found on the infected machine (these days). So, if you're basing the assumption that the machine is infected based on returned emails (NDRs - non-delivery receipts) -- it's more likely someone you know that's infected, rather than you.

-- Scott.
 
We had something similar where a worm was found, but not detected.. but Symantec had come out with a rapid-release installer to bring the defs up to date.. after installing it - it brought us up to date, and the worm was effectively quarentined...
Check for these rapid-releases often..

Alshrim
System Administrator
MCSE, MCP+Internet
 
Status
Not open for further replies.

Part and Inventory Search

Sponsor

Back
Top