Tek-Tips is the largest IT community on the Internet today!

Members share and learn making Tek-Tips Forums the best source of peer-reviewed technical information on the Internet!

  • Congratulations Chris Miller on being selected by the Tek-Tips community for having the most helpful posts in the forums last week. Way to Go!

W32.HLLW.Nebiwo * Help Please !!!!!!!!!!!!

Status
Not open for further replies.

JRMS

MIS
Sep 4, 2003
144
US
I am constantly receiving Norton notification that a virus was found. The virus name is W32.HllW.Nebiwo. The file name is listed as: "C:\WINNT\Profiles\All Users\Start Menu\Programs\Startup\~2.exe". Symantec was unable to clean it. I downloaded a fix from the Symantec website; however, the fix did not locate this virus. User within the entire domain receive this message. Has anyone experienced this and resolved it as well. Help is greatly needed!!!!!!!!!!!!!
 
1. Using XP? If so, disable system restore FIRST.
(Right click My Computer > Properties > System Restore tab > Turn off system restore.

2. Restart your pc in safe mode. Now run your removal tool.

3. Reboot.

Still there?


Tired of waiting for an answer? Try asking better questions. See: faq222-2244
 
Carrr, thanks for your response. I am running Window 2000 servers and 2000 clients. I have a few NT machines as well. Is there a different solution for W2K. Thanks.
 
What would be the impact of navigating to the location and manually deleting the file?
 
Right.
You could simply eliminate step one from above and come in under Safe Mode and either run the tool, or manually delete the offender.

Tired of waiting for an answer? Try asking better questions. See: faq222-2244
 
When you state delete the offender, what are you referring to. Are you referring to the ~2 file? Do you or anyone elso know of ways to prevent this from happening again. Are there ports that need to be closed or are there services that need to stop. Thanks in advance for your help!!
 
look through the list of services, if there are any malicious entries you should know - b/c u should know what should and shouldnt be running as a service :)

try hijackthis if your worried about malicious startups or jackers, also try antivirus...

i would just delete the ~2.exe file if you can, if it's access denied ctrl+alt+del and remove weird processes, then try. if no luck - try removing it in safemode or from the recovery console.

goodluck!
-iB
 
Thanks for your suggestions. I will try it.
 
Status
Not open for further replies.

Part and Inventory Search

Sponsor

Back
Top