Infected with Worm Greatless -What to do now?

Hi,

Yesterday when the kids were on MSN the computer services stopped working.
They turned the computer off and when I came home I noticed I could not do much, not even open up MSCONFIG in Safe Mode.
I briefly could manage through to events and antiviree history in event viewer.
I saw msgsrv32.com cirrusx.oxc kernel.vdx and RPCSS.vdx were infected.
I cant open many programs at all and I can’t get into MSCONFIG in Safe Mode.
I have alway had AVAST on the computer and auto update is on.
What can I do next, AVAST will not open anymore.

Appreciate your help.

Hi kroppkaka,

You could try this removall tool from here:
http://www.ognizer.net/index.php?option=com_remository&Itemid=28&func=fileinfo&id=18

Run computer in safe mode,

polonus

Hi kroppkaka,

There are a number of tools you can run in Safe Mode (Safe Mode with Command Prompt is best) including avast!'s own Virus Cleaner.

I also recommend Dr Web CureIT!, McAfee Stinger and Trend Micro Sysclean.

Links to all here:

http://www.geocities.com/dontsurfinthenude/antivir2.htm

If you can’t download them on the infected computer (malware sometimes blocks connections to anti-virus sites) download them on another computer and transfer them to the root directory (easier to find in Safe Mode).

General cleaning procedures won’t harm…

  1. Disable System Restore on Windows ME or Windows XP. System Restore cannot be disabled on Windows 9x and it’s not available in Windows 2k. After boot you can enable System Restore again after step 3).

  2. Clean your temporary files. You can use CleanUp or the Windows Advanced Care features for that.

  3. Schedule a boot time scanning with avast. Start avast! > Right click the skin > Schedule a boot-time scanning. Select for scanning archives. Boot. Other option is scanning in SafeMode (repeatedly press F8 while booting).

  4. It will be good if you download, install, update and run AVG Antispyware. Some users recommend SUPERantispyware, Spyware Terminator and/or a-squared (take care about false positives).
    If any infection is detected, better and safer is send the file to Quarantine than to simple delete than.

  5. If you still detecting any strange behavior or even you’re sure you’re not clean, maybe it will be good to test your machine with anti-rootkit applications. I suggest AVG, Panda and/or F-Secure BlackLight.

  6. Also, if you still detecting strange behaviors or you want to be sure you’re clean, maybe making a HijackThis log to post here and, specially, scan and submit to on-line analysis the RunScanner log would help to identify the problem and the solution.

  7. After you’re clean, use the immunization of SpywareBlaster or, which is better, the Windows Advanced Care features of spyware/adware cleaning and removal.

  8. Finally, when you’re clean, check for insecure applications with Secunia Software Inspector to update insecure applications and avoid reinfection.

Thank you all for your advise. I will go through them and check them out.

kroppkaka

You’re welcome… come back later and post the results 8)