W32/Mugly.a

Hi ,

I have a worm on my laptop because of my own stupid fault. I got an email from a girl I know that said “You have an admirer” in the subject line and even thought I suspected a virus I was so interested I opened it. I saw a zip file called attachment.zip and (oh my, I don’t know why) I opened it.

Now I have a worm on the computer. It runs a startup called winit.exe and it seems to considerably slow down my laptop. I did some research and discovered that this is the Mugly.A worm. Not too sure what that means though :-\

I tried running Avast but it does not see “Mugly.A” - Avast says my system is clean.

Can anyone tell me where to go from here.

Cheers,
Luke.

Might want to try the free program called Ad-Aware S.E. 1.05, and also the free program called Spybot Search and Destroy. Both those programs might be able to take care of removing it or at least allowing you to quaranteen it. Welcome to the forum. :slight_smile:

Wow, thank you for the fast reply Neal. I will try both Ad Aware and Spybot in the order you suggested.

I am a big fan of Avast Antivirus and this is the first time it has failed me. I suppose the Avast Chappies will get around to sorting this one out soon.

All the best,
Luke.

Most anti virus programs are not designed to detect the majority of “worms” that are floating around on the Internet. They are mainly designed to detect malware infections that are written as viri or as a virus. That is why those programs that I mentioned might do a better job of detecting this particular worm your pc has. :wink:

eeermh,

avast is usually considerable better in detecting WORMS than Adware or Spybot, cause worms are of course a classic target for AV-programs

whereas ad-aware & SSD are better in detecting adware & minor spyware

@Luke
please work through the link “VirusRemoval” below in my sig. and then:

  • post a hijackthis-Log for diagnosis
  • tell us where this malicious file is located on your PC: full path/folder/filename
  • test it with onlineScanners, e.g. JOTTI

if possible, send it in to virus (at) avast.com

and why not afterwasrds follow the removal-instructions here:
TrendMicro

:wink:

P.S.:
avast should detect
Win32:Mugly [Wrm]
since Dec 2nd → earlier than Trendmicro

→ What VPS-Version do you have ?
→ or, if it’s a new mugly-variant which UPTODATE avast doesn’t detect even in SafeMode/thorough/Archives or Boot-time Scan:
please send it in (see above)

:wink:

Personally I believe that speaking of worms, trojans, viruses etc nowadays is not covering the things that causes harm to a system. (It never did in fact, but looking at the recent past it does even less). it is more apropiate to call it malware. And there is no single application that can remove/prevent all malware. That is one of the reasons that the malware removal section on the link in my signature is so powerfull.

I have now installed and ran ad aware, spywareblaster and spybot search and destroy. My system is running at a cripplingly slow pace and is no better.

In answer to your question, yes I did have an up to date avast version. It was updated on 12/12/04.

I tried to delete the file which was the root of all my troubles love_04.scr and then ran the other malware removal progs in the order above. They found quite a few critical files and I have quaranteened all of these.

The executable file winit.exe that appeared with my virus has gone but my system still snails along. The mouse curser moves freely for some seconds, then freezes as if performing some memory intensive operation, then moves again. peforming any operation is s l o w.

Unsure where to go from here.

Thanks for your replies

HiJackThis, should be your next port of call.

HiJackThis - Eddy’s Website and click the “HiJackThis Section” also read the “Malware removal instructions and applications” section and follow the directions there and get back to us if you need more help…

If you want to try an on-line scan of your Hijackthis log file try here [b]http://hijackthis.de/index.php[/b] Or you can use Eddy’s HiJackThis Log File Analyser Or post your log here…

You are all so helpful, thank you. I have to go to work now but I will run Hijack This when I get back and post the log files here.

Cheers,
Luke

Read this:
http://securityresponse.symantec.com/avcenter/venc/data/w32.mugly.a@mm.html
(copy/paste the above address)