McAfee Stinger
http://vil.nai.com/vil/stinger/
Trend Sysclean Package
http://www.trendmicro.com/download/dcs.asp
Latest Trend Pattern File.
http://www.trendmicro.com/download/pattern.asp
Adaware SE (free personal version v1.05)
http://www.lavasoftusa.com/
Create a directory.
On drive "C:\"
(e.g., "c:\New Folder")
or the desktop
(e.g., "C:\Documents and Settings\lipman\Desktop\New Folder")
Download Sysclean.com and place it in that directory.
Dowload the Trend Pattern File by obtaining the ZIP file.
For example; lpt244.zip
Extract the contents of the ZIP file and place the contents in the same directory as
sysclean.com.
2) Update Adaware with the latest definitions.
3) If you are using WinME or WinXP, disable System Restore
http://vil.nai.com/vil/SystemHelpDocs/DisableSysRestore.htm
4) Reboot your PC into Safe Mode
5) Using Trend Sysclean, Stinger and Adaware, perform a Full Scan of your
platform and clean/delete any infectors/parasites found.
(a few cycles may be needed)
6) Restart your PC and perform a "final" Full Scan of your platform using the three
utilities; Trend Sysclean, Stinger and Adaware
7) If you are using WinME or WinXP, Re-enable System Restore and re-apply any
System Restore preferences, (e.g. HD space to use suggested 400 ~ 600MB),
8) Reboot your PC.
9) If you are using WinME or WinXP, create a new Restore point
You can also try some of the below online scanners.
BitDefender:
http://www.bitdefender.com/scan/license.php
Computer Associates:
http://www3.ca.com/securityadvisor/virusinfo/scan.aspx
DialogueScience:
http://www.antivir.ru/english/www_av/
F-Secure:
http://support.f-secure.com/enu/home/ols.shtml
Freedom Online scanner:
http://www.freedom.net/viruscenter/index.html
Kaspersky:
http://www.kaspersky.com/de/scanforvirus
McAfee:
http://www.mcafee.com/myapps/mfs/default.asp
Panda:
http://www.pandasoftware.com/activescan/
RAV
http://www.ravantivirus.com/scan/
Symantec:
http://security.symantec.com/
Trend:
http://housecall.antivirus.com
http://housecall.trendmicro.com
* * * Please report your results ! * * *
Dave
"Teeekay" <Tee...@discussions.microsoft.com> wrote in message
news:25CDCBB2-E312-4AD9...@microsoft.com...
Many thanks Dave for your info re axel dav.
axel dav- is the virus known as vbs_redlof.A
It nearly destroyed my pc... until I chanced upon this forum.. took Dave's
advise -- albeit I had to format the lot..and had to low level format--
then reformatted in fat 32-- then again in nfts-- then again a low level
format-
1776 html files infected..
other files as well-- -- now I don't know what to do re- the files up on
servers and whether they are infected..
If any of you are using hp -- my pc is 4 months old
Clean the Restore disks.
axel.dav.is in the restore disks.
hp-bin
hp-1386 --drivers
Much to my disgust sysclean.com found those when I re-installed windows.
Once again many thanks Dave
Lady_ice
I had the same AXEL.DAV virus. I first tried to re-install windows
using the hp recovery partition, while keeping my user files. That
failed, referring to several AXEL.DAV files. After that I tried to
install Windows XP using a retail vesrion of Windows XP Home. That
failed as well.
Now I have a disk S.M.A.R.T. Status BAD error.
Could that be related to the AXEL.DAV virus?
Frits
--
fritsn
------------------------------------------------------------------------
fritsn's Profile: http://forums.tech-arena.com/member.php?userid=4202
View this thread: http://forums.tech-arena.com/showthread.php?t=16899
Tech-Arena, Largest Technology Forums in India for free I.T. Computer Support - http://forums.tech-arena.com
>
> Hello,
>
> I had the same AXEL.DAV virus. I first tried to re-install windows
> using the hp recovery partition, while keeping my user files. That
> failed, referring to several AXEL.DAV files. After that I tried to
> install Windows XP using a retail vesrion of Windows XP Home. That
> failed as well.
>
> Now I have a disk S.M.A.R.T. Status BAD error.
>
> Could that be related to the AXEL.DAV virus?
>
No. The S.M.A.R.T. monitoring is coming from the hard drive which
indicates a probable mechanical (hardware) failure. To determine the
drive's physical health, download a diagnostic utility from the drive
mftr. Usually you will make a bootable floppy with it. Boot with that,
and run a thorough test. If the drive fails, it will need to be
replaced. Check with HP tech support about how to do that and reinstall
Windows.
Malke
--
MS MVP - Windows Shell/User
Elephant Boy Computers
www.elephantboycomputers.com
"Don't Panic!"
For more info regarding this virus, check out the following pages:
http://www.trendmicro.com/vinfo/virusencyclo/default5.asp?VName=VBS%5FREDLOF%2EA&VSect=Sn
--
wuz2blu
------------------------------------------------------------------------
wuz2blu's Profile: http://forums.techarena.in/member.php?userid=27841
View this thread: http://forums.techarena.in/showthread.php?t=16899
Customer told me he attempted to use the recovery process after a
failed installation of a downloaded DVD app.
My (albeit technically untested and unproven) suspicion is that
AXEL.DAT infestation is a result of a malware infection specificly
targetting the HP (and/or Compaq) recovery partition processes; this
could lie dormant for months/years until the user encounters a problem
and attempts a recovery, whereupon the malware deletes all
docs/settings/program files and dumps itself in each folder.
If you are thinking "but surely HP would know about this and have some
information on it" please refer to comments elsewhere that they should
stick to printers.
As it could be a rootkit best tack would be delete all HDD partitions,
maybe use QTparted on live Linux distro such as Knoppix or Kubuntu to
be sure, merge them, format back to NTFS, recreate partitions as
desired, reinstall clean XP and use 2nd partition to hold Ghosted
backup of clean install. Best of luck.
--
etone
------------------------------------------------------------------------
etone's Profile: http://forums.techarena.in/member.php?userid=27958
Looks like its a full system format and install from fresh XP home
discs
:o) Phil
--
sammons
------------------------------------------------------------------------
sammons's Profile: http://forums.techarena.in/member.php?userid=51263