Jump to content


Register a free account to unlock additional features at BleepingComputer.com
Welcome to BleepingComputer, a free community where people like yourself come together to discuss and learn how to use their computers. Using the site is easy and fun. As a guest, you can browse and view the various discussions in the forums, but can not create a new topic or reply to an existing one unless you are logged in. Other benefits of registering an account are subscribing to topics and forums, creating a blog, and having no ads shown anywhere on the site.

Click here to Register a free account now! or read our Welcome Guide to learn how to use this site.


W32.spybot.worm Removal Tool?

  • Please log in to reply
4 replies to this topic

#1 elahmo


  • Members
  • 4 posts
  • Local time:11:17 PM

Posted 04 June 2006 - 08:17 AM

Sorry guys if this has already been done.

I ran the online scan on the Symantec website, and it found my computer was infected with "w32.spybot.worm". I've run ewido Anti-Malware's full system scan everyday ever since my LimeWire troubles (I posted about that earlier in the week) and that had failed to detect it. A google search for a removal tool just leads me to manual extraction, which Im scared to do incase I ruin my computer forever. Is there an easy way to remove it? I've run numerous online scans and they either a) fail to detect it, or :thumbsup: detect it but haven't told me how to remove it.

Sorry for any inconvenience.

Thanks in advanced :flowers:

BC AdBot (Login to Remove)


#2 rookie147


  • Members
  • 5,321 posts
  • Local time:01:17 PM

Posted 04 June 2006 - 08:25 AM

Hello elahmo,
Don't be too scared about running a manual removal of this worm. There is an article here that is simple to follow and should rid you from this nasty worm. Remember that these walkthroughs have been made by experts, and as such will be reliable, meaning that you will not mess up your computer.

However, if you do not feel confortable running this, I would recommend posting a HijackThis Log, firstly by following this tutorial:
Preparation Guide Before Posting A HijackThis Log
Then, run a scan, and post the log in the HijackThis Analysis forum, and let an expert walk you through step-by-step.

Hope this helps,

If you are pleased with the service I have offered, you may like to consider making a donation. Posted Image
Posted Image

#3 elahmo

  • Topic Starter

  • Members
  • 4 posts
  • Local time:11:17 PM

Posted 04 June 2006 - 08:57 AM

Just a quick question re: manual removal, if it says "In the right pane, reset the original value, if known:

"Start" = "4" ", does that mean reset it to start = 4, or am I supposed to know what this means? Im just reading through the instructions and double checking before I do anything.


#4 Elendil


  • Members
  • 660 posts
  • Gender:Male
  • Location:The US
  • Local time:08:17 AM

Posted 04 June 2006 - 09:14 AM

To set Start = 4 in a specific subkey do the following:

Once you are at the proper subkey, highlight it by clicking on it once. Some data should appear in the right panel of your screen. Look for an entry called Start, right click it, and select Modify. A window will popup, type 4 in the white box underneath Value:, and click ok.
Stanford '14
B.S. Candidate | Computer Science

#5 quietman7


    Bleepin' Janitor

  • Global Moderator
  • 51,953 posts
  • Gender:Male
  • Location:Virginia, USA
  • Local time:07:17 AM

Posted 04 June 2006 - 03:35 PM

To attempt automatic removal of W32.Spybot.Worm download and scan with Trend Micro's Sysclean Package.
1. Create a new folder on drive "C:\" ("C:\New Folder") and rename it Sysclean.
2. Place the sysclean.com inside that folder.
3. Then download the latest Virus Pattern Files (lptXXX.zip).
4. Extract the lptXXX.zip pattern file into the same folder you created for sysclean.com.
5. Close all open applications and DISABLE your current anti-virus software. Some anti-virus programs such as Avast will alert you to a virus attack when running sysclean so it's best to disable them first.
6. Open the Sysclean folder and double-click on sysclean.com to run.
7. It will take some time to complete. Be patient and let it clean whatever it finds.
8. Exit when done and re-enable your anti-virus program.

Note: This tool generates a log file [SYSCLEAN.LOG] in the same folder when the scan is completed and can be run in "SAFE MODE".

If that fails, then try using Trend Micro's Worm_Spybot.gen Manual Removal instructions.

Since W32.Spybot terminates task manager and regedit, you need an alternative tool to terminate the malware process. Download and use ProcessExplorer, a freeware tool with features similar to Windows task manager which can be used during the manual removal process.
Windows Insider MVP 2017-2018
Microsoft MVP Reconnect 2016
Microsoft MVP Consumer Security 2007-2015 kO7xOZh.gif
Member of UNITE, Unified Network of Instructors and Trusted Eliminators

If I have been helpful & you'd like to consider a donation, click 38WxTfO.gif

0 user(s) are reading this topic

0 members, 0 guests, 0 anonymous users