win32:NcaseSpy (help)

  • Thread starter Thread starter Gaz
  • Start date Start date
G

Gaz

Last Saturday evening, I was unfortunate to get caught by, what
my copy of Avast is reporting as:

win32:NcaseSpy (Trj)

Well if I am honest I was STUPID, enough to allow it to happen!

Anyway,

Avast has successfully quaranteened the infect file, in the
vault!

Our PC, is running Win98SE, with the latest version of Avast
(FREE), Zone Alarm (FREE).

I have disabled two lines in the Autoexec.bat, using MSConfig, as
these two lines only appeared after I got the above
virus/worm/trojan!

The first line is:

SET BLASTER=A220 I7 D1 T2

The second line is:

SET SNDSCAPE=C:\WINDOWS

Both have been disabled!

I have also downloaded/installed and run the latest version of
Ad-Aware, which found and quaranteened approx 50 files/cookies
etc!

Now I would rally welcome any advice on what to do next!

Or is it just a simple case of now deleting that infected file
from the Avast vault!

Then if so, how do I safely remove/delete the above two lines
from the Autoexec.bat?

Any Advice and instructions would be GREATLY APPRECIATED!

Many thanks in advance.

Garry.
 
Nether of the two environmental variable lines are part of any infector.
SET BLASTER=A220 I7 D1 T2
SoundBlaster compatible sound card settings --> I/O=220, IRQ=7, DMA=1 model=T2
SET SNDSCAPE=C:\WINDOWS

You can re-enable them both !

Just to make sure Avast does done its job, perfotrm the steps on the following URL...

http://www.claymania.com/removal-trojan-adware.html

--
Dave




| Last Saturday evening, I was unfortunate to get caught by, what
| my copy of Avast is reporting as:
|
| win32:NcaseSpy (Trj)
|
| Well if I am honest I was STUPID, enough to allow it to happen!
|
| Anyway,
|
| Avast has successfully quaranteened the infect file, in the
| vault!
|
| Our PC, is running Win98SE, with the latest version of Avast
| (FREE), Zone Alarm (FREE).
|
| I have disabled two lines in the Autoexec.bat, using MSConfig, as
| these two lines only appeared after I got the above
| virus/worm/trojan!
|
| The first line is:
|
| SET BLASTER=A220 I7 D1 T2
|
| The second line is:
|
| SET SNDSCAPE=C:\WINDOWS
|
| Both have been disabled!
|
| I have also downloaded/installed and run the latest version of
| Ad-Aware, which found and quaranteened approx 50 files/cookies
| etc!
|
| Now I would rally welcome any advice on what to do next!
|
| Or is it just a simple case of now deleting that infected file
| from the Avast vault!
|
| Then if so, how do I safely remove/delete the above two lines
| from the Autoexec.bat?
|
| Any Advice and instructions would be GREATLY APPRECIATED!
|
| Many thanks in advance.
|
| Garry.
|
 
Back
Top