Spy Sweeper with AntiVirus

The most award-winning anti-spyware software

Spy Sweeper with Antivirus

Get serious about removing spyware with Spy Sweeper - the award-winning anti-spyware software trusted by millions of home computer users.

Add to Cart Button

$29.95

Spyware & Virus Directory

A B C D E F G H I J K L M N O P Q R S T U V W X Y Z 


Small_comp.100

Discovered: May 26, 1995
Updated: December 15, 2003 10:56:08 AM PST
Also Known As: Baby.cmp.b [McAfee], Baby.100.a, Baby.100.c, Baby.100.e [Kaspersky]
Type: Virus
Infection Length: 100 bytes
Systems Affected: DOS

SUMMARY


Small_comp.100 is a small companion virus. It infects the .com and .exe files.

Protection

  • Virus Definitions (LiveUpdate™ Weekly) January 31, 1996
  • Virus Definitions (Intelligent Updater) January 31, 1996

TECHNICAL DETAILS


When Small_comp.100virus is executed, it does the following.
  1. Loads itself into memory and stays memory-resident.

  2. Hooks the "load or execute" DOS function (INT 21h, Function 48h).

Once this happens, when you execute a .com or .exe file, the virus does the following:
  1. Takes control of the executed file.

  2. Renames the executed file to <File name>.ex? or <File name>.co?.

  3. Writes the virus itself into a hidden file, <File name>.exe or <File name>.com, and then executes the original program.


Note: <File name> is the original file name without the extension.

"?" is a special character. Different variants of the same virus could use different characters. The following characters have been seen:

 xDB
V





Recommendations

Symantec Security Response encourages all users and administrators to adhere to the following basic security "best practices":

  • Turn off and remove unneeded services. By default, many operating systems install auxiliary services that are not critical, such as an FTP server, telnet, and a Web server. These services are avenues of attack. If they are removed, blended threats have less avenues of attack and you have fewer services to maintain through patch updates.
  • If a blended threat exploits one or more network services, disable, or block access to, those services until a patch is applied.
  • Always keep your patch levels up-to-date, especially on computers that host public services and are accessible through the firewall, such as HTTP, FTP, mail, and DNS services (for example, all Windows-based computers should have the current Service Pack installed.). Additionally, please apply any security updates that are mentioned in this writeup, in trusted Security Bulletins, or on vendor Web sites.
  • Enforce a password policy. Complex passwords make it difficult to crack password files on compromised computers. This helps to prevent or limit damage when a computer is compromised.
  • Configure your email server to block or remove email that contains file attachments that are commonly used to spread viruses, such as .vbs, .bat, .exe, .pif and .scr files.
  • Isolate infected computers quickly to prevent further compromising your organization. Perform a forensic analysis and restore the computers using trusted media.
  • Train employees not to open attachments unless they are expecting them. Also, do not execute software that is downloaded from the Internet unless it has been scanned for viruses. Simply visiting a compromised Web site can cause infection if certain browser vulnerabilities are not patched.

REMOVAL


  1. Restart the computer using a clean system disk.
  2. Use the Norton AntiVirus DOS scanner to run a full system scan and delete all the files detected as Small_comp.100.
  3. Rename all the affected files to their original name, or restore or re-install them.

1. Restarting with a clean system disk
Because this DOS virus is memory-resident, restart the computer using a clean boot disk.

2. Running the Norton AntiVirus DOS scanner
  1. At the C:> prompt, type the following command:

    dir /s /b avdx.exe

    Then press Enter.

    This displays the path to the Norton AntiVirus DOS scanner. If Norton AntiVirus is installed to a different drive, first change to the root of that particular drive. The default is C:Program FilesNorton AntiVirus.

  2. Change to the folder that contains Navdx.exe. Use short file names. For example, if Norton AntiVirus is installed in C:Program FilesNorton AntiVirus, type:

    cd program~1 orton~1

  3. Type one of the following commands:

    CAUTION: This could take several hours or more on some computers. Do not stop the scan once it has started.

    NOTE: The DOS-based scanner can perform one of the following actions when it detects a virus:
    • To be prompted for any file detected as infected, type the following:

      navdx /a /doallfiles /prompt [Enter]

      Press R)epair, D)elete, or C)ontinue for each infected file. If you choose this option and Norton AntiVirus cannot repair an infected file, you will see the message, "Unable to repair the file," followed by the same three choices. In most cases, you should choose D)elete, unless you are sure that the file is not actually infected.

    • To delete any file detected as infected, type the following:

      navdx /a /doallfiles /delete [Enter]

      The disadvantage of doing this is that the repairable files will be deleted.

    • To repair any file detected as infected, type the following:

      navdx /a /doallfiles /repair [Enter]

      CAUTION: If Norton AntiVirus cannot repair a file and you choose this option, the file will be skipped. That is, the infected files will remain on your system. If you choose this option, then run Navdx again, but this time use the /delete switch, as aforementioned.

3. Renaming or replacing the files
Depending on how many .exe or .com files were affected, either rename the files back to the original file names, replace them from a clean backup, or re-install them.


Spy Sweeper 5.2 stops spyware in its tracks while offering home computer users the ability to configure the program to suit their specific needs, such as:

Choose a Quick, Full or Custom Sweep: With Spy Sweeper 5.2, you can easily choose to perform a quick, full or customized sweep. If you're looking for an immediate diagnosis, choose a quick sweep. For a pinpointed search, customize your sweep to have Spy Sweeper skip files by folder or file extension. For a deep cleaning, opt for a full sweep.

Exclude Files from a Sweep: Spy Sweeper allows you to save time during a sweep by skipping specific files or different sections of your PC. You can select specific file extension, such as .xls or .mpg to exclude.

Additional Highlights

As soon as it's installed, Spy Sweeper gives 360 degrees of protection against spyware, including:

Simple Sweeps: Detecting spyware and removing unwanted programs found on your computer in three effortless steps

Easy Management: Quickly and simply configure program, sweep and upgrade options

Fast Home: Use the home screen to access the most commonly used functions of Spy Sweeper

Shields Summary: A redesigned shields summary page makes it simple to see at a glance which shields are on or off

Action Alerts: Receive clear, easy-to-understand notifications when new spyware threats are detected

"Spy Sweeper remains a favorite for protection from spyware."



"This program's dominance is apparent as soon as you install it."