This is a read-only archive. No new posts or registrations. Privacy Page
Spyware / Malware / Virus Removal

W32\Lebreat worm

8 min read

This thread's last reply is from . Advice, software, and links below may be out of date — treat specific steps and download links with caution.

Looking for the outcome? Ask AI

Can anyone tell me how to get rid of this worm!!!!!!! I have Panda Titanium, Adaware se, Spybot search & Destroy, window washer, I've tried everything I can think of to get rid! but nothing has worked. The latest email i got was from "[removed]" with this email. Panda Titanium Antivirus 2005 warning: The file C:WINDOWSsystem32zipx.dat [readme .exe] was infected by the W32/Lebreat.P.worm virus and has been disinfected. ################################################################################################### Predators I know it says its been disinfected but I want rid altogether. Please Help Thanx :wall:
I havn't been able to delete. I've even tried to delete manually but simply can't find where they are. Running Ewido, anti-virus, spybot, regclean, allsorts of things like that don't have an effect. It isn't making my pc play up in any way but i just don't like the fact that theres something there. Any Ideas
Hello Jeff5705 and welcome to TomCoyote. :wavey:

I'll have you clean out temp files than run a scan which should show the location of the worm. I can then instruct you on how to remove them.


Download CCleaner to clean temp files from your computer.
  • Double click on the file to start the installation of the program.
  • Select your language and click OK, then next.
  • Read the license agreement and click I Agree.
  • Click next to use the default install location. Click Install then finish to complete installation.
  • Double click the CCleaner shortcut on the desktop to start the program.
  • Click Options < Advanced and uncheck "Only delete files in Windows Temp folders older than 48 hours".
  • Click Run Cleaner to run the program.
  • After it has completed it's process, click Exit.
Caution : It is not recommended to use the 'Issues' tab as it is known to find legitimate items.


Click here to download mwavscan.
  • Double-click it to run it.
  • Read then accept the agreement.
  • Check Drive, and select all local drives, scan all files, then press 'scan'. (This may take a while and will not fix anything)
  • Once it finds something, it will prompt you so click OK.
  • When it is completed, anything found will be displayed in the lower pane.
  • Highlight it with the mouse, copy it (CTRL+C), and paste (CTRL+V) it in your next reply.
Note : It will find many orphaned registry entries so please do not be alarmed by the amount of items that show.
Object "netster Spyware/Adware" found in File System! Action Taken: No Action Taken. Object "searchexe Spyware/Adware" found in File System! Action Taken: No Action Taken. Object "netster Spyware/Adware" found in File System! Action Taken: No Action Taken. Object "unknown trojan Spyware/Adware" found in File System! Action Taken: No Action Taken. Entry "HKLM\Software\Microsoft\Windows\CurrentVersion\ModuleUsage" refers to invalid object "C:\WINDOWS\Downloaded Program Files\Driver_Detective_v43_Non_Member.ocx". Action Taken: No Action Taken. Entry "HKLM\Software\Microsoft\Windows\CurrentVersion\SharedDlls" refers to invalid object "C:\Program Files\Ahead\Nero BackItUp\BackItUp-Chs.nls". Action Taken: No Action Taken. Entry "HKLM\Software\Microsoft\Windows\CurrentVersion\SharedDlls" refers to invalid object "C:\Program Files\Ahead\Nero BackItUp\BackItUp-Cht.nls". Action Taken: No Action Taken. Entry "HKLM\Software\Microsoft\Windows\CurrentVersion\SharedDlls" refers to invalid object "C:\Program Files\Ahead\Nero BackItUp\BackItUp-Deu.nls". Action Taken: No Action Taken. Entry "HKLM\Software\Microsoft\Windows\CurrentVersion\SharedDlls" refers to invalid object "C:\Program Files\Ahead\Nero BackItUp\BackItUp-Esp.nls". Action Taken: No Action Taken. Entry "HKLM\Software\Microsoft\Windows\CurrentVersion\SharedDlls" refers to invalid object "C:\Program Files\Ahead\Nero BackItUp\BackItUp-Fra.nls". Action Taken: No Action Taken. Entry "HKLM\Software\Microsoft\Windows\CurrentVersion\SharedDlls" refers to invalid object "C:\Program Files\Ahead\Nero BackItUp\BackItUp-Ita.nls". Action Taken: No Action Taken. Entry "HKLM\Software\Microsoft\Windows\CurrentVersion\SharedDlls" refers to invalid object "C:\Program Files\Ahead\Nero BackItUp\BackItUp-Jpn.nls". Action Taken: No Action Taken. Entry "HKLM\Software\Microsoft\Windows\CurrentVersion\SharedDlls" refers to invalid object "C:\Program Files\Ahead\Nero BackItUp\BackItUp-Kor.nls". Action Taken: No Action Taken. Entry "HKLM\Software\Microsoft\Windows\CurrentVersion\SharedDlls" refers to invalid object "C:\Program Files\Ahead\Nero BackItUp\BackItUp-Nld.nls". Action Taken: No Action Taken. Entry "HKLM\Software\Microsoft\Windows\CurrentVersion\SharedDlls" refers to invalid object "C:\Program Files\Ahead\Nero BackItUp\BackItUp-Ptg.nls". Action Taken: No Action Taken. Entry "HKLM\Software\Microsoft\Windows\CurrentVersion\SharedDlls" refers to invalid object "C:\Program Files\Ahead\Nero ShowTime\ShowTime-Chs.nls". Action Taken: No Action Taken. Entry "HKLM\Software\Microsoft\Windows\CurrentVersion\SharedDlls" refers to invalid object "C:\Program Files\Ahead\Nero ShowTime\ShowTime-Cht.nls". Action Taken: No Action Taken. Entry "HKLM\Software\Microsoft\Windows\CurrentVersion\SharedDlls" refers to invalid object "C:\Program Files\Ahead\Nero ShowTime\ShowTime-Deu.nls". Action Taken: No Action Taken. Entry "HKLM\Software\Microsoft\Windows\CurrentVersion\SharedDlls" refers to invalid object "C:\Program Files\Ahead\Nero ShowTime\ShowTime-Esp.nls". Action Taken: No Action Taken. Entry "HKLM\Software\Microsoft\Windows\CurrentVersion\SharedDlls" refers to invalid object "C:\Program Files\Ahead\Nero ShowTime\ShowTime-Fra.nls". Action Taken: No Action Taken. Entry "HKLM\Software\Microsoft\Windows\CurrentVersion\SharedDlls" refers to invalid object "C:\Program Files\Ahead\Nero ShowTime\ShowTime-Ita.nls". Action Taken: No Action Taken. Entry "HKLM\Software\Microsoft\Windows\CurrentVersion\SharedDlls" refers to invalid object "C:\Program Files\Ahead\Nero ShowTime\ShowTime-Jpn.nls". Action Taken: No Action Taken. Entry "HKLM\Software\Microsoft\Windows\CurrentVersion\SharedDlls" refers to invalid object "C:\Program Files\Ahead\Nero ShowTime\ShowTime-kor.nls". Action Taken: No Action Taken. Entry "HKLM\Software\Microsoft\Windows\CurrentVersion\SharedDlls" refers to invalid object "C:\Program Files\Ahead\Nero ShowTime\ShowTime-Nld.nls". Action Taken: No Action Taken. Entry "HKLM\Software\Microsoft\Windows\CurrentVersion\SharedDlls" refers to invalid object "C:\Program Files\Ahead\Nero ShowTime\ShowTime-Ptg.nls". Action Taken: No Action Taken. Entry "HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts" refers to invalid object ".avc". Action Taken: No Action Taken. Entry "HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts" refers to invalid object ".dow". Action Taken: No Action Taken. Entry "HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts" refers to invalid object ".lic". Action Taken: No Action Taken. Entry "HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts" refers to invalid object ".tcp". Action Taken: No Action Taken. Entry "HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts" refers to invalid object ".vnd". Action Taken: No Action Taken. Entry "HKCR\CLSID\{1EFD6A40-3999-11CF-9150-00AA0059F70D}" refers to invalid object "D:\PROGRAM\32\mci32.ocx". Action Taken: No Action Taken. Entry "HKCR\CLSID\{3775D2E0-7C5D-11CF-899E-00AA00688B10}" refers to invalid object "D:\PROGRAM\32\mci32.ocx". Action Taken: No Action Taken. Entry "HKCR\CLSID\{C1A8AF25-1257-101B-8FB0-0020AF039CA3}" refers to invalid object "D:\PROGRAM\32\mci32.ocx". Action Taken: No Action Taken. Entry "HKCR\TypeLib\{C1A8AF28-1257-101B-8FB0-0020AF039CA3}" refers to invalid object "D:\PROGRAM\32\mci32.ocx". Action Taken: No Action Taken. Entry "HKCR\.gif" refers to invalid object "StPaint_gif". Action Taken: No Action Taken. Entry "HKCR\.ksc" refers to invalid object "KscViewer.Document". Action Taken: No Action Taken. Entry "HKCR\.pcb" refers to invalid object "PCBFile". Action Taken: No Action Taken. Entry "HKCR\.sps" refers to invalid object "StPaint_sps". Action Taken: No Action Taken. Entry "HKCR\.wbmp" refers to invalid object "StPaint_wbmp". Action Taken: No Action Taken. Entry "HKCR\Automap.Map.EU" refers to invalid object "{A49EEA01-9231-4C77-AA9E-2F89D72B4804}". Action Taken: No Action Taken. Entry "HKCR\Automap.Map.EU.12" refers to invalid object "{A49EEA01-9231-4C77-AA9E-2F89D72B4804}". Action Taken: No Action Taken. Entry "HKCR\Automap.Template.EU.12" refers to invalid object "{A49EEA01-9231-4C77-AA9E-2F89D72B4804}". Action Taken: No Action Taken. Entry "HKCR\PCheck.PCheck" refers to invalid object "{FD1A9E6B-05DA-4ca2-830D-654DA1DDBD9E}". Action Taken: No Action Taken. Entry "HKCR\PCheck.PCheck.1" refers to invalid object "{FD1A9E6B-05DA-4ca2-830D-654DA1DDBD9E}". Action Taken: No Action Taken. Entry "HKCR\SQLPARSE.vbSQLParser" refers to invalid object "{8F6C7662-E8A1-11D0-B9B3-2A92D0000000}". Action Taken: No Action Taken. Entry "HKCR\SQLPARSE.vbSQLParser.1" refers to invalid object "{8F6C7662-E8A1-11D0-B9B3-2A92D0000000}". Action Taken: No Action Taken. File C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\DyFuCAInternetOptimizer.zip infected by "Password-protected-EXE" Virus! Action Taken: No Action Taken. File C:\System Volume Information\_restore{B9939188-95FC-4ADF-8107-B4F6F1CBA177}\RP164\A0059142.exe infected by "Trojan.Win32.Urbin.c" Virus! Action Taken: No Action Taken. File C:\System Volume Information\_restore{B9939188-95FC-4ADF-8107-B4F6F1CBA177}\RP164\A0059162.ini tagged as "not-a-virus:AdWare.Win32.Sahat.ao". Action Taken: No Action Taken. Hi alsocom, Well there's the log, I hope you can see something in there to help. Thanx for the welcome also. Speak soon I hope Jeff
The only malicious entries found are backed up in System Restore. We'll clean that out and see if Panda Antivirus finds anything now.
The worm itself looks to have been removed from the email. It is no longer present on the computer.

Reset and Re-enable your System Restore to remove bad files that have been backed up by Windows. The files in System Restore are protected to prevent any programs changing those files. This is the only way to clean these files: (You will lose all previous restore points which are likely to be infected.)

1. Right-click My Computer, and then click Properties.
2. On the System Restore tab, put a check mark in the 'Turn Off System Restore' check box.
3. Click OK, and then click Yes.
4. Restart the computer.
5. Repeat steps 1 - 2, this time clearing the box beside 'Turn Off System Restore', click 'OK'.



Now run a scan with Panda Antivirus and let me know if it finds anything.
Hi Allan Thanx for your help. I did as you instructed but when I ran a full scan with Panda it was still picking up the files with the worms. However all this has helped because i suddenley realised where they where. The infected files where 'deleted emails' and although not causing any harm where still being picked up by Panda. By simply permanantly deleting the 'deleted items' folder (or the folders contents I should say) it has cured the problem. Although Panda Titanium is quite good, its not very good at post scan service ie it doesn't give you any options on what to do with whatever it finds. Anyway thanx again for your help, we got there in the end. Take Care Jeff
I'm glad you were able to locate the problem emails. I'm really suprised that mwavscan did not locate them. :scratch:

Since everything seems to be working normally now, I'll give you my security recommendations.

I suggest that you download these programs to help keep the computer clean:

Spyware Blaster - Blocks bad ActiveX items from installing on your computer. Spyware Blaster runs silently in the background.
ie-spyad - Puts over 12,000 bad URLs into your restricted sites for Internet Explorer.
Google Toolbar - Blocks many unwanted pop-ups in Internet Explorer.
Firefox - 'Safer' alternative to the Internet Explorer web browser.
ZoneAlarm - Free firewall program if you currently are not using one.

Here are two very good and free malware scanners:

Spybot Search and Destroy 1.4
AdAware SE v1.06
Set-up Instructions for Spybot S&D; and Adaware SE

If you have them already, check to make sure that they are the newest version.

Update these regularly.

You may also want to read the following posts to learn how to better secure your computer.
"So how did I get infected in the first place"
"Securing Your PC After An Attack"

Be sure to keep Windows and your Anti-virus updated.
Glad we could be of assistance. This topic is now closed. If you wish it reopened, please send us an email (Click for address) with a link to your thread.

Do not bother contacting us if you are not the topic starter. A valid, working link to the closed topic is required along with the user name used. If the user name does not match the one in the thread linked, the email will be deleted.
Make sure you use proper prevention to keep from having problems occur to your computer in the future.

Coyote's Installed programs for prevention:

http://forums.tomcoyote.org/index.php?showtopic=31418

The help you receive here is free. If you wish to show your appreciation, then you may donate to help keep us online.

Visit the CoyoteStore http://TomCoyote.org/coyotestore.php

Ask AI

AI can make mistakes. Check the cited posts. Archived advice can be out-of-date

Don't include personal information. Questions and selected public posts go to OpenAI. About Ask AI