Author Topic: How to remove 2 trojans and a Klez?  (Read 3353 times)

Ma

  • Guest
How to remove 2 trojans and a Klez?
« on: June 11, 2004, 10:41:58 am »
Dell Dimensions 4100 computer with windows XP professional.
With two hard drives on it.

Here’s the story:
Last year we tried to install Norton Anti Virus. It would not update or recognize virus definitions.  So, we took it off. We thought it might have to do the GHOST contents  [saved after a past computer crash].  No help came from Norton. So, I just ignored it-- DUMB idea.   :-[

Anyway, the computer occasionally shuts itself down, won’t open Acrobat, occasionally runs slowly, etc.  So, I went online and scanned the system with Trend Micro’s Housecall.  It listed them as uncleanable from their online site.

It listed two Trojans and one worm [each listed with aliases]:
-Trojan.Spy.Kim
-Trojan:Win32/Revop.C (B, F, etc.)
I-Worm.Win332.Klez.H

Housecall offers ideas on manually deleting or removing the malware.  I tried to do it, but couldn’t find any files listed that they suggested to delete.  The Trojan_Revop was suppose to be removable from the Windows task manager. It wasn’t there.
I tried down loading the Process Explorer and couldn’t figure that out.  The worm was supposedly accessible from the Registry Editor with HKEY_LOCAL_MACHINE>SYSTEM>CurrentControlSet>Services. But in the right column all that is listed is:  Default      REG_SZ     (value not set).

So, how do I get these off the computer?
Do I have to pay someone to fix the computer?
Or, is it destroyed, as my dear, impatient husband is telling me?

I’m not a computer whiz, so a patient reply would be appreciated.
Thanks,
Mrs. H.

P.S. Yes, I have warned our teen not to download anything, nor open email attachments, so I’m not sure how they got there in the first place.  Our teen now has the Gateway and this another of hubby’s previous computers.

Mephisto_kur

  • Cortez the Killer
  • Nice Guy Eddie Cabot
  • Mr Black
  • *
  • Posts: 2913
  • Karma: +16/-5
  • Hi ho.
    • View Profile
    • Heavybrick
Re:How to remove 2 trojans and a Klez?
« Reply #1 on: June 11, 2004, 11:05:01 am »
Okay, first of all, a computer cannot be destroyed by a virus.  Viruses are loaded with the Operating System (in this case, Windows XP), and I know of only a very few viruses that actually attack Windows in such a way as to make it destroy hardware.

My suggestion would be to get the neighborhood computer geek to reload Windows XP from scratch.  That will clear off all viruses and spyware and malware you have on your computer.

Now, after that, your next needs are protection.  If Norton doesn't like your system, get McAffee.  There are a dozen virus scanners out there, and no one should be without one in this day and age.  A virus scanner is always the first thing I install on a new machine.  After you have a virus scanner installed, make sure you set up a Firewall.  This can be done in two ways:

1.  Buy one.  Looks like a hub, and most are preconfigured to keep you safe from the most common attack ports.
2.  Grab a software one.  I've had experience with Zonealarm, BlackIce Defender, and Tiny Personal.  All three are good, but Black Ice is one to avoid.  There are exploits and many viruses\trojans specifically target it.

If you have a cable modem or DSL, I *highly* recommend you do the first option.  Not only are they more complete than a software firewall, most come with extra ports for more machines - all of which remain hidden to your service provider, so they can't charge you extra.

At the very least, turn on Windows XP's built in piece of crap firewall.  It's better than nothing.

As for where to go for anti-virus help, always choose Symantec.  They make Norton Anti-virus, and are always on top of different variations.  Since they are a business anti-virus supplier, their instructions for removal or fix are always better than anyone else's (except maybe McAffee).

Tell your husband to stay the hell away from your computer.  If he's so impatient that he wants to chuck the thing when it gets a virus, he has no business having one in the first place.
« Last Edit: June 11, 2004, 11:05:33 am by Mephisto_kur »


Stingr

  • Marvin Nash
  • Mr Blond
  • *
  • Posts: 173
  • Karma: +2/-0
  • Do not taunt Happy Fun Ball.
    • View Profile
Re:How to remove 2 trojans and a Klez?
« Reply #2 on: June 11, 2004, 11:08:13 am »
First download Avast! Antivirus.  It's a really good free antivirus program that should be able to clean up those viruses.  If, for some reason, it doesn't work check on Symantec's Antivrus Research Center to see if there are removal tools for these viruses.  Remember,  you don't necesarily have to "clean" the infected files.  If the virus created them you can delete them instead.  Post the infected filenames here and I'll let you know if you can delete them or not.  

After you get the viruses cleaned up download Zone Alarm which is a free personal firewall.  This will keep out viruses that are transmitted in ways other than email.  

After you get all of this installed download Spybot - Search & Destroy which will scan for and get rid of any spyware you have on your computer which may be causing you to get viruses.  It works just like an antivirus program except it scans for spyware instead of viruses.  

I know this is a little light on the details so if you need help doing any of this just ask.
$xscreensaver-demo
attraction: domain error: forces on balls too great

Mephisto_kur

  • Cortez the Killer
  • Nice Guy Eddie Cabot
  • Mr Black
  • *
  • Posts: 2913
  • Karma: +16/-5
  • Hi ho.
    • View Profile
    • Heavybrick
Re:How to remove 2 trojans and a Klez?
« Reply #3 on: June 11, 2004, 11:15:00 am »
Hehe, yeah, what HE said.


Stingr

  • Marvin Nash
  • Mr Blond
  • *
  • Posts: 173
  • Karma: +2/-0
  • Do not taunt Happy Fun Ball.
    • View Profile
Re:How to remove 2 trojans and a Klez?
« Reply #4 on: June 11, 2004, 11:47:41 am »
No no...what HE said. :)
« Last Edit: June 11, 2004, 11:48:02 am by Stingr »
$xscreensaver-demo
attraction: domain error: forces on balls too great

nickc

  • Grown-up
  • Mr Blond
  • *
  • Posts: 244
  • Karma: +3/-0
  • I'm a llama!
    • View Profile
Re:How to remove 2 trojans and a Klez?
« Reply #5 on: June 11, 2004, 08:16:37 pm »
Thanks gentlemen I was wanting a goo free anti virus.
Say sumtin secksay

When you lose your mind, you free your life...

KillJoy

  • Trogdor!
  • Nice Guy Eddie Cabot
  • Mr Black
  • *
  • Posts: 1254
  • Karma: +4/-2
  • Mud-whistle!
    • View Profile
Re:How to remove 2 trojans and a Klez?
« Reply #6 on: June 11, 2004, 09:04:15 pm »
Thanks gentlemen I was wanting a goo free anti virus.

Then you gotta stop surfin' the adult sites...

Actually, AVG anti-virus is pretty good, too... although I would defer to Stingr if he recommends that other one...cuz Stingr is the guy who turned me on to AVG.

Ma:  If you're going to reload the OS (I recommend that you do), and you're going to get a local geek to help you, might I recommend that you define what your requirements are for this PC, and have the geek evaluate your other options.  If you run a different OS, you could have much less virus and spyware trouble in the future.  No other platform suffers as much targetted attacks as Windows.  Mac, Linux and BSD users rarely have these problems.  There are other options than Windows.  If you get your local geek to do it, ask them to recommend something based on your requirements.
« Last Edit: June 11, 2004, 09:13:13 pm by KillJoy »
"Dump tell no mandy!"

Stingr

  • Marvin Nash
  • Mr Blond
  • *
  • Posts: 173
  • Karma: +2/-0
  • Do not taunt Happy Fun Ball.
    • View Profile
Re:How to remove 2 trojans and a Klez?
« Reply #7 on: June 11, 2004, 10:38:08 pm »
Quote
Actually, AVG anti-virus is pretty good, too... although I would defer to Stingr if he recommends that other one...cuz Stingr is the guy who turned me on to AVG.

In my experience they are about the same quality in terms of protection.  I usually recommend Avast! because it has a very simple UI making it easy for the average user.
$xscreensaver-demo
attraction: domain error: forces on balls too great

nickc

  • Grown-up
  • Mr Blond
  • *
  • Posts: 244
  • Karma: +3/-0
  • I'm a llama!
    • View Profile
Re:How to remove 2 trojans and a Klez?
« Reply #8 on: June 13, 2004, 02:46:38 am »
Thanks gentlemen I was wanting a goo free anti virus.

Then you gotta stop surfin' the adult sites...

Actually, AVG anti-virus is pretty good, too... although I would defer to Stingr if he recommends that other one...cuz Stingr is the guy who turned me on to AVG.

Ma:  If you're going to reload the OS (I recommend that you do), and you're going to get a local geek to help you, might I recommend that you define what your requirements are for this PC, and have the geek evaluate your other options.  If you run a different OS, you could have much less virus and spyware trouble in the future.  No other platform suffers as much targetted attacks as Windows.  Mac, Linux and BSD users rarely have these problems.  There are other options than Windows.  If you get your local geek to do it, ask them to recommend something based on your requirements.

maybe not the average userage user just I had had just had the same problem with Nortron Amtivirus not loading   and was  using NOTRONANTIVIROUS PRO  which should have had two lincenses areements with it.


Just a bad deal out out of NORTON ANTIVIRUS  if u ask me......................


they get f-------------------

bye
Say sumtin secksay

When you lose your mind, you free your life...

Ma

  • Guest
Re:How to remove 2 trojans and a Klez?
« Reply #9 on: June 17, 2004, 12:21:46 pm »
Hi All,  When we return home on Sunday I'll try out the various things suggested and let you know what happened.  Thanks for these potential ideas.   Mrs. H