Go Back   PCMech Forums > Help & Discussion > Networking & Online Security

Need Some Help? Type Your Keywords Here:

Reply
 
LinkBack Thread Tools Search this Thread Rate Thread Display Modes
Old 03-04-2003, 08:42 PM   #1
Member (7 bit)
 
msolheim's Avatar
 
Join Date: Nov 2000
Location: Seattle
Posts: 119
Can't Install AV software or online scan

Buddy's computer seems to have a virus.
His inbox is filled with "undeliverable" mail from his ISP from
emails he didn't send out. Sounds like a virus.

When he tried to install Norton it started the install process,
then just kicked him out. He tried the online scan at symantec's
site and was kicked off the site.

Anyway to find out what virus this is and remove manually?

I'm going to have him try housecall site. Not real confident that
will work either.

Any ideas?

thanks
Mike
msolheim is offline   Reply With Quote
Old 03-04-2003, 08:48 PM   #2
Member (12 bit)
 
not important's Avatar
 
Join Date: Jul 2002
Location: Illinois
Posts: 3,557
This is a good place also.
http://www.trendmicro.com/en/home/us/enterprise.htm
not important is offline   Reply With Quote
Old 03-05-2003, 01:44 AM   #3
Member (12 bit)
 
Redo40's Avatar
 
Join Date: Jan 2002
Location: Central Arkansas
Posts: 2,170
What operating system? If you can get into DOS, try F-Prot for DOS , here are instructions for setting up the floppies, you will also need a boot disk.
__________________
Roger

"Our greatest glory is not in never falling, but in rising every time we fall."
-Confucius
Redo40 is offline   Reply With Quote
Old 03-05-2003, 09:14 AM   #4
Member (7 bit)
 
msolheim's Avatar
 
Join Date: Nov 2000
Location: Seattle
Posts: 119
Just as I thought,
housecall did not work either, was kicked off the site.

Redo, thanks for the site. I've forgotten all about f-prot.
I remember back in win3.11 that was the shiznit!

I'll let you know what happens.

Also, I had him print off one of the emails that was returned
by is ISP. It had attachements, ATT00020.DAT & New Image().eml

Does this mean anything to anyone?

thanks
Mike
msolheim is offline   Reply With Quote
Old 03-05-2003, 09:46 AM   #5
Banned
 
morriswindgate's Avatar
 
Join Date: Jul 2000
Location: Bakersfield,CA
Posts: 7,761
http://lists.ulv.edu/pipermail/route...st/000243.html
morriswindgate is offline   Reply With Quote
Old 03-05-2003, 09:48 AM   #6
glc
Forum Administrator
Staff
Premium Member
 
glc's Avatar
 
Join Date: May 2000
Location: Joplin MO
Posts: 37,777
Run msconfig and list everything in the startup - I might be able to recognize what virus it is by an entry in there - and by disabling it you may be able to get a good housecall or Norton install. I'm guessing it's probably Klez or Yaha.
glc is offline   Reply With Quote
Old 03-06-2003, 08:18 AM   #7
Member (7 bit)
 
msolheim's Avatar
 
Join Date: Nov 2000
Location: Seattle
Posts: 119
ok
the f-prot on floppy didn't work. I followed their instructions copied the listed files to disk 1 & 2. When it runs it ask for disk with the and when asks for the disk with "sign.def" which is disk 2. put that in then it asks for "sign2.def", put in disk 1 and it
ask for a command module of some sort. Don't know what going on.

MSconfig list looks good, except a line for "winkuko.exe" and "Load=". Tried unchecking all lines, restarting and trying an online scan with no results.

mike
msolheim is offline   Reply With Quote
Old 03-06-2003, 10:06 AM   #8
glc
Forum Administrator
Staff
Premium Member
 
glc's Avatar
 
Join Date: May 2000
Location: Joplin MO
Posts: 37,777
winkuko.exe is the virus.

You got the Klez. Download the removal tool:

http://securityresponse.symantec.com...er/FixKlez.com

Run it in safe mode.
glc is offline   Reply With Quote
Reply

Bookmarks

Still Need Help? Type Your Keywords Here:


Thread Tools Search this Thread
Search this Thread:

Advanced Search
Display Modes Rate This Thread
Rate This Thread:

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is On
HTML code is On
Trackbacks are On
Pingbacks are On
Refbacks are On



All times are GMT -5. The time now is 07:22 PM.
Powered by vBulletin® Version 3.8.7
Copyright ©2000 - 2012, vBulletin Solutions, Inc.
SEO by vBSEO 3.6.0 PL2