Chat LIVE With Programming Experts! There Are 23 Online Right Now...

Welcome to Dream.In.Code
Become an Expert!

Join 244,260 Programmers for FREE! Get instant access to thousands of experts, tutorials, code snippets, and more! There are 1,306 people online right now. Registration is fast and FREE... Join Now!




Klone Virus...need help [DreamInCode.net]

 
Reply to this topicStart new topic

Klone Virus...need help [DreamInCode.net], Virus Removal help

Israel
18 Dec, 2005 - 03:06 AM
Post #1

D.I.C Addict
Group Icon

Joined: 21 Nov, 2004
Posts: 649


Dream Kudos: 175
My Contributions
I've been trying to get rid of a virus I found on the computers here at work. Apparently while I was off someone flooded these things with trojans and the klone virus. AVG, Norton, Hijack This, and Adaware clean-up the trojans good. Unfortunately nothing seems to really get rid of the klone virus. I googled around for it too but came up empty handed. Oh, and I can't use Trend Micros Housecall because I can't get online after removing the trojans. Is anyone fimilar with how to get rid of this?

User is offlineProfile CardPM
+Quote Post


Amadeus
RE: Klone Virus...need Help [DreamInCode.net]
18 Dec, 2005 - 07:09 AM
Post #2

g++ -o drink whiskey.cpp
Group Icon

Joined: 12 Jul, 2002
Posts: 12,977



Thanked: 116 times
Dream Kudos: 25
My Contributions
Have you tried deleting the files manually?
User is online!Profile CardPM
+Quote Post

Israel
RE: Klone Virus...need Help [DreamInCode.net]
18 Dec, 2005 - 08:18 AM
Post #3

D.I.C Addict
Group Icon

Joined: 21 Nov, 2004
Posts: 649


Dream Kudos: 175
My Contributions
You mean through the command line? Or just the file without using the anti-virus?
User is offlineProfile CardPM
+Quote Post

Israel
RE: Klone Virus...need Help [DreamInCode.net]
18 Dec, 2005 - 07:04 PM
Post #4

D.I.C Addict
Group Icon

Joined: 21 Nov, 2004
Posts: 649


Dream Kudos: 175
My Contributions
I don't know about all that. Stopping the process won't necessarialy get rid of a virus. And I know sometimes you need to be out of safe mode for some types of trojans and such so the anti-virus can see it in its entirity. I also saw on google that people were complaining avg didn't get rid of the clone virus. Which I already tried anyway...
User is offlineProfile CardPM
+Quote Post

Lee Allers
RE: Klone Virus...need Help [DreamInCode.net]
18 Dec, 2005 - 09:25 PM
Post #5

D.I.C Regular
***

Joined: 6 Nov, 2001
Posts: 492


Dream Kudos: 4
My Contributions
There is a program called bazooka I think, you should try that out and see if it gets you anywhere
User is offlineProfile CardPM
+Quote Post

Israel
RE: Klone Virus...need Help [DreamInCode.net]
18 Dec, 2005 - 10:05 PM
Post #6

D.I.C Addict
Group Icon

Joined: 21 Nov, 2004
Posts: 649


Dream Kudos: 175
My Contributions
Got it!
User is offlineProfile CardPM
+Quote Post

Nova Dragoon
RE: Klone Virus...need Help [DreamInCode.net]
18 Dec, 2005 - 10:13 PM
Post #7

The Innocent Shall Suffer, Big Time
Group Icon

Joined: 16 Aug, 2001
Posts: 6,169



Thanked: 27 times
Dream Kudos: 515
Expert In: Python, Linux

My Contributions
What did you do to get the virus?

So that others searching will know
User is offlineProfile CardPM
+Quote Post

Israel
RE: Klone Virus...need Help [DreamInCode.net]
19 Dec, 2005 - 12:36 AM
Post #8

D.I.C Addict
Group Icon

Joined: 21 Nov, 2004
Posts: 649


Dream Kudos: 175
My Contributions
Well, honestly I'm not sure cause my boss worked on it while I was asleep (this happened to a computer at work) but he got rid of most of the infected files which allowed us to get back on the internet. From there I ran the free housecall scan from Trend Micro. This got the rest of it. Seems like Trend Micro and PC Pitstop have the most up-to-date definitions lately. These links go to free online scans. But if the virus won't let you online, they won't help you much...

This post has been edited by Israel: 19 Dec, 2005 - 12:39 AM
User is offlineProfile CardPM
+Quote Post

Monty
RE: Klone Virus...need Help [DreamInCode.net]
21 Dec, 2005 - 02:16 AM
Post #9

New D.I.C Head
*

Joined: 21 Dec, 2005
Posts: 1


My Contributions
Well I've just spend an evening removing the Klone virus from mine and my girlfriends PC - seems it came from the Kaaza installation program mad.gif

So the steps I took...

first I looked in the system32 folder for any exe's that were dated with that days date... klone if a self replicating trojan so it makes files

I deleted them - any that wouldn't delete were running as a process so I stopped that process in Task Manager

I did the same in the windows folder.

I checked and deleted and suspicious entries in the "run" and "runonce" registry keys

Finally to stop the virus coming back I noticed a strange entry in the registry

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\shell

which should only have a value "explorer.exe" had another program attached - so I put the value back to "explorer.exe"

rebooted - ran avg - everything was repaired

Hope this helps
User is offlineProfile CardPM
+Quote Post

spydir
RE: Klone Virus...need Help [DreamInCode.net]
21 Dec, 2005 - 03:16 AM
Post #10

New D.I.C Head
*

Joined: 10 Nov, 2005
Posts: 4


My Contributions
Next time use Kaspersky the best AV you can find.!! smile.gif
User is offlineProfile CardPM
+Quote Post

spydir
RE: Klone Virus...need Help [DreamInCode.net]
21 Dec, 2005 - 11:30 AM
Post #11

New D.I.C Head
*

Joined: 10 Nov, 2005
Posts: 4


My Contributions
I would say Zone Alarm Pro.!! smile.gif
User is offlineProfile CardPM
+Quote Post

Dark_Nexus
RE: Klone Virus...need Help [DreamInCode.net]
10 Jan, 2006 - 05:33 AM
Post #12

or something bad...real bad.
Group Icon

Joined: 2 May, 2004
Posts: 1,318



Thanked: 6 times
Dream Kudos: 625
My Contributions
Moved to software forum.
User is offlineProfile CardPM
+Quote Post

Thorian
RE: Klone Virus...need Help [DreamInCode.net]
10 Jan, 2006 - 08:34 AM
Post #13

Pirate Medic
Group Icon

Joined: 6 Jun, 2002
Posts: 5,750



Thanked: 8 times
Dream Kudos: 275
My Contributions
QUOTE(Monty @ 21 Dec, 2005 - 05:13 AM)
Well I've just spend an evening removing the Klone virus from mine and my girlfriends PC - seems it came from the Kaaza installation program mad.gif

So the steps I took...

first I looked in the system32 folder for any exe's that were dated with that days date... klone if a self replicating trojan so it makes files

I deleted them - any that wouldn't delete were running as a process so I stopped that process in Task Manager

I did the same in the windows folder.

I checked and deleted and suspicious entries in the "run" and "runonce" registry keys

Finally to stop the virus coming back I noticed a strange entry in the registry

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\shell

which should only have a value "explorer.exe" had another program attached - so I put the value back to "explorer.exe"

rebooted - ran avg - everything was repaired

Hope this helps

Hey Thanks monty. that is some good info.
User is offlineProfile CardPM
+Quote Post

Israel
RE: Klone Virus...need Help [DreamInCode.net]
11 Jan, 2006 - 04:09 AM
Post #14

D.I.C Addict
Group Icon

Joined: 21 Nov, 2004
Posts: 649


Dream Kudos: 175
My Contributions
Better run Hijackthis too! The klone virus left some browser hijackers on my box that the AV didn't pick up.
User is offlineProfile CardPM
+Quote Post

Fast ReplyReply to this topicStart new topic

Time is now: 7/4/09 11:23AM

Live Help!

Be Social

Dream.In.Code RSS Feed Dream.In.Code LinkedIn Group Follow Us On Twitter Fan Us On Facebook

Tutorials

Programming

Web Development

Reference Sheets

Code Snippets

DIC Chatroom

Bye Bye Ads

Monthly Drawing

Thumb Drive

Top Contributors

Top 10 Kudos This Month