Re: VIRUSES HELP! W32SWEN.A@mm and W32KLEZ.H@mm

Tech-Archive recommends: Repair Windows Errors & Optimize Windows Performance

From: Malke (malke_at_nospoonnotreally.com)
Date: 02/18/04


Date: Wed, 18 Feb 2004 05:00:35 -0800

larry wrote:

> go to
> http://www.grisoft.com/us/us_ts_removers.php
> look for their elkern tool. it runs in DOS off a floppy and will
> clean
> files that the Symantec cleaner won't get because it runs in Windows

This is incorrect information. The Klez removal tool from Symantec runs
in Windows. You need to first turn off System Restore and then run the
tool in Safe Mode.

Deborah, of course there is support available to you when you've made
the mistake of clicking on an attachment in email and gotten infected.
You can always call a good local computer repair person to clean up
your machine. I do this all the time. You are responsible for
practicing safe computing. Not opening attachments in email - no matter
*who* the email is from - is Rule #1.

>From your post, I would strongly suggest you call in outside help to get
your computer back in business.

Best of luck,

Malke

>
> Deborah Sweet wrote:
>> I run Windows XP home ed., on a Toshiba laptop, and find myself the
>> unlucky recipient of one infection of the W32.Swen.A@mm virus, AND of
>> THREE different attacks by the W32.Klez.H@mm virus. All were "caught"
>> by Symantec, and quarantined, but the program could not repair and
>> restore them. The first Klez infected Byf.exe, a TMP file of 90.6 KB.
>> Next infected by Klez was Scd.scr, another TMP file of 88.8KB.
>> Finally, Klez got to size.bat, also TMP, 88.9KB. Swen got to
>> gldtibhn.exe, a TMP file of 104KB. (of course, I have very little
>> idea of what these files are, what they do, or how important they are
>> to the running of my computer, which SEEMS to be fine, except for a
>> few little problems - documents which I had saved to my docs folder,
>> but are now blank, for instance, which I don't know whether or not
>> has anything to do with this).
>> I went to Symantec's site, where they give the information and
>> downloads to get rid of the viruses, and restore the files, and
>> about a ream of paper later, I am sitting here wondering if the
>> average person is capable of doing this? It seems that one set
>> of instructions leads to another, to another, to another....
>> Will I have to back up my registry? Will I have to un/reinstall NAV?
>> or un/reinstall Windows Installer? Am I going to lose information I
>> have worked years on? How difficult IS this to do? Is there any REAL
>> support for this process or are you basically on your own? Thanks,
>> Deborah Sweet

-- 
MS MVP - Windows Shell/User
Elephant Boy Computers
www.elephantboycomputers.com
"Don't Panic!"


Relevant Pages

  • RE: Annoying virus being mailed to me
    ... Details stolen from symantec www site. ... The worm also attempts to copy itself to the following folders on all the ... Infection Length: 65,536 bytes ... Windows 95, Windows 98, Windows NT, Windows 2000, ...
    (Security-Basics)
  • Re: Browser closes unexpectedly
    ... I totally rebuild the machine from bare metal. ... Where & how did you obtain Symantec AntiVirus? ... since expired and/or the machine's not been kept fully-patched at Windows ...
    (microsoft.public.windows.inetexplorer.ie6.browser)
  • Re: After SP2 and the LU Patches Norton Products Still Have a Panopoly of Problems
    ... Symantec would like you to pay to upgrade to their 2004 ... Microsoft Windows MVP/Tablet PC ... > test sites which had the worries, and since last night when Live Update ... > Microsoft Windows MVP/Tablet PC ...
    (microsoft.public.windowsxp.customize)
  • Re: need sound card driver
    ... Windows XP Home Edition Service Pack 3 Intel Corporation ... Missing Microsoft Security Hotfixes ... Symantec - Component Framework 1 ... Microsoft Corporation - Internet Explorer Version 8.00.6001.18702 * ...
    (microsoft.public.windowsxp.hardware)
  • Re: need sound card driver
    ... Windows XP Home Edition Service Pack 3 Intel Corporation ... Missing Microsoft Security Hotfixes ... Symantec - Component Framework 1 ... Microsoft Corporation - Internet Explorer Version 8.00.6001.18702 * ...
    (microsoft.public.windowsxp.hardware)