Forum Home
Press F1
 
Thread ID: 71838 2006-08-19 01:00:00 Win32: Kolweb virus craigdele (9370) Press F1
Post ID Timestamp Content User
479253 2006-08-19 01:00:00 The Avast Antivius program detects the Kolweb virus when I open a folder or sometimes use windows explorer.

I do the recommended and commit the virus to the chest. I have also deleted it other times. However on rebooting the virus reappears.

Can anyone provide me with some solutions please?

Dele
craigdele (9370)
479254 2006-08-19 01:13:00 Try this (http://www.simplysup.com/)

Download update it click on scan and then select the 3rd-7th option under the utils menu.
Speedy Gonzales (78)
479255 2006-08-19 14:15:00 Thanks but Trojan remover does not detect this virus.


After removing this virus with Avast it returns after a reboot.

Dele
craigdele (9370)
479256 2006-08-19 19:22:00 Run it again then go to the file menu / select scan running processes.

Anything it says is a trojan / nasty get it to rename it / delete it.
Speedy Gonzales (78)
479257 2006-08-19 21:35:00 when this virus is detected by Avast, does Avast report as being in system restore if so disable system restore reboot reable ( if you wish) beama (111)
479258 2006-08-19 22:26:00 when this virus is detected by Avast, does Avast report as being in system restore if so disable system restore reboot reable ( if you wish)
Instructions available here (faqf1.net.nz).
FoxyMX (5)
479259 2006-08-20 03:51:00 I would recommend:

disable system restore (FoxyMX's link above)
- full system scan with Avast
- download hijackthis from www.merijn.org
- run it and look for autostart registry keys, particularly this one:
HKEY_LOCAL_MACHINE\software\microsoft\windows\curr entversion\runonce 8j3m65.exe
Fix this one if you find it

If you are comfortable with regedit and deleting files in system folders, look for and remove the other registry entries and files as per this page:

www3.ca.com

Alternatively, install the 30 day trial of CA/eTrust PestPatrol as it claims to remove Kolweb:
consumerdownloads.ca.com
silvero (11011)
1