Hello.

Microsoft Antispyware found Trojan.KillReg on my system. Yesterday I
discovered Trojan.KillReg when Microsoft Antispyware did a scheduled scan of
my system and I deleted the trojan.

However today Microsoft Antispyware found it again so this time I've
quarantined it. If it comes back how can I remove it from my system?

I try to be careful about my security. I surf the net using a limited
account in XP and I even use my HOSTS file to block sites.

I have XP home edition with SP2.
AVG antivirus (up to date)
ZoneAlarm.
Microsoft Antispyware.
Spybot S&D.
SpywareBlaster.
MailWasher.


--
To reply via email, Remove "UNTRUE" and replace "INVALID" with .co.uk
_ _ _

By three methods we may learn wisdom: First, by reflection, which is
noblest; Second, by imitation, which is easiest; and third by experience,
which is the bitterest.
--Confucius--

Re: Trojan problem by Frank

Frank
Sun Aug 07 21:35:52 CDT 2005

"Diatonic_Muttley" <carer@UNTRUEtiscali.INVALID> wrote in message
news:%23REwfA5mFHA.2156@TK2MSFTNGP14.phx.gbl
> Hello.
>
> Microsoft Antispyware found Trojan.KillReg on my system. Yesterday I
> discovered Trojan.KillReg when Microsoft Antispyware did a scheduled
> scan of my system and I deleted the trojan.
>
> However today Microsoft Antispyware found it again so this time I've
> quarantined it. If it comes back how can I remove it from my system?
>
> I try to be careful about my security. I surf the net using a limited
> account in XP and I even use my HOSTS file to block sites.
>
> I have XP home edition with SP2.
> AVG antivirus (up to date)
> ZoneAlarm.
> Microsoft Antispyware.
> Spybot S&D.
> SpywareBlaster.
> MailWasher.

Run Microsoft Anti-Spyware in Safe Mode.

--
Frank Saunders, MS-MVP, IE/OE
Please respond in Newsgroup only. Do not send email
http://www.fjsmjs.com
Protect your PC
http://www.microsoft.com./athome/security/protect/default.aspx
http://defendingyourmachine.blogspot.com/



RE: Trojan problem by Pandaman

Pandaman
Mon Aug 08 05:14:01 CDT 2005

MS Antispyware is BETA version.Beta means not completed,so it cannot remove
all the junk it found.So I recommend you not to use it while it is still in
BETA.

If you want follow these malware removal instructions that should help you
Before that ,you should know that you must not use more than one firewall.
Your Win XP with SP2 has built-in firewall (Windows Firewall ) so if you use
Zone Alarm,disable Windows Firewall)
Control Panel ->Windows Firewall.However ,if you want to use Windows
Firewall,uninstall Zone Alwarm and check the Exception list in Windows
Firewall.

Now the instructions:
General malware removal instructions

1. Delete all Temporary Internet Files
For IE's Temporary Internet Files
Goto Start->Settings->Control Panel->Internet Options

There ,on the General Tab you will see where you can delete temporary
files,cookies,history
Delete them all.

2. Run Disc Clean up
This is very useful Windows system function that allows you to delete/remove
all unnecessary
things from your computer,such as programs and components which havenâ??t been
used for months,temporary and internet temporary files, ,java applets and
stuff like that.

Start -> Programs -> Accessories -> System Tools -> Disc Cleanup

Make sure you have checked Downloaded program files, Temporary files,
Temporary
internet files ,Recycle bin, Web Client/Publisher content


3. Remove spywares ,adwares ,hijackers and other junk

Download Spybot Search & Destroy and Ad-aware SE Personal

http://www.lavasoftusa.com/software/adaware
and
http://www.safer-networking.org/microsoft.en.html

These programs are free of charge, they are compatiable to each other and
also recommended by Microsoft, so use them together.
Be sure to update them before running.
You can also scan in Safe Mode.

4. How to boot your computer in Safe Mode
Do this by repeatedly typing F8 while Windows is starting.
Then you'll open the BIOS menu where you can choose SAFE MODE
(If you are XP user ,find more about Safe Mode in Help and Support Center
; Start-Help and Suport)


5. Scan all your system with antivirus software
Use only 1 av software!!!
( If you do not have an av software,see tip number 6 in protecton steps and
you will see how to get one )

Before scanning make sure all the security settings are turned ON
Make sure the program is updated before running ! Youâ??d rather scan in Safe
Mode,too.

Also goto
http://www.pandasoftware.com/products/activescan/com/activescan_principal.htm
This is PAnda Software free Active Scan where you'll be able to check all
your system for ALL KIND of security threats and also destroy.
Remember...it is free! :)

6. System Restore (for XP and ME only)

If you are running Windows ME or XP,
you have to disable/enable System Restore
AFTER the system is clean of all kind of malware because malware will be in
Restore Points.

Right click on My Computer->Properties->System Restore
Check Turn off system restore.Click OK
Then again Right click on My computer->Properties->System Restore
Uncheck Turn off system restore

7. Windows Update
Download all the security updates - Critical updates with Express install.
Start -> Windows Updates
or
http://windowsupdate.microsoft.com

8. Run an internet firewall <<Use only one firewall ! >>

If you have Windows XP >>>
It has different types of integrared firewall protection :
Internet Connetion Firewall (ICF) for SP1
and Windows Firewall (WF ) for SP 2.
Both can protect you with no need to use separate software firewall.
I advize you to use only Windows Firewall which is easy to use and also good.
Good luck!

Re: Trojan problem by Diatonic_Muttley

Diatonic_Muttley
Mon Aug 08 14:09:38 CDT 2005

Thanks for the instructions Panda_man, I will give them a go.

BTW Microsoft AntiSpyware quarantine appears to have worked. There are no
more recorded instances of Trojan.KillReg on my system.

Here is the info regarding the file according to Microsoft AntiSpyware
c:\system volume
information\_restore{791c461d-ad30-48c5-af08-8499e0a1490a}\rp1021\a0217743.exe

If this quarantine works like AVG antivirus it should be able to permanently
remove the offending file?

As for XP's firewall. I've read in one or two PC magazines and other
security related news that XP's firewall is not as effective at protecting
from outbound threats contacting the internet from your PC as it is for
inbound threats.

So I have chosen to disable XP's firewall in favour of ZoneAlarm which I
have used for years.

Panda_man wrote.
Download Spybot Search & Destroy and Ad-aware SE Personal.

I forgot to include Ad-aware SE Personal to my original list of
security/privacy tools. However I don't use it as often as I used to, since
they disabled the auto scan feature in the SE free version. Hence my
relying more on Spybot Search & Destroy.

I also used to use SpywareGuard from Javacool until I installed Microsoft
AntiSpyware, which performed the same task and more.

I also keep CWShredder & S.T.I.N.G.E.R. updated just in case.

I don't know how this Trojan could have got past my defences as I always
keep them updated. But then again companies and governments with even
better security fall foul from time to time.

I guess that's some consolation. :)


--
To reply via email, Remove "UNTRUE" and replace "INVALID" with .co.uk
_ _ _

By three methods we may learn wisdom: First, by reflection, which is
noblest; Second, by imitation, which is easiest; and third by experience,
which is the bitterest.
--Confucius--