Author Topic: Win32:Kavos?  (Read 8380 times)

0 Members and 1 Guest are viewing this topic.

smoothcrim

  • Guest
Win32:Kavos?
« on: February 26, 2009, 08:12:05 PM »
I keep on getting notifications that my computer is affected by a Win32:Kavos trojan.
I've done a boot scan every day for the last few days and I still keep getting the notification that its infected.
It seems to be stopping startup from happening. As only a few startup options load e.g. my zone alarm firewall
and then the computer becomes non responsive.

Also, I've been getting an error saying that my C:/ drive isn't 'able to run in Win32 mode'.

Can someone please help me?

Offline Lisandro

  • Avast team
  • Certainly Bot
  • *
  • Posts: 67194
Re: Win32:Kavos?
« Reply #1 on: February 26, 2009, 08:55:44 PM »
I suggest:

1. Clean your temporary files.
2. Schedule a boot time scanning with avast with archive scanning turned on. If avast does not detect it, you can try DrWeb CureIT! instead.
3. Use SUPERantispyware, MBAM or Spyware Terminator to scan for spywares and trojans. If any infection is detected, better and safer is send the file to Quarantine than to simple delete them.
4. Test your machine with anti-rootkit applications. I suggest avast! antirootkit or Trend Micro RootkitBuster.
5. Make a HijackThis log to post here or this analysis site. Or even submit the RunScanner log to to on-line analysis.
6. Disable System Restore and then reenable it again.
7. Immunize your system with SpywareBlaster.
8. Check if you have insecure applications with Secunia Software Inspector.
The best things in life are free.

Offline polonus

  • Avast Überevangelist
  • Probably Bot
  • *****
  • Posts: 33938
  • malware fighter
Re: Win32:Kavos?
« Reply #2 on: February 26, 2009, 10:10:06 PM »
Hi smoothcrim,

There is a good removal procedure to be found here:
http://techsalsa.com/steps-to-remove-win32killav-kitrj-and-win32kavostrj-virus/

polonus
Cybersecurity is more of an attitude than anything else. Avast Evangelists.

Use NoScript, a limited user account and a virtual machine and be safe(r)!