Author Topic: trojan LOREZ  (Read 3571 times)

0 Members and 1 Guest are viewing this topic.

Dantou

  • Guest
trojan LOREZ
« on: September 18, 2004, 11:43:42 AM »
Avast4 have found "LOREZ" on 435 files "exe". But Avast don't repare this files. Who can help me.
Thanks Dantou

Offline Eddy

  • Avast Evangelist
  • Maybe Bot
  • ***
  • Posts: 31072
  • Watching (over?) you
    • Malware removal, Biljart and other things.
Re:trojan LOREZ
« Reply #1 on: September 18, 2004, 01:21:47 PM »
Move them to the chest. You may have to run a boottime scan for it to do so.

Offline RejZoR

  • Polymorphic Sheep
  • Serious Graphoman
  • *****
  • Posts: 9412
  • We are supersheep, resistance is futile!
    • RejZoR's Flock of Sheep
Re:trojan LOREZ
« Reply #2 on: September 18, 2004, 01:25:56 PM »
If avast! says they are trojans,you can delete them. Trojans don't infect anything. Also consider about Eddy's second advice...
Visit my webpage Angry Sheep Blog

Dantou

  • Guest
Re:trojan LOREZ
« Reply #3 on: September 19, 2004, 07:47:45 PM »
Hi
Rundll and rundll32.exe are infected, as a great number of the .exe files and IO system! . Avast Home don't succeed to repare or supress them. When i try to supress manually, or put inthe chest, rundll32 keep windows from doing so. And, if i want to suppress then on dos, i'll be obliged to re-format and i'll lost all datas!
Help
Thanks Dantou

whocares

  • Guest
Re:trojan LOREZ
« Reply #4 on: September 19, 2004, 08:43:09 PM »
Hi,

if you delete the files, your system is gone; if you move them, your system won'lt load/boot properly next time

@Eddy: this is a file infector which only works on Win95/98/ME, so no boottime scan

What Win do you have anyway, 98, 98 or ME.. ?
If ME, going back to a CLEAN RESTORE point prioer to infection would be easiest..

Otherwise:
--> Read on proper Cleaning/repairing/Disinfecting of
 Win95:Lorez
here: VGREP
(items 12-18)
--> The red links to Trendmicro, Mcafee and Symantec are usually the most helpful, e.g. these ones..:

1) Cleaning via OnlineScan:
http://www.trendmicro.com/vinfo/virusencyclo/default5.asp?VName=PE_LOREZ

2) http://securityresponse.symantec.com/avcenter/venc/data/w95.lorez.html
(how to replace Kernel32.dll

Or use AV-Boot-CDs/disks to Clean/Repair/disinfect, e.g.
- Avast BART-CD
- F-Prot for DOS together with CLEAN, write-protected WIN-Startdisk
- www.centralcommand.com ->A Download -> AV-Boot-CD/disks
(all these tools need of course be fabricated on a different, CLEAN PC)

Maybe you'd then still have to replace Kernel32.dll with a Clean! copy
-> See above symantec link
 ;)
« Last Edit: September 19, 2004, 08:47:35 PM by whocares »