Sunday, July 26, 2009

A really, really bad trojan/virus: W32.Lovgate.AC@mm

I found this really bad trojan on my father's computer. It's relatively old, but what it can do is a nightmare. I wonder if this was what was wrong with Mike's computer.

Here's a link to a description of this thing: link. To summarize, it decapitates your computer, destroys part of your registry, and starts sending emails to your email list. It's extremely difficult to get all of it out. You have to use several programs to clean up everything. And... well, read on.

The symptom that alerted me to the problem was when I ran the Glary Utilities Startup routine and found the program TKBELLEXE.EXE as a program that runs when the computer starts. I looked that up and found it was associated with this trojan. I ran SpyBot Search and Destroy, the free version, and got a bunch of entries that talked about MyWebSearch. A couple of entries referenced this trojan.

It's always important to take the SpyBot warning seriously, but to really research the entries it identifies. That's because SpyBot can have "false positives" or/and identify some entries that are technically "spyware" but that you have chosen to use on your computer; ie, you have accepted the risk of sharing some of your personal info.

I discovered that I could not install Windows (security) updates. Every time I tried to get an update, even manually, the update would fail. I got a couple of different messages, one giving an error code of 0x80240020.

That was the clincher, as far as I was concerned, that there was something majorly wrong.

So, after a couple day tour of duty with Windows support, I've learned how to remove this monster and fix the registry so download will work.

If you have trouble with Windows updates, and you get an error that looks something like above, it is time to contact me. I'll save you a lot of time, a whole lot of time, and a lot of money fixing the problem.

No comments:

Post a Comment

Printfriendly

Print Friendly and PDF