»
 

Go Back   ResellerRatings Store Ratings > ResellerRatings Forums > Tech Support

Reply
 
LinkBack Thread Tools Display Modes
Old 02-10-2004, 09:06 AM   #1 (permalink)
Registered User
 
Bill in SD, CA's Avatar
 
Join Date: Oct 2002
Location: Bottom left of U.S.
Posts: 4,714
Bill in SD, CA is on a distinguished road
Help With Virus Removal

Not for me but for a friend.

Got 2 viruses here: W32.Randex.gen and Backdoor.Ranky.

From Symantec:

W32.Randex.gen

and

Backdoor.Ranky

Seems like the only way to remove them is in safe mode and then go into regedit and manually remove the references to them.

Anyone with experience on this?

Will there be multiple references to them in the registry?

Would it be safe to do both at the same time or better to do one at a time?

Thanks,

Bill

Bill in SD, CA is offline   Reply With Quote
Old 02-10-2004, 09:16 AM   #2 (permalink)
Registered User
 
Martoch's Avatar
 
Join Date: Mar 2002
Location: Ft. Walton Beach, FL
Posts: 4,056
Martoch is on a distinguished road
Send a message via AIM to Martoch
Haven't had to edit registry entries to remove viruses before...but, whatever you do, export your registry first!

You can open your registry and do a "find" for any references to those nasty buggers...not sure where they would be hiding, but a search should find them all.

Good luck my friend!


EDIT:

Hmm...should be very easy if you follow Symantec's instructions.
Quote:


Click Start, and then click Run. (The Run dialog box appears.)

Type regedit
Then click OK. (The Registry Editor opens.)
Navigate to the key:
HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\Curr entVersion\Run

In the right pane, delete any values that refer to the worm files, which were detected in step 4.

Exit the Registry Editor.

Last edited by Martoch; 02-10-2004 at 09:19 AM.
Martoch is offline   Reply With Quote
Old 02-10-2004, 09:23 AM   #3 (permalink)
Registered User
 
Join Date: Jun 2003
Location: Boston, MA
Posts: 18
TrendyMartini is on a distinguished road
Send a message via AIM to TrendyMartini
TrendMicro gives pretty good removal instructions..

For BKDR_RANKY,here

That worm drops itself in C$\WINNT\System32, as the file MSMONK32.EXE, and will show up in the registry once as Microsoft Windows Runtime DLL Services=msdevdll32.exe

For W32.Randex.gen, here

Hope thats helpful, Good luck!


Last edited by TrendyMartini; 02-10-2004 at 09:27 AM.
TrendyMartini is offline   Reply With Quote
Old 02-10-2004, 09:24 AM   #4 (permalink)
Registered User
 
Bill in SD, CA's Avatar
 
Join Date: Oct 2002
Location: Bottom left of U.S.
Posts: 4,714
Bill in SD, CA is on a distinguished road
One thought .........................

Would a "registry cleaner" find them after deleting the files?

Bill
Bill in SD, CA is offline   Reply With Quote
Old 02-10-2004, 09:27 AM   #5 (permalink)
Registered User
 
Martoch's Avatar
 
Join Date: Mar 2002
Location: Ft. Walton Beach, FL
Posts: 4,056
Martoch is on a distinguished road
Send a message via AIM to Martoch
Shouldn't find them after you manually delete them...all a registry cleaner does is automatically find/remove items for you.
Martoch is offline   Reply With Quote
Old 02-10-2004, 10:01 AM   #6 (permalink)
Registered User
 
Join Date: Oct 2001
Posts: 6,533
John Prophet is on a distinguished road
sometimes symantec and others make "tools" for removal of viruses..have you checked symantecs site yet?
__________________
"Even a fool is thought to be wise if he is silent"
John Prophet is offline   Reply With Quote
Old 02-20-2004, 02:34 AM   #7 (permalink)
Registered User
 
Join Date: Feb 2004
Posts: 11
ppelliniq is on a distinguished road
Help with Virus Removal

John is correct, you can go to www.symantec.com (or McAfee's site) and use their free virus removal tools, even if you don't own their product.

My brother's was unaware that his friend who owned a local computer business, who built and sold him a computer with software did not install any virus program (would never recommend him myself), and couldn't get rid of the virus for him when called 2 months ago. I went to symantec on his computer, ran their free virus checker, it found the virus, ran their free removal tool from the site, and computer's been fine ever since.

Of course I told my brother, go out tomorrow and get a virus program, especially with a cable modem.
ppelliniq is offline   Reply With Quote
Old 03-19-2004, 12:21 AM   #8 (permalink)
Registered User
 
Join Date: Mar 2004
Posts: 1
annierenee is on a distinguished road
Kids w32.randex.gen

I was following all the messages everyone put in about this virus. However I still have one problem. I keep getting this virus popup from norton about w32.randex.gen. I went through the steps to remove it, only it doesn't show up on my computer. Does this mean that something has blocked it from actually settling down in the computer? Or am I missing something? Even though I don't see msdevdll32.exe anywhere that it should be.. I'm still getting the pop up. Nothing has went wrong with my computer that I know of yet other than the popups. Thanks, Annie
annierenee is offline   Reply With Quote
Reply




Currently Active Users Viewing This Thread: 1 (0 members and 1 guests)
 
Thread Tools
Display Modes

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is On
HTML code is Off
Trackbacks are On
Pingbacks are On
Refbacks are On


Most Active Discussions

Recent Discussions

All times are GMT -6. The time now is 10:47 AM.