We’d like to remind Forumites to please avoid political debate on the Forum.

This is to keep it a safe and useful space for MoneySaving discussions. Threads that are – or become – political in nature may be removed in line with the Forum’s rules. Thank you for your understanding.

📨 Have you signed up to the Forum's new Email Digest yet? Get a selection of trending threads sent straight to your inbox daily, weekly or monthly!

Virus Removal - Killav/KLEZ

Hope someone can assist with the following.

My AVG Anti Virus software found the following virus today in

1) C:\ProgramFiles\ehc\hc2virus\WORM_KLEZ.htm

2) C:\ProgramFiles\helpcentre\EHC.zip\EHC\hc2\virus\WORM_KLEZ.htm

3) C:\ProgramFiles\helpcentre\EHC.zip

The program allowed me to move the first file to the Virus Vault but there isn’t an option to move 2 and 3 the status of which is "infected, embedded object" and
"infected, archive" respectively.

Is it ok to delete these files?


Thanks
«1

Comments

  • Browntoa
    Browntoa Posts: 49,612 Forumite
    Part of the Furniture 10,000 Posts Name Dropper Photogenic
    try this (you want the free version)

    http://www.superantispyware.com/

    do a full scan

    let it reboot the Pc if it asks at the end
    Ex forum ambassador

    Long term forum member
  • Browntoa
    Browntoa Posts: 49,612 Forumite
    Part of the Furniture 10,000 Posts Name Dropper Photogenic
    Ex forum ambassador

    Long term forum member
  • upload the file to virustotal where a number of anti virus sites can scan it - it will give you an idea if it is a false positive or not - https://www.virustotal.com/
  • Hotspur
    Hotspur Posts: 528 Forumite
    RS: The zip file in question was too large so it wouldn't upload to virustotal unfortunately.

    Browntoa: I previously ran trand housecall. Have now run superantispyware which found cookies AVG didn't find plus Spybot (nothing found) and Adaware (another tracking file) but nothing about WORM_KLEZ.

    I've run out of time tonight so I'll go through the sticky thread another day.

    Thanks for your posts.
  • Hotspur wrote: »
    RS: The zip file in question was too large so it wouldn't upload to virustotal unfortunately.

    How large is it, you can e-mail them;

    Sending files by email

    Create a new message with scan AT virustotal.com as destination address of your email.

    Write SCAN in the Subject field (write SCAN- if you do not want to distribute your sample to any AV company).
    Attach the file to be scanned. Such file must not exceed 10 MB in size. If the attached file is larger, the system will reject it automatically.
    You will receive an email with a report of the file analysis. Response time will vary depending on the load of the system at the time of placing your request.
  • Browntoa
    Browntoa Posts: 49,612 Forumite
    Part of the Furniture 10,000 Posts Name Dropper Photogenic
    I'm convinced it's a false alert
    Ex forum ambassador

    Long term forum member
  • Google finds nothings and neither has the other programs - I am fast forming the same opinion.
  • Hotspur
    Hotspur Posts: 528 Forumite
    How large is it, you can e-mail them;
    quote]
    The zip file is 19,506KB

    I am running AVG again to see if it picks it up this time.

    The 2 files found previously are located in c\programfiles\helpcentre and are the EHC zip file and an EHC.APM file. Also in the help centre folder are EHC Autoplay Media Studio Indigo Rose Corporation and a Data folder with 3 small files in.

    I couldn't find anything on google either so I hope you are right about the false positive although I was able to quarantine one file yesterday.

    Once again thanks for your help.
  • Hotspur
    Hotspur Posts: 528 Forumite
    AVG has just finished the scan and hasn't picked anything up this time.

    Is it ok to keep the superantispyware program on the PC as well. I'm probably wrong but I thought that having 2 antivirus programs could cause conflict issues or is that only is they are both running? I have the paid for AVG 7 with firewall which updates/runs automatically and has worked well so far.
  • skiddy2k
    skiddy2k Posts: 1,627 Forumite
    AVG and SAS are compatable with eachother... just add each to the other's TrustedZone/Exclusions.
    Yes, you're correct, its not recomended running 2 antivirus programs, but in your case, they're not both antiviruses, one's a antivirus and other other is an antispyware :)
This discussion has been closed.
Meet your Ambassadors

🚀 Getting Started

Hi new member!

Our Getting Started Guide will help you get the most out of the Forum

Categories

  • All Categories
  • 352.5K Banking & Borrowing
  • 253.7K Reduce Debt & Boost Income
  • 454.5K Spending & Discounts
  • 245.5K Work, Benefits & Business
  • 601.5K Mortgages, Homes & Bills
  • 177.6K Life & Family
  • 259.5K Travel & Transport
  • 1.5M Hobbies & Leisure
  • 16K Discuss & Feedback
  • 37.7K Read-Only Boards

Is this how you want to be seen?

We see you are using a default avatar. It takes only a few seconds to pick a picture.