Results 1 to 9 of 9
Like Tree2Likes
  • 2 Post By Ceyfer √

Thread: is there a removal tool for win32/chepvil.k

  1. #1
    Newbie
    Overall activity: 0%

    Join Date
    May 2011
    Posts
    9
    Liked
    0 times
    Points
    781

    is there a removal tool for win32/chepvil.k

    need to work on win 7 x64

    TIA

  2. #2
    The Specialist *
    Overall activity: 76.0%

    Join Date
    May 2010
    Location
    KOLKATA
    Posts
    5,162
    Liked
    731 times
    Points
    47,580
    Which resident protection do you have ?? Download Hitman Pro and scan (Do not activate pro version until you found any virus)& Malwarebytes Anti-Malware make a scan. Clear your cache, cookie, temp file. Post a HijackThis log here.
    I don't need to know everything, I just need to know where to find it, when I need it.

  3. #3
    Newbie
    Overall activity: 0%

    Join Date
    May 2011
    Posts
    9
    Liked
    0 times
    Points
    781

    thanks

    i have malewarebytes and AvastIS windows defender
    but i was not paying attention in my yahoo account downloaded what i thought was a pdf scanned by yahoo's norton and it was an exe that look like a pdf iwill try hitman pro and get back to you i scanned with jotti duhhhhhh after i opened it a copy and avast did not detect but fsecure to name 1 of a few did detect i have full version of fsecure suite but have not installed on this pc will get back to you thanks again

  4. #4
    Rookie
    Overall activity: 7.0%

    Join Date
    Jan 2009
    Location
    Malaysia
    Posts
    2,138
    Liked
    24 times
    Points
    44,879
    Didn't avast detect it? If no, just submit the file to avast virus lab at virus(at)avast.com. It will be added to the next VPS update. Then I think avast should be able to remove it.

    If avast detect it, your system should be safe already as the file is move to quarantine.
    Thoughts are like a never ending ocean where it is deep, endless and dangerous

  5. #5
    Experienced User
    Overall activity: 0%

    Join Date
    Dec 2009
    Location
    INDIA
    Posts
    1,570
    Liked
    201 times
    Points
    28,006
    this specific problem cause building a file name pusk.exe ...
    one of the main reason for infection with this tool is " Downloading pirated stuff" or clicking over the unknown web links....
    use antivirus with " latest updates" ...
    F secure can detect it too..install..update it and scan the whole PC...
    else free Microsoft security essential is also gud..
    else.. hitman pro and malware bytes are very useful.. as said by Indra...
    Last edited by princeaniket; 05-28-2011 at 01:02 PM.
    "I am proud of my heart.. u know y?? It's played, loved, burnt & broken, but somehow it still Works."

  6. #6
    Guest
    Overall activity: 54.0%

    Join Date
    May 2007
    Location
    Philippines
    Posts
    4,006
    Liked
    710 times
    Points
    47,645
    Quote Originally Posted by lynxster View Post
    but i was not paying attention in my yahoo account downloaded what i thought was a pdf scanned by yahoo's norton and it was an exe that look like a pdf iwill after i opened it a copy and avast did not detect but fsecure to name 1 of a few did detect
    Worst thing always happens, when you let any unknown file slip away and executed it for good. The reason why most AV doesn't detect the attached malware file ( mostly trojan dropper/agents ) is because it is continuously design to defeat conventional scanners ( its detection algorithm ).

    And regarding with your concern win32/chepvil.k, my friend this is really a bad news:

    • A new spam campaign using UPS (United Parcel Service) as a social-engineering draw was initiated this week. The spammed message contains an attachment, detected as TrojanDownloader:Win32/Chepvil.I. The spam campaign actually started around March 16th 2011. The threat was originally detected as Backdoor:Win32/Hostil.gen!A (was Backdoor:Win32/Hostil.F). More specific signatures (TrojanDownloader:Win32/Chepvil.I and TrojanDownloader:Win32/Chepvil.J) were added on March 22nd 2011.

      Win32/Chepvil is a trojan that downloads other malware such as Rogue:Win32/Winwebsec, Rogue:Win32/FakeRean, Backdoor:Win32/Cycbot.B and VirTool:Win32/Injector.gen!BG. The retrieved malware is saved to the %TEMP% folder and then executed. Microsoft Malware Protection Center has noticed that detections over the past few days have gone from a handful to around 400k per day.

      ( Source: MMPC )


    Expect some nice foreign backdoors inside your box. It's cleaning time!
    "Stars and the Sun"


  7. #7
    Newbie
    Overall activity: 0%

    Join Date
    Jun 2011
    Posts
    1
    Liked
    0 times
    Points
    580
    Hi, I signed on to this forum, because when googling for key words:
    win32 chepvil.k
    I found this post, so decided to add my experience for the record.

    Just today, I'd gotten notice from HSN that something I purchased last week would be delivered by UPS.

    So it was only natural, that when I simultaneously noticed something from UPS in my SPAM Folder, I clicked on it (since YahooMail has been known to occasionally dump my legitimate email in SPAM.

    Oddly, it was a zip file, but I thought hey, UPS has always been so difficult for me to get normal customer service, that this is just another of their shtick.
    It was from: "UPS" adminsziobame at dhl.com
    It was to: an address other-than-mine (so not sure how it got to my email box!

    Bam - upon clicking I got these warming messages from MS Security Essentials, which I decided to ignore (due to MS so often "crying wolf").
    But Security Essentials persisted in not letting me download, and instead removed chepvil.k (that's how it's listed under the MS "Action Taken" listing, which their "Alert Level" pegged as a severe Trojan.

    I can't believe I was so absentmindedly stupid! (i.e. I usually ignore UPS stuff that's in my spam folder.
    If not for Security Essentials I'd be in hot water which happened to me plenty in the past.

  8. #8
    Righteous Dude
    Overall activity: 50.0%

    Join Date
    Aug 2009
    Location
    Bay Area, California
    Posts
    1,902
    Liked
    784 times
    Points
    25,870
    First [url=http://stopmalvertising.com/spam-scams/unsolicited-email-from-fedex-inc-installs-tdss-rootkit.html]some reading , then a [url=http://support.kaspersky.com/viruses/solutions?qid=208280684]tool . Good luck. A Guy

  9. #9
    Moderator
    Overall activity: 100.0%

    Join Date
    May 2010
    Location
    Eire /The Garden of Ireland
    Posts
    5,486
    Liked
    1750 times
    Points
    31,018
    Thank you A Guy for the link, unfortunately for many UPS was an ideal target as so many of us use their services thankfully the links i have used are directly from the account on the site and then to UPS for tracking.
    Stutz Bearcat

 

 

Similar Threads

  1. Fake antivirus removal tool
    By Networx in forum Spyware/Viruses
    Replies: 7
    Last Post: 12-27-2011, 11:33 AM
  2. BitDefender Free Removal Tool for TDL4 Available Now
    By leofelix in forum Security Bulletin
    Replies: 16
    Last Post: 07-31-2011, 03:27 PM
  3. Kaspersky Virus Removal Tool 2011
    By SAMEERA in forum Security Bulletin
    Replies: 3
    Last Post: 07-17-2011, 10:01 AM
  4. MSN Virus Removal Tool
    By maddoxx in forum Spyware/Viruses
    Replies: 2
    Last Post: 03-13-2010, 05:19 AM
  5. W32/Rungbu removal tool
    By duncan in forum Spyware/Viruses
    Replies: 2
    Last Post: 03-16-2007, 11:38 PM
All times are GMT +8. The time now is 09:45 AM.