Tom's Guide | Tom's Hardware | Tom's Games
![]() |
![]() |
![]() |
I have a virus norton cannot quarantine, cure or delete..W32.Korgo.V...anyone have any info on it??? How to get rid of it?? Also---i keep getting 550 errors when trying to send email..Earthlink has had me go over configurations for 3 days now...NOW they tell me to get rid of my anti-virus protection because it is interfering?? Is this sane????

What actions did you take when Norton identified the virus? Did you turn system restore off and restart the computer and during the boot sequence enter the safe mode and then run Norton's scan while it?

Crash course in maunal virus removal.
assuming you can still use some of your computers functionality i here are some steps you can take to disable the virus and then proceed to delete it your self with out the use of any out side software.
this is a long thread but ive been fixing virus problems for years..please try to follow the instructions.
boot up the computer.. after it has finished booting hit ctrl+alt+del and the task mgr should open... click the tab that says "processes" in it will list all applications and services that either windows is running and that you are running denoted by the name that is displayed next to the running proccess.. to the left will be the process, next to it is the name of what activated it and after that is how much cpu time it is requiring to run.. the worst you can do here is close the wrong service causing your computer to restart with no side effects.. still what you want to do is look for any service that has w32. in front of it... that will be your virus highlight it and click end process.. it might reapear and it might not but this is the first efective way to stop a virus.. side note: it is ok to end all process that are next to YOUR USER NAME except for explorer.exe this is in fact the visual representation of windows that you see.. do not end anything that says SYSTEM next to it unless it has a W32. infront of it...
if you dont see it here dont worry follow the below steps any way
go to the run box in the start menu..
type in "msconfig" in the window that pops up select the start up tab..this will show you all applications that start up with your computer...it is OK to turn all of these off with out doing any damage to the operating system... this is a comon place that you will find that viruses use to start up with in computers.
Next there is a tab next to the start up tab called services...click on it and this will display all of the background services that start up with your computer that you never even see... CHECK the box that says "hide all microsoft services"...this will ensure your dont disable and key operating services.. only a few of the enteries should remain and one of them could possibly be your virus...it is ok to turn these off.. do not uncheck any of the microsoft services unless you know what your doing :)
after you have done all of that go back to the run box in the start menu and type in "regedit" this is where you must go to edit the registry which is another place viruses like to hide there start up seuquence
keep in mind all we are doing now is disable the virus.. after all this yuo still need to find it and delete..
this can be done later with a system searchnow that you are in reg edit click on these in this order
"HKEY_LOCAL_MACHINE"
"SOFTWARE"
"MICROSOFT"
"WINDOWS"
"CURRENT VERSION"
and "RUN"
what you will see on the left is all entries that are told to start up with your computer... you can safly turn all of these off with out any side affects.after you have done all this reboot the computer in safe mode by tapping f8 down when you first turn on the computer and selcting safemode
you want to repeat these step in safe mode to make sure the virus doesnt reactivate it self..
then do a search for w32. or korgo to see if you can find the file on your computer and delete it...
I hope this helps.. it is the long way for sure but it is much better when people arent so dependant on virus removal programs.

Great post, troublesum. I always worry about someone mucking about in the registry and suggest they back it up first. And I try to be specific. You say Sweet Image can safely turn off the programs in the RUN section, but does he/she know what turning them off means? They could interpret it as deleting.
This is not criticism -- far from it. It's a lucid explanation of how to get rid of a virus and should be helpful to everyone who doesn't know it already. I'm just suggesting it could be even more specific.
'Nuf said. Thanks.

well put i will try to be more specific...heh just didnt want to over complicate it as much as i already did

Go here and read this, it also contains the link for the removal tool...
http://securityresponse.symantec.com/avcenter/venc/data/w32.korgo.v.html
Iligitimi non carborundum est

![]() |
![]() |
![]() |

This post is quite old and has been locked from receiving new replies. Please create a new posting instead.
| Ads by Google |