| |
Antivirus World Forum
Thanks - that worked
Posted By: Victor In Response To: I got rid of mine (Kylev)
Date: Saturday, 25 September 2004, at 3:49 a.m.
Thanks Kylev. That worked for me. My trojan had created (I think) and installed itself into mtwirl.dll in the system32 folder. You couldn't touch it under normal conditions. For others:
1. Identify the infected file with an anti-viral.
2. Disable System Restore (important).
3. Re-boot in safe mode.
4. Drag the infected file to the desktop.
5. Delete and emtpy rubbish bin.
6. Normal re-boot.That kills the virus, but then you have to fix the damage it did. It leaves several registry keys and values affected, which continue to screw up Internet Explorer. I manually fixed some (see Symantec's instructions for removing Trojan.startpage, only to find out that the Trojan had also installed a hijack over IE by redirecting my searches. To fix that, I suggest downloading Ad-aware (available widely and freely) and run it. Then CWShredder (also available widley and freely), just to make sure. The hijack is clever in that it blocks access to CWShredder, but it didn't block access to Ad-Aware, so I downloaded and ran that first, which isolated the remaining hijack registry entries.
After you've done all the cleaning, go back to IE and delete cookies, temporary files, and history, and re-set your home page.
Finally, don't forget to re-enable System Restore.
| |
Antivirus World Forum is maintained by Administrator with WebBBS 5.12.