| |
Antivirus World Forum
Re: How to delete Trojan.Startpage? Removal tool?
Posted By: rnfor1 In Response To: Re: How to delete Trojan.Startpage? Removal tool? (Roger)
Date: Sunday, 30 January 2005, at 6:04 p.m.
A bit of a pain as Norton 2005 kept annoyingly telling me it found the virus but could not do anything about it - pretty useless. Anyway, here is what I did:
1. Reboot your maching in safe mode (The old F8 trick)
2. Look for the offending proxy file (in my case this was located in "Documents and settings\Richard Nfor\Local settings\Temp\sp.dll")
3. Do *NOT* remove this file as the trojan will first check to see if it exists. Now simply change this file so it has no read/write/execute permission.
4. This is the hard bit: Go to your WINNT directory and search for any files that end in .dll that were created around the same time as the sp.dll file above. Rename each of these files. Do *NOT* remove them as I do not wish you to completely bollox up your system.
my own was called fpikfa.dll.
I also had some directory in system32/Catroot begining with {F750E6C3 which I renamed as junk.
5. If you are feeling realy brave and fancy your chances you may take on the evil empire (risking the consequences - I am talking here about regedit). Go to http://securityresponse.symantec.com/avcenter/venc/data/trojan.startpage.html and see what keys to delete from your registry.
6. Now restart your computer normally. Fingers crossed, you should have your life back.
Give this a go and see how you get on.
Enjoy.
PS/
I have to add that being a unix head, I had to download cygwin and do all the above as if in a unix environment using find/grep and the rest. If you are not familiar with unix, what I describe above can still be done in safe mode on windows.
| |
Antivirus World Forum is maintained by Administrator with WebBBS 5.12.