Re: Cannot remove virus

From: David H. Lipman (DLipman~nospam~_at_Verizon.Net)
Date: 04/29/05


Date: Fri, 29 Apr 2005 09:38:36 -0400

From: "Stuart Reed" <sr@stureed.co.uk>

| Hi David
|
| Thanks for your help but there was a problem with Sysclean: I couldn't
| download a missing file LPT$VPN.*
|
| Stuart

Stuart:

You didn't follow the directions proprly in "Trend Sysclean Method 1" so follow the
directions in "Trend Sysclean Method 2" as that simplifies the downloading and execution
process.

In addition, I have come up with the following alternate method of removing this infector...

1) Dump the contents of the IE Temporary Internet Folder cache (TIF)
       Start --> Settings --> Control Panel --> Internet Options --> Delete Files

       Dump the contents of the Mozilla FireFox Cache
       Tools --> Options --> Privacy --> Cache --> Clear

2) Disable System Restore
       http://vil.nai.com/vil/SystemHelpDocs/DisableSysRestore.htm

3) Download Pocket KillBox
       http://www.bleepingcomputer.com/files/spyware/KillBox.zip

       Extract killbox.exe from the ZIP file.
       Execute; KillBox.exe

       Click on Tools --> Select; Delete Temp Files.

       Choose; OK

         In the Full Path of File to Delete box, type the entire following line exactly

         C:\Windows\REGIST~\cabplay.dll

       Select; Replace on Reboot

       put a check in the box "Use Dummy"

       Click The Red circle and a white X

       When prompted to Replace on Reboot, click YES

       If prompted to Reboot Now, Click YES

       Allow the PC to shutdown

4) Reboot your PC into Safe Mode and shutdown as many applications as possible.
5) Using your NAV software, perform a Full Scan of your platform and clean/delete any
        infectors found
6) Restart your PC and perform a "final" Full Scan of your platform
7) Re-enable System Restore and re-apply any System Restore preferences,
        (e.g. HD space to use suggested 400 ~ 600MB),
8) Reboot your PC.
9) Create a new Restore point

* * * Please report back your results * * *

-- 
Dave
http://www.claymania.com/removal-trojan-adware.html
http://www.ik-cs.com/got-a-virus.htm


Relevant Pages

  • Re: A headache
    ... Download SYSCLEAN.COM and place it in that directory. ... If you are using WinME or WinXP, disable System Restore ... Restart your PC and perform a "final" Full Scan of your platform using both the ...
    (microsoft.public.security.virus)
  • Re: What is E_FAT19A,EXE ???
    ... Download Sysclean.com and place it in that directory. ... Using both the Trend Sysclean utility and Ad-aware, perform a Full Scan of your ... Restart your PC and perform a "final" Full Scan of your platform using both the ... Re-enable System Restore and re-apply any System Restore preferences, ...
    (microsoft.public.windowsxp.general)
  • Re: Says that svchost.exe is missing
    ... Download TrendMicro Sysclean by one of the following 2 methods ... Trend Sysclean Method 1 ... SYSCLEAN_FE automates the download and execution process of the Trend Sysclean Package. ... Re-enable System Restore and re-apply any System Restore preferences, ...
    (microsoft.public.windowsxp.general)
  • Re: clon.biz Hijacker
    ... Trend Sysclean Method 1 ... Trend Sysclean Package ... Download SYSCLEAN.COM and place it in that directory. ... Re-enable System Restore and re-apply any System Restore preferences, ...
    (microsoft.public.security.virus)
  • Re: possible virus
    ... Trend Sysclean Method 1 ... Trend Sysclean Package ... Download SYSCLEAN.COM and place it in that directory. ... Re-enable System Restore and re-apply any System Restore preferences, ...
    (microsoft.public.security.virus)