A Windows XP help forum. PCbanter

If this is your first visit, be sure to check out the FAQ by clicking the link above. You may have to register before you can post: click the register link above to proceed. To start viewing messages, select the forum that you want to visit from the selection below.

Go Back   Home » PCbanter forum » Microsoft Windows XP » General XP issues or comments
Site Map Home Register Authors List Search Today's Posts Mark Forums Read Web Partners

Trojan Horse Startpage.16.BD Virus



 
 
Thread Tools Display Modes
  #1  
Old March 23rd 05, 12:54 AM
external usenet poster
 
Posts: n/a
Default Trojan Horse Startpage.16.BD Virus

I could not open my IE6 and Windows Explorer because my AVG AntiVirus program always says: While opening files; C:\Document and Setting\Rino\Local Setting\Temp\se.dll, I clicked OK button and rundll windows says; Error Loading C:\Docume~1\Rino\Local~1\Temp\se.dll; Access is denied, I clicked OK button.

My AVG AntiVirus program indicated a 'Trojan Horse Startpage.16.BD' virus infected my se.dll file above. No matter how many times I deleted it or put it in Virus Vault it always built-up again! I knew you might ask me how I could see inside my PC without using Windows Explorer? Well, I used Search and I used My Computer Icon and select the 'se.dll' and press Ctrl+Delete it. Even my AVG has several file of repeated 'Trojan Horse Startpage.16.BD virus' in the virus vault. I even deleted all files inside my Temp folder.

Please fear not because I used another PC to send this call for help. TIA
Ads
  #2  
Old March 23rd 05, 01:37 AM
Rick \Nutcase\ Rogers
external usenet poster
 
Posts: n/a
Default Trojan Horse Startpage.16.BD Virus

Hi,

Try scanning and deleting the file in Safe mode, where it is not active. How
to start in Safe mode:
http://www.rickrogers.org/fixes.htm#Safe%20mode

--
Best of Luck,

Rick Rogers, aka "Nutcase" - Microsoft MVP
http://mvp.support.microsoft.com/
Associate Expert - WindowsXP Expert Zone
www.microsoft.com/windowsxp/expertzone
Windows help - www.rickrogers.org

" R I N O " wrote in message
...
I could not open my IE6 and Windows Explorer because my AVG AntiVirus
program always says: While opening files; C:\Document and
Setting\Rino\Local Setting\Temp\se.dll, I clicked OK button and rundll
windows says; Error Loading C:\Docume~1\Rino\Local~1\Temp\se.dll; Access is
denied, I clicked OK button.

My AVG AntiVirus program indicated a 'Trojan Horse Startpage.16.BD' virus
infected my se.dll file above. No matter how many times I deleted it or
put it in Virus Vault it always built-up again! I knew you might ask me
how I could see inside my PC without using Windows Explorer? Well, I used
Search and I used My Computer Icon and select the 'se.dll' and press
Ctrl+Delete it. Even my AVG has several file of repeated 'Trojan Horse
Startpage.16.BD virus' in the virus vault. I even deleted all files inside
my Temp folder.

Please fear not because I used another PC to send this call for help. TIA



  #3  
Old March 23rd 05, 02:17 AM
external usenet poster
 
Posts: n/a
Default Trojan Horse Startpage.16.BD Virus

Thank You Rick, I'm scanning the infected PC and I'll report my result later. Oops! My typo
--- it should be Shift+Delete and not Ctrl +Delete . . . Sorry.

--Rino


"Rick "Nutcase" Rogers" wrote in message ...
Hi,

Try scanning and deleting the file in Safe mode, where it is not active. How
to start in Safe mode:
http://www.rickrogers.org/fixes.htm#Safe%20mode

--
Best of Luck,

Rick Rogers, aka "Nutcase" - Microsoft MVP
http://mvp.support.microsoft.com/
Associate Expert - WindowsXP Expert Zone
www.microsoft.com/windowsxp/expertzone
Windows help - www.rickrogers.org

" R I N O " wrote in message
...

I could not open my IE6 and Windows Explorer because my AVG AntiVirus
program always says: While opening files; C:\Document and
Setting\Rino\Local Setting\Temp\se.dll, I clicked OK button and rundll
windows says; Error Loading C:\Docume~1\Rino\Local~1\Temp\se.dll; Access is
denied, I clicked OK button.

My AVG AntiVirus program indicated a 'Trojan Horse Startpage.16.BD' virus
infected my se.dll file above. No matter how many times I deleted it or
put it in Virus Vault it always built-up again! I knew you might ask me
how I could see inside my PC without using Windows Explorer? Well, I used
Search and I used My Computer Icon and select the 'se.dll' and press
Shift+Delete it. Even my AVG has several file of repeated 'Trojan Horse
Startpage.16.BD virus' in the virus vault. I even deleted all files inside
my Temp folder.

Please fear not because I used another PC to send this call for help. TIA


  #4  
Old March 23rd 05, 03:21 AM
external usenet poster
 
Posts: n/a
Default Trojan Horse Startpage.16.BD Virus

Hello Rick,
I'm sorry we didn't eliminate the tricky virus. I let it scanned my 3 hard dives and found NOTHING or No Virus! (my virus definitions is only 1 day old). I even did it manually by deleted all my files inside Temp folder again even though I didn't find the culprit 'se.dll' file in Safe Mode. Yes, I can easily open my Windows Explorer in Safe Mode. Maybe I should delete my Temp folder so it could NOT rebuild those files again?

--Rino


" R I N O " wrote in message ...
Thank You Rick, I'm scanning the infected PC and I'll report my result later. Oops! My typo
--- it should be Shift+Delete and not Ctrl +Delete . . . Sorry.

--Rino


"Rick "Nutcase" Rogers" wrote in message ...
Hi,

Try scanning and deleting the file in Safe mode, where it is not active. How
to start in Safe mode:
http://www.rickrogers.org/fixes.htm#Safe%20mode

--
Best of Luck,

Rick Rogers, aka "Nutcase" - Microsoft MVP
http://mvp.support.microsoft.com/
Associate Expert - WindowsXP Expert Zone
www.microsoft.com/windowsxp/expertzone
Windows help - www.rickrogers.org

" R I N O " wrote in message
...

I could not open my IE6 and Windows Explorer because my AVG AntiVirus
program always says: While opening files; C:\Document and
Setting\Rino\Local Setting\Temp\se.dll, I clicked OK button and rundll
windows says; Error Loading C:\Docume~1\Rino\Local~1\Temp\se.dll; Access is
denied, I clicked OK button.

My AVG AntiVirus program indicated a 'Trojan Horse Startpage.16.BD' virus
infected my se.dll file above. No matter how many times I deleted it or
put it in Virus Vault it always built-up again! I knew you might ask me
how I could see inside my PC without using Windows Explorer? Well, I used
Search and I used My Computer Icon and select the 'se.dll' and press
Shift+Delete it. Even my AVG has several file of repeated 'Trojan Horse
Startpage.16.BD virus' in the virus vault. I even deleted all files inside
my Temp folder.

Please fear not because I used another PC to send this call for help. TIA


  #5  
Old March 23rd 05, 04:09 AM
The Aussie Girl
external usenet poster
 
Posts: n/a
Default Trojan Horse Startpage.16.BD Virus

Hey, the virus you have is the exact same virus that I had and I can tell you
that no anti virus system will kill it even if it does find it on your system.

You will need to download the following programs from the address’s I have
provided. You will also need to update these programs as well if possible (I
say if possible because my internet connection was destroyed from this virus
in which made this a hell of a lot harder for me to do:


Download the following programs:

Spybot search and destroy. Once you have downloaded it you will need to
install it to your computer (make sure you make a short cut to your desktop
for quick access to it) and if possible update it as well
http://www.spybot.info/en/download/index.html


Ad Aware SE Personal. Make sure you install this to a handy location as well
and update this program as well (usually this program has a new update every
single day so please make sure you update it)
http://www.download.com/Ad-Aware-SE-...bj=dl&tag=top5


Cwshredder download the stand alone version of this. Once again update if
possible
http://www.intermute.com/spysubtract..._download.html


Hijack this – scroll down on the page below until you find hijack this, make
sure you save this to your hard drive in a location that is handy. Please be
very careful with this program as it can cause a lot of damage if used in the
wrong way. So just click on Hijack this and save it
http://www.spywareinfo.com/downloads.php?cat=sp#det



Once you have downloaded all of the following and have updated the necessary
ones please log into safe mode.

Once in safe mode open spybot and run it. Delete all that it finds.If your
unsure of what it finds it only sticks your deleted items into quarantine
where you can always re install things.

Next open adware and run it. Delete all the items that it finds. Just like
the above you can re install anything if you find your missing certain
things. Although this program gives you a good description on what it has
found.

Next open cwshredder and click on fix – it will delete any viruses it finds.

Next open hijack this and scan your computer. The log that it gives you make
sure you save this (incase you havent fixed your computer you can post this
log and someone will help you)

Log back into your computer as per normal, update and run your anti virus
system.

See how your computer is running now.

If you still have a problem let me know – send a post to this site to me and
I will give you the information you will need to be able to speak to experts.

Best of luck

  #6  
Old March 23rd 05, 05:46 AM
external usenet poster
 
Posts: n/a
Default Trojan Horse Startpage.16.BD Virus

Hello Rick & Aussie Girl,
I did try to delete my Temp folder and then after reboot --- it rebuilt again. All 11 or some times 13 files are intact --- including the culprit one.

OK, I'll descript it fully this time. On closing PC, it will not close normally BUT an End Program Windows appears --- some times only once BUT other times it is 2 and these 3 End Program always comes: Explorer.exe, SysFader and Proxy Desktop. I've to click End Now button in order to close, then WinXP proceed to shutting down.

On reboot, any Quick Launch Program appears will accompanied my AVG Virus Detected! Pop up Windows. Yes, several will appears one on top the others and I've to used Window Task Manager to exits them out. If I click open any Program or Windows --- it instantly pop up Virus Detected! It says: While opening files C:\Document and Setting\Rino\Local Setting\Temp\se.dll and below it indicated Trojan Horse Startpage.16.DB then without clicking anything --- this came out: Error loading C:\Docume~1\Rino\Local~1\Temp\se.dll and below it says: Access is denied. I've to delete several times my Temp folder and its appears I could open my IE6 and Windows Explorer or any Icon I clicked. Even though the Virus Detected! will pop up --- I've decided to ignored it and pressed Continue button so it will not put in Virus Vault. My only problem now is I've to press the Continue button every time I open a Windows and I would like to completely delete those 11 or 13 file in my Temp folder.

Oh yes, my IE6 Home page has also changed by 'about:blank', its a search engine own by unknown owner. If I could have their email address I'll ask them how to take it out. I did tried on my Control Panel and unsuccessful. My 2 cents guess it is they who cause all these problems by hiring a strong team of virus programmers. Oh, this is no good --- Congress should step in.

To Aussie Girl, Thanks for your help BUT must I get all those tools?

--Rino


" R I N O " wrote in message ...
Hello Rick,
I'm sorry we didn't eliminate the tricky virus. I let it scanned my 3 hard dives and found NOTHING or No Virus! (my virus definitions is only 1 day old). I even did it manually by deleted all my files inside Temp folder again even though I didn't find the culprit 'se.dll' file in Safe Mode. Yes, I can easily open my Windows Explorer in Safe Mode. Maybe I should delete my Temp folder so it could NOT rebuild those files again?

--Rino


" R I N O " wrote in message ...
Thank You Rick, I'm scanning the infected PC and I'll report my result later. Oops! My typo
--- it should be Shift+Delete and not Ctrl +Delete . . . Sorry.

--Rino


"Rick "Nutcase" Rogers" wrote in message ...
Hi,

Try scanning and deleting the file in Safe mode, where it is not active. How
to start in Safe mode:
http://www.rickrogers.org/fixes.htm#Safe%20mode

--
Best of Luck,

Rick Rogers, aka "Nutcase" - Microsoft MVP
http://mvp.support.microsoft.com/
Associate Expert - WindowsXP Expert Zone
www.microsoft.com/windowsxp/expertzone
Windows help - www.rickrogers.org

" R I N O " wrote in message
...

I could not open my IE6 and Windows Explorer because my AVG AntiVirus
program always says: While opening files; C:\Document and
Setting\Rino\Local Setting\Temp\se.dll, I clicked OK button and rundll
windows says; Error Loading C:\Docume~1\Rino\Local~1\Temp\se.dll; Access is
denied, I clicked OK button.

My AVG AntiVirus program indicated a 'Trojan Horse Startpage.16.BD' virus
infected my se.dll file above. No matter how many times I deleted it or
put it in Virus Vault it always built-up again! I knew you might ask me
how I could see inside my PC without using Windows Explorer? Well, I used
Search and I used My Computer Icon and select the 'se.dll' and press
Shift+Delete it. Even my AVG has several file of repeated 'Trojan Horse
Startpage.16.BD virus' in the virus vault. I even deleted all files inside
my Temp folder.

Please fear not because I used another PC to send this call for help. TIA


  #7  
Old March 23rd 05, 05:50 AM
Kelly
external usenet poster
 
Posts: n/a
Default Trojan Horse Startpage.16.BD Virus

Rino,

Run this combo now!

Run Ad-Aware SE, Spybot and HijackThis:
http://www.majorgeeks.com/downloads31.html

Note: Update the first two programs, once installed, before running.

Free Online Virus Scan
http://housecall.trendmicro.com/hous...start_corp.asp

Good luck and keep us posted!

--
In memory of our dear friend, MVP Alex Nichol: http://www.dts-l.org/

All the Best,
Kelly (MS-MVP)

Troubleshooting Windows XP
http://www.kellys-korner-xp.com


" R I N O " wrote in message
...
Hello Rick & Aussie Girl,
I did try to delete my Temp folder and then after reboot --- it rebuilt
again. All 11 or some times 13 files are intact --- including the culprit
one.

OK, I'll descript it fully this time. On closing PC, it will not close
normally BUT an End Program Windows appears --- some times only once BUT
other times it is 2 and these 3 End Program always comes: Explorer.exe,
SysFader and Proxy Desktop. I've to click End Now button in order to
close, then WinXP proceed to shutting down.

On reboot, any Quick Launch Program appears will accompanied my AVG Virus
Detected! Pop up Windows. Yes, several will appears one on top the others
and I've to used Window Task Manager to exits them out. If I click open
any Program or Windows --- it instantly pop up Virus Detected! It says:
While opening files C:\Document and Setting\Rino\Local Setting\Temp\se.dll
and below it indicated Trojan Horse Startpage.16.DB then without clicking
anything --- this came out: Error loading
C:\Docume~1\Rino\Local~1\Temp\se.dll and below it says: Access is denied.
I've to delete several times my Temp folder and its appears I could open
my IE6 and Windows Explorer or any Icon I clicked. Even though the Virus
Detected! will pop up --- I've decided to ignored it and pressed Continue
button so it will not put in Virus Vault. My only problem now is I've to
press the Continue button every time I open a Windows and I would like to
completely delete those 11 or 13 file in my Temp folder.

Oh yes, my IE6 Home page has also changed by 'about:blank', its a search
engine own by unknown owner. If I could have their email address I'll ask
them how to take it out. I did tried on my Control Panel and unsuccessful.
My 2 cents guess it is they who cause all these problems by hiring a
strong team of virus programmers. Oh, this is no good --- Congress should
step in.

To Aussie Girl, Thanks for your help BUT must I get all those tools?

--Rino


" R I N O " wrote in message
...
Hello Rick,
I'm sorry we didn't eliminate the tricky virus. I let it scanned my 3 hard
dives and found NOTHING or No Virus! (my virus definitions is only 1 day
old). I even did it manually by deleted all my files inside Temp folder
again even though I didn't find the culprit 'se.dll' file in Safe Mode.
Yes, I can easily open my Windows Explorer in Safe Mode. Maybe I should
delete my Temp folder so it could NOT rebuild those files again?

--Rino


" R I N O " wrote in message
...
Thank You Rick, I'm scanning the infected PC and I'll report my result
later. Oops! My typo
--- it should be Shift+Delete and not Ctrl +Delete . . . Sorry.

--Rino


"Rick "Nutcase" Rogers" wrote in message
...
Hi,

Try scanning and deleting the file in Safe mode, where it is not active.
How
to start in Safe mode:
http://www.rickrogers.org/fixes.htm#Safe%20mode

--
Best of Luck,

Rick Rogers, aka "Nutcase" - Microsoft MVP
http://mvp.support.microsoft.com/
Associate Expert - WindowsXP Expert Zone
www.microsoft.com/windowsxp/expertzone
Windows help - www.rickrogers.org

" R I N O " wrote in message
...
I could not open my IE6 and Windows Explorer because my AVG AntiVirus
program always says: While opening files; C:\Document and
Setting\Rino\Local Setting\Temp\se.dll, I clicked OK button and rundll
windows says; Error Loading C:\Docume~1\Rino\Local~1\Temp\se.dll; Access
is
denied, I clicked OK button.

My AVG AntiVirus program indicated a 'Trojan Horse Startpage.16.BD' virus
infected my se.dll file above. No matter how many times I deleted it or
put it in Virus Vault it always built-up again! I knew you might ask me
how I could see inside my PC without using Windows Explorer? Well, I used
Search and I used My Computer Icon and select the 'se.dll' and press
Shift+Delete it. Even my AVG has several file of repeated 'Trojan Horse
Startpage.16.BD virus' in the virus vault. I even deleted all files
inside
my Temp folder.

Please fear not because I used another PC to send this call for help. TIA





  #8  
Old March 23rd 05, 11:42 PM
external usenet poster
 
Posts: n/a
Default Trojan Horse Startpage.16.BD Virus

Hi Kelly, et al,
Thank You for helping me, I did everything as you told me to do BUT ONLY a little improvement. The annoying Virus Detected always pop up and I've to (always) pressed Continue button. I've to manually delete (now only) 3 files remained in my Temp folder. I knew we didn't defeat it yet because its still can rebuilt it self --- every files and Temp folder included just come back --- if it has a character feature maybe it'll laughing at us. Oh Boy!

I can now open my IE6 and Windows Explorer with annoying Virus Detected pop up. My IE6 Home page is still hijacked by 'about:blank' --- FYI Google it --- you'll discover it is not a new menace. The Net are loaded with many complicated removal method. I preferred to sent my eMail request to 'about:blank' --- hoping they'll response. I'll promise to post if I'm happy about it so all others will also benefited.

Sincerely,
--Rino


"Kelly" wrote in message ...
Rino,

Run this combo now!

Run Ad-Aware SE, Spybot and HijackThis:
http://www.majorgeeks.com/downloads31.html

Note: Update the first two programs, once installed, before running.

Free Online Virus Scan
http://housecall.trendmicro.com/hous...start_corp.asp

Good luck and keep us posted!

--
In memory of our dear friend, MVP Alex Nichol: http://www.dts-l.org/

All the Best,
Kelly (MS-MVP)

Troubleshooting Windows XP
http://www.kellys-korner-xp.com


" R I N O " wrote in message
...

Hello Rick & Aussie Girl,
I did try to delete my Temp folder and then after reboot --- it rebuilt
again. All 11 or some times 13 files are intact --- including the culprit
one.

OK, I'll descript it fully this time. On closing PC, it will not close
normally BUT an End Program Windows appears --- some times only once BUT
other times it is 2 and these 3 End Program always comes: Explorer.exe,
SysFader and Proxy Desktop. I've to click End Now button in order to
close, then WinXP proceed to shutting down.

On reboot, any Quick Launch Program appears will accompanied my AVG Virus
Detected! Pop up Windows. Yes, several will appears one on top the others
and I've to used Window Task Manager to exits them out. If I click open
any Program or Windows --- it instantly pop up Virus Detected! It says:
While opening files C:\Document and Setting\Rino\Local Setting\Temp\se.dll
and below it indicated Trojan Horse Startpage.16.DB then without clicking
anything --- this came out: Error loading
C:\Docume~1\Rino\Local~1\Temp\se.dll and below it says: Access is denied.
I've to delete several times my Temp folder and its appears I could open
my IE6 and Windows Explorer or any Icon I clicked. Even though the Virus
Detected! will pop up --- I've decided to ignored it and pressed Continue
button so it will not put in Virus Vault. My only problem now is I've to
press the Continue button every time I open a Windows and I would like to
completely delete those 11 or 13 file in my Temp folder.

Oh yes, my IE6 Home page has also changed by 'about:blank', its a search
engine own by unknown owner. If I could have their email address I'll ask
them how to take it out. I did tried on my Control Panel and unsuccessful.
My 2 cents guess it is they who cause all these problems by hiring a
strong team of virus programmers. Oh, this is no good --- Congress should
step in.

To Aussie Girl, Thanks for your help BUT must I get all those tools?

--Rino


" R I N O " wrote in message
...
Hello Rick,
I'm sorry we didn't eliminate the tricky virus. I let it scanned my 3 hard
dives and found NOTHING or No Virus! (my virus definitions is only 1 day
old). I even did it manually by deleted all my files inside Temp folder
again even though I didn't find the culprit 'se.dll' file in Safe Mode.
Yes, I can easily open my Windows Explorer in Safe Mode. Maybe I should
delete my Temp folder so it could NOT rebuild those files again?

--Rino


" R I N O " wrote in message
...
Thank You Rick, I'm scanning the infected PC and I'll report my result
later. Oops! My typo
--- it should be Shift+Delete and not Ctrl +Delete . . . Sorry.

--Rino


"Rick "Nutcase" Rogers" wrote in message
...
Hi,

Try scanning and deleting the file in Safe mode, where it is not active.
How
to start in Safe mode:
http://www.rickrogers.org/fixes.htm#Safe%20mode

--
Best of Luck,

Rick Rogers, aka "Nutcase" - Microsoft MVP
http://mvp.support.microsoft.com/
Associate Expert - WindowsXP Expert Zone
www.microsoft.com/windowsxp/expertzone
Windows help - www.rickrogers.org

" R I N O " wrote in message
...

I could not open my IE6 and Windows Explorer because my AVG AntiVirus
program always says: While opening files; C:\Document and
Setting\Rino\Local Setting\Temp\se.dll, I clicked OK button and rundll
windows says; Error Loading C:\Docume~1\Rino\Local~1\Temp\se.dll; Access
is
denied, I clicked OK button.

My AVG AntiVirus program indicated a 'Trojan Horse Startpage.16.BD' virus
infected my se.dll file above. No matter how many times I deleted it or
put it in Virus Vault it always built-up again! I knew you might ask me
how I could see inside my PC without using Windows Explorer? Well, I used
Search and I used My Computer Icon and select the 'se.dll' and press
Shift+Delete it. Even my AVG has several file of repeated 'Trojan Horse
Startpage.16.BD virus' in the virus vault. I even deleted all files
inside
my Temp folder.

Please fear not because I used another PC to send this call for help. TIA





  #9  
Old March 24th 05, 01:01 AM
The Aussie Girl
external usenet poster
 
Posts: n/a
Default Trojan Horse Startpage.16.BD Virus

Hey Rino

im sorry to bring bad news but everything i said has to be done. You will
never get rid of about blank without running the ad aware and the spybot in
the order in which i have told you to do.
About blank isnt actually a virus it is a adware program and as i have
mentioned before deleting your temp files and running anti virus programs
will not delete this.
I had the exact same virus and trust me it is time consuming yes but to get
rid of it fully it is necessary. You might get your system up and running to
a point but unless you do all this it can come back stronger!!!!!!
as i said just write back if you need help or you can email if you want to
email me let me know

" R I N O " wrote:

Hi Kelly, et al,
Thank You for helping me, I did everything as you told me to do BUT ONLY a little improvement. The annoying Virus Detected always pop up and I've to (always) pressed Continue button. I've to manually delete (now only) 3 files remained in my Temp folder. I knew we didn't defeat it yet because its still can rebuilt it self --- every files and Temp folder included just come back --- if it has a character feature maybe it'll laughing at us. Oh Boy!

I can now open my IE6 and Windows Explorer with annoying Virus Detected pop up. My IE6 Home page is still hijacked by 'about:blank' --- FYI Google it --- you'll discover it is not a new menace. The Net are loaded with many complicated removal method. I preferred to sent my eMail request to 'about:blank' --- hoping they'll response. I'll promise to post if I'm happy about it so all others will also benefited.

Sincerely,
--Rino


"Kelly" wrote in message ...
Rino,

Run this combo now!

Run Ad-Aware SE, Spybot and HijackThis:
http://www.majorgeeks.com/downloads31.html

Note: Update the first two programs, once installed, before running.

Free Online Virus Scan
http://housecall.trendmicro.com/hous...start_corp.asp

Good luck and keep us posted!

--
In memory of our dear friend, MVP Alex Nichol: http://www.dts-l.org/

All the Best,
Kelly (MS-MVP)

Troubleshooting Windows XP
http://www.kellys-korner-xp.com


" R I N O " wrote in message
...
Hello Rick & Aussie Girl,
I did try to delete my Temp folder and then after reboot --- it rebuilt
again. All 11 or some times 13 files are intact --- including the culprit
one.

OK, I'll descript it fully this time. On closing PC, it will not close
normally BUT an End Program Windows appears --- some times only once BUT
other times it is 2 and these 3 End Program always comes: Explorer.exe,
SysFader and Proxy Desktop. I've to click End Now button in order to
close, then WinXP proceed to shutting down.

On reboot, any Quick Launch Program appears will accompanied my AVG Virus
Detected! Pop up Windows. Yes, several will appears one on top the others
and I've to used Window Task Manager to exits them out. If I click open
any Program or Windows --- it instantly pop up Virus Detected! It says:
While opening files C:\Document and Setting\Rino\Local Setting\Temp\se.dll
and below it indicated Trojan Horse Startpage.16.DB then without clicking
anything --- this came out: Error loading
C:\Docume~1\Rino\Local~1\Temp\se.dll and below it says: Access is denied.
I've to delete several times my Temp folder and its appears I could open
my IE6 and Windows Explorer or any Icon I clicked. Even though the Virus
Detected! will pop up --- I've decided to ignored it and pressed Continue
button so it will not put in Virus Vault. My only problem now is I've to
press the Continue button every time I open a Windows and I would like to
completely delete those 11 or 13 file in my Temp folder.

Oh yes, my IE6 Home page has also changed by 'about:blank', its a search
engine own by unknown owner. If I could have their email address I'll ask
them how to take it out. I did tried on my Control Panel and unsuccessful.
My 2 cents guess it is they who cause all these problems by hiring a
strong team of virus programmers. Oh, this is no good --- Congress should
step in.

To Aussie Girl, Thanks for your help BUT must I get all those tools?

--Rino


" R I N O " wrote in message
...
Hello Rick,
I'm sorry we didn't eliminate the tricky virus. I let it scanned my 3 hard
dives and found NOTHING or No Virus! (my virus definitions is only 1 day
old). I even did it manually by deleted all my files inside Temp folder
again even though I didn't find the culprit 'se.dll' file in Safe Mode.
Yes, I can easily open my Windows Explorer in Safe Mode. Maybe I should
delete my Temp folder so it could NOT rebuild those files again?

--Rino


" R I N O " wrote in message
...
Thank You Rick, I'm scanning the infected PC and I'll report my result
later. Oops! My typo
--- it should be Shift+Delete and not Ctrl +Delete . . . Sorry.

--Rino


"Rick "Nutcase" Rogers" wrote in message
...
Hi,

Try scanning and deleting the file in Safe mode, where it is not active.
How
to start in Safe mode:
http://www.rickrogers.org/fixes.htm#Safe%20mode

--
Best of Luck,

Rick Rogers, aka "Nutcase" - Microsoft MVP
http://mvp.support.microsoft.com/
Associate Expert - WindowsXP Expert Zone
www.microsoft.com/windowsxp/expertzone
Windows help - www.rickrogers.org

" R I N O " wrote in message
...
I could not open my IE6 and Windows Explorer because my AVG AntiVirus
program always says: While opening files; C:\Document and
Setting\Rino\Local Setting\Temp\se.dll, I clicked OK button and rundll
windows says; Error Loading C:\Docume~1\Rino\Local~1\Temp\se.dll; Access
is
denied, I clicked OK button.

My AVG AntiVirus program indicated a 'Trojan Horse Startpage.16.BD' virus
infected my se.dll file above. No matter how many times I deleted it or
put it in Virus Vault it always built-up again! I knew you might ask me
how I could see inside my PC without using Windows Explorer? Well, I used
Search and I used My Computer Icon and select the 'se.dll' and press
Shift+Delete it. Even my AVG has several file of repeated 'Trojan Horse
Startpage.16.BD virus' in the virus vault. I even deleted all files
inside
my Temp folder.

Please fear not because I used another PC to send this call for help. TIA





  #10  
Old March 24th 05, 02:09 AM
Li'l Roberto
external usenet poster
 
Posts: n/a
Default Trojan Horse Startpage.16.BD Virus

I have had good results removing these sorts of stuborn infectors
with Sysclean from Trend Micro,
http://www.trendmicro.com/download/dcs.asp
D/L the Sysclean package and run it from the GUI it will find and
remove the hidden DLL that keeps re creating the other files.

good luck
rgds
Li'l Roberto




"The Aussie Girl" wrote in
message ...
Hey Rino

im sorry to bring bad news but everything i said has to be done. You
will
never get rid of about blank without running the ad aware and the
spybot in
the order in which i have told you to do.
About blank isnt actually a virus it is a adware program and as i have
mentioned before deleting your temp files and running anti virus
programs
will not delete this.
I had the exact same virus and trust me it is time consuming yes but
to get
rid of it fully it is necessary. You might get your system up and
running to
a point but unless you do all this it can come back stronger!!!!!!
as i said just write back if you need help or you can email if you
want to
email me let me know

" R I N O " wrote:

Hi Kelly, et al,
Thank You for helping me, I did everything as you told me to do BUT
ONLY a little improvement. The annoying Virus Detected always pop up
and I've to (always) pressed Continue button. I've to manually delete
(now only) 3 files remained in my Temp folder. I knew we didn't
defeat it yet because its still can rebuilt it self --- every files
and Temp folder included just come back --- if it has a character
feature maybe it'll laughing at us. Oh Boy!



  #11  
Old March 24th 05, 04:29 AM
Kelly
external usenet poster
 
Posts: n/a
Default Trojan Horse Startpage.16.BD Virus

Hi Rino,

Go to Start/Control Panel/Display Properties/Desktop/Customize/Web and
uncheck Security if it is listed.

Once done, make sure System Restore has been turned off before running the
cleaners I mentioned. If it wasn't, re-run them now. If still no joy:

In most cases without using third party, this takes three steps.

1. Start/Run/Regedit

HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\Curr entVersion\Run
HKEY_CURRENT_USER\Software\Microsoft\Windows\Curre ntVersion\Run

Gain the exact path.
Note: Save these two to regedit favorites.

2. Start/Run/Msconfig/Startup

Gain the exact path.

3. Follow the path via Windows Explorer.

Leave/have all three windows opened, now open the Task Manager.

Once knowing the exact path, end the process via the Task Manager, then
delete the entry via Windows Explorer. From there, delete the run command
from both regedit and msconfig. With regedit still open, hit F5. If it
replaces itself, you didn't do it in a timely manner or you didn't follow
the exact placement path.

Note: In some cases, depending, you will be allowed to rename the .exe via
safe mode and then delete.
--
In memory of our dear friend, MVP Alex Nichol: http://www.dts-l.org/

All the Best,
Kelly (MS-MVP)

Troubleshooting Windows XP
http://www.kellys-korner-xp.com


" R I N O " wrote in message
...
Hi Kelly, et al,
Thank You for helping me, I did everything as you told me to do BUT ONLY a
little improvement. The annoying Virus Detected always pop up and I've to
(always) pressed Continue button. I've to manually delete (now only) 3
files remained in my Temp folder. I knew we didn't defeat it yet because
its still can rebuilt it self --- every files and Temp folder included
just come back --- if it has a character feature maybe it'll laughing at
us. Oh Boy!

I can now open my IE6 and Windows Explorer with annoying Virus Detected
pop up. My IE6 Home page is still hijacked by 'about:blank' --- FYI Google
it --- you'll discover it is not a new menace. The Net are loaded with
many complicated removal method. I preferred to sent my eMail request to
'about:blank' --- hoping they'll response. I'll promise to post if I'm
happy about it so all others will also benefited.

Sincerely,
--Rino


"Kelly" wrote in message
...
Rino,

Run this combo now!

Run Ad-Aware SE, Spybot and HijackThis:
http://www.majorgeeks.com/downloads31.html

Note: Update the first two programs, once installed, before running.

Free Online Virus Scan
http://housecall.trendmicro.com/hous...start_corp.asp

Good luck and keep us posted!

--
In memory of our dear friend, MVP Alex Nichol: http://www.dts-l.org/

All the Best,
Kelly (MS-MVP)

Troubleshooting Windows XP
http://www.kellys-korner-xp.com


" R I N O " wrote in message
...
Hello Rick & Aussie Girl,
I did try to delete my Temp folder and then after reboot --- it rebuilt
again. All 11 or some times 13 files are intact --- including the culprit
one.

OK, I'll descript it fully this time. On closing PC, it will not close
normally BUT an End Program Windows appears --- some times only once BUT
other times it is 2 and these 3 End Program always comes: Explorer.exe,
SysFader and Proxy Desktop. I've to click End Now button in order to
close, then WinXP proceed to shutting down.

On reboot, any Quick Launch Program appears will accompanied my AVG Virus
Detected! Pop up Windows. Yes, several will appears one on top the others
and I've to used Window Task Manager to exits them out. If I click open
any Program or Windows --- it instantly pop up Virus Detected! It says:
While opening files C:\Document and Setting\Rino\Local
Setting\Temp\se.dll
and below it indicated Trojan Horse Startpage.16.DB then without clicking
anything --- this came out: Error loading
C:\Docume~1\Rino\Local~1\Temp\se.dll and below it says: Access is denied.
I've to delete several times my Temp folder and its appears I could open
my IE6 and Windows Explorer or any Icon I clicked. Even though the Virus
Detected! will pop up --- I've decided to ignored it and pressed Continue
button so it will not put in Virus Vault. My only problem now is I've to
press the Continue button every time I open a Windows and I would like to
completely delete those 11 or 13 file in my Temp folder.

Oh yes, my IE6 Home page has also changed by 'about:blank', its a search
engine own by unknown owner. If I could have their email address I'll ask
them how to take it out. I did tried on my Control Panel and
unsuccessful.
My 2 cents guess it is they who cause all these problems by hiring a
strong team of virus programmers. Oh, this is no good --- Congress should
step in.

To Aussie Girl, Thanks for your help BUT must I get all those tools?

--Rino


" R I N O " wrote in message
...
Hello Rick,
I'm sorry we didn't eliminate the tricky virus. I let it scanned my 3
hard
dives and found NOTHING or No Virus! (my virus definitions is only 1 day
old). I even did it manually by deleted all my files inside Temp folder
again even though I didn't find the culprit 'se.dll' file in Safe Mode.
Yes, I can easily open my Windows Explorer in Safe Mode. Maybe I should
delete my Temp folder so it could NOT rebuild those files again?

--Rino


" R I N O " wrote in message
...
Thank You Rick, I'm scanning the infected PC and I'll report my result
later. Oops! My typo
--- it should be Shift+Delete and not Ctrl +Delete . . . Sorry.

--Rino


"Rick "Nutcase" Rogers" wrote in message
...
Hi,

Try scanning and deleting the file in Safe mode, where it is not active.
How
to start in Safe mode:
http://www.rickrogers.org/fixes.htm#Safe%20mode

--
Best of Luck,

Rick Rogers, aka "Nutcase" - Microsoft MVP
http://mvp.support.microsoft.com/
Associate Expert - WindowsXP Expert Zone
www.microsoft.com/windowsxp/expertzone
Windows help - www.rickrogers.org

" R I N O " wrote in message
...
I could not open my IE6 and Windows Explorer because my AVG AntiVirus
program always says: While opening files; C:\Document and
Setting\Rino\Local Setting\Temp\se.dll, I clicked OK button and rundll
windows says; Error Loading C:\Docume~1\Rino\Local~1\Temp\se.dll; Access
is
denied, I clicked OK button.

My AVG AntiVirus program indicated a 'Trojan Horse Startpage.16.BD'
virus
infected my se.dll file above. No matter how many times I deleted it or
put it in Virus Vault it always built-up again! I knew you might ask me
how I could see inside my PC without using Windows Explorer? Well, I
used
Search and I used My Computer Icon and select the 'se.dll' and press
Shift+Delete it. Even my AVG has several file of repeated 'Trojan Horse
Startpage.16.BD virus' in the virus vault. I even deleted all files
inside
my Temp folder.

Please fear not because I used another PC to send this call for help.
TIA







  #12  
Old March 25th 05, 06:26 AM
external usenet poster
 
Posts: n/a
Default Trojan Horse Startpage.16.BD Virus

Hi Aussie Girl,
I should say I'm sorry too --- because I should've followed you all the way BUT I stopped on CWShredder. Luckily you checked how I'm doing and I believed your combined method is really effective and can completely took out the pest that invaded my PC for three days.

Now I must says . . . THANK YOU! ALL KUDOS GOES TO YOU!

Here's what I did to eliminate 'about:blank' pest:
1. I Download and install the following SpyWare software and immediately secured their update and make sure I have their Icons in Desktop: Ad-Aware SE, SpyBot, HijackThis, CWShredder, and AVG AntiVirus SE.

Side note: CWShredder is a separate software which is bundled with
SpySubtract. Get SpySubtract and CWShredder is inside --- yes, a
separate Icon is installed for CWShredder.

2. I launch my PC in Safe Mode by pressing F8 on restarting and used AVG, AD-Aware, SpyBot and HikackThis in that order. I must caution everyone --- be very careful in using HijackThis --- you might delete something critical file for proper operation of programs. I remembered I only make 5 check marks starting from the top box that says R1's which contained the culprit 'about:blank' extension name.

Side note: I chose delete everything what my three programs found. I remembered SpyBot can delete most findings except eXact Advertising Bargain Buddy (2 files) always remained intact --- don't worry.

3. I always restart in Safe Mode and open SpySubtract then with CWShredder. Only now CWShredder found the 3 remaining (trickiest) CWS's: CWS.smartsearch, CWS.Hidden.dll and CWS.affiliate:toolband --- delete them!

4. Repeat No. 2 above for every User name. No. 3 is not possible --- don't worry.
I can still found and deleted many of them.

Test my PC and yelled Yepeekayeah! I can as easily change the IE6 Home page --- no more virus or malicious pest --- no more annoy pop up & headache. All fixed.

Next time I'll ask why use all of them and they're the same SpyWare software (may I answer it?) because each of them has their limited effectiveness BUT the most effective of all is CWShredder. Yes, your combined method is most effective. Oh yes, it is not necessary to follow the correct order to use those software --- only used them all. For those who are interested to download --- you'll find their links on Aussie Girl first posted earlier.

Thanks for everything Aussie Girl,
--Rino


"The Aussie Girl" wrote in message ...
Hey Rino

im sorry to bring bad news but everything i said has to be done. You will
never get rid of about blank without running the ad aware and the spybot in
the order in which i have told you to do.
About blank isnt actually a virus it is a adware program and as i have
mentioned before deleting your temp files and running anti virus programs
will not delete this.
I had the exact same virus and trust me it is time consuming yes but to get
rid of it fully it is necessary. You might get your system up and running to
a point but unless you do all this it can come back stronger!!!!!!
as i said just write back if you need help or you can email if you want to
email me let me know

" R I N O " wrote:


Hi Kelly, et al,
Thank You for helping me, I did everything as you told me to do BUT ONLY a little improvement. The annoying Virus Detected always pop up and I've to (always) pressed Continue button. I've to manually delete (now only) 3 files remained in my Temp folder. I knew we didn't defeat it yet because its still can rebuilt it self --- every files and Temp folder included just come back --- if it has a character feature maybe it'll laughing at us. Oh Boy!

I can now open my IE6 and Windows Explorer with annoying Virus Detected pop up. My IE6 Home page is still hijacked by 'about:blank' --- FYI Google it --- you'll discover it is not a new menace. The Net are loaded with many complicated removal method. I preferred to sent my eMail request to 'about:blank' --- hoping they'll response. I'll promise to post if I'm happy about it so all others will also benefited.

Sincerely,
--Rino


"Kelly" wrote in message ...
Rino,

Run this combo now!

Run Ad-Aware SE, Spybot and HijackThis:
http://www.majorgeeks.com/downloads31.html

Note: Update the first two programs, once installed, before running.

Free Online Virus Scan
http://housecall.trendmicro.com/hous...start_corp.asp

Good luck and keep us posted!

--
In memory of our dear friend, MVP Alex Nichol: http://www.dts-l.org/

All the Best,
Kelly (MS-MVP)

Troubleshooting Windows XP
http://www.kellys-korner-xp.com


" R I N O " wrote in message
...

Hello Rick & Aussie Girl,
I did try to delete my Temp folder and then after reboot --- it rebuilt
again. All 11 or some times 13 files are intact --- including the culprit
one.

OK, I'll descript it fully this time. On closing PC, it will not close
normally BUT an End Program Windows appears --- some times only once BUT
other times it is 2 and these 3 End Program always comes: Explorer.exe,
SysFader and Proxy Desktop. I've to click End Now button in order to
close, then WinXP proceed to shutting down.

On reboot, any Quick Launch Program appears will accompanied my AVG Virus
Detected! Pop up Windows. Yes, several will appears one on top the others
and I've to used Window Task Manager to exits them out. If I click open
any Program or Windows --- it instantly pop up Virus Detected! It says:
While opening files C:\Document and Setting\Rino\Local Setting\Temp\se.dll
and below it indicated Trojan Horse Startpage.16.DB then without clicking
anything --- this came out: Error loading
C:\Docume~1\Rino\Local~1\Temp\se.dll and below it says: Access is denied.
I've to delete several times my Temp folder and its appears I could open
my IE6 and Windows Explorer or any Icon I clicked. Even though the Virus
Detected! will pop up --- I've decided to ignored it and pressed Continue
button so it will not put in Virus Vault. My only problem now is I've to
press the Continue button every time I open a Windows and I would like to
completely delete those 11 or 13 file in my Temp folder.

Oh yes, my IE6 Home page has also changed by 'about:blank', its a search
engine own by unknown owner. If I could have their email address I'll ask
them how to take it out. I did tried on my Control Panel and unsuccessful.
My 2 cents guess it is they who cause all these problems by hiring a
strong team of virus programmers. Oh, this is no good --- Congress should
step in.

To Aussie Girl, Thanks for your help BUT must I get all those tools?

--Rino


" R I N O " wrote in message
...
Hello Rick,
I'm sorry we didn't eliminate the tricky virus. I let it scanned my 3 hard
dives and found NOTHING or No Virus! (my virus definitions is only 1 day
old). I even did it manually by deleted all my files inside Temp folder
again even though I didn't find the culprit 'se.dll' file in Safe Mode.
Yes, I can easily open my Windows Explorer in Safe Mode. Maybe I should
delete my Temp folder so it could NOT rebuild those files again?

--Rino


" R I N O " wrote in message
...
Thank You Rick, I'm scanning the infected PC and I'll report my result
later. Oops! My typo
--- it should be Shift+Delete and not Ctrl +Delete . . . Sorry.

--Rino


"Rick "Nutcase" Rogers" wrote in message
...
Hi,

Try scanning and deleting the file in Safe mode, where it is not active.
How
to start in Safe mode:
http://www.rickrogers.org/fixes.htm#Safe%20mode

--
Best of Luck,

Rick Rogers, aka "Nutcase" - Microsoft MVP
http://mvp.support.microsoft.com/
Associate Expert - WindowsXP Expert Zone
www.microsoft.com/windowsxp/expertzone
Windows help - www.rickrogers.org

" R I N O " wrote in message
...

I could not open my IE6 and Windows Explorer because my AVG AntiVirus
program always says: While opening files; C:\Document and
Setting\Rino\Local Setting\Temp\se.dll, I clicked OK button and rundll
windows says; Error Loading C:\Docume~1\Rino\Local~1\Temp\se.dll; Access
is
denied, I clicked OK button.

My AVG AntiVirus program indicated a 'Trojan Horse Startpage.16.BD' virus
infected my se.dll file above. No matter how many times I deleted it or
put it in Virus Vault it always built-up again! I knew you might ask me
how I could see inside my PC without using Windows Explorer? Well, I used
Search and I used My Computer Icon and select the 'se.dll' and press
Shift+Delete it. Even my AVG has several file of repeated 'Trojan Horse
Startpage.16.BD virus' in the virus vault. I even deleted all files
inside
my Temp folder.

Please fear not because I used another PC to send this call for help. TIA





  #13  
Old March 25th 05, 06:28 AM
external usenet poster
 
Posts: n/a
Default Trojan Horse Startpage.16.BD Virus

Hi Li'l Roberto,
Thank You for giving me your helping hand. I'll put it in my Favorites for my additional tools to combat this malicious menace. I'm glad & happy now because I did finally fixed it and everything returned to normal condition. Read also my complete report to Aussie Girl.

Thanks Again,
--Rino

"Li'l Roberto" wrote in message ...
I have had good results removing these sorts of stuborn infectors
with Sysclean from Trend Micro,
http://www.trendmicro.com/download/dcs.asp
D/L the Sysclean package and run it from the GUI it will find and
remove the hidden DLL that keeps re creating the other files.

good luck
rgds
Li'l Roberto




"The Aussie Girl" wrote in
message ...

Hey Rino

im sorry to bring bad news but everything i said has to be done. You
will
never get rid of about blank without running the ad aware and the
spybot in
the order in which i have told you to do.
About blank isnt actually a virus it is a adware program and as i have
mentioned before deleting your temp files and running anti virus
programs
will not delete this.
I had the exact same virus and trust me it is time consuming yes but
to get
rid of it fully it is necessary. You might get your system up and
running to
a point but unless you do all this it can come back stronger!!!!!!
as i said just write back if you need help or you can email if you
want to
email me let me know

" R I N O " wrote:


Hi Kelly, et al,
Thank You for helping me, I did everything as you told me to do BUT
ONLY a little improvement. The annoying Virus Detected always pop up
and I've to (always) pressed Continue button. I've to manually delete
(now only) 3 files remained in my Temp folder. I knew we didn't
defeat it yet because its still can rebuilt it self --- every files
and Temp folder included just come back --- if it has a character
feature maybe it'll laughing at us. Oh Boy!


  #14  
Old March 25th 05, 06:28 AM
external usenet poster
 
Posts: n/a
Default Trojan Horse Startpage.16.BD Virus

Hi Kelly,
I'm sorry because I give up. I cannot understand what I'm doing with regedit command. I did it before but not this method --- too technical will break my brain. My sincere thanks for helping me out.

Luckily I looked back for all available suggestions and found CWShredder is the most effective tools to remove 'about:blank' pest. I'll post my full report in Aussie Girl reply.

Many Thanks Again,
--Rino


"Kelly" wrote in message ...
Hi Rino,

Go to Start/Control Panel/Display Properties/Desktop/Customize/Web and
uncheck Security if it is listed.

Once done, make sure System Restore has been turned off before running the
cleaners I mentioned. If it wasn't, re-run them now. If still no joy:

In most cases without using third party, this takes three steps.

1. Start/Run/Regedit

HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\Curr entVersion\Run
HKEY_CURRENT_USER\Software\Microsoft\Windows\Curre ntVersion\Run

Gain the exact path.
Note: Save these two to regedit favorites.

2. Start/Run/Msconfig/Startup

Gain the exact path.

3. Follow the path via Windows Explorer.

Leave/have all three windows opened, now open the Task Manager.

Once knowing the exact path, end the process via the Task Manager, then
delete the entry via Windows Explorer. From there, delete the run command
from both regedit and msconfig. With regedit still open, hit F5. If it
replaces itself, you didn't do it in a timely manner or you didn't follow
the exact placement path.

Note: In some cases, depending, you will be allowed to rename the .exe via
safe mode and then delete.
--
In memory of our dear friend, MVP Alex Nichol: http://www.dts-l.org/

All the Best,
Kelly (MS-MVP)

Troubleshooting Windows XP
http://www.kellys-korner-xp.com


" R I N O " wrote in message
...

Hi Kelly, et al,
Thank You for helping me, I did everything as you told me to do BUT ONLY a
little improvement. The annoying Virus Detected always pop up and I've to
(always) pressed Continue button. I've to manually delete (now only) 3
files remained in my Temp folder. I knew we didn't defeat it yet because
its still can rebuilt it self --- every files and Temp folder included
just come back --- if it has a character feature maybe it'll laughing at
us. Oh Boy!

I can now open my IE6 and Windows Explorer with annoying Virus Detected
pop up. My IE6 Home page is still hijacked by 'about:blank' --- FYI Google
it --- you'll discover it is not a new menace. The Net are loaded with
many complicated removal method. I preferred to sent my eMail request to
'about:blank' --- hoping they'll response. I'll promise to post if I'm
happy about it so all others will also benefited.

Sincerely,
--Rino


"Kelly" wrote in message
...
Rino,

Run this combo now!

Run Ad-Aware SE, Spybot and HijackThis:
http://www.majorgeeks.com/downloads31.html

Note: Update the first two programs, once installed, before running.

Free Online Virus Scan
http://housecall.trendmicro.com/hous...start_corp.asp

Good luck and keep us posted!

--
In memory of our dear friend, MVP Alex Nichol: http://www.dts-l.org/

All the Best,
Kelly (MS-MVP)

Troubleshooting Windows XP
http://www.kellys-korner-xp.com


" R I N O " wrote in message
...

Hello Rick & Aussie Girl,
I did try to delete my Temp folder and then after reboot --- it rebuilt
again. All 11 or some times 13 files are intact --- including the culprit
one.

OK, I'll descript it fully this time. On closing PC, it will not close
normally BUT an End Program Windows appears --- some times only once BUT
other times it is 2 and these 3 End Program always comes: Explorer.exe,
SysFader and Proxy Desktop. I've to click End Now button in order to
close, then WinXP proceed to shutting down.

On reboot, any Quick Launch Program appears will accompanied my AVG Virus
Detected! Pop up Windows. Yes, several will appears one on top the others
and I've to used Window Task Manager to exits them out. If I click open
any Program or Windows --- it instantly pop up Virus Detected! It says:
While opening files C:\Document and Setting\Rino\Local
Setting\Temp\se.dll
and below it indicated Trojan Horse Startpage.16.DB then without clicking
anything --- this came out: Error loading
C:\Docume~1\Rino\Local~1\Temp\se.dll and below it says: Access is denied.
I've to delete several times my Temp folder and its appears I could open
my IE6 and Windows Explorer or any Icon I clicked. Even though the Virus
Detected! will pop up --- I've decided to ignored it and pressed Continue
button so it will not put in Virus Vault. My only problem now is I've to
press the Continue button every time I open a Windows and I would like to
completely delete those 11 or 13 file in my Temp folder.

Oh yes, my IE6 Home page has also changed by 'about:blank', its a search
engine own by unknown owner. If I could have their email address I'll ask
them how to take it out. I did tried on my Control Panel and
unsuccessful.
My 2 cents guess it is they who cause all these problems by hiring a
strong team of virus programmers. Oh, this is no good --- Congress should
step in.

To Aussie Girl, Thanks for your help BUT must I get all those tools?

--Rino


" R I N O " wrote in message
...
Hello Rick,
I'm sorry we didn't eliminate the tricky virus. I let it scanned my 3
hard
dives and found NOTHING or No Virus! (my virus definitions is only 1 day
old). I even did it manually by deleted all my files inside Temp folder
again even though I didn't find the culprit 'se.dll' file in Safe Mode.
Yes, I can easily open my Windows Explorer in Safe Mode. Maybe I should
delete my Temp folder so it could NOT rebuild those files again?

--Rino


" R I N O " wrote in message
...
Thank You Rick, I'm scanning the infected PC and I'll report my result
later. Oops! My typo
--- it should be Shift+Delete and not Ctrl +Delete . . . Sorry.

--Rino


"Rick "Nutcase" Rogers" wrote in message
...
Hi,

Try scanning and deleting the file in Safe mode, where it is not active.
How
to start in Safe mode:
http://www.rickrogers.org/fixes.htm#Safe%20mode

--
Best of Luck,

Rick Rogers, aka "Nutcase" - Microsoft MVP
http://mvp.support.microsoft.com/
Associate Expert - WindowsXP Expert Zone
www.microsoft.com/windowsxp/expertzone
Windows help - www.rickrogers.org

" R I N O " wrote in message
...

I could not open my IE6 and Windows Explorer because my AVG AntiVirus
program always says: While opening files; C:\Document and
Setting\Rino\Local Setting\Temp\se.dll, I clicked OK button and rundll
windows says; Error Loading C:\Docume~1\Rino\Local~1\Temp\se.dll; Access
is
denied, I clicked OK button.

My AVG AntiVirus program indicated a 'Trojan Horse Startpage.16.BD'
virus
infected my se.dll file above. No matter how many times I deleted it or
put it in Virus Vault it always built-up again! I knew you might ask me
how I could see inside my PC without using Windows Explorer? Well, I
used
Search and I used My Computer Icon and select the 'se.dll' and press
Shift+Delete it. Even my AVG has several file of repeated 'Trojan Horse
Startpage.16.BD virus' in the virus vault. I even deleted all files
inside
my Temp folder.

Please fear not because I used another PC to send this call for help.
TIA








  #15  
Old March 25th 05, 09:04 AM
Li'l Roberto
external usenet poster
 
Posts: n/a
Default Trojan Horse Startpage.16.BD Virus

Rino
good to hear you licked it - ! ONYA aussie girl !!

stay clean
rgds
Li'l Roberto



" R I N O " wrote in message ...
Hi Li'l Roberto,
Thank You for giving me your helping hand. I'll put it in my Favorites for my additional tools to combat this malicious menace. I'm glad & happy now because I did finally fixed it and everything returned to normal condition. Read also my complete report to Aussie Girl.

Thanks Again,
--Rino

"Li'l Roberto" wrote in message ...
I have had good results removing these sorts of stuborn infectors
with Sysclean from Trend Micro,
http://www.trendmicro.com/download/dcs.asp
D/L the Sysclean package and run it from the GUI it will find and
remove the hidden DLL that keeps re creating the other files.

good luck
rgds
Li'l Roberto




"The Aussie Girl" wrote in
message ...
Hey Rino

im sorry to bring bad news but everything i said has to be done. You
will
never get rid of about blank without running the ad aware and the
spybot in
the order in which i have told you to do.
About blank isnt actually a virus it is a adware program and as i have
mentioned before deleting your temp files and running anti virus
programs
will not delete this.
I had the exact same virus and trust me it is time consuming yes but
to get
rid of it fully it is necessary. You might get your system up and
running to
a point but unless you do all this it can come back stronger!!!!!!
as i said just write back if you need help or you can email if you
want to
email me let me know

" R I N O " wrote:

Hi Kelly, et al,
Thank You for helping me, I did everything as you told me to do BUT
ONLY a little improvement. The annoying Virus Detected always pop up
and I've to (always) pressed Continue button. I've to manually delete
(now only) 3 files remained in my Temp folder. I knew we didn't
defeat it yet because its still can rebuilt it self --- every files
and Temp folder included just come back --- if it has a character
feature maybe it'll laughing at us. Oh Boy!



 




Thread Tools
Display Modes

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

vB code is On
Smilies are On
[IMG] code is Off
HTML code is Off

Similar Threads
Thread Thread Starter Forum Replies Last Post
Need Help:trojan horse backdoor virus anelkapal General XP issues or comments 2 January 28th 05 07:04 AM
Microsoft Malicious Software Removal Tool Randy General XP issues or comments 21 January 13th 05 12:20 AM
Thinking a trojan virus wrecked my computer. James Windows XP Help and Support 3 December 15th 04 05:06 AM
Can't get to any Internet page//1 Trojan horse still Barbara Z Security and Administration with Windows XP 2 December 13th 04 06:35 PM
Trojan Horse Downloader Lance Cook Security and Administration with Windows XP 1 July 25th 04 05:30 AM






All times are GMT +1. The time now is 10:13 PM.


Powered by vBulletin® Version 3.6.4
Copyright ©2000 - 2024, Jelsoft Enterprises Ltd.
Copyright ©2004-2024 PCbanter.
The comments are property of their posters.