Backdoor.hacarmy.c Problem removing

  • Thread starter Thread starter Robert W. Rafferty
  • Start date Start date
R

Robert W. Rafferty

I have Norton Anti-Virus on my XP machine, but I am having a problem
deleting this infected file (ipconfigs.exe). I am following the
instructions on the Norton Website. When I try to bring up regedit, the
screen comes up and then closes immediately. This means I cannot remove the
ipconfigs.exe file to delete the virus. Suggestions?? Can I change the
attributes of the file to delete from another window?
 
Robert,

I have a feeling you are not following the instructions on Symantec's site
exactly as they are stated.

The following is copied from Symantec's instructions;

1. Disable System Restore (Windows Me/XP).
2. Update the virus definitions.
3. Restart the computer in Safe mode or VGA mode.
4. Run a full system scan and delete all the files detected as
Backdoor.Hacarmy.C.
5. Delete the value that was added to the registry.

Are you starting the system in safe mode as stated in step #3?

The following instructions copied from Symantec's site will provide the
necessary steps to do so;

This document provides two methods for starting the computer in Safe Mode.
One method uses the F8 key during system startup, and the other method uses
the System Configuration Utility, which is a feature of some Windows
operating systems. Please note the following:
a.. System Configuration Utility: If you try the System Configuration
Utility and cannot start its dialog box, use the F8 method instead. If the
System Configuration Utility method is not listed for your operating system,
the utility is not available in that operating system.
b.. F8 key: Using the F8 key can be more difficult than using the System
Configuration Utility because you must press the F8 key at just the right
time. If the F8 method does not work, repeat the steps, but press the F8 key
more quickly, or press it several times. If the F8 key still does not work,
use the System Configuration Utility method instead. On some older
computers, the F8 key method does not work because the computer has disabled
the F8 key for this purpose or the computer is designed to use a different
key.
HTH
 
Back
Top