belgianexpatria
01-10-2003, 04:06 PM
Hi,
This morning my Windows 98 PC got infected with BKDR_OPTIXPRO.12 (=Trojan horse Backdoor.Optix). My AVG anti-virus detected it and blocked access to infected file REGSRV.EXE but not before it had installed itself.
Stupidly enough I did reboot my PC before checking and removing every component.
I then did an extra scan with Trend Micro Housecall (http://housecall.antivirus.com/housecall/start_corp.asp) which detected 1 more infected file in my C:/WINDOWS directory - winampw.exe
I deleted it, as the anti-virus software couldn't clean it.
After doing that I could not run ANY application unless I click on an associated file. After checking the File Types Tab under Windows Folder Options I discovered that ALL Applications had been reassociated with that infected winampw.exe file to be able to run. I obviously cannot run regedit.exe or any registry editing app under Windows anymore to change the association and the File Types Tab under Windows Folder Options does not allow editing of that particular association.
I am stumped!!! I there any way I can change the application association back to its original state?
I checked these 2 links:
http://www.trendmicro.com/vinfo/virusencyclo/default5.asp?VName=BKDR_OPTIXPRO.12
http://securityresponse.symantec.com/avcenter/venc/data/backdoor.optixpro.12.html
but none of them deal with this particular problem I got.
Please help me out! :( Throw me a bone. I'd be much obliged.
This morning my Windows 98 PC got infected with BKDR_OPTIXPRO.12 (=Trojan horse Backdoor.Optix). My AVG anti-virus detected it and blocked access to infected file REGSRV.EXE but not before it had installed itself.
Stupidly enough I did reboot my PC before checking and removing every component.
I then did an extra scan with Trend Micro Housecall (http://housecall.antivirus.com/housecall/start_corp.asp) which detected 1 more infected file in my C:/WINDOWS directory - winampw.exe
I deleted it, as the anti-virus software couldn't clean it.
After doing that I could not run ANY application unless I click on an associated file. After checking the File Types Tab under Windows Folder Options I discovered that ALL Applications had been reassociated with that infected winampw.exe file to be able to run. I obviously cannot run regedit.exe or any registry editing app under Windows anymore to change the association and the File Types Tab under Windows Folder Options does not allow editing of that particular association.
I am stumped!!! I there any way I can change the application association back to its original state?
I checked these 2 links:
http://www.trendmicro.com/vinfo/virusencyclo/default5.asp?VName=BKDR_OPTIXPRO.12
http://securityresponse.symantec.com/avcenter/venc/data/backdoor.optixpro.12.html
but none of them deal with this particular problem I got.
Please help me out! :( Throw me a bone. I'd be much obliged.