HOW TO REMOVE Trojan.Bookmarker VIRUS

You are here: HOME > COMPUTER > ANTIVIRUS

Trojan.Bookmarker.J

Reported: 30-Nov-05

Description:

Trojan.Bookmarker.J has the capacity to modify Internet Explorer settings by changing the home page and search page, it will add Web sites URL and links to the Favorites menu. The Trojan also downloads remote files and opens a back door.

Technical Name:

Trojan.Bookmarker.J

Threat Level:

Low

Type:

Trojan Horse

Systems Affected:

Windows All

Detection Date:

November 30, 2005

 

 

Trojan.Bookmarker.J removal procedures requires technical know-how on  computer troubleshooting. It is better to consult your LAN Administrator or Technical Persons to avoid additional damage on your computer if modifications on Services and Registry have to be done.
 

MANUAL REMOVAL:

1. Disable System Restore (Windows Me/XP).

2. Update the virus definitions.

3. Run a full system scan and delete all the files detected.

4. Delete any values added to the registry.

Navigate to the subkeys and delete value:

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run
HKEY_CURRENT_USER\Software\Microsoft\Windows NT\CurrentVersion\Windows
Value: "xp_system" = "%Windir%\inet20004\[FILE NAME]"

Navigate to the subkey and delete value:
HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Main
Value: "Enable Browser Extensions" = "yes"

Navigate to and delete the following subkey:
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{5321E378-FFAD-4999-8C62-03CA8155F0B3}

6. Exit the Registry Editor.


7.
Edit the Win.ini file.

In the [windows] section of the file, look for a line similar to any of the following:
"load=%Windir%\inet20004\[FILE NAME]"
"run=%Windir%\inet20004\[FILE NAME]"
*If this line exists, delete everything to the right of run= or load=

 

8. Edit the System.ini file.

In the [boot] section of the file, look for a line similar to:
"load=%Windir%\inet20004\[FILE NAME]"
"run=%Windir%\inet20004\[FILE NAME]"

 

9. Reset the Internet Explorer home page.
 

10. Reset the Internet Explorer search page.

*for full instructions please visit the Symantec Website.

 

11. In order to make sure that trojan bookmarker.j is completely eliminated from your computer, carry out a full scan of your computer using AntiVirus and Antispyware Software. Another way to delete the virus using various Antivirus Program without the need to install can be done with Online Virus Scanner.

 

Download and run any of these Anti-Spyware:

Spy Sweeper

Spyware Doctor

Pest Patrol

Spy Hunter

 

Click here to download

 

Click here to proceed

 

home | computer : securing your pc | antivirus | firewall | anti-spyware | links & resources
pda : securing your handheld | antivirus | security | top top picks | links & resources
cellphone : securing your cellphone | top picks | links & resources