Trojan horse Startpage.3.AR

Latest post 03-15-2004 1:00 PM by mirrorshades. 1 replies.

Trojan horse Startpage.3.AR

03-15-2004 11:44 AM

I picked up a virus that came through my Internet Explorer and subsequently was picked up by my Grisoft AVG anti-virus software. Small number of files were infected and were subsequently healed by the AVG software but, there are 2 files that my AVG says it can't heal and that I should place such files in the virus vault. What the AVG also says is that the actual name of the virus is "Trojan horse Startpage.3.AR" and that the infected object is a file named c:\\windows\olehelp.exe . In your opinion what should I do to remove this virus other than to just move it to the virus vault? Also, the other files that my AVG said that it healed are also in my virus vault. The name of these infected files are verifier bug [1].class; Blackbox[1].class: another named Blackbox [1].class , and one that says msdos.exe . The olehelp.exe file is infected by the Trojan horse Startpage.3.AR ; one of those files are infected by something called the Backdoor.Jeemp.A, and the other 4 files are infected by something called the Java/Byte Verify. Currently my hard drive is virus free as all of those files are in my virus vault. What should I do with those files as all of the infected files in the virus vault have a red "healed" marker next to them saying that they are healed except for the olehelp.exe which as I said could not be healed. If I restore any one of those files in from my virus vault to my hard drive, I get a virus detected message again when I run my AVG. Also, for your information, when the infection occurred, a page by the name of www.-my-find.com attempted to hijack my homepage. I did successfully remove that hijacking page from my registry as it is not now hijacking my homepage, but the infected files are still in my vault. I just need to know why they are still there; why can't they all be healed; why I can't just delete them. Thanks.

RE: Trojan horse Startpage.3.AR

03-15-2004 1:00 PM

Sounds like this might be bundled with some spyware. Try downloading Spybot S&D from this site:

http://security.kolla.de/

Install it and update the definitions ("check for program updates"), then do a system scan. You might also want to check out the "immunization" options to permanently protect your computer.