Friday, June 22, 2007

How to remove Costrat Trojan & xpds.sys file?

Yesterday my office PC with Windows XP pro was affected with Vundo trojan & Costrat Trojan.

I tried to remove it with my McAfee Antivirus & Xsoft spy.Both the programs were detecting the file , but it couldn't remove completley.I even tried with Windows defender, but it couldn't detect the file.Xsoft Spy has detected following file

c:/Windows/system32/xpdx.sys


& tried to remove it by restarting the computer, but it couldn't delete this file xpdx.sys.

Then I find a tool to remove this trojan by googling.

Thanks to http://forums.pcpitstop.com/lofiversion/index.php/t128220.html for showing me this little tool.

You can download this from SDFix

  • Download SDFix and save it to your Desktop.
  • Double click SDFix.exe and choose Install to extract it to its own folder on the Desktop.

Please then reboot your computer in Safe Mode by doing the following :

  • Restart your computer
  • After hearing your computer beep once during startup, but before the Windows icon appears, tap the F8 key continually
  • Instead of Windows loading as normal, the Advanced Options Menu should appear
  • Select the first option (SAFE MODE), to run Windows in Safe Mode, then press Enter.
  • Choose your usual account.
  • Open the extracted SDFix folder and double click RunThis.bat to start the script.
  • Type Y to begin the cleanup process.
  • It will remove any Trojan Services or Registry Entries found then prompt you to press any key to Reboot.
  • Press any Key and it will restart the PC.
  • When the PC restarts the Fixtool will run again and complete the removal process then display Finished, press any key to end the script and load your desktop icons.

0 comments: