TUCoPS :: Hacking Techniques :: fix13.txt

Fixing SubSeven 1.3 - 1.4 - 1.5 BKI:

HackFix - SubSeven - Fix v1.3 + 1.4 + 1.5

Step one is to go to your Start menu, click Shutdown, and select "Restart
the computer in MS-DOS mode", then click ok.
When you do this, you should be in MS-DOS looking at a c:\windows\ prompt.
This version places itself at c:\windows\nodll.exe

Simply type
del nodll.exe
This will delete the trojan.

If this errors, you may need to type
attrib nodll.exe -h
to remove the hidden flag, and then type the delete command above.

Type exit to return to windows.

Note that when Windows starts, you may see a number of errors about a
missing file. Simply click OK to dismiss this warning and continue below to

Next, use Windows Explorer to open the C:\windows\ directory, then find the
file titled win.ini
Simply double click this file to open it in a text editor.

At the top, you should see a line such as run=nodll
You will want to delete the 'nodll' section, leaving 'run='.
Save the file and close it.

Your now disinfected!

