This is a read-only archive. No new posts or registrations. Privacy Page
Spyware / Malware / Virus Removal

[Closed] I have a nasty virus on Win XP laptop

2 min read

This thread's last reply is from . Advice, software, and links below may be out of date — treat specific steps and download links with caution.

Looking for the outcome? Ask AI

I've been getting regular interruptions from a strange (never before seen) window claiming I have a virus and need to download "virus scanning software". I've heard about these things so I quickly answered "no" when prompted. Problem is it keeps popping up, and now when I try to open windows task manager or go to add/remove programs (assuming something has been downloaded by mistake) I am told the function cannot be performed. Almost as if the virus is protecting itself. I finally knew for sure I had something when random porn sites (not that I mind too much…) would open up without me even being online. Have tried a system restore (-2 weeks) and things cleared up for a few days, but eventually came back, so it must still be living somewhere. I have spybot S&D, but that has not been effective so far. What do I do? Thanks! Bren
Hi,

Please do the following:


First


Click Start >Run type notepad into the run box click OK
Click Format and make certain that Word Wrap is NOT checked.

Copy the text inside of the code box, Press Ctrl+C (or right click on the highlighted section and choose 'copy')

Now paste the copied text into the open notepad, press CTRL+V (or right click and choose 'paste')

Note: There must be NO blank lines in front of the pasted text, but ensure that there is a blank line at the end of the text, otherwise the registry merge will not work.

REGEDIT4

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Winlogon]
"Userinit"="C:\\windows\\system32\\userinit.exe,"
"Shell"="explorer.exe"

Now go to File > and click Save As,
From the drop down menu at the top of the box choose Desktop as the location to save this file.
Go down to the File Name box and type in fixme.reg as the file name, then choose All Files as the save as file type.
Then click the save button.
Once you have clicked the save button, close Notepad.

You should now see a file on your desktop that looks like this:

[external image: Posted Image]

Locate the fixme.reg icon on your desktop and double click it, an information box will pop up asking if you want to merge the information in the file into the registry, click YES.

Once the file has run, the information will have merged with your registry so you can delete fixme.reg from your desktop as you won't be needing it any more.


NEXT


Go to Start > Run > copy past the following command into the run box > OK
reg add "HKCU\Software\Microsoft\Windows\CurrentVersion\Policies\System" /v DisableTaskMgr /t reg_dword /d 0 /f



That will restore your task manager.


Now open Task Manager (Ctrl + Alt + Del)

see if any of the following listed processes are running > If they are > end process


smss32.exe
winlogon32.exe
winupdate86.exe
msa.exe
a.exe
b.exe
c.exe
notepad.exe
41.exe
logon.exe
critical_warning.html
lsm32.sys
opeia.exe
IS2010.exe
xxxsysguard.exe
antimalware.exe
wscsvc32.exe



NEXT


Please download exeHelper to your desktop.
Double-click on exeHelper.com to run the fix.
A black window should pop up, press any key to close once the fix is completed.
Post the contents of log.txt (Will be created in the directory where you ran exeHelper.com)
Note: If the window shows a message that says "Error deleting file", please re-run the program before posting a log - and post the two logs together (they will both be in the one file).


NEXT

Please download DDS from either of these links

LINK 1
LINK 2

and save it to your desktop.
  • Disable any script blocking protection
  • Double click dds.pif to run the tool.
  • When done, two DDS.txt's will open.
  • Save both reports to your desktop.
—————————————————
Please include the contents of the following in your next reply:

DDS.txt
Attach.txt.

NEXT


[external image: Posted Image]
Download GMER Rootkit Scanner from here or here.
  • Extract the contents of the zipped file to desktop.
  • Double click GMER.exe. If asked to allow gmer.sys driver to load, please consent .
  • If it gives you a warning about rootkit activity and asks if you want to run scan…click on NO.

    [external image: Posted Image]
    Click the image to enlarge it
  • In the right panel, you will see several boxes that have been checked. Uncheck the following …
    • Sections
    • IAT/EAT
    • Drives/Partition other than Systemdrive (typically C:\)
    • Show All (don't miss this one)
  • Then click the Scan button & wait for it to finish.
  • Once done click on the [Save..] button, and in the File name area, type in "Gmer.txt" or it will save as a .log file which cannot be uploaded to your post.
  • Save it where you can easily find it, such as your desktop, and post it in your next reply.

**Caution**
Rootkit scans often produce false positives. Do NOT take any action on any "<— ROOKIT" entries
I cannot run notepad or download anything because "antivirus live" is blocking all activity. I get the following message…"application cannot be executed". The file (insert whatever it is I am trying to open, e.g., notepad..) is infected. do you want to activate antivirus software now?" Thats it for everything. I can search my hard drive for malware, but the file names on these blogs and forums are not showing up. Help.
No. cmd prompt is not functioning either. I get the same error for each command I use. I am on a different computer right now b/c I cannot do anything on my laptop (location of my troubles), so cutting and pasting isn't an option. I am running in safe mode now and trying to dismantle some sketchy files I found. moywssysguard.exe and others…
Hi,

look at the list I provided:

most of those files (if they are present) will be located in your C:\windows\system32 folder

be careful deleting these two files if you find them - leave them till we can verify your userinit value is in place

winlogon32.exe
winupdate86.exe


they hook into your winlogon replacing the legitimate userinit file, resulting in a log on log off loop - that was why i gave you the registry fix.

Just do enough to get the task manager and run box to function, then we can use tools to safely remove the rest.

If you have a USB exeHelper can be run from the USB without having to download it to your desktop


the desktop is locked by a file called warning.html

it usually resides in C:\windows

Ask AI

AI can make mistakes. Check the cited posts. Archived advice can be out-of-date

Don't include personal information. Questions and selected public posts go to OpenAI. About Ask AI