
[Resolved] Your system is infected desktop
#1
Posted 26 January 2010 - 07:28 PM
Register to Remove
#2
Posted 26 January 2010 - 07:50 PM
Please do the following:
Download OTL to your Desktop
- Double click on the icon to run it. Make sure all other windows are closed and to let it run uninterrupted.
- Under the Custom Scans/Fixes box at the bottom, paste in the following
:Reg [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon] "Shell"="explorer.exe" "Userinit"="C:\\WINDOWS\\system32\\Userinit.exe," [HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\System] "DisableTaskMgr"=- [HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\System] "DisableTaskMgr"=- [HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\Explorer] "NoSetActiveDesktop"=- "NoActiveDesktopChanges"=- [HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\Explorer] "NoSetActiveDesktop"=- "NoActiveDesktopChanges"=- :Files helper32.dll /lsp winhelper86.dll /lsp %HOMEDRIVE%\Internet Security 2010.lnk /s %systemroot%\System32\winlogon32.exe %systemroot%\System32\smss32.exe %systemroot%\System32\AVR10.exe %systemroot%\System32\helper32.dll %systemroot%\System32\winlogon32.exe %systemroot%\System32\smss32.exe %systemroot%\System32\warning.html %systemroot%\system32\IS15.exe %systemroot%\System32\winhelper86.dll %HOMEDRIVE%\trhh.exe %HOMEDRIVE%\sdigdvmg.exe %HOMEDRIVE%\wgqi.exe %HOMEDRIVE%\byyk.exe %systemroot%\lsass.exe %systemroot%\odbn0.exe %systemroot%\System32\sdra64.exe %systemroot%\System32\41.exe %systemroot%\System32\153.exe %systemroot%\System32\292.exe %systemroot%\System32\491.exe %systemroot%\System32\1869.exe %systemroot%\system32\2876.exe %systemroot%\System32\2995.exe %systemroot%\System32\3902.exe %systemroot%\System32\4827.exe %systemroot%\System32\5436.exe %systemroot%\System32\5447.exe %systemroot%\System32\5705.exe %systemroot%\System32\6334.exe %systemroot%\System32\7376.exe %systemroot%\System32\9961.exe %systemroot%\System32\11478.exe %systemroot%\System32\11538.exe %systemroot%\System32\11942.exe %systemroot%\System32\12382.exe %systemroot%\system32\12662.exe %systemroot%\System32\13931.exe %systemroot%\system32\14070.exe %systemroot%\System32\14604.exe %systemroot%\System32\14771.exe %systemroot%\System32\15724.exe %systemroot%\System32\16827.exe %systemroot%\System32\16944.exe %systemroot%\system32\17125.exe %systemroot%\System32\17421.exe %systemroot%\System32\18467.exe %systemroot%\System32\18716.exe %systemroot%\System32\19169.exe %systemroot%\System32\19718.exe %systemroot%\System32\19895.exe %systemroot%\system32\19905.exe %systemroot%\System32\19912.exe %systemroot%\system32\21386.exe %systemroot%\System32\21726.exe %systemroot%\system32\22934.exe %systemroot%\System32\23281.exe %systemroot%\system32\24242.exe %systemroot%\System32\24464.exe %systemroot%\system32\24478.exe %systemroot%\System32\26308.exe %systemroot%\System32\26500.exe %systemroot%\System32\26962.exe %systemroot%\system32\27213.exe %systemroot%\System32\28145.exe %systemroot%\system32\28466.exe %systemroot%\System32\29358.exe %systemroot%\System32\32391.exe %systemroot%\System32\32439.exe %systemroot%\system32\ndisdrv.sys %HOMEDRIVE%\s %systemroot%\system32\kbdsock.dll %systemroot%\system32\mshlps.dll %systemroot%\system32\drivers\kdrhkukb.sys %PROGRAMFILES%\InternetSecurity2010 %systemroot%\System32\lowsec :Services lmuytnv ndisdrv qvazdxe :Commands [purity] [emptytemp] [CREATERESTOREPOINT] [resethosts]
- Then click the Run Fix button at the top
- Let the program run unhindered, it wont take long.
Microsoft MVP 2010, 2011, 2012, 2013, 2014, 2015
#3
Posted 26 January 2010 - 07:57 PM
#4
Posted 26 January 2010 - 08:12 PM
http://oldtimer.geekstogo.com/OTL.exe
Microsoft MVP 2010, 2011, 2012, 2013, 2014, 2015
#5
Posted 26 January 2010 - 08:22 PM
#6
Posted 26 January 2010 - 08:28 PM
Microsoft MVP 2010, 2011, 2012, 2013, 2014, 2015
#7
Posted 26 January 2010 - 08:31 PM
#8
Posted 26 January 2010 - 08:39 PM
go to start > run
copy/paste the following command into the run box > OK
reg add "HKCU\Software\Microsoft\Windows\CurrentVersion\Policies\System" /v DisableTaskMgr /t Reg_dword /d 0 /f
This should enable your Task Manager.
Now go into your task manager (ctrl +alt +del)
see if there are any processes lited from the list below: If there are > end process (do not reboot) > that should be enough to get the OTL program downloaded:
winlogon32.exe
smss32.exe
AVR10.exe
helper32.dll
winlogon32.exe
smss32.exe
warning.html
IS15.exe
winhelper86.dll
trhh.exe
sdigdvmg.exe
wgqi.exe
byyk.exe
odbn0.exe
sdra64.exe
41.exe
153.exe
Microsoft MVP 2010, 2011, 2012, 2013, 2014, 2015
#9
Posted 26 January 2010 - 08:44 PM
#10
Posted 26 January 2010 - 08:51 PM
http://www.raktor.ne...er/explorer.exe
Microsoft MVP 2010, 2011, 2012, 2013, 2014, 2015
Register to Remove
#11
Posted 26 January 2010 - 09:01 PM
#12
Posted 26 January 2010 - 09:05 PM
Microsoft MVP 2010, 2011, 2012, 2013, 2014, 2015
#13
Posted 26 January 2010 - 09:10 PM
#14
Posted 26 January 2010 - 09:13 PM
re-run exe helper
then copy paste the path for OTL into your browser again
http://oldtimer.geekstogo.com/OTL.exe
a file should start to download - save it to your desktop.
If a download doesn't start tell me what happens when you try it?
Microsoft MVP 2010, 2011, 2012, 2013, 2014, 2015
#15
Posted 26 January 2010 - 09:18 PM
0 user(s) are reading this topic
0 members, 0 guests, 0 anonymous users