Quote:
|
Originally Posted by digit i am thinking
Please help me,whenever i right click on my external HDD insted of open is shows somthing ????(o). what is this? is it becaue of virus.
|
Your system is infected with malware.
Name: Trojan.vb.atv
Risk:High
This Trojan is usually transmitted from pen-drives. It opens two exe process "wsctf.exe" and "EXPLORER.exe". On transmitting further it kills most of the system32 process and has a disastrous effect on the computer. Proceeding further it will also make some changes in the registry, making "My Documents" folder to open automatically at Windows log-in. It also adds a value "EXPLORER.EXE" in winlogon key value and makes EXPLORER.EXE to run at start-up.
This is a Trojan, hence most of the antivirus won't recognise it. However antisyware applications do recognise it. Please follow the instructions I gave given exactly.
Removal Instructions:
1. Download and install "
AVG Antispyware Free Edition".
2. Disable "System Restore" in Windows. This is very important to see that the trojan doesn't come back.
3. Restart Windows in "Safe Mode"
4. Make sure all windows are closed. Now scan complete system using AVG Antispyware
5. Quarantine all the infections displayed after scanning.
6. Now restart Windows in normal mode.
If "My Documents" folder is opening automatically after log-on, do the following changes in the registry:
1. Start>Run
2. Type "regedit" and enter
3. Propogate to:
Code:
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon
4. In the right pane, right-click Userinit, and then click Modify.
5. In the String dialog box, you will find "EXPLORER.EXE". This is the entry left by Trojan. Type C:\WINDOWS\system32\userinit.exe under Value data, and then click OK. (I am assuming that you installed Windows in C drive. The drive letter may vary depending upon where you installed Windows)
6. Now propogate to:
Code:
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\Advanced
7. In the right pane, right-click PersistBrowsers, and then click Modify.
8. In the DWORD Value dialog box, type 0 under Value data, and then click OK.
9. Exit Registry editor
10. Log-off Windows and Log-in again, "My Documents" will not open automatically now.
Your problem must be solved if you follow all these exactly.