Forum     

Go Back   Digit Technology Discussion Forum > Software > Software Q&A
Register FAQ Calendar Mark Forums Read

Software Q&A Having trouble with software? Find solutions here


Closed Thread
 
LinkBack Thread Tools Display Modes
Old 11-03-2008, 05:13 PM   #1 (permalink)
Juke Box Hero
 
Join Date: Aug 2007
Posts: 1,204
Default Aftermath of a virus/worm!


My Windows XP/SP2 was infected with a virus/worm recently(can't remember the name though) and it was removed using AVG Free Antivirus with latest definition updates. The system is back to normal and is working fine except for one quirky thing. I get this message everytime I start XP.



I have tried the manual registry editing, X-setup, manual startup and services but still am unable to find the source of this entry, I know its there somewhere in the registry but where. If anyone can help me trace it, I would appreciate it.

Thanks.
Hitboxx is offline  
Advertisements. Register and be a member of the community to get rid of them.
Advertisement

Old 11-03-2008, 05:18 PM   #2 (permalink)
Search for Adventure
 
ITTechPerson's Avatar
 
Join Date: Apr 2007
Location: Kolkata, India
Posts: 220
Default Re: Aftermath of a virus/worm!

HAve u tried "msconfig" ? I think it will should be in the startup list of msconfig.
__________________
Nobody is Perfect. I am "Nobody"
ITTechPerson is offline  
Old 11-03-2008, 05:27 PM   #3 (permalink)
Juke Box Hero
 
Join Date: Aug 2007
Posts: 1,204
Default Re: Aftermath of a virus/worm!

Yes, seen there too, but not there.

I forgot to add one more thing, if it helps to identify the virus, during the virus period, the system would run fine except some lag during internet operations and also had registry editor and msconfig disabled. Other than this, there wasn't any visible damage.
Hitboxx is offline  
Old 11-03-2008, 05:34 PM   #4 (permalink)
Think Zen.
 
ray|raven's Avatar
 
Join Date: Dec 2005
Posts: 1,498
Default Re: Aftermath of a virus/worm!

Dude try this: In Regedit ,goto
Quote:
HKEY_LOCAL_MACHINE>SOFTWARE>Microsoft>Windows NT>CurrentVersion>Winlogon
There you should see this:
Quote:
Shell = Explorer.exe "C:\Windows\eksplorasi.exe"
Change it to
Quote:
Shell = "Explorer.exe"
Should work.
__________________
Do what you will; but not because you must. -- Zen Quote
ray|raven is offline  
Old 11-03-2008, 05:43 PM   #5 (permalink)
Juke Box Hero
 
Join Date: Aug 2007
Posts: 1,204
Default Re: Aftermath of a virus/worm!

Thanks man, that should work. If anybody wants to know, I had this in the above mentioned location

Quote:
Explorer.exe "C:\WINDOWS\eksplorasi.exe"
Hitboxx is offline  
Old 11-03-2008, 05:49 PM   #6 (permalink)
Think Zen.
 
ray|raven's Avatar
 
Join Date: Dec 2005
Posts: 1,498
Default Re: Aftermath of a virus/worm!

^Anytime.
__________________
Do what you will; but not because you must. -- Zen Quote
ray|raven is offline  
Old 11-03-2008, 09:26 PM   #7 (permalink)
Techtree Reviewer
 
krazzy's Avatar
 
Join Date: Nov 2007
Location: Mumbai
Posts: 2,190
Default Re: Aftermath of a virus/worm!

Actually Googleing the whole error message would've given you the solution much faster. Same thing happened to me once and thats what I did.
__________________
Prasad Naik
Technology Reviewer for TechTree.com
krazzy is offline  
Old 12-03-2008, 05:58 PM   #8 (permalink)
MVP Awardee 07
 
uzair's Avatar
 
Join Date: Aug 2006
Posts: 67
Default Re: Aftermath of a virus/worm!

The virus u r taking about is the brontok virus
__________________
Probability of me getting a ps3=0

Probability of me getting crazy about ps3=1
uzair is offline  
Old 14-03-2008, 12:03 AM   #9 (permalink)
Distinguished Member
 
anandk's Avatar
 
Join Date: Mar 2005
Location: Pune
Posts: 3,783
Default Re: Aftermath of a virus/worm!

run ccleaner and see ...
__________________
> www.TheWindowsClub.com <
= www.WinVistaClub.com =
Microsoft® MVP
anandk is offline  
Old 14-03-2008, 01:34 AM   #10 (permalink)
ico
.
 
ico's Avatar
 
Join Date: Jun 2007
Location: New Delhi
Posts: 8,936
Default Re: Aftermath of a virus/worm!

Quote:
Originally Posted by uzair View Post
The virus u r taking about is the brontok virus
+1, Its Brontok....

Brontok/Rontokbro was a very good friend of mine in my school. Every computer was infected with it.

Its characterstic is: It creates an .exe which has an icon of a folder with the same name as the folder in every folder. So, the user gets fooled that it is a folder or not. But actually, if you click on the file, you can clearly see that it is an .exe in the Details panel on the left side. of the explorer.

Here are some removal tools. They'll help you in removing the registry entries and other infections if they remain:
http://download.bitdefender.com/reso...rontokA-en.exe
or
http://www.sophos.com/support/cleaners/brontgui.com
or
http://dnl-eu5.kaspersky-labs.com/utils/klwk/klwk.zip


Try everyone of them. This is what I did in my school.....


Also, do install a good AV like NOD32 or Kaspersky. If you want a Free AV, then I'll say to have avast instead of AVG. AVG is the worst.....
__________________
.

Last edited by ico; 14-03-2008 at 01:40 AM.
ico is offline  
Closed Thread

Bookmarks

Thread Tools
Display Modes

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is On
HTML code is Off
Trackbacks are On
Pingbacks are On
Refbacks are On


Similar Threads
Thread Thread Starter Forum Replies Last Post
WORM SPREAD - Skype worm jumps to ICQ, MSN techtronic Technology News 1 25-05-2007 03:19 PM
WORM BEWARE : New Worm Targets Portable Memory Drives techtronic Technology News 1 07-05-2007 05:18 PM
virus Worm.Win32.Detnat.d---URGENT hahahari Software Q&A 2 04-03-2007 12:34 PM
my 6600gt aftermath sunnydiv Gamerz 4 29-03-2005 12:54 AM
Virus/Worm..??? saROMan Software Q&A 1 07-03-2005 02:13 PM

 
Latest Threads
- by Who
- by abhidev
- by icebags
- by Sarath
- by Krow

Advertisement




All times are GMT +5.5. The time now is 09:38 PM.


Powered by vBulletin® Version 3.8.7
Copyright ©2000 - 2012, vBulletin Solutions, Inc.

Search Engine Optimization by vBSEO 3.3.2