Re: Explorer.exe infected

From: Mike Burgess (winhelp2002_at_spamthis.com)
Date: 02/24/04


Date: Tue, 24 Feb 2004 12:50:14 -0500

Alex,
Run HijackThis, an entry will show up for that entry.
Select that entry and reboot, you may need to do this in Safe Mode.
http://www.mvps.org/winhelp2002/unwanted.htm
____________________________________________________________
Mike Burgess [MVP Windows Shell\User] http://www.mvps.org/winhelp2002/
Blocking Spyware, Adware, Parasites, Hijackers, Trojans, with a HOSTS file
http://www.mvps.org/winhelp2002/hosts.htm [updated 02-24-04]
Please post replies to this Newsgroup, email address is invalid

--
"Alex" <anonymous@discussions.microsoft.com> wrote in message
news:075601c3fae8$5d759710$a301280a@phx.gbl...
> I downloaded the file, right clicked to 'merge' it with
> my registry, but the dialog to select 'OK' disappers just
> as quickly as the Registry Editing Tool dissapears after
> I tried to run regedit initially?
>
> Also tried to run regedit and no change.  Can't get into
> the registry.
>
> When I reboot the systom remains the same - two explorer
> windows launch at startup.
>
> Anything else I can be doing? Thanks.
>
>
> >-----Original Message-----
> >Alex,
> >Download: EnableRegistryTools.reg
> >[Unlocks the "Disable Regedit" entry]
> >http://www.mvps.org/winhelp2002/unwanted.htm
> >
> >Restart in Safe Mode and follow the instructions:
> >http://securityresponse.symantec.com/avcenter/venc/data/w
> 32.spybot.worm.html
> >_________________________________________________________
> ___
> >Mike Burgess  [MVP Windows Shell\User]
> http://www.mvps.org/winhelp2002/
> >Blocking Spyware, Adware, Parasites, Hijackers, Trojans,
> with a HOSTS file
> >http://www.mvps.org/winhelp2002/hosts.htm [updated 02-18-
> 04]
> >Please post replies to this Newsgroup, email address is
> invalid
> >--
> >
> >"Alex" <anonymous@discussions.microsoft.com> wrote in
> message
> >news:001901c3fa68$60b82710$3501280a@phx.gbl...
> >> I am using Norton Antivirus and its telling me that
> >> explorer.exe is infected with w32.spybot.worm and it
> >> can't be quarantined or deleted.
> >>
> >> Also I follow the instructions in their knowledgebase
> >> article:
> >>
> http://securityresponse.symantec.com/avcenter/venc/data/w3
> >> 2.spybot.worm.html
> >>
> >> but i can't open the registry to edit the keys and
> values
> >> they mention. when i run regedit the registry window
> >> disappears afer a couple of seconds (even in safe mode)
> >>
> >> What to do?
> >
> >
> >.
> >


Relevant Pages

  • stuck on welcome sreen after removing reg strings because of trojan #2
    ... Ad-watch was blocking an entry to the registry So I updated ... So on rebooting, the pc stays on the welcome screen, and in safe mode it ...
    (microsoft.public.windowsxp.help_and_support)
  • cant run the fixblast.exe
    ... Try to open the registry to delete the entry and the ... registry appears for a brief minute and disappears. ... access through safe mode but the entry is not in the ...
    (microsoft.public.windowsxp.security_admin)
  • RE: cant run the fixblast.exe
    ... Try the manual cleanup of the registry/file system using this link: ... Try to open the registry to delete the entry and the ... >access through safe mode but the entry is not in the ...
    (microsoft.public.windowsxp.security_admin)
  • Re: Registry Entry Removal
    ... Taskbar Repair Tool ... and/or try safe mode. ... but unistall did not remve the registry entry under ... How can I remove this registry ...
    (microsoft.public.windowsxp.general)
  • Re: Windows Start Menu
    ... Took my life in my hands and gave CCLeaner a go specifically the Registry Cleaner. ... I should mention I no longer try and use Trend Micro Housecalls - it has lousy communication screens and I found that it was telling me it was going through phases, but leaving it alone for some 30 minutes I got the message it was in a loop. ... So I switched to IE, which I don't normally use and there was a prompt to download Google Chrome, which I did. ... I tried Safe Mode but without selecting 'Safe Mode with Networking' I couldn't e-mail or browse. ...
    (comp.lang.cobol)