Welcome to Tech Support Forum home to more then 136,000 problems solved. Issues have included: Spyware, Malware, Virus Issues, Windows, Microsoft, Linux, Networking, Security, Hardware, and Gaming Getting your problem solved is as easy as:
1. Registering for a free account
2. Asking your question
3. Receiving an answer

Registered members:
* Get free support
* Communicate privately with other members (PM).
* Removal of this message
* See fewer ads.
* And much more..

 



Want to know how to post a question? click here Having problems with spyware and pop-ups? First Steps
Go Back   Tech Support Forum > Networking Forum > Security and Firewalls
User Name
Password
Site Map Register Donate Rules Blogs Mark Forums Read


Security and Firewalls Protecting you against unwanted people and programs

Closed Thread
 
LinkBack Thread Tools
Old 05-23-2008, 02:14 PM   #1 (permalink)
Registered User
 
Join Date: May 2008
Posts: 4
OS: windows vista


desktop not loading-virus?

Hi,

Im having problems with loading windows explorer. I think I got a virus from torrents that I was downloading. I ran scans with Malwarebytes anti-malware and NIS. Here's what came up in the last 2 malwarebytes scans:

Files Infected:
C:\Windows\System32\sSmNhhIy.dll (Trojan.Vundo) -> Delete on reboot.
C:\Windows\System32\yIhhNmSs.ini (Trojan.Vundo) -> Quarantined and deleted successfully.
C:\Windows\System32\yIhhNmSs.ini2 (Trojan.Vundo) -> Quarantined and deleted successfully.
C:\Windows\System32\ugoacipi.dll (Trojan.Vundo) -> Delete on reboot.
C:\Windows\System32\ipicaogu.ini (Trojan.Vundo) -> Quarantined and deleted successfully.
C:\Windows\System32\urqqNgDV.dll (Trojan.Vundo) -> Quarantined and deleted successfully.
C:\ptgttuaq.exe (Trojan.Agent) -> Quarantined and deleted successfully.
C:\regxpcom.exe (Trojan.FBrowsingAdvisor) -> Quarantined and deleted successfully.
C:\Program Files\FBrowsingAdvisor\XPCOMEvents.dll (Trojan.FBrowsingAdvisor) -> Quarantined and deleted successfully.
C:\Program Files\PlayMP3z\PlayMP3.exe (Adware.Agent) -> Quarantined and deleted successfully.
C:\Users\Sarah\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\R5HT4LEQ\tuhvzqdrv[1].htm (Trojan.Agent) -> Quarantined and deleted successfully.
C:\Users\Sarah\AppData\Local\Temp\tem6747.tmp.exe (Adware.Agent) -> Quarantined and deleted successfully.
C:\Users\Sarah\AppData\Local\Temp\tem8091.tmp.exe (Adware.Agent) -> Quarantined and deleted successfully.
C:\Users\Sarah\AppData\Local\Temp\tem823A.tmp.exe (Trojan.FBrowsingAdvisor) -> Quarantined and deleted successfully.
C:\Users\Sarah\AppData\Local\Temp\tem825.tmp.exe (Adware.Agent) -> Quarantined and deleted successfully.
C:\Users\Sarah\AppData\Local\Temp\temA11F.tmp.exe (Trojan.FBrowsingAdvisor) -> Quarantined and deleted successfully.
C:\Users\Sarah\AppData\Local\Temp\temD4B9.tmp.exe (Trojan.FBrowsingAdvisor) -> Quarantined and deleted successfully.
C:\Windows\System32\gsbgqpwwfw.sys (Rootkit.Agent) -> Quarantined and deleted successfully.
C:\Program Files\FBrowsingAdvisor\IXPCOMEvents.xpt (Trojan.FBrowsingAdvisor) -> Quarantined and deleted successfully.
C:\Program Files\FBrowsingAdvisor\Logo.png (Trojan.FBrowsingAdvisor) -> Quarantined and deleted successfully.
C:\Program Files\FBrowsingAdvisor\main.db (Trojan.FBrowsingAdvisor) -> Quarantined and deleted successfully.
C:\Program Files\FBrowsingAdvisor\unins000.dat (Trojan.FBrowsingAdvisor) -> Quarantined and deleted successfully.
C:\Program Files\FBrowsingAdvisor\unins000.exe (Trojan.FBrowsingAdvisor) -> Quarantined and deleted successfully.
C:\Program Files\PlayMP3z\uninstall.exe (Adware.PlayMP3Z) -> Quarantined and deleted successfully.
C:\ProgramData\Microsoft\Windows\Start Menu\Programs\PlayMP3z\Run PlayMP3z.lnk (Adware.PlayMP3Z) -> Quarantined and deleted successfully.
C:\Windows\System32\crypts.dll (Trojan.Agent) -> Quarantined and deleted successfully.
C:\Windows\System32\iiFwtUNE.dll (Trojan.Agent) -> Delete on reboot.
C:\d.exe (Trojan.Agent) -> Quarantined and deleted successfully.
C:\Windows\System32\mssrv32.exe (Rootkit.Agent) -> Delete on reboot.
C:\Windows\System32\pmnlkHBr.dll (Trojan.Vundo) -> Delete on reboot.


Files Infected:
C:\Windows\System32\iiFwtUNE.dll (Trojan.Agent) -> Quarantined and deleted successfully.
C:\Users\Sarah\AppData\Local\Temp\pMddBTNF.dll (Trojan.Agent) -> Quarantined and deleted successfully.
C:\Windows\System32\mssrv32.exe (Rootkit.Agent) -> Delete on reboot.
C:\Windows\System32\pmnlkHBr.dll (Trojan.Vundo) -> Quarantined and deleted successfully.
C:\Windows\System32\fCRhHyXq.dll (Trojan.Vundo) -> Quarantined and deleted successfully.
C:\Windows\System32\iifcyYoo.dll (Trojan.Vundo) -> Quarantined and deleted successfully


If you could help at all that would be great.

Thanks,
Sarah
skbehan is offline  
Digg this Post!Add Post to del.icio.usBookmark Post in TechnoratiFurl this Post!Reddit!
Important Information
Join the #1 Tech Support Forum Today - It's Totally Free!

TechSupportForum.com is a leading support website for your computer needs. We offer free, friendly and personalized computer support. Why pay to have your computer fixed when you can do it for free.

Join TechSupportforum.com Today - Click Here

Old 05-23-2008, 05:43 PM   #2 (permalink)
Moderator Hardware Team
 
koala's Avatar
 
Join Date: Mar 2005
Location: UK
Posts: 12,381
OS: XP/7/Ubuntu

My System

Re: desktop not loading-virus?

Hi Sarah, welcome to TSF

Please follow these instructions (5 pages) and post the requested logs in a new thread here.

The security forum is extremely busy, so please be patient and you will receive a reply as soon as possible. If you go to Thread Tools > Subscribe at the top of your new thread you will receive an email as soon as a reply is posted.
__________________

New members: Subscribe to your thread (Thread Tools) to
receive an instant email notification when you get a reply.

TSF Folding@Home Team 85015 - details here
koala is offline  
Digg this Post!Add Post to del.icio.usBookmark Post in TechnoratiFurl this Post!Reddit!
Old 08-26-2008, 06:13 PM   #3 (permalink)
Registered User
 
Join Date: Aug 2008
Location: Ecuador
Posts: 1
OS: WinXP SP3


Re: desktop not loading-virus?

I had the same problem after removing viruses using Avast!. Finally, after rebooting the computer, the desktop does not load. I pressed Ctl-Alt-Del to open Task Manager, then from File menu, I chose the New Task (run) option, I typed regedit and opened Windows Registry for editing. In HKLM\Software\Microsoft\WindowsNT\CurrentVersion\winlogon I noticed that the value for Shell was blank, so I typed C:\windows\explorer.exe. And the problem was solved..
cesarhc is offline  
Digg this Post!Add Post to del.icio.usBookmark Post in TechnoratiFurl this Post!Reddit!
Old 11-19-2009, 10:26 AM   #4 (permalink)
Registered User
 
Join Date: Nov 2009
Posts: 1
OS: Vista


Re: desktop not loading-virus?

Quote:
Originally Posted by cesarhc View Post
I had the same problem after removing viruses using Avast!. Finally, after rebooting the computer, the desktop does not load. I pressed Ctl-Alt-Del to open Task Manager, then from File menu, I chose the New Task (run) option, I typed regedit and opened Windows Registry for editing. In HKLM\Software\Microsoft\WindowsNT\CurrentVersion\winlogon I noticed that the value for Shell was blank, so I typed C:\windows\explorer.exe. And the problem was solved..
I just registered only to thank you caesarhc! You saved me a lot of work and time.

And just in case someone else found this thread through a google search and your desktop also keeps blank after log on:
I had a trojan which was routing my explorer start-up through its own routine. Cleaning caused the virus to die, and my Explorer did not start anymore.
So you just have to set (for Vista)
HKEY_CURRENT_USER\Software\Microsoft\Windows NT\CurrentVersion\Winlogon
to C:\windows\explorer.exe (like caesarhc decribed it already- again thx!)


oh... and so for resurrecting an old post....

Last edited by Townx; 11-19-2009 at 10:29 AM.
Townx is offline  
Digg this Post!Add Post to del.icio.usBookmark Post in TechnoratiFurl this Post!Reddit!
Closed Thread


Thread Tools

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is On
HTML code is Off
Trackbacks are Off
Pingbacks are Off
Refbacks are Off




All times are GMT -7. The time now is 12:51 AM.



Copyright 2001 - 2009, Tech Support Forum
Home Tips Plus | Outdoor Basecamp | Automotive Support Forum

1 2 3 4 5 6 7 8 9 10 11 12 13 14 15 16 17 18 19 20 21 22 23 24 25 26 27 28 29 30 31 32 33 34 35 36 37 38 39 40 41 42 43 44 45 46 47 48 49 50 51 52 53 54 55 56 57 58 59 60 61 62 63 64 65 66 67 68 69 70 71 72 73 74 75 76 77 78 79 80 81 82 83 84 85