Compatible Support Forums: my microsoft xp doesnt want to shut down..i have this virus and tried to fix it

Jump to content

Page 1 of 1
  • You cannot start a new topic
  • You cannot reply to this topic

my microsoft xp doesnt want to shut down..i have this virus and tried to fix it

#1 User is offline   zinniasunflower 

  • stranger
  • Group: Members
  • Posts: 2
  • Joined: 27-March 06

Posted 27 March 2006 - 04:47 PM

I had a virus / worm, heres the link of the exact worm my computer has

http://securityresponse.symantec.com/avcenter/venc/data/w32.rontokbro.k@mm.html

..i tried to follow all instructions there..now the only problem is that my pc wont shut down...nothing happens when i click "shut down" im using xp!! pls pls pls help..i also installed nortons anti virus professional edition..

pls pls pls help! ;(
0

#2 User is offline   tool_462 

  • enthusiast
  • Group: Members
  • Posts: 200
  • Joined: 22-November 04

Posted 27 March 2006 - 05:24 PM

Did you run the scan in safe-mode?
Did you delete/reset these in the registry?



Navigate to the subkey and delete value:
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run
Value: "Bron-Spizaetus" = ""%Windir%\ShellNew\sempalong.exe""

Navigate to the subkey and delete value:
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run
Value: "Tok-Cirrhatus" = "%UserProfile%\Local Settings\Application Data\smss.exe""

Navigate to the subkey and reset value to default if required:
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon
Value: "Shell" = "Explorer.exe"

Navigate to the subkey and reset value to default if required:
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\Explorer
Value: "NoFolderOptions" = "0" or "NoFolderOptions" = "1"

Navigate to the subkey and reset values to default if required:
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\explorer\advanced
Values:
"Hidden" = "0" or "Hidden" = "1"
"ShowSuperHidden" = "0" or "ShowSuperHidden" = "1"
"HideFileExt" = "0" or "HideFileExt" = "1"

7. Exit Registry and Restart the computer.
0

#3 User is offline   Cormac 

  • enthusiast
  • Group: Members
  • Posts: 396
  • Joined: 17-June 05
  • LocationUSA

Posted 27 March 2006 - 07:37 PM

Zinnia, do what Tool has suggested and if you are still having problems.
Go to A Squared and download their trojan detection program. It is free of charge and run it. You can get it here at this address. http://www.emsisoft.com/en/software/free/.
If that doesn't help the problem then post back for more ideas.
Good Luck
0

#4 User is offline   zinniasunflower 

  • stranger
  • Group: Members
  • Posts: 2
  • Joined: 27-March 06

Posted 28 March 2006 - 12:36 AM

I did all, but i didnt run in safe mode because my nortons was able to delete the virus..it says to run in safe mode only if virus couldnt delelet..

Yup..i delete and followed what it says..

My friend gave me a registry fix..it fixed about 512 problems..but still it wont shut down..and now..worst..it wont restart..i just pull of the plug..
0

#5 User is offline   mainman 

  • stranger
  • Group: Members
  • Posts: 1
  • Joined: 28-March 06

Posted 28 March 2006 - 08:09 PM

Two quick thoughts that may help.

Have you tried this shutdown & restart troubleshooter?

http://aumha.org/win5/a/shtdwnxp.htm

If nothing there works are you able to download HijackThis from here ....

http://www.majorgeeks.com/download3155.html

....to either the infected computer or to a CD/floppy another one?

If so then scan the infected PC with it and post the final Notepad log report to this thread. It may reveal what your problem is.
0

#6 User is offline   Cormac 

  • enthusiast
  • Group: Members
  • Posts: 396
  • Joined: 17-June 05
  • LocationUSA

Posted 28 March 2006 - 08:18 PM

Sounds like you still have the trojan or you picked up another one. Did you go to A Squared and download and run their program yet?
Since the info at Symantec list's nearly every anti-virus maker that can cause the trojan to restart your computer, including norton. Go here http://support.f-secure.com/enu/home/ols.shtml and run their online scan and see what it comes up with and then post the results back in this posting and then we can go from there.

Also do as mainman suggests and grab and run hijack this. It can't hurt to cover all bases.
0

Share this topic:


Page 1 of 1
  • You cannot start a new topic
  • You cannot reply to this topic

1 User(s) are reading this topic
0 members, 1 guests, 0 anonymous users