Computing.Net > Forums > Security and Virus > How to remove explorer.exe virus?

Computer Problems? Computing.Net has over 1,000,000 posts about all things technology related! Over 90% answered within 24 hours! Click here to start participating now! Also, be sure to check out the New User Guide.

How to remove explorer.exe virus?

Reply to Message Icon

Name: Qasim Ali
Date: May 12, 2009 at 10:55:23 Pacific
OS: Windows XP
CPU/Ram: 1 GH / 256 MB
Subcategory: Viruses
Comment:

Hi, Guys!

I have a virus in my PC. When I scanned my full Computer by AVG 8.5 Free Edition, then it caught a virus whose name given by AVG is "Trojan horse Generic10.BTM" and also called "explorer.exe". Now virus is removed but when I Double click on any drive (C:, D: etc) then it opens in a new Window and if I do right single click then in menu an anknown language is replaced by "OPEN" command. So I request you to tell me how can I remove that unknown language and can open any drive by Double click?

If anyone knows about that I request him to answer me as soon as possible.

Regards,

Qasim Ali.
http://qaswallpapers.sitesled.com .



Sponsored Link
Ads by Google

Response Number 1
Name: ComBatch
Date: May 13, 2009 at 02:13:24 Pacific
Reply:

1. Click Start > Run.
2. Type regedit
3. Click OK.

Note: If the registry editor fails to open the threat may have modified the registry to prevent access to the registry editor. Security Response has developed a tool to resolve this problem. Download and run this tool, and then continue with the removal.
4. Navigate to and delete the following entries:

HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run\"IEXPLORER"="%System%\iexplorer.exe"

5. Navigate to and delte the following registry subkeys:

* HKEY_CURRENT_USER\Software\mmtest
* HKEY_CURRENT_USER\Software\mmtest\IEXPLORER


6. Restore the following registry entries to their original values, if required:

* HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\explorer\advanced\folder\hidden\showall\"CheckedValue" = "0"
* HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\[FILE NAME]\"Debugger" = "%System%\wuauc1t.exe"

[FILE NAME] represents any application executable file on the compromised computer, including, but not limited to the following strings:

* 360rpt.exe
* 360safe.exe
* 360tray.exe
* ANTIARP.exe
* Ast.exe
* AutoRunKiller.exe
* AvMonitor.exe
* AVP.exe
* CCenter.exe
* Frameworkservice.exe
* IceSword.exe
* Iparmor.exe
* KASARP.exe
* KRegEx.exe
* KVMonxp.kxp
* KVSrvXP.exe
* KVWSC.exe
* Mmsk.exe
* Navapsvc.exe
* Nod32kui.exe
* QQDOCTOR.exe
* Regedit.exe
* VPC32.exe
* VPTRAY.exe
* WOPTILITIES.exe
* Wuauclt.exe


7. Exit the Registry Editor.

Note: If the risk creates or modifies registry subkeys or entries under HKEY_CURRENT_USER, it is possible that it created them for every user on the compromised computer. To ensure that all registry subkeys or entries are removed or restored, log on using each user account and check for any HKEY_CURRENT_USER items listed above.



0
Reply to Message Icon

Related Posts

See More







Post Locked

This post is quite old and has been locked from receiving new replies. Please create a new posting instead.


Go to Security and Virus Forum Home


Sponsored links

Ads by Google


Results for: How to remove explorer.exe virus?

how to remove z connect virus www.computing.net/answers/security/how-to-remove-z-connect-virus-/27136.html

how to remove winser.exe www.computing.net/answers/security/how-to-remove-winserexe/15231.html

How to remove autorun.inf virus www.computing.net/answers/security/how-to-remove-autoruninf-virus/23742.html