Symptom: At every boot the desktop is empty, and the only way to launch a program is through the task manager window.
The infection is detected as 'Adware.Dynamic', published by Dynamic Desktop Media.
Its an 'adware' prg requirin manual installation.
Heard of its contractions via trinsic.org, cracks.am & cerials.net (they belong to the same ring i think)
(Sheesh! risky biz :-p )
Symantec has identified it, but liveupdate (presently) doesnt detect sysu.exe, it detects as yet only Msbb.exe (Adware.Ncase) Optimize.exe (Adware.NetOptimizer) Winpup.exe (Adware.Winpup)
Adaware doesnt detect it yet either.
Anyways, so to get rid of it nicks' manual method is to b done.
But have to be careful to also clean the comps registry as well.
To get the os to continue boot upon the suspension...
a)hit ctrl+alt+del, check the processes running
b)end the process sysu.exe
Thats the easy part, now for gettin rid of it permanently (& >>safely<<),
i found a neat summary for that at one site...
1) Ctrl+alt+delete and identify sysu.exe in the processes list.
2) Close it, and go to C:\Program Files.
3) Locate the folder ddm and delete it.
4) Click on start > run and type in regedit.
5) Under HKEY_LOCAL_MACHINE > SOFTWARE remove the folder ddm.
6) Click on start > run and type in msconfig.
7) Click on the right-most tab labeled startup.
8) Scroll down and locate an entry with no command line.
9) Uncheck the box and apply all changes.
10) Reset your computer, check the checkbox for a window that comes up
saying you changed startup settings.
11) Enjoy, and spread the word.
IMP: dont forget to backup ur registry first, just in case!!
This shud do the trick, till ofcourse there is a patch released to deal with it.
I think sysu.exe particularly is a mistake, cos by not lettin the comp boot, it itself overtakes the primary function of a adware. Well atleast thats wat it seems to be.
Anyways, hope all this proves somewat useful
||CheTaN||
eof()