Microsoft Windows XP Professional Logo

Related Topics:

Anonymous Posted on Oct 19, 2009

My computer is infected with the messenger blocker virus. I am following instructions given on the symantec.com web site to resolve it. One of the steps requires editing the registry, but whenever i try to click start>run> type regedit, the registry flashes for a second and then dissappears. I also tried the inf solution given on symantec.com but thats of no use. Please help.

2 Answers

Anonymous

Level 2:

An expert who has achieved level 2 by getting 100 points

Hot-Shot:

An expert who has answered 20 questions.

Corporal:

An expert that has over 10 points.

Mayor:

An expert whose answer got voted for 2 times.

  • Expert 86 Answers
  • Posted on Oct 19, 2009
Anonymous
Expert
Level 2:

An expert who has achieved level 2 by getting 100 points

Hot-Shot:

An expert who has answered 20 questions.

Corporal:

An expert that has over 10 points.

Mayor:

An expert whose answer got voted for 2 times.

Joined: Oct 19, 2009
Answers
86
Questions
0
Helped
17441
Points
165

Go to google and type in trojan remover install it and run the program.

Anonymous

Level 2:

An expert who has achieved level 2 by getting 100 points

MVP:

An expert that got 5 achievements.

Governor:

An expert whose answer got voted for 20 times.

Scholar:

An expert who has written 20 answers of more than 400 characters.

  • Expert 89 Answers
  • Posted on Oct 19, 2009
Anonymous
Expert
Level 2:

An expert who has achieved level 2 by getting 100 points

MVP:

An expert that got 5 achievements.

Governor:

An expert whose answer got voted for 20 times.

Scholar:

An expert who has written 20 answers of more than 400 characters.

Joined: Sep 04, 2009
Answers
89
Questions
1
Helped
18343
Points
268

Try using Combofix, then update and run your virus scan. Combofix will attempt to delete and viruses it can, but it will clean the registry so you can perform some scanning and virus removals. Works Great and highly recommended. I use it all the time on client PCs.

http://www.combofix.org/download.php

Ad

Add Your Answer

×

Uploading: 0%

my-video-file.mp4

Complete. Click "Add" to insert your video. Add

×

Loading...
Loading...

Related Questions:

0helpful
2answers

I help how to remove trojan/other virus from my window 7 laptop.please help me.

Here's a fee-based service to do it for you:

http://us.norton.com/nortonlive/

To detect the threat level, you may want to try the free (& advertised on TV) web site
www.MySafePC.com, but virus removal will cost $$ - they're happy to tell you you're infected for
free, though.

Here's Symantec's list of things to do:

If you suspect that your computer is infected with a threat or you receive a threat alert, and you want to make sure that your computer is secure.

You can perform a virus scan to eliminate any known threat from your computer. Scanning your computer for threats is easy if you follow the step-by-step instructions provided in this article. The scanning process may take an hour or more, depending on the number of files you have on your computer.

To detect and remove all the threats from your computer, follow these five steps:

• Install the latest virus definitions.

• Stop all running programs and temporarily disconnect the computer from any network.

• Run the virus scan.

• Install the latest Windows updates.

• Run a full system scan once again to ensure that there are no threats.

The first step is to check whether you can install the latest virus definitions, as some threats may block your access to all the security products' Web sites including Symantec's Web site. The subsequent steps vary depending on whether you can download the latest definitions from the Symantec Web site or not.
tip

WEB based virus scanning

If you have been infected with a virus and you do not have a virus scanning program installed on your computer or laptop, you can try removing the virus using a WEB based virus program provided you can still access the Internet.
Once your have suceeded in removing the virus, I suggest you install a virus program. There are freeware virus programs on the Internet such as AVG, but generally a commerical verson offers better protection.

Try these WEB-based Virus Scan
Trend Micro HouseCall
http://housecall.trendmicro.com
Symantec - Norton Security Scan
http://security.symantec.com
Malware file download
http://www.malwarebytes.org/mbam.php
on Aug 30, 2010 • Computers & Internet
0helpful
2answers

I have virus problem need to solve it and protect my laptop from virus

If it is a bad virus that won't let you do anything on the computer, follow the instructions on this link. If you can install programs on your computer, follow only steps 7 and 8 from the above link.
0helpful
1answer

My computer was a dangres virus arounh with vary bad

if your computer is infected with virus,
go to the following site
www.tinyurl.com/npelatest
go to this site to download norton power eraser tool and run it
after runnig that if your computer has got infections then it will be displayed in the scan
click on fix to remove the ifections
restart the computer
0helpful
1answer

I HAVE A VIRUS ON MY COMPUTER I NEED TO FIX

You maybe able to remove the virus from your computer using a WEB based virus program provided you can connect to the Internet. Please click on these links to these WEB sites :-
WEB-based Virus Scan Trend Micro HouseCall
http://housecall.trendmicro.com
Symantec - Norton Security Scan
http://security.symantec.com
Malware file download
http://www.malwarebytes.org/mbam.php
After removing the virus, I suggest you install a virus program to stop
further virus infections.
0helpful
1answer

What is runtime error 216 at005FD748

Make sure that all your infected computers are physically disconnected from the Internet and any other networks while you work to resolve this issue. For instructions about how to recover an infected computer, visit the following Carnegie Mellon Web site: http://www.cert.org/tech_tips/win-UNIX-system_compromise.html Microsoft does not provide software that can detect or remove computer viruses. If you suspect or confirm that your computer is infected with a virus, obtain current antivirus software. For a list of antivirus software manufacturers, click the following article number to see the article in the Microsoft Knowledge Base: 49500 List of Antivirus Software Vendors Back to the top MORE INFORMATION For additional information about distributed denial-of-service attacks and Trojan viruses, visit the following Microsoft Web site: http://technet.microsoft.com/en-us/library/cc722931.aspx Microsoft provides third-party contact information to help you find technical support. This contact information may change without notice. Microsoft does not guarantee the accuracy of this third-party contact information.
For additional information about the "Runtime Error 216" error message, see the following article in the Microsoft Knowledge Base: 189989 Error Message: Runtime Error 216 at 00009275





0helpful
1answer

Runtime error 216 at 0016D758 - what is this about

You are infected with the Sub seven trojan.

To determine if your computer is infected with this virus, visit the following Web sites:
http://www.symantec.com/avcenter/venc/data/backdoor.subseven.html (http://www.symantec.com/avcenter/venc/data/backdoor.subseven.html)
http://www.europe.f-secure.com/v-descs/subseven.shtml (http://www.europe.f-secure.com/v-descs/subseven.shtml)
0helpful
2answers

Internet explorer problem

This issue can occur if your computer is infected with a SubSeven Trojan virus.

I'd re-install the Norton if possible. Are you still able to access the internet? If so, a good free AV that I use is AVG.

Go to Majorgeeks.com and search for AVG.

Never run a computer on the Internet without a good anti-virus.

Honest1abe
0helpful
2answers

How do i get rid of a W32.SillyFDC virus

The following instructions pertain to all current and recent Symantec antivirus products, including the Symantec AntiVirus and Norton AntiVirus product lines.
  1. Disable System Restore (Windows Me/XP).
  2. Update the virus definitions.
  3. Run a full system scan.
  4. Delete any values added to the registry.

For specific details on each of these steps, read the following instructions.

1. To disable System Restore (Windows Me/XP)
If you are running Windows Me or Windows XP, we recommend that you temporarily turn off System Restore. Windows Me/XP uses this feature, which is enabled by default, to restore the files on your computer in case they become damaged. If a virus, worm, or Trojan infects a computer, System Restore may back up the virus, worm, or Trojan on the computer.

Windows prevents outside programs, including antivirus programs, from modifying System Restore. Therefore, antivirus programs or tools cannot remove threats in the System Restore folder. As a result, System Restore has the potential of restoring an infected file on your computer, even after you have cleaned the infected files from all the other locations.

Also, a virus scan may detect a threat in the System Restore folder even though you have removed the threat.

For instructions on how to turn off System Restore, read your Windows documentation, or one of the following articles:

Note: When you are completely finished with the removal procedure and are satisfied that the threat has been removed, reenable System Restore by following the instructions in the aforementioned documents.

For additional information, and an alternative to disabling Windows Me System Restore, see the Microsoft Knowledge Base article: Antivirus Tools Cannot Clean Infected Files in the _Restore Folder (Article ID: Q263455).

2. To update the virus definitions
Symantec Security Response fully tests all the virus definitions for quality assurance before they are posted to our servers. There are two ways to obtain the most recent virus definitions:
  • Running LiveUpdate, which is the easiest way to obtain virus definitions.

    If you use Norton AntiVirus 2006, Symantec AntiVirus Corporate Edition 10.0, or newer products, LiveUpdate definitions are updated daily. These products include newer technology.

    If you use Norton AntiVirus 2005, Symantec AntiVirus Corporate Edition 9.0, or earlier products, LiveUpdate definitions are updated weekly. The exception is major outbreaks, when definitions are updated more often.


  • Downloading the definitions using the Intelligent Updater: The Intelligent Updater virus definitions are posted daily. You should download the definitions from the Symantec Security Response Web site and manually install them.

The latest Intelligent Updater virus definitions can be obtained here: Intelligent Updater virus definitions. For detailed instructions read the document: How to update virus definition files using the Intelligent Updater.

3. To run a full system scan
  1. Start your Symantec antivirus program and make sure that it is configured to scan all the files.

    For Norton AntiVirus consumer products: Read the document: How to configure Norton AntiVirus to scan all files.

    For Symantec AntiVirus Enterprise products: Read the document: How to verify that a Symantec Corporate antivirus product is set to scan all files.


  2. Run a full system scan.
  3. If any files are detected, follow the instructions displayed by your antivirus program.
  4. Delete the autorun.inf file from writeable removable devices, if necessary.
Important: If you are unable to start your Symantec antivirus product or the product reports that it cannot delete a detected file, you may need to stop the risk from running in order to remove it. To do this, run the scan in Safe mode. For instructions, read the document, How to start the computer in Safe Mode. Once you have restarted in Safe mode, run the scan again.


After the files are deleted, restart the computer in Normal mode and proceed with the next section.

Warning messages may be displayed when the computer is restarted, since the threat may not be fully removed at this point. You can ignore these messages and click OK. These messages will not appear when the computer is restarted after the removal instructions have been fully completed. The messages displayed may be similar to the following:

Title: [FILE PATH]
Message body: Windows cannot find [FILE NAME]. Make sure you typed the name correctly, and then try again. To search for a file, click the Start button, and then click Search.

4. To delete the value from the registry
Important: Symantec strongly recommends that you back up the registry before making any changes to it. Incorrect changes to the registry can result in permanent data loss or corrupted files. Modify the specified subkeys only. For instructions refer to the document: How to make a backup of the Windows registry.
  1. Click Start > Run.
  2. Type regedit
  3. Click OK.

    Note: If the registry editor fails to open the threat may have modified the registry to prevent access to the registry editor. Security Response has developed a tool to resolve this problem. Download and run this tool, and then continue with the removal.

  4. Navigate to the following registry subkeys:

    HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run
    HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\Shell Folders
    HKEY_CURRENT_USER\Software\Microsoft\Windows NT\CurrentVersion\Windows\"load"

  5. In the right pane, delete any values associated with the worm.


  6. Exit the Registry Editor.
1helpful
1answer

I have win32 virus in my pc...

The following instructions pertain to all current and recent Symantec antivirus products, including the Symantec AntiVirus and Norton AntiVirus product lines.


Disable System Restore (Windows Me/XP).
Remove all the entries that the risk added to the hosts file.
Update the virus definitions.
Run a full system scan and delete all the files detected.
Delete any values added to the registry.

For specific details on each of these steps, read the following instructions.

1. To disable System Restore (Windows Me/XP)
If you are running Windows Me or Windows XP, we recommend that you temporarily turn off System Restore. Windows Me/XP uses this feature, which is enabled by default, to restore the files on your computer in case they become damaged. If a virus, worm, or Trojan infects a computer, System Restore may back up the virus, worm, or Trojan on the computer.

Windows prevents outside programs, including antivirus programs, from modifying System Restore. Therefore, antivirus programs or tools cannot remove threats in the System Restore folder. As a result, System Restore has the potential of restoring an infected file on your computer, even after you have cleaned the infected files from all the other locations.

Also, a virus scan may detect a threat in the System Restore folder even though you have removed the threat.

For instructions on how to turn off System Restore, read your Windows documentation, or one of the following articles:
How to disable or enable Windows Me System Restore
How to turn off or turn on Windows XP System Restore

Note: When you are completely finished with the removal procedure and are satisfied that the threat has been removed, reenable System Restore by following the instructions in the aforementioned documents.

For additional information, and an alternative to disabling Windows Me System Restore, see the Microsoft Knowledge Base article: Antivirus Tools Cannot Clean Infected Files in the _Restore Folder (Article ID: Q263455).


2. To remove all the entries that the risk added to the hosts file

Navigate to the following location:


Windows 95/98/Me:
%Windir%
Windows NT/2000/XP:
%Windir%\System32\drivers\etc

Notes:
The location of the hosts file may vary and some computers may not have this file. There may also be multiple copies of this file in different locations. If the file is not located in these folders, search your disk drives for the hosts file, and then complete the following steps for each instance found.
%Windir% is a variable that refers to the Windows installation folder. By default, this is C:\Windows (Windows 95/98/Me/XP) or C:\Winnt (Windows NT/2000).


Double-click the hosts file.
If necessary, deselect the "Always use this program to open this program" check box.
Scroll through the list of programs and double-click Notepad.
When the file opens, delete all the entries added by the risk. (See the Technical Details section for a complete list of entries.)
Close Notepad and save your changes when prompted.


3. To update the virus definitions
Symantec Security Response fully tests all the virus definitions for quality assurance before they are posted to our servers. There are two ways to obtain the most recent virus definitions:
Running LiveUpdate, which is the easiest way to obtain virus definitions: These virus definitions are posted to the LiveUpdate servers once each week (usually on Wednesdays), unless there is a major virus outbreak. To determine whether definitions for this threat are available by LiveUpdate, refer to Virus Definitions (LiveUpdate).
Downloading the definitions using the Intelligent Updater: The Intelligent Updater virus definitions are posted daily. You should download the definitions from the Symantec Security Response Web site and manually install them. To determine whether definitions for this threat are available by the Intelligent Updater, refer to Virus Definitions (Intelligent Updater).

The latest Intelligent Updater virus definitions can be obtained here: Intelligent Updater virus definitions. For detailed instructions read the document: How to update virus definition files using the Intelligent Updater.


4. To scan for and delete the infected files
Start your Symantec antivirus program and make sure that it is configured to scan all the files.
For Norton AntiVirus consumer products: Read the document: How to configure Norton AntiVirus to scan all files.
For Symantec AntiVirus Enterprise products: Read the document: How to verify that a Symantec Corporate antivirus product is set to scan all files.
Run a full system scan.
If any files are detected, click Delete.

Important: If you are unable to start your Symantec antivirus product or the product reports that it cannot delete a detected file, you may need to stop the risk from running in order to remove it. To do this, run the scan in Safe mode. For instructions, read the document, How to start the computer in Safe Mode. Once you have restarted in Safe mode, run the scan again.

After the files are deleted, restart the computer in Normal mode and proceed with the next section.

Warning messages may be displayed when the computer is restarted, since the threat may not be fully removed at this point. You can ignore these messages and click OK. These messages will not appear when the computer is restarted after the removal instructions have been fully completed. The messages displayed may be similar to the following:

Title: [FILE PATH]
Message body: Windows cannot find [FILE NAME]. Make sure you typed the name correctly, and then try again. To search for a file, click the Start button, and then click Search.


5. To delete the value from the registry
Important: Symantec strongly recommends that you back up the registry before making any changes to it. Incorrect changes to the registry can result in permanent data loss or corrupted files. Modify the specified subkeys only. For instructions refer to the document: How to make a backup of the Windows registry.

Click Start > Run.
Type regedit
Click OK.

Note: If the registry editor fails to open the threat may have modified the registry to prevent access to the registry editor. Security Response has developed a tool to resolve this problem. Download and run this tool, and then continue with the removal.


Navigate to and delete the subkey:

HKEY_LOCAL_MACHINE\System\CurrentControlSet\Services\RpcRemotes


Navigate to the subkey:

HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Setup


In the right pane, delete the value:

"Ph4nt0m" = "Ph4nt0m"


Navigate to the subkey:

HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\wuauserv


In the right pane, reset the value to the original value if applicable:

"Start"


Navigate to the subkey:

HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess


In the right pane, reset the value to the original value if applicable:

"Start"


Exit the Registry Editor.



also u can use the link for free download of virus removal tool
http://www.bitdefender.com/site/Download/browseFreeRemovalTool/
Not finding what you are looking for?

61 views

Ask a Question

Usually answered in minutes!

Top Microsoft Computers & Internet Experts

Grand Canyon Tech
Grand Canyon Tech

Level 3 Expert

3867 Answers

k24674

Level 3 Expert

8093 Answers

Brad Brown

Level 3 Expert

19187 Answers

Are you a Microsoft Computer and Internet Expert? Answer questions, earn points and help others

Answer questions

Manuals & User Guides

Loading...