my microsoft xp doesnt want to shut down..i have this virus and tried to fix it
I had a virus / worm, heres the link of the exact worm my computer has. . i tried to follow all instructions there. . now the only problem is that my pc wont shut down. . . nothing happens when i click shut down im using xp!! pls pls pls help.
I had a virus / worm, heres the link of the exact worm my computer has
http://securityresponse.symantec.com/avcenter/venc/data/w32.rontokbro.k@mm.html
..i tried to follow all instructions there..now the only problem is that my pc wont shut down...nothing happens when i click "shut down" im using xp!! pls pls pls help..i also installed nortons anti virus professional edition..
pls pls pls help! ;(
http://securityresponse.symantec.com/avcenter/venc/data/w32.rontokbro.k@mm.html
..i tried to follow all instructions there..now the only problem is that my pc wont shut down...nothing happens when i click "shut down" im using xp!! pls pls pls help..i also installed nortons anti virus professional edition..
pls pls pls help! ;(
Participate on our website and join the conversation
This topic is archived. New comments cannot be posted and votes cannot be cast.
Responses to this topic
Did you run the scan in safe-mode?
Did you delete/reset these in the registry?
Navigate to the subkey and delete value:
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run
Value: "Bron-Spizaetus" = ""%Windir%\ShellNew\sempalong.exe""
Navigate to the subkey and delete value:
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run
Value: "Tok-Cirrhatus" = "%UserProfile%\Local Settings\Application Data\smss.exe""
Navigate to the subkey and reset value to default if required:
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon
Value: "Shell" = "Explorer.exe"
Navigate to the subkey and reset value to default if required:
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\Explorer
Value: "NoFolderOptions" = "0" or "NoFolderOptions" = "1"
Navigate to the subkey and reset values to default if required:
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\explorer\advanced
Values:
"Hidden" = "0" or "Hidden" = "1"
"ShowSuperHidden" = "0" or "ShowSuperHidden" = "1"
"HideFileExt" = "0" or "HideFileExt" = "1"
7. Exit Registry and Restart the computer.
Did you delete/reset these in the registry?
Navigate to the subkey and delete value:
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run
Value: "Bron-Spizaetus" = ""%Windir%\ShellNew\sempalong.exe""
Navigate to the subkey and delete value:
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run
Value: "Tok-Cirrhatus" = "%UserProfile%\Local Settings\Application Data\smss.exe""
Navigate to the subkey and reset value to default if required:
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon
Value: "Shell" = "Explorer.exe"
Navigate to the subkey and reset value to default if required:
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\Explorer
Value: "NoFolderOptions" = "0" or "NoFolderOptions" = "1"
Navigate to the subkey and reset values to default if required:
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\explorer\advanced
Values:
"Hidden" = "0" or "Hidden" = "1"
"ShowSuperHidden" = "0" or "ShowSuperHidden" = "1"
"HideFileExt" = "0" or "HideFileExt" = "1"
7. Exit Registry and Restart the computer.
Zinnia, do what Tool has suggested and if you are still having problems.
Go to A Squared and download their trojan detection program. It is free of charge and run it. You can get it here at this address. http://www.emsisoft.com/en/software/free/.
If that doesn't help the problem then post back for more ideas.
Good Luck
Go to A Squared and download their trojan detection program. It is free of charge and run it. You can get it here at this address. http://www.emsisoft.com/en/software/free/.
If that doesn't help the problem then post back for more ideas.
Good Luck
I did all, but i didnt run in safe mode because my nortons was able to delete the virus..it says to run in safe mode only if virus couldnt delelet..
Yup..i delete and followed what it says..
My friend gave me a registry fix..it fixed about 512 problems..but still it wont shut down..and now..worst..it wont restart..i just pull of the plug..
Yup..i delete and followed what it says..
My friend gave me a registry fix..it fixed about 512 problems..but still it wont shut down..and now..worst..it wont restart..i just pull of the plug..
Two quick thoughts that may help.
Have you tried this shutdown & restart troubleshooter?
http://aumha.org/win5/a/shtdwnxp.htm
If nothing there works are you able to download HijackThis from here ....
http://www.majorgeeks.com/download3155.html
....to either the infected computer or to a CD/floppy another one?
If so then scan the infected PC with it and post the final Notepad log report to this thread. It may reveal what your problem is.
Have you tried this shutdown & restart troubleshooter?
http://aumha.org/win5/a/shtdwnxp.htm
If nothing there works are you able to download HijackThis from here ....
http://www.majorgeeks.com/download3155.html
....to either the infected computer or to a CD/floppy another one?
If so then scan the infected PC with it and post the final Notepad log report to this thread. It may reveal what your problem is.
Sounds like you still have the trojan or you picked up another one. Did you go to A Squared and download and run their program yet?
Since the info at Symantec list's nearly every anti-virus maker that can cause the trojan to restart your computer, including norton. Go here http://support.f-secure.com/enu/home/ols.shtml and run their online scan and see what it comes up with and then post the results back in this posting and then we can go from there.
Also do as mainman suggests and grab and run hijack this. It can't hurt to cover all bases.
Since the info at Symantec list's nearly every anti-virus maker that can cause the trojan to restart your computer, including norton. Go here http://support.f-secure.com/enu/home/ols.shtml and run their online scan and see what it comes up with and then post the results back in this posting and then we can go from there.
Also do as mainman suggests and grab and run hijack this. It can't hurt to cover all bases.