Relatives machine -- infected files -- cleaning up the damage

explorer2012

Honorable
Feb 4, 2013
1
0
10,510
ESET anti-virus found 4 infected files which were quarantined. The files were "probably a variant of Win32/InstallIQ potentially unwanted application". Examination of the machine shows a few problems.

In the root of C drive, there are several directories that are composed of strings of characters. Some of these strings are 30 characters long. I'm assuming these directories were created by windows updates over time. One of these directories is:

c:\980b8ba83e25aa813c

and it contains a subdirectory called "Start Menu". This Start Menu gives "access denied" error if I attempt to enter it. The permissions "read only" and "hidden" are unchecked.

Now -- To the point -- If I right-click the "Start" button and select "explore", XP complains:

----------------

C:\980b8ba83e25aa813c\StartMenu is not accessible

Access is denied.

----------------

So .... something has taken the explorer pointer from C:\windows and has set it to C:\980b8ba83e25aa813c\StartMenu.


Also, all the menu items in my Start --> Programs menu are gone. Clicking on the "programs" entry shows: (Empty)

Any ideas on how to fix these problems?









 


Anti-virus programs may remove the virus, but will not fix the damage once it's changed files and the registry.