Problem and Solution: Dirves are opening "Open With" window?

Hello all,

If you all are facing problem during double click on your local drive and it show you “Open with”. Then I am sure it’s a virus attack. Generally these viruses speared by Yahoo messenger.

Follow the steps given below to clean this virus and make your PC up to date:

1. First you need to fix this “Open With” window problem:

Click here for Reference:

Generally when a virus infects a windows system which causes a drive opening problem, it automatically creates a file named autorun.inf in the root directory of each drive.

This autorun.inf file is a read only ,hidden and a system file and the folder option is also disabled by the virus. This is deliberately done by the virus in order to protect itself. autorun.inf initiates all the activities that the virus performs when you try to open any drive.

You have to just delete this file and restart your system to correct this problem.

Follow the set of commands below to show and delete the autorun.inf

1. Open Start>>Run and type cmd and press enter. This will open a command prompt window. On this command prompt window type the following steps.

2. type cd\

3. type attrib -r -h -s autorun.inf

4. type del autorun.inf

5. now type d: and press enter for d: drive partition. Now repeat steps 3 and 4. Similarly repeat step 5 for all your hard disk partition.

Restart your system and your trouble will be fixed.

2. After Restarting of system, if you face problem like :

a.

Windows cannot find 'C:\WINDOWS\System32\WinSit.exe'. Make sure you typed the name correctly, and then try again. To search for a file, click the Start button, and then click Search."

b.

Windows cannot find "C:\WINDOWS\inf\Other.exe". Make sure you typed the name correctly, and then try again.TO search for a file,click the start button, and then click search.

You need to follow these steps to resolve this problem or click here:

Go to Start --> run typein msconfig then goto the Startup tab then disable the exe from starting with windows


1. Click on OK button and restart the window.

2. WinSit.exe is part of a Worm named 'W32/VB-DXN' as far a i know it is spread via Yahoo instant messenger, it installs itself to various locations on the host computer you should check the following locations on your machine and remove any of the lsited files:-

C:\WINDOWS\Help\Other.exe
C:\WINDOWS\inf\Other.exe
C:\WINDOWS\dc.exe
C:\WINDOWS\sviq.exe
C:\WINDOWS\SYSTEM\Fun.exe
C:\WINDOWS\SYSTEM\WinSit.exe
C:\WINDOWS\config\Win.exe

It also creates the registry entries:-

HKCU\Software\Microsoft\Windows NT\CurrentVersion\Windows
run
\config\Win.exe

HKCU\Software\Microsoft\Windows\CurrentVersion\Run
dc2k5
\SVIQ.EXE

HKCU\Software\Microsoft\Windows\CurrentVersion\Run
Fun
\Fun.exe

HKCU\Software\Microsoft\Windows\CurrentVersion\Run
dc
\dc.exe

HKCU\Software\Microsoft\Windows NT\CurrentVersion\Windows
load
\inf\Other.exe

You should remove any of these occurrences that you find.


Please also check the following registry entry:

HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon

Shell

Explorer.exe \WinSit.exe

You should remove this entry. But save or print this information before removing.

Because after these changes if we restart the system, it might be possible that your desktop will not load so you just follow these steps to restore this entry in windows Registry.

1. Press ALT+Ctrl+Del to open Windows Task Manager.

2. Go on File -- > New Task ( Run ).

3. type regedit and press ok.

4. locate HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogo

5. Double click on shell.

6. Insert “Explorer.exe C:\WINDOWS\system32\WinSit.exe” in to “Value Data”.

7. Close the Registry.

8. Restart machine.

9. That’s it.

Comments

Popular posts from this blog

CSS Mouse Cursors and Custom Cursors

Block right click or disable keyboard on web pages

What is PAD file? "Submit your software with PAD file to Download.com"