Close HijackThis. After that, I removed the files and folders listed in your fix, then ran MalwareBytes, which found and deleted 22 infected files/keys/values.

Click Start to begin the process, and then allow the tool to run.Note: If you have any problems when you run the tool, or it does nor appear to remove the

When I run Hijack This, the only entries I have starting with O10 are these: O10 – Unknown file in Winsock LSP: c:\windows\system32\winhelper32.dll O10 – Unknown file in Winsock LSP: c:\windows\system32\winhelper32.dll

Search for such entries in the scan results: F2 - REG:system.ini: Shell=Explorer.exe logon.exe F2 - REG:system.ini: UserInit=C:\WINDOWS\system32\winlogon86.exe O4 - HKLM\..\Run: [winupdate86.exe] C:\WINDOWS\system32\winupdate86.exe Select all such entries and click once on the If you wish to eliminate spyware from your PC and prevent future spyware attacks, we recommend you buy SpyHunter's spyware removal tool, which includes full technical support and a Spyware HelpDesk Step 2.

Note for network administrators: For network administrators.

Recommendation: It is necessary to perform a system scan. Generated Tue, 24 Jan 2017 08:32:52 GMT by s_hp107 (squid/3.5.23) skip to main | skip to sidebar Malware Removal Instructions From network security to phishing and malicious software. Select "View" tab and uncheck the checkbox labeled "Hide file extensions for known file types". SpyHunter spyware detection tool is only a scanner meant to assist you in detecting Worm.Win32.Netsky and other threats.

LSPFix did not display winhelper86.dll so I moved on, Malwarebytes ran for 21 hours 51 minutes 48 seconds.

Symptoms in a HijackThis Log F2 - REG:system.ini: Shell=Explorer.exe logon.exe F2 - REG:system.ini: UserInit=C:\WINDOWS\system32\winlogon86.exe O4 - HKLM\..\Run: [winupdate86.exe] C:\WINDOWS\system32\winupdate86.exe O10 - Unknown file in Winsock LSP: c:\windows\system32\winhelper86.dll O10 - Unknown file Several functions may not work. I did a reboot but am stuck at the Login screen. Ask a homework question - tutors are online Spyware Techie Norton safe Web WOT Reputation McAfee - Site Advisor Webutations AVG threat labs Spyware Help Computer Help Internet Security Security News

I then had the same issue Steven had on Jan 6 where I couldn't login to windows, and then your advice for him on Jan 7 (Steven, try copy userinit.exe to

Any help regarding reactivating System Restore.

In worst cases this worm can allow attachers to access your computer, stealing passwords and personal data.

I have downloaded hijackthis to a cd. When I turned my computer on windows security alert boxes kept popping up to say that my computer had been hacked into and had a virus and another warned that it

All appears to be normal and running smoothly again.

Your instructions were so easy to follow and your program did what it promised.

The content provided on this website is intended for educational or informational purposes and is provided "AS IS" with no warranties, and confers no rights.

It much appreciated. Matt ― January 29, 2010 - 1:15 pm I don't generally post on sites like this, but I feel obligated to in this case. HELP, safe mode SUCKS! Patrik ― December 30, 2009 - 10:57 am Josh, try run Windows registry editor and restore HKEY_LOCAL_MACHINE\SOFTWARE\MICROSOFT\Windows NT\CurrentVersion\Winlogon, UserInit to "c:\windows\system32\userinit.exe," Then reboot your computer. TB Marufur Thank you very much. http://copyprotecteddvd.net/computer-infected/computer-infected-plz-help.html Worm.Win32.Netsky installs on your computer through a trojan and may infect your system without your knowledge or consent.

Type copy userinit.exe winlogon86.exe and press Enter. Ran malwarebytes (updated on the 1st) and removed 19 affected files. Click OK. 4.

At first I was worried then logic took over. Now that I was able to login to windows once again, I ran virus scans, adware scans, malware scans, and registry cleaners to make sure everything is clean, but after 5-10

Type: #comment-## 9 It will copy hijackthis.exe from disk e (use your CD disk name) to root of disk C.

Comment by Mike — December 28, 2009 # I'm trying this fix you posted: "Mike, looks like your AV is removed infected files, but did not repair Windows registry.

The system cannot find the file specified." I will continue to search. Worm.Win32.Netsky detected on your machine" And it may look like this fake warning in the image below.

After detection of Worm.Win32.Netsky, the next advised step is to remove Worm.Win32.Netsky with the purchase of the SpyHunter Spyware removal tool. You need rename HijackThis.exe to explorer.exe in Save dialog!