Re: virus
There was some malware that changed the logon shell, called 'hotfix.exe' that ran as the new shell, CTRL-ALT-DEL and killed the hotfix.exe in Task Manager program and then ran explorer.exe from the File > New Task menu which then let me run REGEDIT and found the registry key had been hijacked by malware!!
Just check this registry key:
HKEY_LOCAL_MACHINE>Software>Microsoft>WindowsNT>Cu rrentVersion>Winlogon
and check that 'Shell' = explorer.exe
If it isn't, change it to explorer.exe then find the program that was there and delete it!!
|