Restoration Method for desktop tampering after Trojans in Windows

Source: Internet
Author: User

Today, I accidentally got something and ran it. In 2 seconds, the desktop was refreshed about 4-5 times. As a result, there was a white unsung icon on the desktop, which could not be deleted, could not be copied, and could not be cut, unable to edit, cannot open, cannot ...... In addition, the "My document" (displayed as the user name in the system after Vista) and "network" icons are missing, and both of them are checked in the Change desktop icon. I searched the internet and found the registry was tampered.

Essentially, items in the Registry under HKEY_LOCAL_MACHINE \ SOFTWARE \ Microsoft \ Windows \ CurrentVersion \ Explorer \ Desktop \ namespace \ are deleted or tampered. The following shows the normal registry key value. You can copy it to a text file and name it *. Reg. Then, you can import it to the Registry.

----- XP -----

Windows Registry Editor Version 5.00
[HKEY_LOCAL_MACHINE \ SOFTWARE \ Microsoft \ Windows \ CurrentVersion \ Explorer \ Desktop \ namespace]
[HKEY_LOCAL_MACHINE \ SOFTWARE \ Microsoft \ Windows \ CurrentVersion \ Explorer \ Desktop \ namespace \ {1f4de370-d627-11d1-ba4f-00a0c91eedba}]
@ = "Computer search results folder"
[HKEY_LOCAL_MACHINE \ SOFTWARE \ Microsoft \ Windows \ CurrentVersion \ Explorer \ Desktop \ namespace \ {d8fba-ad25-11d0-98a8-0800361b1103}]
@ = ""
"Removal message" = "@ mydocs. dll,-900"
[HKEY_LOCAL_MACHINE \ SOFTWARE \ Microsoft \ Windows \ CurrentVersion \ Explorer \ Desktop \ namespace \ {645ff040-5081-101b-9f08-00aa002f954e}]
@ = "Recycle bin"
[HKEY_LOCAL_MACHINE \ SOFTWARE \ Microsoft \ Windows \ CurrentVersion \ Explorer \ Desktop \ namespace \ {e17d4fc0-5564-11d1-83f2-00a0c90dc849}]
@ = "Search Results folder"

----- Vista -----

[HKEY_LOCAL_MACHINE \ SOFTWARE \ Microsoft \ Windows \ CurrentVersion \ Explorer \ Desktop \ namespace \ {04731b67-d933-440a-90e6-4acd2e9408fe}]
@ = "Search folder"
[HKEY_LOCAL_MACHINE \ SOFTWARE \ Microsoft \ Windows \ CurrentVersion \ Explorer \ Desktop \ namespace \ {21ec2020-3aea-1069-a2dd-08002b30309d}]
@ = "Controlpanelclassicview"
[HKEY_LOCAL_MACHINE \ SOFTWARE \ Microsoft \ Windows \ CurrentVersion \ Explorer \ Desktop \ namespace \ {26ee0668-a00a-44d7-9371-beb064c98683}]
@ = "Controlpanelcategoryview"
[HKEY_LOCAL_MACHINE \ SOFTWARE \ Microsoft \ Windows \ CurrentVersion \ Explorer \ Desktop \ namespace \ {4336a54d-038b-4685-ab02-99bb52d3fb8b}]
@ = "Public folder"
[HKEY_LOCAL_MACHINE \ SOFTWARE \ Microsoft \ Windows \ CurrentVersion \ Explorer \ Desktop \ namespace \ {d8fba-ad25-11d0-98a8-0800361b1103}]
@ = "Documents"
"Removal message" = "@ mydocs. dll,-900"
[HKEY_LOCAL_MACHINE \ SOFTWARE \ Microsoft \ Windows \ CurrentVersion \ Explorer \ Desktop \ namespace \ {59031a47-3f72-44a7-89c5-5595fe6b30ee}]
@ = "Usersfiles"
"Removal message" = "@ shell32.dll,-9047"
[HKEY_LOCAL_MACHINE \ SOFTWARE \ Microsoft \ Windows \ CurrentVersion \ Explorer \ Desktop \ namespace \ {645ff040-5081-101b-9f08-00aa002f954e}]
@ = "Recycle bin"
[HKEY_LOCAL_MACHINE \ SOFTWARE \ Microsoft \ Windows \ CurrentVersion \ Explorer \ Desktop \ namespace \ {89d83576-6bd1-4c86-9454-beb04e94c819}]
@ = "Mapi folder"
[HKEY_LOCAL_MACHINE \ SOFTWARE \ Microsoft \ Windows \ CurrentVersion \ Explorer \ Desktop \ namespace \ {9343812e-1c37-4a49-a12e-4b2d810d956b}]
@ = "Search home"
[HKEY_LOCAL_MACHINE \ SOFTWARE \ Microsoft \ Windows \ CurrentVersion \ Explorer \ Desktop \ namespace \ {BD7A2E7B-21CB-41b2-A086-B309680C6B7E}]
@ = "CSC folder"
[HKEY_LOCAL_MACHINE \ SOFTWARE \ Microsoft \ Windows \ CurrentVersion \ Explorer \ Desktop \ namespace \ {ED228FDF-9EA8-4870-83b1-96b02CFE0D52}]
"Removal message" = "@ gameux. dll,-10038"
[HKEY_LOCAL_MACHINE \ SOFTWARE \ Microsoft \ Windows \ CurrentVersion \ Explorer \ Desktop \ namespace \ {F02C1A0D-BE21-4350-88B0-7367FC96EF3C}]
@ = "Computers and devices"

----- Win 7 -----

[HKEY_LOCAL_MACHINE \ SOFTWARE \ Microsoft \ Windows \ CurrentVersion \ Explorer \ Desktop \ namespace \ {031e4825-7b94-4dc3-b131-e946b44c8dd5}]
@ = "Userslibraries"
"Removal message" = "@ shell32.dll,-9047"
[HKEY_LOCAL_MACHINE \ SOFTWARE \ Microsoft \ Windows \ CurrentVersion \ Explorer \ Desktop \ namespace \ {04731b67-d933-440a-90e6-4acd2e9408fe}]
@ = "Clsid_searchfolder"
[HKEY_LOCAL_MACHINE \ SOFTWARE \ Microsoft \ Windows \ CurrentVersion \ Explorer \ Desktop \ namespace \ {11016101-e366-4d22-bc06-4ada335c892b}]
@ = "Ie history and feeds shell data source for Windows Search"
[HKEY_LOCAL_MACHINE \ SOFTWARE \ Microsoft \ Windows \ CurrentVersion \ Explorer \ Desktop \ namespace \ {26ee0668-a00a-44d7-9371-beb064c98683}]
@ = "Controlpanelhome"
[HKEY_LOCAL_MACHINE \ SOFTWARE \ Microsoft \ Windows \ CurrentVersion \ Explorer \ Desktop \ namespace \ {4336a54d-038b-4685-ab02-99bb52d3fb8b}]
@ = "Public folder"
[HKEY_LOCAL_MACHINE \ SOFTWARE \ Microsoft \ Windows \ CurrentVersion \ Explorer \ Desktop \ namespace \ {d8fba-ad25-11d0-98a8-0800361b1103}]
@ = "Documents"
"Removal message" = "@ mydocs. dll,-900"
[HKEY_LOCAL_MACHINE \ SOFTWARE \ Microsoft \ Windows \ CurrentVersion \ Explorer \ Desktop \ namespace \ {5399e694-6ce5-4d6c-8fce-1d8870fdcba0}]
@ = "Controlpanelstartuppage"
[HKEY_LOCAL_MACHINE \ SOFTWARE \ Microsoft \ Windows \ CurrentVersion \ Explorer \ Desktop \ namespace \ {59031a47-3f72-44a7-89c5-5595fe6b30ee}]
@ = "Usersfiles"
[HKEY_LOCAL_MACHINE \ SOFTWARE \ Microsoft \ Windows \ CurrentVersion \ Explorer \ Desktop \ namespace \ {645ff040-5081-101b-9f08-00aa002f954e}]
@ = "Recycle bin"
[HKEY_LOCAL_MACHINE \ SOFTWARE \ Microsoft \ Windows \ CurrentVersion \ Explorer \ Desktop \ namespace \ {89d83576-6bd1-4c86-9454-beb04e94c819}]
@ = "Mapi folder"
[HKEY_LOCAL_MACHINE \ SOFTWARE \ Microsoft \ Windows \ CurrentVersion \ Explorer \ Desktop \ namespace \ {8fd8b88d-30e1-4f25-ac2b-553d65f0ea}]
@ = "Dxp"
[HKEY_LOCAL_MACHINE \ SOFTWARE \ Microsoft \ Windows \ CurrentVersion \ Explorer \ Desktop \ namespace \ {9343812e-1c37-4a49-a12e-4b2d810d956b}]
@ = "Search home"
[HKEY_LOCAL_MACHINE \ SOFTWARE \ Microsoft \ Windows \ CurrentVersion \ Explorer \ Desktop \ namespace \ {98d99750-0b8a-4c59-9151-589054253d73}]
@ = "Windows Search Service Media Center namespace extension handler"
[HKEY_LOCAL_MACHINE \ SOFTWARE \ Microsoft \ Windows \ CurrentVersion \ Explorer \ Desktop \ namespace \ {B4FB3F98-C1EA-428d-A78A-D1F5659CBA93}]
@ = "Other users"
[HKEY_LOCAL_MACHINE \ SOFTWARE \ Microsoft \ Windows \ CurrentVersion \ Explorer \ Desktop \ namespace \ {BD7A2E7B-21CB-41b2-A086-B309680C6B7E}]
@ = "CSC folder"
[HKEY_LOCAL_MACHINE \ SOFTWARE \ Microsoft \ Windows \ CurrentVersion \ Explorer \ Desktop \ namespace \ {daf95313-e44d-46af-be1b-cbacea2c3065}]
@ = "Clsid_startmenuproviderfolder"
[HKEY_LOCAL_MACHINE \ SOFTWARE \ Microsoft \ Windows \ CurrentVersion \ Explorer \ Desktop \ namespace \ {e345f35f-9397-435c-8f95-4e922c26259e}]
@ = "Clsid_startmenupathcompleteproviderfolder"
[HKEY_LOCAL_MACHINE \ SOFTWARE \ Microsoft \ Windows \ CurrentVersion \ Explorer \ Desktop \ namespace \ {ED228FDF-9EA8-4870-83b1-96b02CFE0D52}]
"Removal message" = "@ gameux. dll,-10038"
[HKEY_LOCAL_MACHINE \ SOFTWARE \ Microsoft \ Windows \ CurrentVersion \ Explorer \ Desktop \ namespace \ {F02C1A0D-BE21-4350-88B0-7367FC96EF3C}]
@ = "Computers and devices"
[HKEY_LOCAL_MACHINE \ SOFTWARE \ Microsoft \ Windows \ CurrentVersion \ Explorer \ Desktop \ namespace \ {F3F5824C-AD58-4728-AF59-A1EBE3392799}]
@ = "Sticky notes namespace extension for Windows Desktop Search"

Related Article

Contact Us

The content source of this page is from Internet, which doesn't represent Alibaba Cloud's opinion; products and services mentioned on that page don't have any relationship with Alibaba Cloud. If the content of the page makes you feel confusing, please write us an email, we will handle the problem within 5 days after receiving your email.

If you find any instances of plagiarism from the community, please send an email to: info-contact@alibabacloud.com and provide relevant evidence. A staff member will contact you within 5 working days.

A Free Trial That Lets You Build Big!

Start building with 50+ products and up to 12 months usage for Elastic Compute Service

  • Sales Support

    1 on 1 presale consultation

  • After-Sales Support

    24/7 Technical Support 6 Free Tickets per Quarter Faster Response

  • Alibaba Cloud offers highly flexible support services tailored to meet your exact needs.