Thanks for your reply Peter. I see safe mode is blocked then. They guy above suggests Task Manager, however the virus totally overrules it and displays an error sound indicating the administrator blocked it.
I did get rid of it by system restore. But, here's something you can try. Boot to safe mode. But then on your keyboard press the windows key and r when on icon less desktop. This should open up the run command. Then type regedit. Then, navigate to the following directories:
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\”Shell” = “[random].exe”
The random exe is a bunch of numbers and letters. Just right click and delete the entries.
The following are also files associated with the virus. Just type the paths into the run command, then find and delete these:
%Documents and Settings%\[UserName]\Application Data\[random].exe
%Documents and Settings%\[UserName]\Local Settings\Temp\[random].tmp
%Documents and Settings%\[UserName]\Desktop\[random].lnk
If you can not access the run command and any of these. Then it may be handy to have your installation disk with you as we may need to run a System Restore.
Edited by cookmiester, 16 December 2011 - 01:10 PM.