How to restore the Windows desktop after a virus attack?

The Windows operating system of all versions (especially without installed updates) is known for a huge number of vulnerabilities if you did not take care of security in advance.

These measures should include installing an antivirus, using the system from a regular account (without administrative rights), replacing standard Windows programs with alternative ones (Firefox or Opera) and "personal vigilance", including a ban on visiting suspicious sites.

If you do not comply with any of these points, then with a high degree of probability you will pick up a malicious program. Often this is the so-called blocker, extorting money for paid SMS, otherwise the system refuses to boot, and you just want to restore the desktop again.

Any cleaning antivirus will help get rid of such software (AVZ and Cure IT utilities are recommended). It usually takes 2-3 hours to remove the virus. Specialized utilities have also appeared to get rid of blockers. They perfectly solve the problem of how to restore the desktop after the banner. For example, Kaspersky Windows Unlocker, which completely eliminates the infection and its consequences.

Usually, after removing such malicious programs (if a specialized recovery utility is not used), only the desktop background is displayed without any signs of icons and the Start menu, then the question arises of how to restore the desktop. However, the cursor works. In this case, there are two ways - simple and relatively complex.

The first is to "cure" the system using the special AVZ function. This is done extremely simply (even for an inexperienced user). Download the latest version of this program on a β€œhealthy” computer and write it to a USB flash drive. After that we start Windows on the computer where help is required.

After the appearance of the desktop background, we press the key combination "control + alt + divides" - in this sequence. In the menu that appears, select the "File" item. We launch a new task - AVZ. Now you need to find the path to the startup file on the USB flash drive.

In the window of the launched program, once again select the "File" menu and then "System Restore", mark a couple of daws options for restoring explorer startup parameters, and also with "Delete system process debuggers". After that, we certainly click the "Run" button. So we answered the burning question of how to restore the desktop in most cases.

Now you can reboot and the standard explorer.exe shell will start on its own.

The second method is more labor-intensive and requires at least basic registry editing skills, it is difficult, but it also gives an answer to the question of how to restore the desktop. This is absolutely not suitable for beginners. Although, if the PC is not working, and you just want to experiment, then why not? So, we press the familiar shortcut keys - "control + alt + divides". We start the registry editor using the regedit command and sequentially check the following:

1. The absence of keys called useinit, explorer and authorization winlogon in the "Image File Execution Options" section on the following intricate path to the system storage settings HKEY_LOCAL_MACHINE (then go to SOFTWARE \ Microsoft \ Windows NT \ CurrentVersion). If you still have the keys, fearlessly delete them.

2. We search for the insidious explorer.exe section and delete it if we find HKEY_CURRENT_USER in the "bush", that is, in fact, the user profile (the "bush" is created at the moment of the first login) at the same complex address Software \ Microsoft \ Windows NT \ CurrentVersion \ Devices.

3. It remains only to check the shell startup parameters that are in HKEY_LOCAL_MACHINE for validity, select the SOFTWARE "bush".

We go down even lower in the hierarchy - we select Microsoft, and then Windows NT. We stop at the endpoint - the CurrentVersion section.

First, we look that Shell is exclusively explorer.exe, and Userinit is strictly logonui.exe.

Secondly, the line C: \ WINDOWS \ system32 \ userinit.exe, (yes, directly with a comma) is the correct value for the ULHost parameter. This is guaranteed to solve the question of how to restore the desktop. After adjusting these parameters and rebooting (through "Task Manager"> "Shutdown"> "Reboot"), you can again see all the desktop icons, as well as the taskbar and, accordingly, the Start menu.

Source: https://habr.com/ru/post/K15377/


All Articles