Most viruses now change the association of "exefile" and sometimes ".exe" in HKEY_CLASSES_ROOT ... normally, .exe should be:
Name Type Data
(Default) REG_SZ exefile
Content REG_SZ application/x-msdownload
exefile\shell\open\command should be:
Name Type Data
(Default) REG_SZ "%1" %*
IsolatedCommand REG_SZ "%1" %*
They change it from "%1" %* to the path to their fake AV soft so that whenever you try to open a program, it opens the fake AV and runs a fake scan.
Holy Crap! That's one of the issues the computer has. Any exe I click on and the intended program doesn't run. Well, I get no fake antivirus popup, so I assume it got deleted somehow. But there's still other problems like internet explorer constant redirects, task manager & antivirus won't work, virus somehow locked a standard user account but cannot remove or change it with the admin account, huge font size on startup, etc etc.
I've been hit by a few of those drive-by irritants myself. It's nothing a quick system restore hasn't solved, but it's still annoying as hell.
System restore doesn't delete certain files like those left behind by viruses. So I doubt it'll work with all the problems I have. Besides, I stopped believing in System Restore for a long time and just turn it off. If it had more of a "ghost image" feature, then it would be hella lot better.
I use Nortan Ghost quite often, works well.* I normally use Drive to Drive mirroring (It copies by file, not bit to bit, so full defrag, woo!) but it should be fully capable of both making an image of a 'new' drive and putting it back later.
*your experiance may vary
If the virus infects the ghost partition, then it will be useless, right? Or I'll have to burn to DVDs, I guess. I'm gonna play with Norton Ghost on my own time to get familiar with the software...see if it has improved since.
Start charging money for your services....I usually charge $25 to scrub viruses, $50 for a full Windows reinstall.
I'm more evil: I charge $75 for virus removal and $125 for reinstall with other people

But still, he has helped me out a few times around the house, like a handyman and never charged me. So you see how I can't charge him back. I'm just annoyed I have to do this like every month or so.
Yeah, I'm gonna try going the Kubuntu route. Some ppl just don't deserve Windows, plain and simple. Since I don't have to install antivirus, that's a plus. We'll see what happens. Thanks for your help, everyone
