There are no tools for deleting this nightmare so I will have to do it manually
Download and run ERUNT
http://www.larshederer.homepage.t-online.de/erunt/Start ERUNT, confirm the Welcome message.
Type in the name of a restore folder where the backed up registry
files should be saved, or click "..." to browse your computer's drives
and select a folder. You can also simply leave the default, which is a
folder named ERDNT inside your Windows folder, the advantage being
that you have access to this folder from the Windows Recovery Console
in case Windows does not boot anymore.
Next, select the backup options:
-
System registry:-
Current user registy: .
-
Other open user registries: Click "OK" and wait until the backup process is complete. (Note that
depending on your system configuration this may take some time, and
that the first bar is NOT a progress bar, just an indicator that the
program is still running.) The ERDNT program for later restoration of
the registry is automatically copied to the restore folder.
WARNING these fixes are designed for this user only and may cause damage if run on an uninfected machineREGISTRY FIXREGEDIT4
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"blank"=-
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"blank"=-
[HKEY_CURRENT_USER\ Software\ Microsoft\ Windows\ CurrentVersion\ Policies\ Explorer]
"NoFolderOptions"=0
[HKEY_CURRENT_USER\ Software\ Microsoft\ Internet Explorer\ Main]
"Window Title"=""
[HKEY_LOCAL_MACHINE\ SOFTWARE\ Microsoft\ Windows NT\ CurrentVersion\ Winlogon]
"Shell"="Explorer.exe"
[HKEY_LOCAL_MACHINE\ SOFTWARE\ Microsoft\ Windows NT\ CurrentVersion\ Winlogon]
"Userinit"="%sysdir%\userinit.exe"
[HKEY_CURRENT_USER\ Software\ Microsoft\ Windows NT\ CurrentVersion\ Windows]
"Load"=""
[HKEY_CURRENT_USER\ Software\ Microsoft\ Internet Explorer\ Main]
"Search Page"=""
[HKEY_CURRENT_USER\ Software\ Microsoft\ Internet Explorer\ Main]
"Start Page"=""
[HKEY_LOCAL_MACHINE\ SOFTWARE\ Microsoft\ Windows NT\ CurrentVersion\ Winlogon]
"SFCDisable"=00, 00, 00, 00
[HKEY_LOCAL_MACHINE\ SOFTWARE\ Microsoft\ Windows NT\ CurrentVersion]
"RegisteredOrganization"=""
[HKEY_LOCAL_MACHINE\ SOFTWARE\ Microsoft\ Windows NT\ CurrentVersion]
"RegisteredOwner"=""
[HKEY_LOCAL_MACHINE\ SOFTWARE\ Microsoft\ Windows NT\ CurrentVersion\ Winlogon]
"LegalNoticeCaption"=""
[HKEY_LOCAL_MACHINE\ SOFTWARE\ Microsoft\ Windows NT\ CurrentVersion\ Winlogon]
"LegalNoticeText"=""
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon]
"LogonPrompt"=""
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon]
"Welcome"=""
[HKEY_CURRENT_USER\ Software\ Microsoft\ Windows\ CurrentVersion\ Explorer\ Advanced]
"Hidden"=01, 00, 00, 00
[HKEY_CURRENT_USER\ Software\ Microsoft\ Windows\ CurrentVersion\ Explorer\ Advanced]
ShowSuperHidden"=01, 00, 00, 00
Next you will need to create the repair registry fix to do that copy and paste
ALL of the above in the quote box to a notepad file. Ensure there is
no space above the REGEDIT4.
Then in notepad go to
FILE > SAVE AS and in the dropdown box select
SAVE AS TYPE to
ALL FILES Then in the
FILE NAME box type
fix.regThis will create a fix.reg file on your desktop

To use this file you will need to right click the icon and select merge, accept the warning if it appears and you are done.
NEXTDuring this run you will loose your desktop
1. Please
open Notepad- Click Start , then Run
- Type notepad .exe in the Run Box.
2. Now
copy/paste the entire content of the codebox below into the Notepad window:
KillAll::
File::
C:\WINDOWS\SHELL.EXE
C:\WINDOWS\VXDS.EXE
C:\WINDOWS\system32\SYS.EXE
C:\WINDOWS\system32\OEMINFO.INI
C:\WINDOWS\system32\OEMLOGO.BMP
C:\WINDOWS\system32\BLANK.HTM
C:\WINDOWS\help\HLPS.EXE
C:\WINDOWS\media\WMA.EXE
C:\WINDOWS\media\WINDOWS XP RINGIN.WAV
3. Then in the text file go to
FILE > SAVE AS and in the dropdown box select
SAVE AS TYPE to
ALL FILES 4.
Save the above as
CFScript.txt5. Then
drag the CFScript.txt into ComboFix.exe as depicted in the animation below. This will start ComboFix again.

5. After reboot, (in case it asks to reboot), please post the following reports/logs into your next reply:
- Combofix.txt
- A new HijackThis log.