Antivirus XP 2010 manual removal:
Kill processes:
av.exe
Delete registry values:HKEY_CURRENT_USER\Software\Classes\.exe\shell\open\command "(Default)" = "%UserProfile%\Local Settings\Application Data\av.exe" /START "%1" %*
HKEY_CURRENT_USER\Software\Classes\secfile\shell\open\command "(Default)" = "%UserProfile%\Local Settings\Application Data\av.exe" /START "%1" %*
HKEY_CLASSES_ROOT\.exe\shell\open\command "(Default)" = "%UserProfile%\Local Settings\Application Data\av.exe" /START "%1" %*
HKEY_CLASSES_ROOT\secfile\shell\open\command "(Default)" = "%UserProfile%\Local Settings\Application Data\av.exe" /START "%1" %*
HKEY_LOCAL_MACHINE\SOFTWARE\Clients\StartMenuInternet\FIREFOX.EXE\shell\open\command "(Default)" = "%UserProfile%\Local Settings\Application Data\av.exe" /START "C:\Program Files\Mozilla Firefox\firefox.exe"
HKEY_LOCAL_MACHINE\SOFTWARE\Clients\StartMenuInternet\FIREFOX.EXE\shell\safemode\command "(Default)" = "%UserProfile%\Local Settings\Application Data\av.exe" /START "C:\Program Files\Mozilla Firefox\firefox.exe" -safe-mode
HKEY_LOCAL_MACHINE\SOFTWARE\Clients\StartMenuInternet\IEXPLORE.EXE\shell\open\command "(Default)" = "%UserProfile%\Local Settings\Application Data\av.exe" /START "C:\Program Files\Internet Explorer\iexplore.exe"
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center "AntiVirusOverride" = "1"
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center "FirewallOverride" = "1"
Delete files:%UserProfile%\\Local Settings\\Application Data\\av.exe %UserProfile%\\Local Settings\\Application Data\\WRblt8464P
This was becoming so frustrating, and now I can finally run a virus-scanner!
can you help!!!!!!
Windows
Registry Editor
Version 5.00
after changing it, it worked
also, as of this writing, AVG will NOT find this virus. You may have to go through other means...
how do I do this?
Be sure that after you delete the regkeys you reset your .exe to application in the folder type menu.
Thanks
It's like sooooo great
I can't access the internet! It's like blocked. (I'm using my phone.)
Can I use the ZoneAlarm software that I have? Help and thank you in advance!
I can't access the internet! It's like blocked. (I'm using my phone.)
Can I use the ZoneAlarm software that I have? Help and thank you in advance!
I picked up this virus while browsing peopleofwalmart.com, must be a script in one of their ads.
Didn't buy Spydoctor. Installed MS Windows Defender. Did the trick just as well.
Well done.
your attempt is fake.....bull shit
Now all i gotta do is use a malware scanner, but its a work computer so i dont think i can.
I'm gonna headbutt the dumb bitch at work that got it on there in the first place :)
I had to use another pc to copy and past to notepad and run the infected pc in safe mode.
Thank You again! ! !
i mean, what does it do on the system?, will it delete all of the executable file even if its not a virus?, what if it deletes important executable files? what should i do?
also, i cant find the av.exe process or anything similar.
it does not allow me to run .pif files either.
Thanks.
There are no free ones
That sucks... ALOT :(
How does is able to install itself?
How is this able to install this even with Microsoft security essentials enabled?
Thanks!
2. Type “notepad” as shown in the image below and press Enter. Notepad will open.
3. Copy and past the following text into Notepad:
Windows Registry Editor Version 5.00[-HKEY_Present_USERSoftwareClasses.exeshellopencommand]
[-HKEY_Present_USERSoftwareClassessecfileshellopencommand]
[-HKEY_CLASSES_ROOT.exeshellopencommand]
[HKEY_CLASSES_ROOT.exe]
@=”exefile”
“Content Type”=”application/x-msdownload”
[-HKEY_CLASSES_ROOTsecfile]
5. Double-click to open exefix.reg. Click “Yes” for Registry Editor prompt window.
6. Download kingsoft pc doctor as an automatic removal tool below.
If you can’t total the above methods then please use yet another PC to download an automatic removal tool and exefix.reg (Right Click (Save Target As)) to download file. Copy these files to USB flash drive or any other external media and transfer them to infected computer. Launch exefix.reg file first and then install kingsoft pc doctor."
KPCD could be a useful tool for removing this. (Replace the references from SpyHunter, STOPzilla! etc. into Kingsoft PC Doctor)
Post Comment: