Severity scale:  
  (46/100)

Virus.BAT.Gary.705. How to remove? (Uninstall guide)

removal by Lucia Danes - - | Type: Malware
12

Virus.BAT.Gary.705 is a false security threat displayed by the rogue spyware remover Windows Security Suite. This false threat is supposedly related with file named exec.sys, whereas process exec.exe is classified as malicious and registered as W32/Spybot-Z Trojan. There is a chance that your computer is infected with this trojan as well as with Windows Security Suite. That’s why you should your PC with reputable anti-spyware application.

The false Virus.BAT.Gary.705 reads as follows:

“Your computer is infected. Warning! Spyware found! Detected: Spyware; File Name: exec.sys; Name: Virus.BAT.Gray.705… This is a dangerous nonmemory resident BAT infector. It writes itself to the end of C:\AUTOEXEC.BAT file”

The only solution in this case is Windows Security Suite removal. Please use the removal guide below to remove this infection for your computer for free.

We might be affiliated with any product we recommend on the site. Full disclosure in our Agreement of Use. By Downloading any provided Anti-spyware software to remove Virus.BAT.Gary.705 you agree to our privacy policy and agreement of use.
do it now!
Download
Reimage (remover) Happiness
Guarantee
Download
Reimage (remover) Happiness
Guarantee
Compatible with Microsoft Windows Compatible with OS X
What to do if failed?
If you failed to remove infection using Reimage, submit a question to our support team and provide as much details as possible.
Reimage is recommended to uninstall Virus.BAT.Gary.705. Free scanner allows you to check whether your PC is infected or not. If you need to remove malware, you have to purchase the licensed version of Reimage malware removal tool.

Note: Manual assistance required means that one or all of removers were unable to remove parasite without some manual intervention, please read manual removal instructions below.

More information about this program can be found in Reimage review.

More information about this program can be found in Reimage review.
Alternate Software
Plumbytes Anti-Malware
We have tested Plumbytes Anti-Malware's efficiency in removing Virus.BAT.Gary.705 (2009-07-09)
Malwarebytes Anti Malware
We have tested Malwarebytes Anti Malware's efficiency in removing Virus.BAT.Gary.705 (2009-07-09)
Hitman Pro
We have tested Hitman Pro's efficiency in removing Virus.BAT.Gary.705 (2009-07-09)
Webroot SecureAnywhere AntiVirus
We have tested Webroot SecureAnywhere AntiVirus's efficiency in removing Virus.BAT.Gary.705 (2009-07-09)
Virus.BAT.Gary.705 snapshot
Virus.BAT.Gary.705

Virus.BAT.Gary.705 manual removal:

Kill processes:
WI345d.exe

CLSV.exe

snl2w.exe

std.exe

Delete registry values:
HKEY_CLASSES_ROOTCLSID{3F2BBC05-40DF-11D2-9455-00104BC936FF}

HKEY_CLASSES_ROOTWI345d.DocHostUIHandler

HKEY_CURRENT_USERSoftwareMicrosoftWindowsCurrentVersionInternet Settings5.0User AgentPost Platform "698909210803"

HKEY_CURRENT_USERSoftwareMicrosoftWindowsCurrentVersionRun "Windows Security Suite"

Unregister DLLs:
mozcrt19.dll

sqlite3.dll

energy.dll

grid.dll

kernel32.dll

PE.dll

runddl.dll

SM.dll

tempdoc.dll

Delete files:
26.mof

mozcrt19.dll

sqlite3.dll

WI345d.exe

WINSS.ico

working.log

vd952342.bd

winss.cfg

Windows Security Suite.lnk

cookies.sqlite

Instructions.ini

ANTIGEN.drv

CLSV.exe

DBOLE.drv

dudl.sys

energy.dll

grid.dll

grid.sys

kernel32.dll

PE.dll

PE.tmp

runddl.dll

SM.dll

snl2w.exe

std.exe

tempdoc.dll

search.xml

Delete directories:
c:ADWARE_LOG

c:Documents and SettingsAll UsersApplication Data345d567

c:Documents and SettingsAll UsersApplication Data345d567WINSSSys

c:Documents and SettingsAll UsersApplication DataWINSSSys

%UserProfile%Application DataWindows Security Suite