Virus Protector manual removal:
Kill processes:
[random].exe
Delete registry values:HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run "Virus Protector"
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows "LoadAppInit_DLLs" = "1"
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows "AppInit_DLLs" = "
.dll"
Unregister DLLs:
[random].dll
Delete files:
C:\\Documents and Settings\\[User]\\Application Data\\[random].exe C:\\Documents and Settings\\[User]\\Application Data\\[random].dll C:\\Documents and Settings\\[User]\\Local Settings\\Temp\\[random].exe C:\\Documents and Settings\\[User]\\Local Settings\\Temp\\[random].dll C:\\Program Files\\Internet Explorer\\[random].exe C:\\Program Files\\Internet Explorer\\[random].dll C:\\WINDOWS\\[random].exe C:\\WINDOWS\\[random].dll C:\\WINDOWS\\system32\\[random].exe C:\\WINDOWS\\system32\\[random].dll C:\\WINDOWS\\system32\\drivers\\[random].exe C:\\WINDOWS\\system32\\drivers\\[random].dll
Thanks
From there I was able to run system restore
%systemroot%system32restorerstrui.exe
Hope this helps.
%systemroot%system32restorerstrui.exe
Hope this helps
What can I do
Bertrand
Any idea what to do?
Mario
i have already malwarebytes installed in my laptop
so i started laptop in debuge mode, so this dirty virus could run in that mode
and then i run malwarebytes which remove all virus files
and i got my laptop back
THANK YOU GUYS!!!!!!
for WIN XP - open in safe mode / command prompt
type in %systemroot%system32
estore
strui.exe
this starts system restore, then restore to an earlier time
for you make sure you're using a / instead of = like he said
Type explorer.exe in command window.
it will bring up my documents.
Go to system32.
search for random.dll and random.exe in recent dates.
rename it.
reboot to safe mode with n/w
use task manger to open IE download a fix to enable task manager and registry.
Thank you VERY much for this guide! Exelent job! It helped me to prevent this crap
Post Comment: