Virus Alert, page 1
Pages:
ATS Members have flagged this thread 2 times


reply posted on 1-4-2011 @ 05:49 AM by pop_science
reply to post by lifeform11




Godlike Productions.

A site kinda like this one.


Anyway OP thanks I once got a virus like that from ATS and had to re install everything on my laptop.
edit on 1-4-2011 by pop_science because: I cant type.



reply posted on 1-4-2011 @ 05:51 AM by pcrobotwolf
reply to post by bargoose


thanks for the heads up
edit on 1-4-2011 by pcrobotwolf because: (no reason given)



reply posted on 1-4-2011 @ 10:51 AM by phoenix_zephyr
See if you can download Malware Bytes , once downloaded change it from a .exe to a .bat and see if it will run. If so, get it to scan.

- Phoenix


reply posted on 1-4-2011 @ 11:08 AM by Pr0t0
I fell victim to this too.

The virus in question, for myself, was the XP Security Centre Anti-Virus 2011 which emulates your Security Centre in XP and is a pain to remove.

If altering file associations fails you may have to stop processes and edit registry - DO NOT edit any registry keys if you are not comfortable with this.

CTRL + ALT + DEL or CTRL + SHIFT + ESC to enter Task Manager, click Processes tab and stop the following process:

CB130_287.exe

Find and delete these files:

Navigate to the file folder using explorer (as explained in an earlier post, My Computer etc)

C:\Documents and Settings\All Users\Application Data\23077d\CB130_287.exe

Finally, remove Windows Antivirus 2011 Registry Values:

Only do this if you are comfortable making these changes. If not you may want to ask someone with a little more technical experience.

Go to Start and Run and type in regedit. You will need to find and delete the following registry keys. They may or may notexist. Do not delete anything not on this list or you risk deleting critical system files.

HKEY_CURRENT_USER\Software\Classes\.exe\shell\open\command “(Default)” = “%UserProfile%\Local Settings\Application Data\pw.exe” /START “%1″ %*
HKEY_CURRENT_USER\Software\Classes\pezfile
HKEY_CURRENT_USER\Software\Classes\pezfile\shell\open\command “(Default)” = “%UserProfile%\Local Settings\Application Data\pw.exe” /START “%1″ %*

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center “AntiVirusOverride” = “1″
HKEY_LOCAL_MACHINE\SOFTWARE\Clients\StartMenuInternet\FIREFOX.EXE\shell\safemode\command “(Default)” = “%UserProfile%\Local Settings\Application Data\pw.exe” /START “C:\Program Files\Mozilla Firefox\firefox.exe” -safe-mode
HKEY_LOCAL_MACHINE\SOFTWARE\Clients\StartMenuInternet\IEXPLORE.EXE\shell\open\command “(Default)” = “%UserProfile%\Local Settings\Application Data\pw.exe” /START “C:\Program Files\Internet Explorer\iexplore.exe”
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center “FirewallOverride” = “1″
HKEY_LOCAL_MACHINE\SOFTWARE\Clients\StartMenuInternet\FIREFOX.EXE\shell\open\command “(Default)” = “%UserProfile%\Local Settings\Application Data\pw.exe” /START “C:\Program Files\Mozilla Firefox\firefox.exe”

HKEY_CLASSES_ROOT\.exe\shell\open\command “(Default)” = “%UserProfile%\Local Settings\Application Data\pw.exe” /START “%1″ %*
HKEY_CLASSES_ROOT\pezfile\shell\open\command “(Default)” = “%UserProfile%\Local Settings\Application Data\pw.exe” /START “%1″ %*
HKEY_CLASSES_ROOT\pezfile

I hope this may help.


reply posted on 1-4-2011 @ 11:14 AM by phoenix_zephyr
reply to post by Pr0t0



The scareware file names tend to be randomly generated though you can mostly found out what it is via msconfig by going Start Menu -> Run -> Msconfig -> Start Up Tab and have a look through.

I echo what you've said though and only start going through the registry if you really know what you're doing otherwise you can make a mess of things.

OP feel free to u2u me for advice on spyware/scareware removal, this goes to anyone really

- Phoenix
Pages:     ^^TOP^^



Interesting conspiracy website: WHALE
  Posted 9 days ago with 3 member flags
RSOE EDIS alert map not loading. Is it just me?
  Posted 8 days ago with 2 member flags
The Power Principle : Eye Opening, Blood Boiling Documentary
  Posted 4 days ago with 1 member flags
What Is Reality
  Posted 2 days ago with 0 member flags