My computer was infected by password-viewer.exe and pc-off.bat virus. A virus that when you type cmd on the command prompt, your pc automatically shuts down.
Thank God to this article... This one saved me. :) Here it is. :)
Article from:
http://edzzy.i.ph/blogs/edzzy/2008/03/19/command-prompt-pc-shuts-down/
Thank God to this article... This one saved me. :) Here it is. :)
This is the symptom of a computer having bar311.exe virus A.K.A. winzip123. The virus comprises bar311.exe, password_viewer.exe, photos.zip.exe and pc-off.bat.
When you boot your Windows XP in Safe Mode the message appears: Thank You!!!
Password:Winzip123
The pc-off.bat contains the syntax like this"C:/path/shutdown -s -f -t 2 -c" which automatically shutdown your computer when you run the cmd.exe. So heres the solution to this problem… just follow these simple steps that im goin to discuss….
Manual removal:
1. upon start up…. after os loading… go to task manager by pressing CTRL+ALT+DEL then kill (end process) password_viewer.exe or bar311.exe or photos.zip.exe…
2. EDIT the following registry entries thru regedit at start/run
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon]
"Userinit"="userinit.exe,bar311.exe" —> remove ", bar311.exe" only… leave userinit.exe because this is used by Windows when you log-in…
[HKEY_CURRENT_USER\Software\Microsoft\Windows\
CurrentVersion\Explorer\Advanced]
"Hidden"=dword:00000001
"HideFileExt"=dword:00000000
"ShowSuperHidden"=dword:00000001
[HKEY_CURRENT_USER\Software\Microsoft\Command Processor]
"autorun"="c:\Windows\pc-off.bat" –> remove "c:\Windows\pc-off.bat" or delete the autorun key.
3. go to your thumb drive, please use the folders view in the explorer and use the navigation panel on the left side when accessing the drives to avoid triggering the autorun… then delete autorun.inf and password_viewer.exe or bar311.exe
4. open notepad then type what is shown below as is…
@echo off
del /a /f c:\Windows\bar311.exe
del /a /f c:\Windows\password_viewer.exe
del /a /f c:\Windows\photos.zip.exe
del /a /f c:\Windows\pc-off.bat
pause
then save this as remove.bat then click to run…. it will remove this annoying types of PC shut-off thing of virus…
Article from:
http://edzzy.i.ph/blogs/edzzy/2008/03/19/command-prompt-pc-shuts-down/
Comments
http://img361.imageshack.us/img361/5930/capturesn6.jpg
pano ko ba maibabalik sa dati yan? help naman! salamat!
nabura nga yung virus but...nasa regedit pa sya. Ang gawin mo ganito.
Type mo regedit sa Run...
Tapos Ctrl-F mo to Find.
Tapos itayp mo ung pc-off.bat. Lahat ng occurences noon sa registry burahin mo. Delete lang.
Check mo rin kung meron password.exe..etc. Delete mo rin yun. :)
Try mo nagwork sa akin eh :)
ang nasa isip ko...hindi mo masyadong nalinis yung registry. check mo ulit...step by step kung...nagawa mo tlaga..oks?
let me know mark kapag naayos na:)
s processes, meron plng tumatakbo n Auto.exe. i stopped the process, tapos, sa C: ko, binuksan ko ung windows and removed d pc-off.bat and auto.exe n andun..
so iun, nung ngwa ko n un, naedit ko n ung registry, d n xa bmblik ^_^
aun..
tnx 4 d hospitality.. :p
meron nmng babae n tntwag n pre db,:p
salamt ulit :p
oks lang pare..tawag mo sa akin... ;)
pero girl ako ha...hahaha
http://guideandtips.blogspot.com/2008/10/how-to-remove-bar311exe-virus-manually.html
http://freetools-virus-remover.notlong.com ......all free!!!
sharing is caring =)