Tuesday, August 26, 2008

HOW TO REMOVE PC-OFF.BAT Trojan

1. Open "task manager" by pressing CTRL-ALT-DEL. Under tab 'processes', select 'password_viewer.exe' or 'bar311.exe' or 'photo.zip.exe' and Click ‘End Process’

2. Open "register editor"( click 'START’--> ‘RUN’ , type “regedit”) .

• GO TO ‘HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon’

FIND KEY
"Userinit" = C:\WINDOWS\system32\userinit.exe,bar311.exe"
----> remove value ‘bar311.exe’ ONLY!!!!
OR
"Userinit" = C:\WINDOWS\system32\userinit.exe,photo.zip.exe"
----> remove value ‘photo.zip.exe’ ONLY!!!!
OR
"Userinit" = C:\WINDOWS\system32\userinit.exe,password_viewer.exe"
----> remove value ‘password_viewer.exe’ ONLY!!!!

*/DO NOT REMOVE “USERINIT.EXE” VALUE OR “USERINIT” KEY, OR ELSE YOUR PC CANNOT ENTER YOUR WINDOWS/*

• GO TO ‘HKEY_CURRENT_USER \software\microsoft\windows\currentversion\explorer\advanced’
Change Value data for Key As Shown Below :-

"Hidden"=dword:00000001 (1) - Change to ‘1’
"HideFileExt"=Dword:00000000 (0) - Change to ‘0’
"ShowSupperHidden"=Dword:00000001 (1) – Change to ‘1’


• GO TO
‘HKEY_CURRENT_USER \software\microsoft\Command Processor’

FIND KEY

"autorun=c:\windows\pc-off.bat"
-----> Remove "c:\windows\pc-off.bat" or Delete autorun key



. go to ThumbDrive DRIVE(Do not doubleclick the drive,Use Address panel to view file inside DRIVE)

4. delete - autorun.inf
password_viewer.exe
bar311.exe
photo.zip.exe

5. Open Notepad and Type -

@echo off
del /a /f c:\windows\bar311.exe
del /a /f c:\windows\password_viewer.exe
del /a /f c:\windows\photo.zip.exe
del /a /f c:\windows\pc-off.bat
pause


6. Save As "remove.bat"

7. Run remove.bat

8. GO TO
C:\Windows\

Find bar311.exe OR password_viewer.exe OR photo.zip.exe OR pc-off.bat and delete it.

Tips About Choosing Your Computer
Check Out

http://choosingcomputer.blogspot.com