Jump to content

Welcome to Pure Warfare - The #1 Community for Pures

Welcome to Pure Warfare - The #1 Community for Pures, like most online communities you must register to view or post in our community, but don't worry this is a simple free process that requires minimal information for you to signup. Be apart of Pure Warfare - The #1 Community for Pures by signing in or creating an account.
  • Start new topics and reply to others
  • Subscribe to topics and forums to get email updates
  • Get your own profile page and make new friends
  • Send personal messages to other members.

How to get rid of elvy666's virus


Marty

Recommended Posts

http://www.threatexpert.com/report.aspx?md...9a6ec672ec63a88

 

i'll probably make a tool to check if your infected & do all this for you at a later time

 

 

  1. Start up in Windows Safe Mode
  2. Open up Task Manager and kill any processes running under your user(not system) with the following name(s): explorer.exe, iexplorer.exe, server.exe
  3. Run the Windows Registry Editor and delete any registry values referring to "%RootDrive%\directory\CyberGate\install\server.exe":
    • HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Active Setup\Installed Components\{X3345FLR-12IQ-3C01-1K75-CU1KOA37JVG1}
    • HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer
    • HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\Run
    • HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\MediaResources\msvideo
    • HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\MediaResources\msvideo
    • HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\Explorer\Run
    • HKEY_CURRENT_USER\Software\Microsoft\Windows Script Host
    • HKEY_CURRENT_USER\Software\Microsoft\Windows Script Host\Settings
    • HKEY_CURRENT_USER\Software\ZXZ

[*]Go to your root drive(probably c:\) and delete the folder "directory" and its contents.

[*]Go to your appdata folder and delete a file that is named "<your computer username>log.dat"

 

and then your probably free from that scum :)

 

 

 

some known youtube channels that he posts his trash on:

http://www.youtube.com/user/woopssafty

http://www.youtube.com/user/shadowgod170 (i think?)

Link to comment
Share on other sites

First of all why would you go through the registry looking for elvys Rat when it doesn't just add to HKLM and HKCU it also saves to the startup-folder as well as uses Active-Startup?

 

You obviously lack knowledge of such a topic and would like to act as if you know what you're talking about.

 

Last of all, you specified the default directory that CBG would save to, why would he have it save to the default directory?

 

I suggest you do some real research before attempting to inform people of something you know nothing about.


corrupt3d.png
Link to comment
Share on other sites

Lets go fishing =] Yes fishing

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

For turtles.

"Practice + Determination isn't coincidence." Retired
am0ns.jpg
Link to comment
Share on other sites

First of all why would you go through the registry looking for elvys Rat when it doesn't just add to HKLM and HKCU it also saves to the startup-folder as well as uses Active-Startup?

 

You obviously lack knowledge of such a topic and would like to act as if you know what you're talking about.

 

Last of all, you specified the default directory that CBG would save to, why would he have it save to the default directory?

 

I suggest you do some real research before attempting to inform people of something you know nothing about.

 

 

Oh god


tLVAN.png
VEES3.png
Link to comment
Share on other sites

First of all why would you go through the registry looking for elvys Rat when it doesn't just add to HKLM and HKCU it also saves to the startup-folder as well as uses Active-Startup?

 

You obviously lack knowledge of such a topic and would like to act as if you know what you're talking about.

 

Last of all, you specified the default directory that CBG would save to, why would he have it save to the default directory?

 

I suggest you do some real research before attempting to inform people of something you know nothing about.

 

 

Oh god

 

wat.


corrupt3d.png
Link to comment
Share on other sites

  • 2 weeks later...
First of all why would you go through the registry looking for elvys Rat when it doesn't just add to HKLM and HKCU it also saves to the startup-folder as well as uses Active-Startup?

 

You obviously lack knowledge of such a topic and would like to act as if you know what you're talking about.

 

Last of all, you specified the default directory that CBG would save to, why would he have it save to the default directory?

 

I suggest you do some real research before attempting to inform people of something you know nothing about.

 

 

Oh god

 

wat.

 

inb4 skiddie

Link to comment
Share on other sites

Guest
This topic is now closed to further replies.
×
  • Create New...