Jump to content

How to get rid of elvy666's virus


Marty
 Share

Recommended Posts

http://www.threatexpert.com/report.aspx?md...9a6ec672ec63a88

 

i'll probably make a tool to check if your infected & do all this for you at a later time

 

 

  1. Start up in Windows Safe Mode
  2. Open up Task Manager and kill any processes running under your user(not system) with the following name(s): explorer.exe, iexplorer.exe, server.exe
  3. Run the Windows Registry Editor and delete any registry values referring to "%RootDrive%\directory\CyberGate\install\server.exe":
    • HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Active Setup\Installed Components\{X3345FLR-12IQ-3C01-1K75-CU1KOA37JVG1}
    • HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer
    • HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\Run
    • HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\MediaResources\msvideo
    • HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\MediaResources\msvideo
    • HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\Explorer\Run
    • HKEY_CURRENT_USER\Software\Microsoft\Windows Script Host
    • HKEY_CURRENT_USER\Software\Microsoft\Windows Script Host\Settings
    • HKEY_CURRENT_USER\Software\ZXZ

[*]Go to your root drive(probably c:\) and delete the folder "directory" and its contents.

[*]Go to your appdata folder and delete a file that is named "<your computer username>log.dat"

 

and then your probably free from that scum :)

 

 

 

some known youtube channels that he posts his trash on:

http://www.youtube.com/user/woopssafty

http://www.youtube.com/user/shadowgod170 (i think?)

Link to comment
Share on other sites

First of all why would you go through the registry looking for elvys Rat when it doesn't just add to HKLM and HKCU it also saves to the startup-folder as well as uses Active-Startup?

 

You obviously lack knowledge of such a topic and would like to act as if you know what you're talking about.

 

Last of all, you specified the default directory that CBG would save to, why would he have it save to the default directory?

 

I suggest you do some real research before attempting to inform people of something you know nothing about.


corrupt3d.png
Link to comment
Share on other sites

Lets go fishing =] Yes fishing

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

For turtles.

"Practice + Determination isn't coincidence." Retired
am0ns.jpg
Link to comment
Share on other sites

First of all why would you go through the registry looking for elvys Rat when it doesn't just add to HKLM and HKCU it also saves to the startup-folder as well as uses Active-Startup?

 

You obviously lack knowledge of such a topic and would like to act as if you know what you're talking about.

 

Last of all, you specified the default directory that CBG would save to, why would he have it save to the default directory?

 

I suggest you do some real research before attempting to inform people of something you know nothing about.

 

 

Oh god


tLVAN.png
VEES3.png
Link to comment
Share on other sites

First of all why would you go through the registry looking for elvys Rat when it doesn't just add to HKLM and HKCU it also saves to the startup-folder as well as uses Active-Startup?

 

You obviously lack knowledge of such a topic and would like to act as if you know what you're talking about.

 

Last of all, you specified the default directory that CBG would save to, why would he have it save to the default directory?

 

I suggest you do some real research before attempting to inform people of something you know nothing about.

 

 

Oh god

 

wat.


corrupt3d.png
Link to comment
Share on other sites

  • 2 weeks later...
First of all why would you go through the registry looking for elvys Rat when it doesn't just add to HKLM and HKCU it also saves to the startup-folder as well as uses Active-Startup?

 

You obviously lack knowledge of such a topic and would like to act as if you know what you're talking about.

 

Last of all, you specified the default directory that CBG would save to, why would he have it save to the default directory?

 

I suggest you do some real research before attempting to inform people of something you know nothing about.

 

 

Oh god

 

wat.

 

inb4 skiddie

Link to comment
Share on other sites

Guest
This topic is now closed to further replies.
 Share

×
  • Create New...