The Linker
03-31-2011, 05:46 AM
Um... so, current status: virus quelled, scan running... and I have to specifically run any .exes as an administrator if I want them to work. This means Steam and other such programs no longer come up on startup, which is inconvenient, but I can use my computer again! Hooray!
I'm trying to get it back to normal, but, uh, class starts soon. If anyone knows of a way to reverse the damage I did in my registry and make Windows Vista easily recognize that my .exe applications are, in fact, .exe applications, I would love you forever and bake rice krispie squares.
Specifically, I'm pretty sure I need to have something in:
HKEY_CURRENT_USER\Software\Classes\Wow6432Node\exe file\shell\open\command "(Default)" =
Default is currently blank. I think there needs to be... something, there. :smallconfused:
This thread was originally a 'crap crap crap virus' thread, but I've gotten over that now. Full text below, for full disclosure.
Note: As I currently type from an iPod and really want to get this going asap, my grammar and punctuation will be, uh, hampered.
So, yeah. Virus got me, titled 'vista internet security 2011', trying to convince me that I'm infected (well, I am) and should go buy more viruses. I mean, the full version. There are plenty of helpful guides on removal of this very virus, which pinpoint exact processes to close and files to delete.
None of them exist for me. I must have a different version of the virus. All the guides give 'pw.exe' and 'MSASCui.exe' as both processes to close and files to delete, but there's nothing there.
Here's my one lead. I dug into the registry to look for what the guides say to delete. It wants me to go after:
HKEY_CURRENT_USER\Software\Classes\.exe\shell\open \command "(Default)" = "%UserProfile%\Local Settings\Application Data\pw.exe" /START "%1" %*
Hey, pw.exe! That's one of the files they wanted me to delete! I figure this hijacks any .exe process and makes it open pw.exe instead. Ah, but that's not actually ON here. Furthermore, it hasn't actually prevented me from executing anything -- just opening webpages, hence the iPod. BUT! In place of pw.exe in the registry path above, it reads 'sub.exe', giving me:
HKEY_CURRENT_USER\Software\Classes\.exe\shell\open \command "(Default)" = "%UserProfile%\Local Settings\Application Data\sub.exe" /START "%1" %*
Actually, this thing just deleted by a script I copied and ran. Default is empty now. Uh, put the past couple paragraphs in past tense. None of my problems are gone, though,
However, I'm still hopeful this could be a lead. If sub.exe is the program being used by this version of the virus, then perhaps one can use this information to find an up-to-date removal guide? I failed, but searching is slow on this thing and man my fingers hurt by now.
Any help would be incredibly appreciated and rewarded with cookies and pony-baked muffins. Clarification will be offered upon query, I'm sure I've missed like seventeen things trying to write this out.
--Second post--
Hmmm, sub.exe still exists. Want to delete it, but don't to accidentally kill something vital. It doesn't exist on your uninfected machines, does it? Full path: users\[your profile name]\AppData\local\sub.exe
Edit: Ah-ha! I can use the 'find' function with the registry editor to find things that still point to sub.exe. But I REALLY don't want to mess with the registry unless vaguely trusted source tells me to.
Edit edit: only one more place points to sub.exe:
HKEY_CURRENT_USER\Software\Classes\Wow6432Node\exe file\shell\open\command "(Default)" = "%UserProfile%\AppData\local\sub.exe" -a "%1" %*
Edit the third: sub.exe is also a running process. Absolutely everything Points to this being a malicious thing I need to delete and end. I'm, um, I'm just nervous.
Edit the fourth: bit the bullet and did all that. I'm back on the computer and no signs of the virus are present. But, uh, now my computer has forgotten what .exes are and how to open them -- UNLESS I open them 'as administrator'. It's almost like the registry editor wasn't supposed to be messed around in by someone with only a moderate idea of what they're doing. o_O Currently looking at how to rebuild the set association.
I'm trying to get it back to normal, but, uh, class starts soon. If anyone knows of a way to reverse the damage I did in my registry and make Windows Vista easily recognize that my .exe applications are, in fact, .exe applications, I would love you forever and bake rice krispie squares.
Specifically, I'm pretty sure I need to have something in:
HKEY_CURRENT_USER\Software\Classes\Wow6432Node\exe file\shell\open\command "(Default)" =
Default is currently blank. I think there needs to be... something, there. :smallconfused:
This thread was originally a 'crap crap crap virus' thread, but I've gotten over that now. Full text below, for full disclosure.
Note: As I currently type from an iPod and really want to get this going asap, my grammar and punctuation will be, uh, hampered.
So, yeah. Virus got me, titled 'vista internet security 2011', trying to convince me that I'm infected (well, I am) and should go buy more viruses. I mean, the full version. There are plenty of helpful guides on removal of this very virus, which pinpoint exact processes to close and files to delete.
None of them exist for me. I must have a different version of the virus. All the guides give 'pw.exe' and 'MSASCui.exe' as both processes to close and files to delete, but there's nothing there.
Here's my one lead. I dug into the registry to look for what the guides say to delete. It wants me to go after:
HKEY_CURRENT_USER\Software\Classes\.exe\shell\open \command "(Default)" = "%UserProfile%\Local Settings\Application Data\pw.exe" /START "%1" %*
Hey, pw.exe! That's one of the files they wanted me to delete! I figure this hijacks any .exe process and makes it open pw.exe instead. Ah, but that's not actually ON here. Furthermore, it hasn't actually prevented me from executing anything -- just opening webpages, hence the iPod. BUT! In place of pw.exe in the registry path above, it reads 'sub.exe', giving me:
HKEY_CURRENT_USER\Software\Classes\.exe\shell\open \command "(Default)" = "%UserProfile%\Local Settings\Application Data\sub.exe" /START "%1" %*
Actually, this thing just deleted by a script I copied and ran. Default is empty now. Uh, put the past couple paragraphs in past tense. None of my problems are gone, though,
However, I'm still hopeful this could be a lead. If sub.exe is the program being used by this version of the virus, then perhaps one can use this information to find an up-to-date removal guide? I failed, but searching is slow on this thing and man my fingers hurt by now.
Any help would be incredibly appreciated and rewarded with cookies and pony-baked muffins. Clarification will be offered upon query, I'm sure I've missed like seventeen things trying to write this out.
--Second post--
Hmmm, sub.exe still exists. Want to delete it, but don't to accidentally kill something vital. It doesn't exist on your uninfected machines, does it? Full path: users\[your profile name]\AppData\local\sub.exe
Edit: Ah-ha! I can use the 'find' function with the registry editor to find things that still point to sub.exe. But I REALLY don't want to mess with the registry unless vaguely trusted source tells me to.
Edit edit: only one more place points to sub.exe:
HKEY_CURRENT_USER\Software\Classes\Wow6432Node\exe file\shell\open\command "(Default)" = "%UserProfile%\AppData\local\sub.exe" -a "%1" %*
Edit the third: sub.exe is also a running process. Absolutely everything Points to this being a malicious thing I need to delete and end. I'm, um, I'm just nervous.
Edit the fourth: bit the bullet and did all that. I'm back on the computer and no signs of the virus are present. But, uh, now my computer has forgotten what .exes are and how to open them -- UNLESS I open them 'as administrator'. It's almost like the registry editor wasn't supposed to be messed around in by someone with only a moderate idea of what they're doing. o_O Currently looking at how to rebuild the set association.