Computing.Net > Forums > Windows 95/98 > Virus - protoride

Computer Problems? Computing.Net has over 1,000,000 posts about all things technology related! Over 90% answered within 24 hours! Click here to start participating now! Also, be sure to check out the New User Guide.

Virus - protoride

Reply to Message Icon

Name: dphelka
Date: February 18, 2004 at 09:36:08 Pacific
OS: win98 SE
CPU/Ram: Celeron/ 256
Comment:

I have irradicated Protoride.B virus six times in the last week. AVG virus checker finds it and heals it but it keeps coming back. I don't open any threatening email. Where can it be coming from? I use AOL instant messanger. My ISP is ameritech dialup. Help! Thanks in advance.

Dan



Sponsored Link
Ads by Google

Response Number 1
Name: IamBiGePaNtS
Date: February 18, 2004 at 10:43:19 Pacific
Reply:

Scan with you anti virus and write down everything it find's (or you can print off a report).

Remember to back up your registry before you mess with it (name it "with_virus");And after you verify everything is working properly back it up again and remove the virus infected version of backup and of course keep the clean one!

Terminating the Malware Program

This procedure terminates the running malware process from memory. You will need the name(s) of the file(s) detected earlier.

Open Windows Task Manager.
On Windows 95/98/ME systems, press CTRL+ALT+DELETE

In the list of running programs, locate the malware file or files detected earlier.
Select the malware process, then press either the End Task or the End Process button, depending on the version of Windows on your system.

To check if the malware process has been terminated, close Task Manager, and then open it again.

Close Task Manager.
*NOTE: On systems running Windows 9x/ME, Task Manager may not show certain processes. You may use a third party process viewer to terminate the malware process. Otherwise, continue with the next procedure, noting additional instructions.

Removing Autostart Entries from the Registry

Removing autostart entries from registry prevents the malware from executing during startup. This is also an effective way to terminate its process. In this procedure, you will need the name/s of the file/s detected earlier.

Open Registry Editor. Click Start>Run, type Regedit then hit Enter.

In the left panel, double click the following:

HKEY_LOCAL_MACHINE>Software>Microsoft>
Windows>CurrentVersion>Run

In the right panel, locate and delete the entry or entries whose data value is the malware path and file name of the file/s detected earlier.

Close Registry Editor.

NOTE: If you were not able to terminate the malware process from memory as described in the previous procedure, restart your system.

Addressing Registry Shell Spawning

Registry shell spawning executes the malware whenever a user opens files with EXE extensions. The following procedures should restore the registry to its original settings.

Click Start>Run.

In the Open input box, type:
command /c copy %WinDir%\regedit.exe regedit.com | regedit.com

Press Enter.

In the left panel, double-click the following:

HKEY_CLASSES_ROOT>exefile>shell>open>command

In the right panel, locate the registry entry:
Default

Check whether its value is the path and filename of the malware file.

If the value is the malware file, right-click Default and select Modify to change its value.

In the Value data input box, delete the existing value and type the default value:
"%1"%*

Close Registry Editor.



Got this info here



0

Response Number 2
Name: beansoup
Date: February 18, 2004 at 11:02:08 Pacific
Reply:

Hi

No listing anywhere. Is there any unusual activity?

beansoup

"Error: Keyboard not attached."
"Press F1 to continue."



0

Sponsored Link
Ads by Google
Reply to Message Icon

Related Posts

See More







Post Locked

This post is quite old and has been locked from receiving new replies. Please create a new posting instead.


Go to Windows 95/98 Forum Home


Sponsored links

Ads by Google


Results for: Virus - protoride

Cant Remove W32 PROTORIDE virus! www.computing.net/answers/windows-95/cant-remove-w32-protoride-virus/160091.html

virus (urgent) www.computing.net/answers/windows-95/virus-urgent/138109.html

Is This A Virus Problem? www.computing.net/answers/windows-95/is-this-a-virus-problem/110724.html