 |
Removal PROrat + attached virusses in 25 steps.
| Anti-Virus Discuss, Removal PROrat + attached virusses in 25 steps. at Tech Zone forum; Dear members,
If you want to remove PROrat and its virusses you need not only need to edit your registery ... |
| Notices | Welcome to the Gamerz Needs forums. You are currently viewing our boards as a guest which gives you limited access to view most discussions and access our other features. By joining our free community you will have access to post topics, communicate privately with other members (PM), respond to polls, upload content and access many other special features. Registration is fast, simple and absolutely free so please, join our community today! If you have any problems with the registration process or your account login, please contact contact us. |  | 
08-06-2007, 01:49 AM
|  | Mendelity Inc | | | Last Online: 12-03-2008 04:40 PM Join Date: Mar 2006 Location: GunZ/GzN ((F)) FEYENOORD ((F))
Posts: 3,581
Thanks: 145
Thanked 332 Times in 218 Posts
Nominated 0 Times in 0 Posts TOTW/F/M Award(s): 0
Latest Blog: sixth seventh and eight day
Rep Power: 18 Points: 1,450.00 Bank: 204,314.07 Total Points: 205,764.07 | | | Removal PROrat + attached virusses in 25 steps.
Dear members,
If you want to remove PROrat and its virusses you need not only need to edit your registery but start in Safe Mode too. So if you want to remove the virus print this page. I will also make an TXT file for those who dont have an printer.
Since i cant type backslashes replace every slash for a backslash
Here we go. Windows 2000/NT/XP for Windows 95/98/ME skip step number 11,12 Quote: Step 1
Go to Start > Run Step 2
type regedit and press enter ok click ok Step 3
Navigate to this key HKEY_LOCAL_MACHINE/SOFTWARE/Microsoft/Windows/CurrentVersion/Run Step 4
Delete this value MSNMESENGER"="%System%/Main.exe Step 5
Navigate to this key HKEY_LOCAL_MACHINE/SOFTWARE/Microsoft/Windows/CurrentVersion/
Policies/Explorer/Run Step 6
Delete this value DirectX for Microsoft Windows"="%System%/Fservice.exe Step 7
Navigate to this key HKEY_LOCAL_MACHINE/SOFTWARE/Microsoft/Active Setup/Installed Components/{5Y99AE78-58TT-11dW-BE53-Y67078979Y} Step 8
Delete this value DirectX for Microsoft Windows"="%System%/Sservice.exe Step 9
Navigate to this key HKEY_CURRENT_USER/SOFTWARE/Microsoft/Windows/CurrentVersion/Run Step 10
Delete this value StubPath"="C:/Windows/system/Sservice.exe Step 11
Navigate to this key HKEY_LOCAL_MACHINE/Software/Microsoft/Windows NT/CurrentVersion/Winlogon Step 12
Modify this"Shell"="explorer.exe %System%/Fservice.exe" into this "Shell"="explorer.exe" Step 13
Exit your Registry Editor and restart your PC in Safe mode with Command prompt (shut down then start up and hit and hold F8 untill and black screen with white letters appears) Step 14
log on your own account and then you should see command prompt on the left and nothing else exept maybe some writing like Safe Mode Windows blahblahblah. Step 15
type in cd/windows like that. Step 16
type in erase services.exe Step 17
Then type in cd/windows/system Step 18
Type in erase sservice.exe like that. I did not misspelled it. Step 19
Then type in cd/windows/system32 Step 20
Then type the following codes in Code: erase C:/windows/system32/reginv.dll
erase C:/windows/system32/fservice.exe
erase C:/windows/system32/winkey.dll
erase C:/windows/system32/wininv.dll Step 21
Then type in cd/ and then start explorer Note: you dont have internet Step 22
Browse to your windows folder and check if the following files are deleted. Code: C:/windows/system32/reginv.dll
C:/windows/system32/fservice.exe
C:/windows/system32/winkey.dll
C:/windows/services.exe
C:/windows/system/sservice.exe
C:/windows/system32/wininv.dll Step 23
If you havent deleted it already delete PROrat without running it. the go to Start > Run again and if the following still exsist. If so delete/modify it again. Code: HKEY_LOCAL_MACHINE/SOFTWARE/Microsoft/Windows/CurrentVersion/Run
MSNMESENGER"="%System%/Main.exe
HKEY_LOCAL_MACHINE/SOFTWARE/Microsoft/WindowsCurrent/Version/
Policies/Explorer/Run
DirectX for Microsoft Windows"="%System%/Fservice.exe
HKEY_LOCAL_MACHINE/SOFTWARE/Microsoft/Active Setup/Installed Components/{5Y99AE78-58TT-11dW-BE53-Y67078979Y}
DirectX for Microsoft Windows"="%System%/Sservice.exe
HKEY_CURRENT_USER/SOFTWARE/Microsoft/Windows/CurrentVersion/Run
StubPath"="C:/Windows/system/Sservice.exe
HKEY_LOCAL_MACHINE/Software/Microsoft/Windows NT/CurrentVersion/Winlogon
"Shell"="explorer.exe %System%/Fservice.exe" must be "Shell"="explorer.exe"
Step 24
Now restart your PC again and browse to your windows folder again to check if these files are gone. if not repeat from step 1. Code: C:/windows/system32/reginv.dll
C:/windows/system32/fservice.exe
C:/windows/system32/winkey.dll
C:/windows/services.exe
C:/windows/system/sservice.exe
C:/windows/system32/wininv.dll Step 25
Run your virusscanner to check for virusses. Now it should say nothing unless you have other virussses or hacks...
|
Congratulations. Your PC is now Good to Go again. Have a nice day.
Credits to:
Me for writing.
Symantec© for providing the Keys.
Toscane of PChelper.nl for helping me.
__________________  Hall of respect: Hornstar6969, BleachNaruto, Kanon, Joriannn, Flamee, Kamil077, Bam, zone1992, +CrackKing1, +Demonite, +killah4eva, +kmaster22, +xslayer Dave Chappelle - What did the five fingers say to the Face Make your PC Safer and Better! Visit this thread! Wanna be 1337 just like me??? Buy Premium+ Now and PWN just like me. Member of the BleachNaruto fan club!
Last edited by GameLordquest; 08-27-2007 at 04:28 AM..
| | The Following 8 Users Say Thank You to GameLordquest For This Useful Post: | | 
08-06-2007, 03:35 AM
|  | Armenia | | | Last Online: Today 03:12 AM Join Date: Mar 2006 Location: Boss World :D
Posts: 2,673
Thanks: 230
Thanked 541 Times in 348 Posts
Nominated 0 Times in 0 Posts TOTW/F/M Award(s): 0
Latest Blog:
Rep Power: 14 Points: 43,873.61 Bank: 522.55 Total Points: 44,396.16 | | |
Thank you very much, this is very important for people pwho want to delete ProRat.
Ill contact choad and we'll discuss aobut stickying ^^
| 
08-06-2007, 04:57 AM
|  | Mendelity Inc | | | Last Online: 12-03-2008 04:40 PM Join Date: Mar 2006 Location: GunZ/GzN ((F)) FEYENOORD ((F))
Posts: 3,581
Thanks: 145
Thanked 332 Times in 218 Posts
Nominated 0 Times in 0 Posts TOTW/F/M Award(s): 0
Latest Blog: sixth seventh and eight day
Rep Power: 18 Points: 1,450.00 Bank: 204,314.07 Total Points: 205,764.07 | | |
Ok no problem.. Im here to help.
__________________  Hall of respect: Hornstar6969, BleachNaruto, Kanon, Joriannn, Flamee, Kamil077, Bam, zone1992, +CrackKing1, +Demonite, +killah4eva, +kmaster22, +xslayer Dave Chappelle - What did the five fingers say to the Face Make your PC Safer and Better! Visit this thread! Wanna be 1337 just like me??? Buy Premium+ Now and PWN just like me. Member of the BleachNaruto fan club! | 
08-06-2007, 07:38 AM
|  | P I N K | | | Last Online: Today 03:12 AM Join Date: Jan 2006 Location: In Someone's Heart.
Posts: 2,152
Thanks: 42
Thanked 195 Times in 113 Posts
Nominated 10 Times in 4 Posts TOTW/F/M Award(s): 0
Latest Blog: About myself.
Rep Power: 13 Points: 1,448.16 Bank: 0.00 Total Points: 1,448.16 | | |
Nice but I just uninstall it and no virus. Good Job anyway. Hope it would be stickied
| 
08-06-2007, 09:01 AM
|  | Armenia | | | Last Online: Today 03:12 AM Join Date: Mar 2006 Location: Boss World :D
Posts: 2,673
Thanks: 230
Thanked 541 Times in 348 Posts
Nominated 0 Times in 0 Posts TOTW/F/M Award(s): 0
Latest Blog:
Rep Power: 14 Points: 43,873.61 Bank: 522.55 Total Points: 44,396.16 | |
i uninstall and found some virusses in my registry..  they are there
| 
08-06-2007, 10:17 AM
|  | Mendelity Inc | | | Last Online: 12-03-2008 04:40 PM Join Date: Mar 2006 Location: GunZ/GzN ((F)) FEYENOORD ((F))
Posts: 3,581
Thanks: 145
Thanked 332 Times in 218 Posts
Nominated 0 Times in 0 Posts TOTW/F/M Award(s): 0
Latest Blog: sixth seventh and eight day
Rep Power: 18 Points: 1,450.00 Bank: 204,314.07 Total Points: 205,764.07 | | |
yea you installed the program but I advise you to follow this guide if you want to uninstall it.
__________________  Hall of respect: Hornstar6969, BleachNaruto, Kanon, Joriannn, Flamee, Kamil077, Bam, zone1992, +CrackKing1, +Demonite, +killah4eva, +kmaster22, +xslayer Dave Chappelle - What did the five fingers say to the Face Make your PC Safer and Better! Visit this thread! Wanna be 1337 just like me??? Buy Premium+ Now and PWN just like me. Member of the BleachNaruto fan club! | 
08-08-2007, 08:22 AM
|  | | | | Last Online: 11-17-2008 07:27 PM Join Date: Sep 2006 Location: Las Pinche El Paso
Posts: 314
Thanks: 30
Thanked 30 Times in 25 Posts
Nominated 0 Times in 0 Posts TOTW/F/M Award(s): 0
Latest Blog:
Rep Power: 6 Points: 727.40 Bank: 13,977.08 Total Points: 14,704.48 | | |
wow nicely explained gj XD
__________________ 
Current Goals: 350 Posts, Get In GFX Team im Mexican Blink-182
R.I.P Tom you will be Rememberd Toms Farewell threadEHS WRESTLING JV SQUAD! | 
08-08-2007, 01:01 PM
|  | Mendelity Inc | | | Last Online: 12-03-2008 04:40 PM Join Date: Mar 2006 Location: GunZ/GzN ((F)) FEYENOORD ((F))
Posts: 3,581
Thanks: 145
Thanked 332 Times in 218 Posts
Nominated 0 Times in 0 Posts TOTW/F/M Award(s): 0
Latest Blog: sixth seventh and eight day
Rep Power: 18 Points: 1,450.00 Bank: 204,314.07 Total Points: 205,764.07 | | |
np for this type of problems i make time...
__________________  Hall of respect: Hornstar6969, BleachNaruto, Kanon, Joriannn, Flamee, Kamil077, Bam, zone1992, +CrackKing1, +Demonite, +killah4eva, +kmaster22, +xslayer Dave Chappelle - What did the five fingers say to the Face Make your PC Safer and Better! Visit this thread! Wanna be 1337 just like me??? Buy Premium+ Now and PWN just like me. Member of the BleachNaruto fan club! | 
08-25-2007, 08:19 PM
|  | GunzBustar | | | Last Online: 08-02-2008 02:03 PM Join Date: Nov 2006 Location: Secretly hacking your Computer
Posts: 842
Thanks: 87
Thanked 140 Times in 77 Posts
Nominated 0 Times in 0 Posts TOTW/F/M Award(s): 0
Latest Blog:
Rep Power: 7 Points: 446.10 Bank: 5,826.55 Total Points: 6,272.65 | | |
i never liekd prorat
but this is awsome..
__________________
Current : |  | |
Currently Active Users Viewing This Thread: 1 (0 members and 1 guests) | | | | Thread Tools | | | | Display Modes | Linear Mode |
Posting Rules
| You may not post new threads You may not post replies You may not post attachments You may not edit your posts HTML code is Off | | | | |