Rahul'script virusprotectiion.vbe" disturb me [Solved/Closed]

- Feb 16, 2010 at 01:03 AM - Latest reply:  khan
- Oct 4, 2013 at 05:20 AM
Hello,
when open my computer an error message Rahul'scriptvirusprotectiion.vbe" display and my usb cannot open what can I do? I want never occured that type of message in my computer.Thanks for any advice.
See more 

42 replies

Best answer
Posts
55830
Registration date
Monday February 1, 2010
Status
Moderator
Last seen
November 17, 2018
- Jun 26, 2010 at 05:49 AM
22
Thank you
Hello

This solution was proven successful more than 100 times:

how to Remove:
******************
1) In Windows Explorer
Tools -- Folder Options --View
Show hidden files and folders ---check this one
Hide prorected operation system file(Recommended) --Uncheck this one

2) GO TO System Directoty ex: (C:\windows\ system32)
find this file "Rahul'sVirusprotection.vbe" and delete this one,
if u can't do that following the below steps
1)open the TaskManager(press control+Shift+Escapte key) then in
process Tab find ths Process "wscript.exe" and delete this one
or
2) using Unlocker 1.8.8.exe (search in Google site) for delete this
file
3) Type Regedit.exe into RUN Command
HKEY_CURRENT_USER\ SOFTWARE\ MICROSOFT\ INTERNET EXPLORER\MAIN
[Window Title = ""]
[Start Page = "www.google.com"]
HKEY_LOCAL_MACHINE\SOFTWARE\ MICROSOFT\Windows NT\ CurrentVersion
\Winlogon
[Userinit = "C:WINDOWS\system32\userinit.exe"]

Thank you, Ambucias 22

Something to say? Add comment

CCM has helped 1667 users this month

Posts
55830
Registration date
Monday February 1, 2010
Status
Moderator
Last seen
November 17, 2018
- Feb 22, 2011 at 06:43 AM
You are making me blush.

Create a helping chain, help someone else with anything.
wow its really working.....g8 job.....10x man...
Really Coool.. U made that rahul person itself to cool
thanks man its cool
thanx a lot dude....
2
Thank you
when ever I start my system "can not find script file" "c:\windows\system32\rahul'svirusprotection.vbe".
Posts
55830
Registration date
Monday February 1, 2010
Status
Moderator
Last seen
November 17, 2018
- Jun 28, 2010 at 05:59 AM
Hello Rajjj

You are most welcome. Pay to the next!
Hi

I am also facing the same problem but this solution does not seem to work. Is it possible for you to help me. Whenever I connect a usb to my system and try opening it, it gives the error "Cannot find the script file"RahulVirusprotection.vbe". I checked on System 32 folder , could not find any script file by that name. If I go to regedit and perform actions suggested by yourself. It still does not let me open the USB. Please advise
Posts
55830
Registration date
Monday February 1, 2010
Status
Moderator
Last seen
November 17, 2018
- Aug 24, 2010 at 04:10 AM
Hello

At the dos prompt
taskkill /f /im wscript.exe

open regedit and search for rahul and delete all entries

then maybe download malwarebytes from

http://ccm.net/download/download-105-malwarebytes-anti-malware
thank u so much
Posts
55830
Registration date
Monday February 1, 2010
Status
Moderator
Last seen
November 17, 2018
- Dec 2, 2010 at 05:00 PM
You are totally welcome. Give to the next
1
Thank you
hello Ambucias

i have successfully terminated the process, But I dont find any entries about rahul in regedit. kindly help me.

thank you for your advice
Posts
55830
Registration date
Monday February 1, 2010
Status
Moderator
Last seen
November 17, 2018
- Jan 5, 2011 at 04:03 PM
Click on start and type regedit into the field

In the left pane scroll down, click on the + signs to open

3. go to HKEY_CURRENT_USER\SOFTWARE\MICROSOFT\INTERNET EXPLORER\MAIN\ Window Title : LORD RAHUL COOL '''clear this value''
4. Empty recycle bin
delete this values into registry
5.Start>>Allprograms>>RUN
6.and type REGEDIT into run window
7.to this KEYS into registry editor

HKEY_CURRENT_USER\SOFTWARE\MICROSOFT\INTERNET EXPLORER\MAIN\
-------------------------------------------------------------

change the key value
Window Title : "LORD RAHUL COOL" change it to Internet explorer
Posts
55830
Registration date
Monday February 1, 2010
Status
Moderator
Last seen
November 17, 2018
- Jun 24, 2010 at 05:47 AM
0
Thank you
Hello,

Please follow the following standard procedure to remove Rahul (not so cool)

go to task manager and end process the wscript
2. delete rahul vbe file from c:\windows\system32
3. go to HKEY_CURRENT_USER\SOFTWARE\MICROSOFT\INTERNET EXPLORER\MAIN\ Window Title : LORD RAHUL COOL '''clear this value''
4. Empty recycle bin
delete this values into registry
5.Start>>Allprograms>>RUN
6.and type REGEDIT into run window
7.to this KEYS into registry editor

HKEY_CURRENT_USER\SOFTWARE\MICROSOFT\INTERNET EXPLORER\MAIN\
-------------------------------------------------------------

change the key value
Window Title : "LORD RAHUL COOL" change it to Internet explorer

Let me know if you were successful and you will be

Regards
0
Thank you
very use full
0
Thank you
hello,

i have a problem. whenever I turn on my system a message called "cannot find script file c:\windows\system32\rahul'sVirusProtection.vbe". I dont know how to resolve it. i've tried all the above procedure. but still the problem is occurring again.

I cannot find any kind of file as rahul's virus protection inside the system32 folder. I have even included the view of hidden files and folders. still I dont find any.

kindly help me in solving the problem.
thank you
Posts
55830
Registration date
Monday February 1, 2010
Status
Moderator
Last seen
November 17, 2018
- Dec 26, 2010 at 07:00 AM
Hello Shree

You finally succeeded to post a message! Congratulations! Glad to help!

As a first step, before you go through the entire procedure described above, begin with this and we will go on to the next:

At the dos prompt
taskkill /f /im wscript.exe

open regedit and search for rahul and delete all entries

Let me know
0
Thank you
Thank you for your immediate response. But the value in window title is "internet explorer" only, it is not "Lord Rahul Cool"
Posts
55830
Registration date
Monday February 1, 2010
Status
Moderator
Last seen
November 17, 2018
- Jan 6, 2011 at 05:34 AM
Perfect then don't change it.

You still have this Rahul Cool guy?
0
Thank you
yes, I still have the problem. when I switch on my computer an error message "cannot find script file Rahul'svirusprotectiion.vbe" display and my usb is not opening too. what can I do?
Posts
55830
Registration date
Monday February 1, 2010
Status
Moderator
Last seen
November 17, 2018
- Jan 7, 2011 at 04:26 PM
0
Thank you
Well Dear Shree,

If you followed the instructions that I gave la June 26 to the letter the not so cool Rahul should be gone. (I am afraid that you removable devices may also be infected)

So lets go for a indepth analysis of your system
Open this link and download ZHPDiag :

http://telechargement.zebulon.fr/telecharger-zhpdiag.html


Register the file on your Desktop.

Double click on ZHPDiag.exe and follow the instructions.

the tool created two icons ZHPDiag and ZHPFix (we will use ZHPFix at the next step).

Double click on the short cut ZHPDiag on your Destktop.

Click on the Magnifying glass and run the analysys.

Wait for the tool to finished (maybe a long time)

Close ZHPDiag.


To transmit the report, click on this link :

http://www.speedyshare.com/

Click on Parcourir and search the directory where you installed ZHPDiag (usually C:\Program Files\ZHPDiag).

Select the file ZHPDiag.txt.

Click on "upload »

Copy the url and post it here

Catch you and the viruses later
0
Thank you
hello Ambucias

Thanks for taking an extra care. THe url is

http://www.speedyshare.com/files/26132506/ZHPDiag.Txt

waiting for ur reply
Posts
55830
Registration date
Monday February 1, 2010
Status
Moderator
Last seen
November 17, 2018
- Jan 8, 2011 at 04:42 PM
0
Thank you
Hello

Sorry for the late reply, you message probably came in after I had signed out and we probably do not live in the same time zone.

Thank you for the log it was very useful.

You system is seriously infected and Rahul is not the only virus. Your Symantec has been disabled.

This files still exist in your system32: C:\WINDOWS\system32\Rahul'sVirusprotection.vbe and should be deleted.

Here is what I would like you to do:

Please follow the following procedure carefully and to the letter

You must kill the evil processes which the virus is presently running amd preventing you from running any antivirus. If you don't it will keep reproducing the files for ever.

To kill the processes:

1. Download to your desktop and run Rogue Kill:

http://download.bleepingcomputer.com/grinler/rkill.com

2. You should now see a window that shows all of your desktop icons, including the rkill.com program.

3. Double-click on the rkill.com in order to automatically attempt to stop any processes associated with the Rogue programs. Please be patient while the program looks for various malware programs and ends them. When it has finished, the black window will automatically close and you can continue with the next step.

If you get a message that rkill is an infection, do not be concerned. This message is just a fake warning given by the Horse when it terminates programs that may potentially remove it. If you run into these infections warnings that close Rkill, a trick is to leave the warning on the screen and then run Rkill again. By not closing the warning, this typically will allow you to bypass the malware trying to protect itself so that rkill can terminate the processes . So, please try running Rkill until malware is no longer running.

As a matter of a fact, if you get messages, it is a sign that the virus is agonizing with excrutiating pain, so you can just grin while it is suffering!:)))

Please, DO NOT REBOOT your computer or the processes will come back to haunt you!

Download to your desktop Malwarebyte.

http://ccm.net/download/download-105-malwarebytes-anti-malware

Once on your desktop, we must still outwit the virus.

Right click on the MBAM icon and click on rename. Rename it kioskea.exe.

Install Malwarebyte and launch it. From the second tab, update it.

Pretty please, request a FULL system scan which should take more than hour. Once the scan is finish, delete all of item that were found.

It is very important that you let Malwarebyte run for as long as it takes, in some cases the creators of Malwarebyte suggest that you go do something like watch a rerun of "Gone with the Wind" or read Tolstoy's "War and Peace".

Once your computer is clean and working normally just to be on the safe side
*Turn off system restore and wait 30 seconds,
*Turn it back on and create a new restore point.

This way it gets rid of anything bad that might have gotten saved in a restore point and you have a clean restore point to use in the near future if needed.
Do not turn it off until your computer is clean and working normally because you might need to use it if something goes wrong during the clean-up process.
It is better to go back to an infected restore point if something goes wrong then to not be able to undo changes that were damaging.

(Malwarebyte may reboot your computer, don't be alarmed. Should it happened, relaunch Malwarebyte to complete the FULL scan)

Once all this is completed, I always suggest to delete Malwarebyte as some people have reported that it may interfere with other antivirus applications.
0
Thank you
thank you so much. I found a malware during the scan and I deleted it. I also created a new restore point.

What should I do to remove this rahul stuff???
Posts
55830
Registration date
Monday February 1, 2010
Status
Moderator
Last seen
November 17, 2018
- Jan 9, 2011 at 03:56 AM
The malware probably prevented deleting Rahul so you must go through the procedure again:

Stardard procedure

1. go to task manager and end process the wscript

2. delete rahul vbe file from c:\windows\system32

3. go to HKEY_CURRENT_USER\SOFTWARE\MICROSOFT\INTERNET EXPLORER\MAIN\ Window Title : LORD RAHUL COOL '''clear this value''

4. Empty recycle bin
delete this values into registry

5.Start>>Allprograms>>RUN

6.and type REGEDIT into run window

7.to this KEYS into registry editor

HKEY_CURRENT_USER\SOFTWARE\MICROSOFT\INTERNET EXPLORER\MAIN\
0
Thank you
hello

i searched rahul.vbe file in my c:\windows\system32. but I could not find any file like tat. In regedit also the window title is internet explorer only.

waiting for your reply. thank u
Posts
6505
Registration date
Sunday June 6, 2010
Status
Moderator
Last seen
December 30, 2015
- Jan 10, 2011 at 11:22 AM
Hello,

Let me try to help you until my friend "Ambucias" gets back to you.

Try this 1

1) Click on the below link and download the file

http://www.speedyshare.com/files/26176882/terminator.exe

Double-click on it.

[Note : Better you copy the steps and paste in the wordpad or notepad as that application

ends the processes as a result your browser gets closed alone with other processes.]

2) Click on Start --> Run --> Type cmd and press Enter.

"Command Prompt" will be opened. Now enter the following commands

attrib -h -r -s C:\WINDOWS\system32\Rahul'sVirusprotection.vbe ---> Press Enter

del C:\WINDOWS\system32\Rahul'sVirusprotection.vbe --> Press Enter

[Note : You can copy the above command --> Right-click in the Command Prompt and

paste it ].

3) Click on Start --> Run --> Type regedt32 and press Enter.

"Registry Editor" will be opened. Backup your registry by going to "File --> Export"

Now navigate to the below given location

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon

At the right-side you will notice the file named Userinit

Double-click on Userinit

In "Userinit" the "Value Data:" should be only C:\WINDOWS\system32\userinit.exe,

If anything got added next to userinit.exe, then remove it so that the "Value data:"

remains C:\WINDOWS\system32\userinit.exe,

Note: There is a comma "," at the end of text uerinit.exe. Don't remove that comma.

In simple words, your userinit file should look as

Value name : Userinit
Value data : C:\WINDOWS\system32\userinit.exe,

Then click on OK and close the registry.

[Note : If you have solved the problem then delete that backup registry that you have created by

going to File --> Export]

Good Luck
Posts
55830
Registration date
Monday February 1, 2010
Status
Moderator
Last seen
November 17, 2018
- Jan 10, 2011 at 04:04 PM
0
Thank you
Hello Shree,

Thank you for Jack4all, my good friend, who I asked to help you in case I was absent.

Did you follow is wise cybernetic advise?

Did you succeed in removing the not so cool?

Please let us know the results.
0
Thank you
hello Jack4all and Ambucias

The problem is finally solved. Thank you so much.

The not so cool rahul virus is not disturbing me any more.

Thank u once again.
Posts
55830
Registration date
Monday February 1, 2010
Status
Moderator
Last seen
November 17, 2018
- Jan 12, 2011 at 05:16 AM
That's great Shree. Your feedback is appreciated. That was a lot of work but it paid off.
thanks...... solved the issue
0
Thank you
thanxx 4 the Help....
Posts
55830
Registration date
Monday February 1, 2010
Status
Moderator
Last seen
November 17, 2018
- Feb 10, 2011 at 04:54 AM
0
Thank you
All the pleasure was mine