How to remove the katrina scandal.vbs

Solved/Closed
hackimist Posts 37 Registration date Thursday October 28, 2010 Status Member Last seen December 28, 2013 - Oct 28, 2010 at 07:39 AM
 Rap - Mar 19, 2011 at 01:19 AM
Hello,

Ladies & Gentleman

My problem starts when i borrowed my classmates USB flash drive.
i click a katrinascandal.vbs and readme.txt. . . . then i found out my drive C: has it to so i delete it but then it came back then all my drive has it to my F: and G: even my PSP has it.

i opened some site that mite help but then they all say open regedit in the cmd but i can't my regedit is block it always says something like:
registry editing has been disabled by your administrator
and even my task manager is block(grayed)
even if i push Ctrl+Alt_Del i can't see start task manager

Script is removed for security reasons


1 response

jack4rall Posts 6428 Registration date Sunday June 6, 2010 Status Moderator Last seen July 16, 2020
Nov 1, 2010 at 08:29 AM
Hello,

Try this 1.

Follow the below steps to remove the katrinascandal.vbs

First you need to download the below applicatons. Click on the below links

and download it.

https://spybot-updates.com

https://filehippo.com/download_process_explorer/

------------------------------------------------------------------------
Click on start --> In search box, type notepad and press Enter.

Notepad will be opened. Copy the below commands starting from cd \ and

ending at del, paste it in the notepad and save it as fix.bat.

Note : Don't forget the extension .bat and make sure you save the file on the desktop

cd \
cd windows
attrib -h -r -s AdobeCS4.vbs
del AdobeCS4.vbs
-------------------------------------------------

Open the following applications, but don't close it after opening

1) Install the regalyz in your PC --> Open it by going to Start --> Programs -->

Safer Networking --> RegAlyzer

2) Extract the process explorer and double-click on "procexp" --> click on

"Agree". Now you can list of processes.

3) Click on start --> In search box, type msconfig and press "Enter".

"System Configuration Utility" will be opened --> Click on "Startup" tab.

Here you should be quick enough for the 3 steps as there is a timer allocated

in that script.

So, first

i) In "Process Explorer" window --> Right-click on the "wscript.exe" process

and select the option "Kill Process Tree".

ii) In "System Configuration Utility" --> In "Startup" tab --> uncheck the

checkbox "AdobeCS4.vbs" --> Click on OK.

iii) Run the fix.bat file.

Since you are using windows 7, right-click on fix.bat --> Select the option "Run

as Administrator".

4) In RegAlyzer, at the top you can find the Search box, copy each registy lines

in the below steps --> paste it and press Enter.

Or you can go manually at the left-side.

i) HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\System

At the right-side, select "DisableTaskMgr" and press the "Del" key and select

"Yes to all"

Select "DisableRegistryTools" and press the "Del" key and select "Yes to all"

ii) HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\Explorer

At the right-side, select "NoFolderOptions" and press the "Del" key and select

"Yes to all"

Double-click on "NoDriveTypeAutoRun" change the value from 128 to 255.

iii) HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Advanced

At the right-side, double-click on the "Hidden" file and change from 1 to 2.

iv) HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run

If you find the file "AdobeCS4.vbs" or "AdobePhotoshopCS4", delete it.

Now you should be able to open task manager.

Good Luck.
3
hackimist Posts 37 Registration date Thursday October 28, 2010 Status Member Last seen December 28, 2013 129
Nov 3, 2010 at 08:26 AM
Jack4all thanks for your help. . . .

by the way i did not do this

ii) In "System Configuration Utility" --> In "Startup" tab --> uncheck the

checkbox "AdobeCS4.vbs" --> Click on OK

Because i did not see any Adobe or any Adobe.exe there


so i skip it and go to phase 3 . . . . .


And how to fis regedit it is also lock you see?

and thanks to Everyone . . . .
0
jack4rall Posts 6428 Registration date Sunday June 6, 2010 Status Moderator Last seen July 16, 2020
Nov 3, 2010 at 08:30 AM
Hello,
Are you able to open task manager ?
Good Luck.
0
hackimist Posts 37 Registration date Thursday October 28, 2010 Status Member Last seen December 28, 2013 129
Nov 3, 2010 at 08:54 AM
Yeah it's running now When i push Ctrl+Alt+Del or tab Then start task manager. . .


Thank you for your great Help,i really appreciate it. . . .


And do you know where i should post this question of mine it's all about . . . .

When i push right click then New. . . there are files that should not be there

If i remember correctly it should only have New folder,shortcut,Briefcase,etc

But mine has contact,cc2game,and many more


Should i post this in the windows forum?


Thanks,
0
jack4rall Posts 6428 Registration date Sunday June 6, 2010 Status Moderator Last seen July 16, 2020
Nov 3, 2010 at 09:03 AM
Hello,
You can post it in the windows form.
What about your registry editor ? Are you able to open it. If you are having problem with it then
Use RegAlyzer and go to this location once again
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\System
At the right side, select "DisableRegistryTools" and press the "Del" key and click on "Yes to all"
Good Luck.
0
hackimist Posts 37 Registration date Thursday October 28, 2010 Status Member Last seen December 28, 2013 129
Nov 3, 2010 at 09:09 AM
Thanks for this again i'm all done thanks for your hardwork. . .

Best Regards
0