How to remove the katrina scandal.vbs [Solved/Closed]

hackimist 37 Posts Thursday October 28, 2010Registration date December 28, 2013 Last seen - Oct 28, 2010 at 07:39 AM - Latest reply:  Rap
- Mar 19, 2011 at 01:19 AM
Hello,

Ladies & Gentleman

My problem starts when i borrowed my classmates USB flash drive.
i click a katrinascandal.vbs and readme.txt. . . . then i found out my drive C: has it to so i delete it but then it came back then all my drive has it to my F: and G: even my PSP has it.

i opened some site that mite help but then they all say open regedit in the cmd but i can't my regedit is block it always says something like:
registry editing has been disabled by your administrator
and even my task manager is block(grayed)
even if i push Ctrl+Alt_Del i can't see start task manager

Script is removed for security reasons


See more 

8 replies

Best answer
jack4rall 6507 Posts Sunday June 6, 2010Registration dateModeratorStatus December 30, 2015 Last seen - Nov 1, 2010 at 08:29 AM
3
Thank you
Hello,

Try this 1.

Follow the below steps to remove the katrinascandal.vbs

First you need to download the below applicatons. Click on the below links

and download it.

http://www.spybot-updates.com/files/regalyz.exe

http://www.filehippo.com/download_process_explorer/

------------------------------------------------------------------------
Click on start --> In search box, type notepad and press Enter.

Notepad will be opened. Copy the below commands starting from cd \ and

ending at del, paste it in the notepad and save it as fix.bat.

Note : Don't forget the extension .bat and make sure you save the file on the desktop

cd \
cd windows
attrib -h -r -s AdobeCS4.vbs
del AdobeCS4.vbs
-------------------------------------------------

Open the following applications, but don't close it after opening

1) Install the regalyz in your PC --> Open it by going to Start --> Programs -->

Safer Networking --> RegAlyzer

2) Extract the process explorer and double-click on "procexp" --> click on

"Agree". Now you can list of processes.

3) Click on start --> In search box, type msconfig and press "Enter".

"System Configuration Utility" will be opened --> Click on "Startup" tab.

Here you should be quick enough for the 3 steps as there is a timer allocated

in that script.

So, first

i) In "Process Explorer" window --> Right-click on the "wscript.exe" process

and select the option "Kill Process Tree".

ii) In "System Configuration Utility" --> In "Startup" tab --> uncheck the

checkbox "AdobeCS4.vbs" --> Click on OK.

iii) Run the fix.bat file.

Since you are using windows 7, right-click on fix.bat --> Select the option "Run

as Administrator".

4) In RegAlyzer, at the top you can find the Search box, copy each registy lines

in the below steps --> paste it and press Enter.

Or you can go manually at the left-side.

i) HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\System

At the right-side, select "DisableTaskMgr" and press the "Del" key and select

"Yes to all"

Select "DisableRegistryTools" and press the "Del" key and select "Yes to all"

ii) HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\Explorer

At the right-side, select "NoFolderOptions" and press the "Del" key and select

"Yes to all"

Double-click on "NoDriveTypeAutoRun" change the value from 128 to 255.

iii) HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Advanced

At the right-side, double-click on the "Hidden" file and change from 1 to 2.

iv) HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run

If you find the file "AdobeCS4.vbs" or "AdobePhotoshopCS4", delete it.

Now you should be able to open task manager.

Good Luck.

Thank you, jack4rall 3

Something to say? Add comment

CCM has helped 1695 users this month

hackimist 37 Posts Thursday October 28, 2010Registration date December 28, 2013 Last seen - Nov 3, 2010 at 08:26 AM
Jack4all thanks for your help. . . .

by the way i did not do this

ii) In "System Configuration Utility" --> In "Startup" tab --> uncheck the

checkbox "AdobeCS4.vbs" --> Click on OK

Because i did not see any Adobe or any Adobe.exe there


so i skip it and go to phase 3 . . . . .


And how to fis regedit it is also lock you see?

and thanks to Everyone . . . .
jack4rall 6507 Posts Sunday June 6, 2010Registration dateModeratorStatus December 30, 2015 Last seen - Nov 3, 2010 at 08:30 AM
Hello,
Are you able to open task manager ?
Good Luck.
hackimist 37 Posts Thursday October 28, 2010Registration date December 28, 2013 Last seen - Nov 3, 2010 at 08:54 AM
Yeah it's running now When i push Ctrl+Alt+Del or tab Then start task manager. . .


Thank you for your great Help,i really appreciate it. . . .


And do you know where i should post this question of mine it's all about . . . .

When i push right click then New. . . there are files that should not be there

If i remember correctly it should only have New folder,shortcut,Briefcase,etc

But mine has contact,cc2game,and many more


Should i post this in the windows forum?


Thanks,
jack4rall 6507 Posts Sunday June 6, 2010Registration dateModeratorStatus December 30, 2015 Last seen - Nov 3, 2010 at 09:03 AM
Hello,
You can post it in the windows form.
What about your registry editor ? Are you able to open it. If you are having problem with it then
Use RegAlyzer and go to this location once again
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\System
At the right side, select "DisableRegistryTools" and press the "Del" key and click on "Yes to all"
Good Luck.
hackimist 37 Posts Thursday October 28, 2010Registration date December 28, 2013 Last seen - Nov 3, 2010 at 09:09 AM
Thanks for this again i'm all done thanks for your hardwork. . .

Best Regards