login about faq


my friend is sending me a s.o.s about this virus anyone have any ideas on how to rid of it windows xp pro is his o.s

asked Jun 12 '10 at 14:11

overclockedto420's gravatar image

overclockedto420
(suspended)

edited Jun 12 '10 at 14:32

Acilius's gravatar image

Acilius
(suspended)

changed the tag "Wondows" to "Windows"

(Jun 12 '10 at 14:32) Acilius Acilius's gravatar image

Get a Mac, then you won't have to deal with this problem.

answered Jun 12 '10 at 14:12

AppleHack23's gravatar image

AppleHack23
(suspended)

Lol, see, getting virus's comes from stupidity and ignorance. Not knowing what to and what not to download. Spending over $1,000 would fix this problem. How? You're being stupid on a system that can handle any capacity of dumb actions.

(Jun 12 '10 at 14:17) Acilius Acilius's gravatar image

Which is why the only virus I have ever had on my Mac is the one I created, which hasn't even been executed yet. Chances are, his friend isn't going to know anything about UNIX commands, and therefore, would not know what to type. He most likely wouldn't know about Terminal for a while either.

(Jun 12 '10 at 14:20) AppleHack23 AppleHack23's gravatar image

Yep its malware! Here's how to remove it! **http://www.myantispyware.com/2010/06/02/how-to-remove-cntprot-exe-malware/** or click "here"

While cntprot.exe is running, it will block the Windows Task Manager and most legitimate Windows applications, flood your computer with nag screens, fake security alerts and notifications from your Windows taskbar. Follow that guide!!!

Step 1. Repair “running of .exe files”. Click Start, Run. Type command and press Enter. Command console “black window” opens. Type notepad as shown below. alt text

Press Enter. Notepad opens. Copy all the text below into Notepad.

Windows Registry Editor Version 5.00

[HKEY_CLASSES_ROOTexefileshellopencommand] @=""%1" %*"

You will see window similar to the one below. alt text

Save this as fix.reg to your Desktop (remember to select Save as file type: All files in Notepad.) Double Click fix.reg and click YES for confirm. Reboot your computer.

If you can`t create fix.reg, then download fix.zip from here, unzip it. Double Click fix.reg and click YES for confirm. Reboot your computer.

Step 2. Remove TDSS trojan-rootkit You need remove TDSS trojan, after that, you will be able to remove cntprot.exe malware without any problem.

Download TDSSKiller from here and unzip to your desktop.

Open TDSSKiller folder. Right click to tdsskiller and select rename. Type a new name (123myapp, for example). Press Enter. Double click the TDSSKiller icon to start scanning Windows registry for TDSS trojan. If it is found, the you will see a screen similar to the one below.

alt text

When TDSSKiller will prompt you to press “Y”, type Y and press Enter. Your computer will be rebooted.

Step 3. Remove cntprot.exe malware and any associated malware.

Download MalwareBytes Anti-malware (MBAM). Once downloaded, close all programs and windows on your computer.

Double-click on the icon on your desktop named mbam-setup.exe. This will start the installation of MalwareBytes Anti-malware onto your computer. When the installation begins, keep following the prompts in order to continue with the installation process. Do not make any changes to default settings and when the program has finished installing, make sure a checkmark is placed next to “Update Malwarebytes’ Anti-Malware” and Launch “Malwarebytes’ Anti-Malware”. Then click Finish.

MalwareBytes Anti-malware will now automatically start and you will see a message stating that you should update the program before performing a scan. If an update is found, it will download and install the latest version.

As MalwareBytes Anti-malware will automatically update itself after the install, you can press the OK button to close that box and you will now be at the main menu. You will see window similar to the one below.

alt text

Make sure the “Perform quick scan” option is selected and then click on the Scan button to start scanning your computer for cntprot.exe malware. This procedure can take some time, so please be patient.

When the scan is finished a message box will appear that it has completed scanning successfully. Click OK. Now click “Show Results”. You will see a list of infected items similar as shown below. Note: list of infected items may be different than what is shown in the image below.

alt text

Make sure all entries have a checkmark at their far left and click “Remove Selected” button to remove cntprot.exe malware. MalwareBytes Anti-malware will now remove all of associated cntprot.exe malware files and registry keys and add them to the programs’ quarantine. When MalwareBytes Anti-malware has finished removing the infection, a log will open in Notepad and you may be prompted to Restart.

Note 1: if you can not download, install, run or update Malwarebytes Anti-malware, then follow the steps: Malwarebytes won`t install, run or update – How to fix it.

Note 2: if you need help with the instructions, then post your questions in our Spyware Removal forum.

Note 3: your current antispyware and antivirus software let the infection through ? Then you may want to consider purchasing the FULL version of MalwareBytes Anti-malware to protect your computer in the future.

cntprot.exe malware creates the following files and folders C:Program FilesProtection Center %UserProfile%Start MenuProgramsProtection Center C:Program FilesProtection Centercnthook.dll C:Program FilesProtection Centercntprot.exe C:Program FilesProtection Centerabout.ico C:Program FilesProtection Centeractivate.ico C:Program FilesProtection Centerbuy.ico C:Program FilesProtection Centerhelp.ico C:Program FilesProtection Centerscan.ico C:Program FilesProtection Centersettings.ico C:Program FilesProtection Centersplash.mp3 C:Program FilesProtection Centeruninstall.exe C:Program FilesProtection Centerupdate.ico C:Program FilesProtection Centercnt.db C:Program FilesProtection Centercntext.dll C:Program FilesProtection Centervirus.mp3 %UserProfile%Start MenuProgramsProtection CenterAbout.lnk %UserProfile%Start MenuProgramsProtection CenterActivate.lnk %UserProfile%Start MenuProgramsProtection CenterBuy.lnk %UserProfile%Start MenuProgramsProtection CenterScan.lnk %UserProfile%Start MenuProgramsProtection CenterSettings.lnk %UserProfile%Start MenuProgramsProtection CenterUpdate.lnk %UserProfile%Start MenuProgramsProtection CenterProtection Center Support.lnk %UserProfile%Start MenuProgramsProtection CenterProtection Center.lnk %UserProfile%Application DataMicrosoftInternet ExplorerQuick LaunchProtection Center.lnk %UserProfile%DesktopProtection Center Support.lnk %UserProfile%DesktopProtection Center.lnk

cntprot.exe malware creates the following registry keys and values HKEY_CURRENT_USERSOFTWAREMicrosoftWindowsCurrentVersionRunProtection Center HKEY_CURRENT_USERSOFTWAREMicrosoftWindowsCurrentVersionPoliciesSystemDisableTaskMgr HKEY_LOCAL_MACHINESOFTWAREMicrosoftWindowsCurrentVersionPoliciesSystemDisableTaskMgr

answered Jun 12 '10 at 14:13

Acilius's gravatar image

Acilius
(suspended)

edited Jun 12 '10 at 14:30

if it's an exe and you can still use windows functions then if he preforms a search he should just be able to delete it and end his problem.

answered Jun 12 '10 at 14:15

jakek090's gravatar image

jakek090
3.7k3893123

well thank you for a not so stupid answer
he says he can even run his os its just freezing and nothing seems to detect its presence

(Jun 12 '10 at 14:25) overclockedto420 overclockedto420's gravatar image

can he log in???????

(Jun 12 '10 at 15:34) bigbang bigbang's gravatar image
Your answer
toggle preview

Follow this question

By Email:

Once you sign in you will be able to subscribe for any updates here

By RSS:

Answers

Answers and Comments

Markdown Basics

  • *italic* or __italic__
  • **bold** or __bold__
  • link:[text](http://url.com/ "title")
  • image?![alt text](/path/img.jpg "title")
  • numbered list: 1. Foo 2. Bar
  • to add a line break simply add two spaces to where you would like the new line to be.
  • basic HTML tags are also supported


Join Us in the Chat Room

Tags:

×1,937
×976
×147
×1

Asked: Jun 12 '10 at 14:11

Seen: 672 times

Last updated: Jun 12 '10 at 15:34