Recommended Posts

Alright long story short, I have been infected with Winspywarepro which is a virus that doesn't allow me to do anything unless I boot in safe mode. Does anyone know how to get rid of the whole thing? There are registry screw ups that it altered so I can't use taskmanager or get into my control panel. (Control panel is hidden in the start menu along with some other programs and task manager shows an error saying 'Administrator has disabled task manager' but I didn't). Please help.

Note: This virus slows down the computer extremly and right now Im on my dads laptop. I can barely load anything.

Edited by Violent
Link to comment
https://www.neowin.net/forum/topic/648545-winspywarepro/
Share on other sites

Here is a list of commands to get to things from the run command

http://vlaurie.com/computers2/Articles/control.htm

At the run type

control.exe

to get the control panel

Try these fixes to regain control

Kelly XP Site

http://www.kellys-korner-xp.com/xp_tweaks.htm

To regain control panel lockout...

http://www.kellys-korner-xp.com/regs_edits...tionrestore.reg

Task manager

http://www.kellys-korner-xp.com/regs_edits/taskmanager.reg

You could also try to regain the task manager using this site.

http://windowsxp.mvps.org/Taskmanager_error.htm

Edited by redvamp128
Link to comment
https://www.neowin.net/forum/topic/648545-winspywarepro/#findComment-589548850
Share on other sites

Follow these steps:

Turn off system restore

Check add/remove programs for Winspywarepro listed and uninstall or check the directory for a uninstaller.

Go into msconfig and kill whatever you don't need to startup and run including stuff you don't know what is OFF in the startup tab

Download/update Superantispyware Free version

Download/Update Avast Free antivirus...register it free and lasts 16months

Download/update Spybot S&D

Download CCleaner latest version and select all boxes and clean.

Navigate to your Local folder(hidden) under your Documents folder and delete all Temp/temp internet files

Ok, now boot into safe mode...

Set avast to do a boot scan upon next reboot and set it to remove anything automatically that it finds!!!

Close avast and open superantispyware.... start a Full scan and remove whatever it finds and most likely it will ask to reboot..do it.

Upon this reboot avast will kick in and clean whatever is left over and that it finds.

Once backin to windows open and run spybot, remove whatever it finds then run CCleaner once more and reboot again.

Last download Hijackthis scan and remove all the things that says filemissing and stuff that looks bad...if your unsure post the log here and someone will help you.

That should do it as these steps have worked for me many times in the past year. Good Luck!

Link to comment
https://www.neowin.net/forum/topic/648545-winspywarepro/#findComment-589548908
Share on other sites

Or just get SuperAntiSpyware Free and take all the hard work out of the job.

Violent has previously tried that and he said this.

I tryed installing Superantispywarepro but I get an error saying: The system administrator has set policies to prevent this installation.

Where can I edit that?

Link to comment
https://www.neowin.net/forum/topic/648545-winspywarepro/#findComment-589548920
Share on other sites

If it will let you into it- at the run type gpedit.msc. (if on XP pro) don't think it will work on XP home- I think it is in all versions of Vista.

If it won't then merge this registry and it should let you in.

http://www.kellys-korner-xp.com/regs_edits/mmc.reg

I have home so it won't work.

Follow these steps:

Turn off system restore

Check add/remove programs for Winspywarepro listed and uninstall or check the directory for a uninstaller.

Go into msconfig and kill whatever you don't need to startup and run including stuff you don't know what is OFF in the startup tab

Download/update Superantispyware Free version

Download/Update Avast Free antivirus...register it free and lasts 16months

Download/update Spybot S&D

Download CCleaner latest version and select all boxes and clean.

Navigate to your Local folder(hidden) under your Documents folder and delete all Temp/temp internet files

Ok, now boot into safe mode...

Set avast to do a boot scan upon next reboot and set it to remove anything automatically that it finds!!!

Close avast and open superantispyware.... start a Full scan and remove whatever it finds and most likely it will ask to reboot..do it.

Upon this reboot avast will kick in and clean whatever is left over and that it finds.

Once backin to windows open and run spybot, remove whatever it finds then run CCleaner once more and reboot again.

Last download Hijackthis scan and remove all the things that says filemissing and stuff that looks bad...if your unsure post the log here and someone will help you.

That should do it as these steps have worked for me many times in the past year. Good Luck!

I can only access the internet in safe mode, if I try to in regular mode it freezes/slows incredibly. I can't even run regedit in the run thing because 'the admin has disabled it'.

Link to comment
https://www.neowin.net/forum/topic/648545-winspywarepro/#findComment-589548923
Share on other sites

Try this

http://www.dougknox.com/xp/utils/xp_emerutils.htm

run that and it should create backup copies of the files that are locked out- then you can run them- They will list as .bat files but windows will bypass the block

it probably has a block on .msc and .exe files but probably no block on .bat ....

That should restore regedit

because it will create a backup copy that will list it as regedit.bat

but should run

if that does not work

then try this registry fix

http://www.kellys-korner-xp.com/regs_edits...mcmdrestore.vbs

Link to comment
https://www.neowin.net/forum/topic/648545-winspywarepro/#findComment-589548927
Share on other sites

Try this

http://www.dougknox.com/xp/utils/xp_emerutils.htm

run that and it should create backup copies of the files that are locked out- then you can run them- They will list as .bat files but windows will bypass the block

it probably has a block on .msc and .exe files but probably no block on .bat ....

That should restore regedit

because it will create a backup copy that will list it as regedit.bat

but should run

if that does not work

then try this registry fix

http://www.kellys-korner-xp.com/regs_edits...mcmdrestore.vbs

I tryed both (in safe mode) and they didn't work. The first thing with the copies downloaded and I tryed to run the exe file but I just clicked and it did nothing. The second one ran and said finished but did nothing.

Boot into a Linux liveCD, mount the drive as read-only. Copy data (as in, documents and stuff you want to keep) to an external drive for backup. Reboot, with XP install CD in drive. Reinstall. Reinstall applications. Be more careful in the future. Voila.

Not sure what that means.

I CANNOT access internet in normal mode only in safe mode.

Link to comment
https://www.neowin.net/forum/topic/648545-winspywarepro/#findComment-589548950
Share on other sites

Violent has previously tried that and he said this.

I tryed installing Superantispywarepro but I get an error saying: The system administrator has set policies to prevent this installation.

Where can I edit that?

Sorry missed that. ;)

Next I'd try the Avira Rescue CD - the link is in my signature. Does a great job.

Link to comment
https://www.neowin.net/forum/topic/648545-winspywarepro/#findComment-589548959
Share on other sites

I have home so it won't work.

I can only access the internet in safe mode, if I try to in regular mode it freezes/slows incredibly. I can't even run regedit in the run thing because 'the admin has disabled it'.

Well what you do is get into safe mode and then msconfig and kill stuff from starting up... run ccleaner from within safemode to and then get back into regular mode just to follow what I said.

Its obvious you have things starting up thats killing you in normal mode that you need to terminate.

You may also consider just backing up certain files to keep while your able to and then reinstall the OS, cause at this point it would appear you may have more issues than what your describing.

Link to comment
https://www.neowin.net/forum/topic/648545-winspywarepro/#findComment-589548969
Share on other sites

This topic is now closed to further replies.
  • Recently Browsing   0 members

    • No registered users viewing this page.
  • Posts

    • Looks like no official TBW rating, which should be a required listing in my opinion for sites like Amazon (hell, put it on the box too.)
    • I think I understood the article fine. Online password managers open users up to more possibilities of getting hacked, and due to KeePass being offline and local it reduces the idea of getting hacked. If someone chooses to put their database online they're kinda missing the point. With regards to the idea of the on-prem idea, I would have two issues. I'm not sure about the first issue, but I wouldn't be surprised about them offering a cloud storage for the passwords that most wouldn't bother to switch off, regardless of if they went for on-prem or not. The second issue is that the on-prem solution for Bitwarden costs money, whereas KeePass is free and open-source (as far as I am aware). The article points out how to sync the database between devices, and I recognise that deficiency in security. But it isn't a necessity. So both services can offer a same idea, but one is free and the other isn't...choices, choices.... But to each their own.
    • AB Download Manager 1.9.2 by Razvan Serea AB Download Manager is an open-source, feature-rich download manager designed to accelerate downloads, organize files efficiently, and provide seamless control over downloads. With support for multiple connections, resume capability, and an intuitive interface, it enhances the downloading experience for users seeking speed and reliability. The software integrates with various browsers, enabling quick link grabbing and batch downloading. It supports HTTP, HTTPS, and FTP protocols, ensuring broad compatibility with different file sources. Users can schedule downloads, set speed limits, and categorize files automatically for better organization. AB Download Manager is lightweight yet powerful, making it a great alternative to proprietary download managers. Its open-source nature allows developers to contribute, customize, and improve the software as needed. Whether you're downloading large files, managing multiple downloads at once, or seeking an ad-free experience, this tool offers a practical and efficient solution. Key features of AB Download Manager: Multi-Connection Support – Accelerates downloads by splitting files into multiple segments. Resume Capability – Allows paused or interrupted downloads to be resumed without starting over. Batch Downloading – Supports downloading multiple files at once for improved efficiency. Browser Integration – Captures download links directly from browsers for seamless operation. HTTP, HTTPS, and FTP Support – Ensures compatibility with a wide range of file sources. Download Scheduling – Enables users to automate downloads at specific times. Speed Limiting – Lets users control bandwidth usage for optimized performance. File Categorization – Automatically organizes downloaded files into designated folders. User-Friendly Interface – Simple and intuitive design for easy navigation. Cross-Platform Compatibility – Works on multiple operating systems. Ad-Free Experience – No intrusive ads or tracking for a clean user experience. AB Download Manager 1.9.2 changelog: Added New Twilight theme (#1292) Optional download completion notifications on Android (#1290) Fixed Fixed a crash on some older CPUs on Windows Fixed oversized system tray icon on macOS Improved Updated translations Prevented Android devices from sleeping while downloads are active (#1291) Various UI and UX improvements Download: AB Download Manager 1.9.2 | Portable | ~80.0 MB (Open Source) Download: ARM64 | Portable ARM64 | Android Links: AB Download Manager Website | Github Page | Screenshot Get alerted to all of our Software updates on Twitter at @NeowinSoftware
    • I am not surprised because life is the product of a lot of biochemical and physical processes that releases various energies as a by-product. The only thing new here is the detection of these photon emissions. The researches noted this "glow" is not a metaphysical one. They don't even immediately end when one is dead. Things like fires, light bulbs, and on a bigger scale stars release a lot more "light" and they are hardly alive.
  • Recent Achievements

    • Conversation Starter
      sumytbe earned a badge
      Conversation Starter
    • One Year In
      B4dM1k3 earned a badge
      One Year In
    • One Year In
      DarkWun earned a badge
      One Year In
    • Dedicated
      Almohandis earned a badge
      Dedicated
    • Dedicated
      JuvenileDelinquent earned a badge
      Dedicated
  • Popular Contributors

    1. 1
      +primortal
      516
    2. 2
      +Edouard
      186
    3. 3
      PsYcHoKiLLa
      87
    4. 4
      Michael Scrip
      79
    5. 5
      Steven P.
      73
  • Tell a friend

    Love Neowin? Tell a friend!