Author Topic: Solution to remove COOL.vbs virus from your PC  (Read 14455 times)

0 Members and 1 Guest are viewing this topic.

Offline Michael (alan1998)

  • Massive Poster
  • ****
  • Posts: 2768
  • Volunteer
Re: Solution to remove COOL.vbs virus from your PC
« Reply #15 on: December 11, 2013, 09:53:30 PM »
Hows the file going to run on boot-up? You didn't look everywhere.

Regedit: HKEY Current User > Software > Microsoft > Windows > Current Version > Run

There should be a key there.

You have not looked everywhere
VOLUNTEER

Senior Security Analyst; Sys Admin (Linux); Forensics/Incident Response.

Security is a mindset, not an application. Think BEFORE you click.

fahim9n

  • Guest
Re: Solution to remove COOL.vbs virus from your PC
« Reply #16 on: December 11, 2013, 10:03:07 PM »
Yes I found out there. But there was given value 0. no exe file  or path of exe file.

Thanks
fahim

Offline Michael (alan1998)

  • Massive Poster
  • ****
  • Posts: 2768
  • Volunteer
Re: Solution to remove COOL.vbs virus from your PC
« Reply #17 on: December 11, 2013, 10:06:40 PM »
Means they'll be more. Do you still have the virus? If so, zip it, password protect it password should be: infected

Send it to me via google drive, wikisend etc

From there, I can point out everything that the file drops
VOLUNTEER

Senior Security Analyst; Sys Admin (Linux); Forensics/Incident Response.

Security is a mindset, not an application. Think BEFORE you click.

fahim9n

  • Guest
Re: Solution to remove COOL.vbs virus from your PC
« Reply #18 on: December 11, 2013, 10:10:32 PM »
Sorry, I don't have any symptom of that virus now. I have connected two usb devices, 2 android devices, but no sign of making shortcut or something abnormal.

Thanks
fahim

Offline Michael (alan1998)

  • Massive Poster
  • ****
  • Posts: 2768
  • Volunteer
Re: Solution to remove COOL.vbs virus from your PC
« Reply #19 on: December 12, 2013, 03:29:11 PM »
Sorry life is busy, we are finishing major assignments in school.

As for your post. As people here and all over would say. Just because they're no symptoms, does NOT mean it's gone. Post an OTL log and MCShield log. I'm sure Essex or Argus or another remover can find something

Also, how does one go about trying to fix a windows activation error on a school computer? The key has been deleted. I told a tech, however. THeir solution is reinstall windows lol
VOLUNTEER

Senior Security Analyst; Sys Admin (Linux); Forensics/Incident Response.

Security is a mindset, not an application. Think BEFORE you click.