This is the symptom of a computer having bar311.exe virus A.K.A. winzip123. The virus comprises bar311.exe, password_viewer.exe, photos.zip.exe and pc-off.bat.
When you boot your Windows XP in Safe Mode the message appears: Thank You!!!
Password:Winzip123
The pc-off.bat contains the syntax like this"C:/path/shutdown -s -f -t 2 -c" which automatically shutdown your computer when you run the cmd.exe.
Manual removal is outlined below. Download bar311.exe - winzip123.exe Automatic Remover here.
Manual removal:
1. upon start up.... after os loading... go to task manager by pressing CTRL+ALT+DEL then kill password_viewer.exe or bar311.exe or photos.zip.exe...
2. EDIT the following registry entries thru regedit at start/run
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon]
"Userinit"="userinit.exe,bar311.exe" ---> remove ", bar311.exe" only... leave userinit.exe because this is used by Windows when you log-in...
[HKEY_CURRENT_USER\Software\Microsoft\Windows\
CurrentVersion\Explorer\Advanced]
"Hidden"=dword:00000001
"HideFileExt"=dword:00000000
"ShowSuperHidden"=dword:00000001
[HKEY_CURRENT_USER\Software\Microsoft\Command Processor]
"autorun"="c:\Windows\pc-off.bat" --> remove "c:\Windows\pc-off.bat" or delete the autorun key.
3. go to your flash drive (USB drive), please use the folders view in the explorer and use the navigation panel on the left side when accessing the drives to avoid triggering the autorun... then delete autorun.inf and password_viewer.exe or bar311.exe
4. open notepad then type what is shown below as is...
@echo off
del /a /f c:\Windows\bar311.exe
del /a /f c:\Windows\password_viewer.exe
del /a /f c:\Windows\photos.zip.exe
del /a /f c:\Windows\pc-off.bat
pause
then save this as remove.bat then click to run.... this will remove the virus...
Your Suggestation is very help ful thans a lot
ReplyDeletethanks, it works
ReplyDeleteThank you. You're the man! :)
ReplyDeletethanks a lot..but how did u know? did u develop the virus urself?
ReplyDeletekick @ss! killed the virus in a snap. Now, time to get an avs. Thanks!
ReplyDeletewth, avg can't piss it off...
ReplyDeletenicely done sir!
ReplyDeleteThanks for sharing this solution.. was very helpful! Thanks again
ReplyDeletenice tut man....^^
ReplyDeletedam avg....
Great! It really helps.
ReplyDeleteThank you...
salamat
ReplyDeleteThanks for this blog, now I can use my cmd :)
ReplyDeleteMore power to you sir! :)
IT WORKS!!!!
ReplyDeleteTHANK YOU!!!!
YIPEEE!!!
wow galeng
ReplyDeleteyou're a genius! lufet!
ReplyDeleteI love you for that
ReplyDeletesalamat
ReplyDeleteI'm a Believer!!!! WAHOOO!!!!! Curse the one who created that virus, and all hail to you for your solution!!!
ReplyDeletethanks so much!
ReplyDeletethank you sooooo..much.... your post is superb..:)
ReplyDeletew00t! Thanks to you problem has been resolved. It's kinda crappy that my AVG is up to date but it can't detect it. :S
ReplyDeletewow!..thanks alot!,it really works!..:)
ReplyDeletethanks. ang sarap mo!
ReplyDeleteThe amount of replies giving me some confidence, i've been chasing this solution for almost five-six months now... let me have a try!!
ReplyDeleteStill have the "shtdown running cmd.exe " I tried all these, not a single file is present what you have specified. All seemed OK in regisry as well. What could be the issue?
ReplyDeletethank u very much..i've been worried sick...thank u thank u thank u
ReplyDeleteyour the man!!!!.....
ReplyDeletethank you very much for this post... I remove now the #$^&*& virus... :D
Both Task Manager and Registry Editor were disabled. What now?
ReplyDeleteWOW!!! I was about to reformat my PC when I saw this link. Thanks a lot!!!
ReplyDeletemagaling magaling magaling!!!!!! salamat ng marami!!!!!!
ReplyDeletethanks...meron pla n2 eh!!thanks bro,try qoh 2...
ReplyDeleteHello. I'm having the same problem, but I can't seem to find the exe files you mentioned in my processes. Pls. help. Thaks in advance! :)
ReplyDeleteHi, my problem was solved already. This article is really helpful, but if it doesn't solve your problems, you can try http://www.troublefixers.com/command-prompt-disabled-by-virus/. This worked for me. Goodluck. :)
ReplyDeleterak rakan na toh. . galing mo pare. . astig. . salamat. . wag na magtiwala sa anti-virus. . sayo nako magtitiwala. .\m/
ReplyDeleteDUDE!!! THANKS ALOT! WHEW! THAT WAS VERY HELPFUL, EASY STEP BY STEP TOO:)
ReplyDeleteGREAT JOB!
hi.. thank you for posting this.. i've been having this problem for a long time now.. you're d man!
ReplyDeletewonderful, halatang pinoy eh! haha panalo!
ReplyDeletewow. this was very helpful. good thing this post is available online. i couldn't thank you enough. cheers mate!
ReplyDeletemy norton detect the said file as a virus and unsafe to run.
ReplyDeleteThanks...it helps a lot...
ReplyDeleteMy computer shuts down not just when running CMD but also when installing any anti-virus program so I'm thinking that it's the same virus.
But now it's solved. Thanks alot!!!
Mabuhay ka! :)
i also can't open task manager, it's disabled T_T
ReplyDeletewow! it worked!!! finally got rid of that stoopid problem. thank god i found this blog. thanks dude!! da best ka!!!
ReplyDeleteyou're the man! one thing.. the automated removal of the virus - the file itself is infected.
ReplyDeleteum. di ko dn magets #3. paexplain nmn ung thumb drive mo..?
ReplyDeleteI found this very useful.
ReplyDeleteThanks! You make my day
Download movies /
videos
thanks very helpful...
ReplyDeletethanx! good job!
ReplyDeleteI was struggling with this issue for the past 5 months and your article for manual removal helped to resolve the problem.
ReplyDeleteThanks alot for posting the solution.
Thank you very much, you are an angel, it worked like a charm.
ReplyDeleteIt's really TRUE! i'm searching for this answer for so long! UR A BLESSING DUDE! thank u!
ReplyDeletei remove viruses through the command prompt, and one day it refuses to work properly!! thanks to your guide i got it working again. thank you very much!!
ReplyDeletena-typo ka siguro sa #3.. are u pinoy? salamat!
thanks been infected since last week after backing up some pics from a friends pc
ReplyDeletesalamat po nang marami..
ReplyDeleteie,
thanks a lot po...
3. go to your thumb drive mo, please use the folders view in the explorer and use the navigation panel on the left side when accessing the drives to avoid triggering the autorun... then delete autorun.inf and password_viewer.exe or bar311.exe
ReplyDeleteHELP IM STUCK HIR PLSS HELP ME
hi!
ReplyDeletei was following the step by step manual removal of the virus kaso pagdting ko sa #3 wala na..wat does he mean by thumb drive mo?
superb man thanks a lot...bravo
ReplyDeleteYou're a genius!!!!
ReplyDeleteYou helped me solve my problem. Mabuhay ka, brader.
You're a genius!!!!
ReplyDeleteYou helped me solve my problem. Mabuhay ka, brader.
THANK YOU VERY VERY VERY MUCH!!!
ReplyDeleteThanks a lot. It really helps. Godbless.
ReplyDeletewhat's thumb drive mo?
ReplyDeleteEdited it a while ago. Thumb drive a.k.a. flash drive.
ReplyDeleteTHANK YOU!!! shit it worked! thanks a lot!
ReplyDeleteyou are damm great!!!!! it works!!
ReplyDeleteTHANKS,YOUR THE MAN
ReplyDeletegood job man your very helpful
ReplyDeletewow i downloaded the auto removal..it worked..we have two desktops and one laptop that shuts down everytime i open command prompt..tried it on my laptop and my cmd works now..will try it on the 2 other units..thanks again
ReplyDeletethis is how you make a great technical guide. very easy to follow.. thanks
ReplyDeletewow! man u saved a a lot of time! i was thinking of reformatting the system! thanks a lot bro! ur d man!!
ReplyDeletethanks dude :)
ReplyDeleteSir! Thx alot..
ReplyDelete:D
thanks! downloaded the file.. works!
ReplyDeletedo I have to delete the following too?:
ReplyDelete"Hidden"=dword:00000001
"HideFileExt"=dword:00000000
"ShowSuperHidden"=dword:00000001
I did not find any bar311.exe, password_viewer.exe, and photos.zip.exe but did find the pc-off.bat on my laptop..
will it work the same? and please do answer my question. Do I have to delete the 3 things that I have mentioned above?
whoa, this thing was posted July 2008, and is still helpful up to now. thank you so much! i enjoyed the step-by-step fix. =)
ReplyDeleteFor problem of this kind I would recommend that you use the System Restore tool which can easily solve problems of these kinds.
ReplyDeletetwo years on the net and still very usefull...
ReplyDeletebtw YOUR MY HERO!!!!
after trying to find the fix for my computer for a long time, you're simple automatic remover program was absolutely brilliant!!!
ReplyDeleteUltimate props!!!
thank you very much!!! :)
ReplyDeleteThere definitely can be the issue of virus attacking your system.
ReplyDeleteI was also facing the same problem recently, you need to get the program re installed and then get it installed again....
ReplyDeletei had experienced this once from windows xp and did the step-by-step procedure...now that i have win7, i cant find those batch files and when running the cmd prmpt shuts my pc down.. :(
ReplyDeleteYou're the best man! This helped me a month ago, but I didn't get to post... so thank you! XD
ReplyDelete