Jump to content

OpenSecurity Help Please tried everything..


Recommended Posts

Hi Guys,

I could really use your help, I have tried following over 10 guides to get rid of the OpenSecurity virus/malware but I cannot get it off. So far I have:

Removed all associated registry entries:

HKEY_CLASSES_ROOT\exefile\shell\open\command “(Default)” = ‘C:\Program Files\conhost.exe “%1″ %*’

Deleted all files associated with it:

%UserProfile%\Desktop\OpenCloud Security.lnk

%AppData%\OpenCloud Security

%AppData%\OpenCloud Security\OpenCloud Security.exe

%AppData%\OpenCloud Security\OpenCloud Security.ico

%AppData%\OpenCloud Security\sysl32.dll

%AppData%\OpenCloud Security\wf.conf

%StartMenu%\Programs\OpenCloud Security

%StartMenu%\Programs\OpenCloud Security\OpenCloud Security.lnk

Removed random files from C:\Windows\System32\

Booted into Safe Mode, copied rkill,hijackthis,OTL,avg,etc,etc from another computer to this computer but no matter what I do or if I reboot in safe mode everytime I try and launch any exe I get the message "The file does not have a program associated with it for performing this action". So I cannot continue with any of the cleanup guides. Please help!

Hi Guys,

I could really use your help, I have tried following over 10 guides to get rid of the OpenSecurity virus/malware but I cannot get it off. So far I have:

Removed all associated registry entries:

HKEY_CLASSES_ROOT\exefile\shell\open\command “(Default)” = ‘C:\Program Files\conhost.exe “%1″ %*’

Deleted all files associated with it:

%UserProfile%\Desktop\OpenCloud Security.lnk

%AppData%\OpenCloud Security

%AppData%\OpenCloud Security\OpenCloud Security.exe

%AppData%\OpenCloud Security\OpenCloud Security.ico

%AppData%\OpenCloud Security\sysl32.dll

%AppData%\OpenCloud Security\wf.conf

%StartMenu%\Programs\OpenCloud Security

%StartMenu%\Programs\OpenCloud Security\OpenCloud Security.lnk

Removed random files from C:\Windows\System32\

Renamed all executables I downloaded to iexplore.exe,iexplorer.exe, winlogon.exe,etc

Booted into Safe Mode, copied rkill,hijackthis,OTL,avg,etc,etc from another computer to this computer but no matter what I do or if I reboot in safe mode everytime I try and launch any exe I get the message "The file does not have a program associated with it for performing this action". So I cannot continue with any of the cleanup guides. Please help!

Link to post
Share on other sites

post-32477-1261866970.gif

Logs will be closed if you haven't replied within 3 days

Please do not attach the scan results. Use copy/paste.

DO NOT use any TOOLS such as Combofix, or HijackThis fixes without supervision.

Doing so could make your pc inoperatible and could require a full reinstall of your OS, losing all your programs and data.

Stay with this topic until I give you the final 'All clean' post.

Vista / Win7 users:

1. These tools MUST be run from the executable. (.exe)

2. With Admin Rights (Right click, choose "Run as Administrator") every time you run them

1) exeHelper

Please download exeHelper to your desktop.

Double-click on exeHelper.com to run the fix.

A black window should pop up, press any key to close once the fix is completed.

Post the contents of log.txt (Will be created in the directory where you ran exeHelper.com)

Note: If the window shows a message that says "Error deleting file", please re-run the program before posting a log - and post the two logs together (they will both be in the one file).

Link to post
Share on other sites

Due to the lack of feedback this topic is closed to prevent others from posting here. If you need this topic reopened, please send a Private Message to any one of the moderating team members. Please include a link to this thread with your request. This applies only to the originator of this thread.

Other members who need assistance please start your own topic in a new thread. Thanks!

Link to post
Share on other sites

Guest
This topic is now closed to further replies.
  • Recently Browsing   0 members

    • No registered users viewing this page.
Back to top
×
×
  • Create New...

Important Information

This site uses cookies - We have placed cookies on your device to help make this website better. You can adjust your cookie settings, otherwise we'll assume you're okay to continue.