
This freakin’ virus/ worm/ whatever bugged my laptop for days. It shuts down my laptop just after I have booted it but only when I am connected to our local area netwrok (LAN). When its not connected to the network, the laptop boots properly. The sad thing is that our Corporate Anti-Virus Software wasn’t able to detect this thing. I also don’t know it this thing is related to the trojan which is also not detected by our AV but is scanned and detected by the freeware AVG Anti-Spyware.
I’ve searched the net and find this one very helpful. I have applied the same principles since the password viewer.exe and bar311.exe seem to have the same effect on the system.
Since the hidden files and folders are restricted from view because the password viewer.exe file is somehow preventing it, I just opened the task manager, right-clicked password viewer.exe, and ended the process tree, and clicked YES on the pop up window.
On C:/Windows folder, I have enabled the viewing of hidden files through Tools > Folder options; View tab; Show hidden files and folders. Make sure that the “Hide operating system files(Recommended)” setting is also unchecked.
Locate the files named “pc-off.bat” (a batch file which causes the system to reboot) and “password_viewer.exe” and delete these files from the C:/Windows folder.
If you run cmd prompt/ command, you may still encounter the “pc-off.bat” being called by the program because it is still in the registry. This will do no more harm, i guess but if you want, you can change the registry by running regedit which is what I did. Go to HKEY_CURRENT_USER > Software > Microsoft > Command Processor and delete “C:/Windows/pc-off.bat” in the autorun configuration.
There is also this gamot.exe but we had difficulty downloading and running it in my laptop. It is even scanned and detected by AVG as a virus.
Glad I had stumbled on the site noted above. Hope this works the same for you.














Discussions