How to remove Bar311.exe Shuts down a PC Virus

I was plagued by this virus once in our Computer Laboratory and searching google was my first option... i searched google but solutions are vague or incomplete but I finally managed to find the correct solution.

so, I would like to share it to you hoping that this will aid you in vanquishing bar311.. :)

Symptoms when infected by Bar311.exe or Winzip123

The virus comprises bar311.exe, password_viewer.exe, photos.zip.exe and pc-off.bat.

When you boot your Windows XP in Safe Mode the message appears: Thank You!!! Password:Winzip123

The pc-off.bat contains the syntax like this"C:/path/shutdown -s -f -t 2 -c" which automatically shutdown your computer when you run the cmd.exe.

Manual Removal of Bar311.exe

1. Go to Task Manager by pressing CTRL+ALT+DEL then kill (end process) password_viewer.exe or bar311.exe or photos.zip.exe...

2. EDIT the following registry entries thru Regedit

How to access Regedit?

  1. Go to Start Menu > Run
  2. Type Regedit and Press Enter key

Just follow the directory and click the folder...
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon] 

"Userinit"="userinit.exe,bar311.exe" -> remove ", bar311.exe" only...

>leave userinit.exe because this is used by Windows when you log-in...

[HKEY_CURRENT_USER\Software\Microsoft\Windows\ CurrentVersion\Explorer\Advanced]
"Hidden"=dword:00000001 
"HideFileExt"=dword:00000000 
"ShowSuperHidden"=dword:00000001

HKEY_CURRENT_USER\Software\Microsoft\Command Processor] "autorun"="c:\Windows\pc-off.bat" -> remove "c:\Windows\pc-off.bat" or delete the autorun key.

3. go to your thumb drive, please use the folders view in the explorer and use the navigation panel on the left side when accessing the drives to avoid triggering the autorun... then delete autorun.inf and password_viewer.exe or bar311.exe

4. open notepad then type what is shown below as is...

@echo off 

del /a /f c:\Windows\bar311.exe

del /a /f c:\Windows\password_viewer.exe

del /a /f c:\Windows\photos.zip.exe

del /a /f c:\Windows\pc-off.bat

pause



then save this as remove.bat then double click to run

Hope this helps!!!!

More by this Author


Comments 11 comments

sTALLION 7 years ago

WHAT IS A THUMB DRIVE?


isyan 7 years ago

a thumbdrive is also called USB or flashdisk.


tomsorrow 7 years ago

bro, please elaborate these:

open notepad then type what is shown below as is...

@echo off

del /a /f c:\Windows\bar311.exe

del /a /f c:\Windows\password_viewer.exe

del /a /f c:\Windows\photos.zip.exe

del /a /f c:\Windows\pc-off.bat

pause

then save this as remove.bat then double click to run

Hope this helps!!!!


isyan profile image

isyan 7 years ago Author

the command @echo off will Only display the command output on screen

the command del will delete the mentioned file

then the command pause will pause the command screen until you press any key..

the commands above will delete the virus that is residing on your hard disk...


Anu 7 years ago

This works!!Thanks!


alex 7 years ago

thanks man.. your post helped me alot...


isyan profile image

isyan 7 years ago Author

your welcome.. :)


Kennth 7 years ago

You save my pc's life THANK YOU!!!!!!!!!


Natzz 7 years ago

when i restart my computer,it appears again..my avast anti-virus detects..anyone here can help this problem?thanx..


dynomight 6 years ago

THANK YOU! IT TRULY WORKED! i can now make my projects :D


jen 6 years ago

thank you.. :)

    Sign in or sign up and post using a HubPages Network account.

    0 of 8192 characters used
    Post Comment

    No HTML is allowed in comments, but URLs will be hyperlinked. Comments are not for promoting your articles or other sites.


    Click to Rate This Article
    working