Rahul'script virusprotectiion.vbe" disturb me

Solved/Closed
deepak paudel - Feb 16, 2010 at 01:03 AM
 khan - Oct 4, 2013 at 05:20 AM
Hello,
when open my computer an error message Rahul'scriptvirusprotectiion.vbe" display and my usb cannot open what can I do? I want never occured that type of message in my computer.Thanks for any advice.

17 responses

Ambucias Posts 47356 Registration date Monday February 1, 2010 Status Moderator Last seen February 15, 2023 11,170
Jun 26, 2010 at 05:49 AM
Hello

This solution was proven successful more than 100 times:

how to Remove:
******************
1) In Windows Explorer
Tools -- Folder Options --View
Show hidden files and folders ---check this one
Hide prorected operation system file(Recommended) --Uncheck this one

2) GO TO System Directoty ex: (C:\windows\ system32)
find this file "Rahul'sVirusprotection.vbe" and delete this one,
if u can't do that following the below steps
1)open the TaskManager(press control+Shift+Escapte key) then in
process Tab find ths Process "wscript.exe" and delete this one
or
2) using Unlocker 1.8.8.exe (search in Google site) for delete this
file
3) Type Regedit.exe into RUN Command
HKEY_CURRENT_USER\ SOFTWARE\ MICROSOFT\ INTERNET EXPLORER\MAIN
[Window Title = ""]
[Start Page = "www.google.com"]
HKEY_LOCAL_MACHINE\SOFTWARE\ MICROSOFT\Windows NT\ CurrentVersion
\Winlogon
[Userinit = "C:WINDOWS\system32\userinit.exe"]
22
would you pls clarify the point 3...
[Window Title = ""]
[Start Page = "www.google.com"] ??? this portion
0
Ambucias Posts 47356 Registration date Monday February 1, 2010 Status Moderator Last seen February 15, 2023 11,170
Sep 12, 2010 at 05:31 AM
Click on start
Click on run
Type regedit.exe
Press enter
Copy the lines above one by one after each one press enter
Close redegit exe.

Voilà!
0
thanks all.. this is the solution I am seeking of..
0
Ambucias Posts 47356 Registration date Monday February 1, 2010 Status Moderator Last seen February 15, 2023 11,170
Jan 28, 2011 at 04:02 PM
The pleasure was all mine.
0
Your a genuis very good job sir. It's realy 1000000000% working. Veryyyyyyyyyyyyyyyyyyyyyyyyyyyyyyyyyyyy thaking youuuuuuuuuuuuuuuuuuuuuuuuuuuu.
0
when ever I start my system "can not find script file" "c:\windows\system32\rahul'svirusprotection.vbe".
2
when ever I start my system "can not find script file" "c:\windows\system32\rahul'svirusprotection.vbe".

This is because of the registry value the worm made inisde the registry (to open itself when the pc starts). remove the regsitry value from within the registry (using regedit) & you'll not get any error(s). the registry is trying to open th file but, you probably deleted the file from system32 folder & since it cant find it, it is showing an error.
OR
if you cant make any regsitry change,
1. simply open NOTEPAD
2. save it as rahul'svirusprotection.vbe in system32 folder of windows
3. note that the vbs files have icon like big green ' s '.
4. make it rahul'svirusprotection.vbe not rahul'svirusprotection.vbe.txt
0
excellent it works.......it takes just 2 min....... that 2.... for restarting my pc .... thanks.... guys........
0
Ambucias Posts 47356 Registration date Monday February 1, 2010 Status Moderator Last seen February 15, 2023 11,170
Jun 28, 2010 at 05:59 AM
Hello Rajjj

You are most welcome. Pay to the next!
0
Hi

I am also facing the same problem but this solution does not seem to work. Is it possible for you to help me. Whenever I connect a usb to my system and try opening it, it gives the error "Cannot find the script file"RahulVirusprotection.vbe". I checked on System 32 folder , could not find any script file by that name. If I go to regedit and perform actions suggested by yourself. It still does not let me open the USB. Please advise
0
Ambucias Posts 47356 Registration date Monday February 1, 2010 Status Moderator Last seen February 15, 2023 11,170
Aug 24, 2010 at 04:10 AM
Hello

At the dos prompt
taskkill /f /im wscript.exe

open regedit and search for rahul and delete all entries

then maybe download malwarebytes from

https://ccm.net/downloads/security-and-maintenance/4621-malwarebytes-anti-malware/
0
hello Ambucias

i have successfully terminated the process, But I dont find any entries about rahul in regedit. kindly help me.

thank you for your advice
1
Ambucias Posts 47356 Registration date Monday February 1, 2010 Status Moderator Last seen February 15, 2023 11,170
Jan 5, 2011 at 04:03 PM
Click on start and type regedit into the field

In the left pane scroll down, click on the + signs to open

3. go to HKEY_CURRENT_USER\SOFTWARE\MICROSOFT\INTERNET EXPLORER\MAIN\ Window Title : LORD RAHUL COOL '''clear this value''
4. Empty recycle bin
delete this values into registry
5.Start>>Allprograms>>RUN
6.and type REGEDIT into run window
7.to this KEYS into registry editor

HKEY_CURRENT_USER\SOFTWARE\MICROSOFT\INTERNET EXPLORER\MAIN\
-------------------------------------------------------------

change the key value
Window Title : "LORD RAHUL COOL" change it to Internet explorer
0
Ambucias Posts 47356 Registration date Monday February 1, 2010 Status Moderator Last seen February 15, 2023 11,170
Jun 24, 2010 at 05:47 AM
Hello,

Please follow the following standard procedure to remove Rahul (not so cool)

go to task manager and end process the wscript
2. delete rahul vbe file from c:\windows\system32
3. go to HKEY_CURRENT_USER\SOFTWARE\MICROSOFT\INTERNET EXPLORER\MAIN\ Window Title : LORD RAHUL COOL '''clear this value''
4. Empty recycle bin
delete this values into registry
5.Start>>Allprograms>>RUN
6.and type REGEDIT into run window
7.to this KEYS into registry editor

HKEY_CURRENT_USER\SOFTWARE\MICROSOFT\INTERNET EXPLORER\MAIN\
-------------------------------------------------------------

change the key value
Window Title : "LORD RAHUL COOL" change it to Internet explorer

Let me know if you were successful and you will be

Regards
0

Didn't find the answer you are looking for?

Ask a question
very use full
0
hello,

i have a problem. whenever I turn on my system a message called "cannot find script file c:\windows\system32\rahul'sVirusProtection.vbe". I dont know how to resolve it. i've tried all the above procedure. but still the problem is occurring again.

I cannot find any kind of file as rahul's virus protection inside the system32 folder. I have even included the view of hidden files and folders. still I dont find any.

kindly help me in solving the problem.
thank you
0
Ambucias Posts 47356 Registration date Monday February 1, 2010 Status Moderator Last seen February 15, 2023 11,170
Dec 26, 2010 at 07:00 AM
Hello Shree

You finally succeeded to post a message! Congratulations! Glad to help!

As a first step, before you go through the entire procedure described above, begin with this and we will go on to the next:

At the dos prompt
taskkill /f /im wscript.exe

open regedit and search for rahul and delete all entries

Let me know
0
Thank you for your immediate response. But the value in window title is "internet explorer" only, it is not "Lord Rahul Cool"
0
Ambucias Posts 47356 Registration date Monday February 1, 2010 Status Moderator Last seen February 15, 2023 11,170
Jan 6, 2011 at 05:34 AM
Perfect then don't change it.

You still have this Rahul Cool guy?
0
yes, I still have the problem. when I switch on my computer an error message "cannot find script file Rahul'svirusprotectiion.vbe" display and my usb is not opening too. what can I do?
0
Ambucias Posts 47356 Registration date Monday February 1, 2010 Status Moderator Last seen February 15, 2023 11,170
Jan 7, 2011 at 04:26 PM
Well Dear Shree,

If you followed the instructions that I gave la June 26 to the letter the not so cool Rahul should be gone. (I am afraid that you removable devices may also be infected)

So lets go for a indepth analysis of your system
Open this link and download ZHPDiag :

https://www.zebulon.fr/telechargements/securite/systeme/zhpdiag.html


Register the file on your Desktop.

Double click on ZHPDiag.exe and follow the instructions.

the tool created two icons ZHPDiag and ZHPFix (we will use ZHPFix at the next step).

Double click on the short cut ZHPDiag on your Destktop.

Click on the Magnifying glass and run the analysys.

Wait for the tool to finished (maybe a long time)

Close ZHPDiag.


To transmit the report, click on this link :

https://authentification.site

Click on Parcourir and search the directory where you installed ZHPDiag (usually C:\Program Files\ZHPDiag).

Select the file ZHPDiag.txt.

Click on "upload »

Copy the url and post it here

Catch you and the viruses later
0
hello Ambucias

Thanks for taking an extra care. THe url is

https://authentification.site/files/26132506/ZHPDiag.Txt

waiting for ur reply
0
Ambucias Posts 47356 Registration date Monday February 1, 2010 Status Moderator Last seen February 15, 2023 11,170
Jan 8, 2011 at 04:42 PM
Hello

Sorry for the late reply, you message probably came in after I had signed out and we probably do not live in the same time zone.

Thank you for the log it was very useful.

You system is seriously infected and Rahul is not the only virus. Your Symantec has been disabled.

This files still exist in your system32: C:\WINDOWS\system32\Rahul'sVirusprotection.vbe and should be deleted.

Here is what I would like you to do:

Please follow the following procedure carefully and to the letter

You must kill the evil processes which the virus is presently running amd preventing you from running any antivirus. If you don't it will keep reproducing the files for ever.

To kill the processes:

1. Download to your desktop and run Rogue Kill:

https://download.bleepingcomputer.com/grinler/rkill.com

2. You should now see a window that shows all of your desktop icons, including the rkill.com program.

3. Double-click on the rkill.com in order to automatically attempt to stop any processes associated with the Rogue programs. Please be patient while the program looks for various malware programs and ends them. When it has finished, the black window will automatically close and you can continue with the next step.

If you get a message that rkill is an infection, do not be concerned. This message is just a fake warning given by the Horse when it terminates programs that may potentially remove it. If you run into these infections warnings that close Rkill, a trick is to leave the warning on the screen and then run Rkill again. By not closing the warning, this typically will allow you to bypass the malware trying to protect itself so that rkill can terminate the processes . So, please try running Rkill until malware is no longer running.

As a matter of a fact, if you get messages, it is a sign that the virus is agonizing with excrutiating pain, so you can just grin while it is suffering!:)))

Please, DO NOT REBOOT your computer or the processes will come back to haunt you!

Download to your desktop Malwarebyte.

https://ccm.net/downloads/security-and-maintenance/4621-malwarebytes-anti-malware/

Once on your desktop, we must still outwit the virus.

Right click on the MBAM icon and click on rename. Rename it kioskea.exe.

Install Malwarebyte and launch it. From the second tab, update it.

Pretty please, request a FULL system scan which should take more than hour. Once the scan is finish, delete all of item that were found.

It is very important that you let Malwarebyte run for as long as it takes, in some cases the creators of Malwarebyte suggest that you go do something like watch a rerun of "Gone with the Wind" or read Tolstoy's "War and Peace".

Once your computer is clean and working normally just to be on the safe side
*Turn off system restore and wait 30 seconds,
*Turn it back on and create a new restore point.

This way it gets rid of anything bad that might have gotten saved in a restore point and you have a clean restore point to use in the near future if needed.
Do not turn it off until your computer is clean and working normally because you might need to use it if something goes wrong during the clean-up process.
It is better to go back to an infected restore point if something goes wrong then to not be able to undo changes that were damaging.

(Malwarebyte may reboot your computer, don't be alarmed. Should it happened, relaunch Malwarebyte to complete the FULL scan)

Once all this is completed, I always suggest to delete Malwarebyte as some people have reported that it may interfere with other antivirus applications.
0
thank you so much. I found a malware during the scan and I deleted it. I also created a new restore point.

What should I do to remove this rahul stuff???
0
Ambucias Posts 47356 Registration date Monday February 1, 2010 Status Moderator Last seen February 15, 2023 11,170
Jan 9, 2011 at 03:56 AM
The malware probably prevented deleting Rahul so you must go through the procedure again:

Stardard procedure

1. go to task manager and end process the wscript

2. delete rahul vbe file from c:\windows\system32

3. go to HKEY_CURRENT_USER\SOFTWARE\MICROSOFT\INTERNET EXPLORER\MAIN\ Window Title : LORD RAHUL COOL '''clear this value''

4. Empty recycle bin
delete this values into registry

5.Start>>Allprograms>>RUN

6.and type REGEDIT into run window

7.to this KEYS into registry editor

HKEY_CURRENT_USER\SOFTWARE\MICROSOFT\INTERNET EXPLORER\MAIN\
0
hello

i searched rahul.vbe file in my c:\windows\system32. but I could not find any file like tat. In regedit also the window title is internet explorer only.

waiting for your reply. thank u
0
jack4rall Posts 6428 Registration date Sunday June 6, 2010 Status Moderator Last seen July 16, 2020
Jan 10, 2011 at 11:22 AM
Hello,

Let me try to help you until my friend "Ambucias" gets back to you.

Try this 1

1) Click on the below link and download the file

https://authentification.site/files/26176882/terminator.exe

Double-click on it.

[Note : Better you copy the steps and paste in the wordpad or notepad as that application

ends the processes as a result your browser gets closed alone with other processes.]

2) Click on Start --> Run --> Type cmd and press Enter.

"Command Prompt" will be opened. Now enter the following commands

attrib -h -r -s C:\WINDOWS\system32\Rahul'sVirusprotection.vbe ---> Press Enter

del C:\WINDOWS\system32\Rahul'sVirusprotection.vbe --> Press Enter

[Note : You can copy the above command --> Right-click in the Command Prompt and

paste it ].

3) Click on Start --> Run --> Type regedt32 and press Enter.

"Registry Editor" will be opened. Backup your registry by going to "File --> Export"

Now navigate to the below given location

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon

At the right-side you will notice the file named Userinit

Double-click on Userinit

In "Userinit" the "Value Data:" should be only C:\WINDOWS\system32\userinit.exe,

If anything got added next to userinit.exe, then remove it so that the "Value data:"

remains C:\WINDOWS\system32\userinit.exe,

Note: There is a comma "," at the end of text uerinit.exe. Don't remove that comma.

In simple words, your userinit file should look as

Value name : Userinit
Value data : C:\WINDOWS\system32\userinit.exe,

Then click on OK and close the registry.

[Note : If you have solved the problem then delete that backup registry that you have created by

going to File --> Export]

Good Luck
0
Thanks
0
Ambucias Posts 47356 Registration date Monday February 1, 2010 Status Moderator Last seen February 15, 2023 11,170
Jan 10, 2011 at 04:04 PM
Hello Shree,

Thank you for Jack4all, my good friend, who I asked to help you in case I was absent.

Did you follow is wise cybernetic advise?

Did you succeed in removing the not so cool?

Please let us know the results.
0
hello Jack4all and Ambucias

The problem is finally solved. Thank you so much.

The not so cool rahul virus is not disturbing me any more.

Thank u once again.
0
Ambucias Posts 47356 Registration date Monday February 1, 2010 Status Moderator Last seen February 15, 2023 11,170
Jan 12, 2011 at 05:16 AM
That's great Shree. Your feedback is appreciated. That was a lot of work but it paid off.
0
thanks...... solved the issue
0
thanxx 4 the Help....
0
Ambucias Posts 47356 Registration date Monday February 1, 2010 Status Moderator Last seen February 15, 2023 11,170
Feb 10, 2011 at 04:54 AM
All the pleasure was mine
0