Search
Search titles only
By:
Search titles only
By:
Log in
Register
Search
Search titles only
By:
Search titles only
By:
Menu
Install the app
Install
Forums
New posts
All threads
Latest threads
New posts
Trending threads
Trending
Search forums
What's new
New posts
New ads
New profile posts
Latest activity
Free Ads
Latest reviews
Search ads
Members
Current visitors
New profile posts
Search profile posts
Contact us
Latest ads
Ad icon
Sell your Land, House on idamata.lk for FREE
sajith.xp.pk
Updated:
Today at 9:03 AM
Handmade Character Soft Toys
anil1961
Updated:
Tuesday at 2:11 PM
Bodim.lk out now !
Manoj Suranga Bandara
Updated:
Sunday at 3:05 AM
Power Lifting Lever Belt
SkullVamp
Updated:
Jun 13, 2026
Ad icon
port.lk Domain for sale
Lankan-Tech
Updated:
Jun 13, 2026
Electronics
Vehicles
Property
Search
Reply to thread
Forums
General
ElaKiri Talk!
Beware This Trojan Virus!!
Get the App
JavaScript is disabled. For a better experience, please enable JavaScript in your browser before proceeding.
You are using an out of date browser. It may not display this or other websites correctly.
You should upgrade or use an
alternative browser
.
Message
<blockquote data-quote="sanjeewawga" data-source="post: 9971838" data-attributes="member: 150949"><p><span style="font-size: 12px">Last night I found serious problem with my computer.</span></p><p><span style="font-size: 12px">it's very harmful Trojan virus. I don't know even someone suffer with this, but finally I found the solution..</span></p><p><span style="font-size: 12px">please read carefully and collect the information..</span></p><p><span style="font-size: 12px"></span></p><p><span style="font-size: 12px">First you boot the com you cannot see anything.. just only Blank screen and you can see little dialog box write as " win32 guided tour application". You should click it and it open like this dialog box</span></p><p><span style="font-size: 12px">[ATTACH]28123[/ATTACH]</span></p><p><span style="font-size: 12px"></span></p><p><span style="font-size: 12px">when it appear and before you can't use even task manager. <img src="/styles/default/xenforo/smilies/default/sad.gif" class="smilie" loading="lazy" alt=":(" title="Sad :(" data-shortname=":(" /><img src="/styles/default/xenforo/smilies/default/sad.gif" class="smilie" loading="lazy" alt=":(" title="Sad :(" data-shortname=":(" /><img src="/styles/default/xenforo/smilies/default/sad.gif" class="smilie" loading="lazy" alt=":(" title="Sad :(" data-shortname=":(" /></span></p><p><span style="font-size: 12px">it says like this things</span></p><p><span style="font-size: 12px"></span></p><p><span style="font-size: 12px">"1. call one of the following numbers</span></p><p><span style="font-size: 12px">for landline phones</span></p><p><span style="font-size: 12px">00263778289408</span></p><p><span style="font-size: 12px">002392216542</span></p><p><span style="font-size: 12px">00261221000183</span></p><p><span style="font-size: 12px">0037190100546</span></p><p><span style="font-size: 12px">0025270701161</span></p><p><span style="font-size: 12px">0088213090413</span></p><p><span style="font-size: 12px"></span></p><p><span style="font-size: 12px">2. wait for the answer and write down your identification key</span></p><p><span style="font-size: 12px">3.enter the identification key received by phone, click next to continue"</span></p><p><span style="font-size: 12px"></span></p><p><span style="font-size: 12px">Don't do anything </span></p><p><span style="font-size: 12px">if you need to boot your machine use this number 27496</span></p><p><span style="font-size: 12px"></span></p><p><span style="font-size: 12px">but this Fu*king virus still alive on our Machine <img src="/styles/default/xenforo/smilies/default/growl.gif" class="smilie" loading="lazy" alt=":growl:" title="Growl :growl:" data-shortname=":growl:" /><img src="/styles/default/xenforo/smilies/default/growl.gif" class="smilie" loading="lazy" alt=":growl:" title="Growl :growl:" data-shortname=":growl:" /><img src="/styles/default/xenforo/smilies/default/growl.gif" class="smilie" loading="lazy" alt=":growl:" title="Growl :growl:" data-shortname=":growl:" /></span></p><p><span style="font-size: 12px"></span></p><p><span style="font-size: 12px">Heres the steps what we should to do after got this matter</span></p><p><span style="font-size: 12px"></span></p><p><span style="font-size: 12px">Trojan.Ransomware removal instructions:</span></p><p><span style="font-size: 12px"></span></p><p><span style="font-size: 12px">1. Reboot your computer is "Safe Mode with Command Prompt". As the computer is booting tap the "F8 key" continuously which should bring up the "Windows Advanced Options Menu" as shown below. Use your arrow keys to move to "Safe Mode with Command Prompt" and press Enter key. Login as the same user you were previously logged in with in the normal Windows mode. </span></p><p><span style="font-size: 12px"></span></p><p><span style="font-size: 12px">2. When Windows loads, the Windows command prompt will show up as show in the image below. At the command prompt, type "explorer", and press Enter. Windows Explorer opens. </span></p><p><span style="font-size: 12px"></span></p><p><span style="font-size: 12px">3. Then open the Registry editor using the same Windows command prompt. Type "regedit"and press Enter. The Registry Editor opens.</span></p><p><span style="font-size: 12px"></span></p><p><span style="font-size: 12px">4. Locate the following registry entries:</span></p><p><span style="font-size: 12px"></span></p><p><span style="font-size: 12px">"HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon"</span></p><p><span style="font-size: 12px"></span></p><p><span style="font-size: 12px">In the righthand pane select the registry key named Shell. Right click on this registry key and choose "Modify"</span></p><p><span style="font-size: 12px">Default value is Explorer.exe. </span></p><p><span style="font-size: 12px">Modified value data points to Trojan.Ransomware executable file</span></p><p><span style="font-size: 12px"></span></p><p><span style="font-size: 12px">If Trojan.Ransomware modified the Shell value data, please copy the location of the executable file it points to into Notepad and then change value data to Explorer.exe. Click OK to save your changes and exit the Registry editor.</span></p><p><span style="font-size: 12px"></span></p><p><span style="font-size: 12px">If the default value data (Explorer.exe) wasn't modified, please locate the second registry entry:</span></p><p><span style="font-size: 12px"></span></p><p><span style="font-size: 12px">HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run</span></p><p><span style="font-size: 12px"></span></p><p><span style="font-size: 12px">In the righthand pane select the randomly named registry key. In our case it was 22997148. </span></p><p><span style="font-size: 12px">Copy the location of the executable file into Notepad and then delete the registry key. Right click on the registry key and choose Delete. Click Yes to confirm and exit the Registry editor.</span></p><p><span style="font-size: 12px"></span></p><p><span style="font-size: 12px">5. Delete Trojan.Ransomware files. Use the file location you saved into Notepad or otherwise noted in step 4. In our case, Trojan.Ransomware resided in %UserProfile% directory. There was a randomly named folder 22997148. </span></p><p><span style="font-size: 12px"></span></p><p><span style="font-size: 12px">Full path: C:\Documents and Settings\Michael\22997148\22997148.EXE</span></p><p><span style="font-size: 12px"></span></p><p><span style="font-size: 12px">NOTE: %UserProfile% refers to:</span></p><p><span style="font-size: 12px">C:\Documents and Settings\[UserName] (for Windows 2000/XP)</span></p><p><span style="font-size: 12px">C:\Users\[UserName]\ (for Windows Vista & Windows 7)</span></p><p><span style="font-size: 12px"></span></p><p><span style="font-size: 12px">6. Go back into "Normal Mode". Download free anti-malware software from the list below and run a full system scan.</span></p><p><span style="font-size: 12px"></span></p><p><span style="color: DarkRed"><a href="http://www.malwarebytes.org/" target="_blank">Here it</a></span></p><p></p><p><span style="font-size: 12px">Thats it... If not we have no any solution to do.. Just use the above number and open the system, get data what you need and format your machine..<img src="/styles/default/xenforo/smilies/default/sad.gif" class="smilie" loading="lazy" alt=":(" title="Sad :(" data-shortname=":(" /><img src="/styles/default/xenforo/smilies/default/sad.gif" class="smilie" loading="lazy" alt=":(" title="Sad :(" data-shortname=":(" /></span></p><p><span style="font-size: 12px"></span></p><p><span style="font-size: 12px">Thanks for read this.. (This post not 4 Rep, Just only solve your problems)</span></p><p><span style="font-size: 12px"></span></p><p></p><p>If not really understand</p><p></p><p><a href="http://deletemalware.blogspot.com/2011/03/remove-trojanransomware-uninstall-guide.html" target="_blank">source</a></p></blockquote><p></p>
[QUOTE="sanjeewawga, post: 9971838, member: 150949"] [SIZE="3"]Last night I found serious problem with my computer. it's very harmful Trojan virus. I don't know even someone suffer with this, but finally I found the solution.. please read carefully and collect the information.. First you boot the com you cannot see anything.. just only Blank screen and you can see little dialog box write as " win32 guided tour application". You should click it and it open like this dialog box [ATTACH]28123._xfImport[/ATTACH] when it appear and before you can't use even task manager. :(:(:( it says like this things "1. call one of the following numbers for landline phones 00263778289408 002392216542 00261221000183 0037190100546 0025270701161 0088213090413 2. wait for the answer and write down your identification key 3.enter the identification key received by phone, click next to continue" Don't do anything if you need to boot your machine use this number 27496 but this Fu*king virus still alive on our Machine :growl::growl::growl: Heres the steps what we should to do after got this matter Trojan.Ransomware removal instructions: 1. Reboot your computer is "Safe Mode with Command Prompt". As the computer is booting tap the "F8 key" continuously which should bring up the "Windows Advanced Options Menu" as shown below. Use your arrow keys to move to "Safe Mode with Command Prompt" and press Enter key. Login as the same user you were previously logged in with in the normal Windows mode. 2. When Windows loads, the Windows command prompt will show up as show in the image below. At the command prompt, type "explorer", and press Enter. Windows Explorer opens. 3. Then open the Registry editor using the same Windows command prompt. Type "regedit"and press Enter. The Registry Editor opens. 4. Locate the following registry entries: "HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon" In the righthand pane select the registry key named Shell. Right click on this registry key and choose "Modify" Default value is Explorer.exe. Modified value data points to Trojan.Ransomware executable file If Trojan.Ransomware modified the Shell value data, please copy the location of the executable file it points to into Notepad and then change value data to Explorer.exe. Click OK to save your changes and exit the Registry editor. If the default value data (Explorer.exe) wasn't modified, please locate the second registry entry: HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run In the righthand pane select the randomly named registry key. In our case it was 22997148. Copy the location of the executable file into Notepad and then delete the registry key. Right click on the registry key and choose Delete. Click Yes to confirm and exit the Registry editor. 5. Delete Trojan.Ransomware files. Use the file location you saved into Notepad or otherwise noted in step 4. In our case, Trojan.Ransomware resided in %UserProfile% directory. There was a randomly named folder 22997148. Full path: C:\Documents and Settings\Michael\22997148\22997148.EXE NOTE: %UserProfile% refers to: C:\Documents and Settings\[UserName] (for Windows 2000/XP) C:\Users\[UserName]\ (for Windows Vista & Windows 7) 6. Go back into "Normal Mode". Download free anti-malware software from the list below and run a full system scan. [/SIZE] [COLOR="DarkRed"][URL="http://www.malwarebytes.org/"]Here it[/URL][/COLOR] [SIZE="3"]Thats it... If not we have no any solution to do.. Just use the above number and open the system, get data what you need and format your machine..:(:( Thanks for read this.. (This post not 4 Rep, Just only solve your problems) [/SIZE] If not really understand [URL="http://deletemalware.blogspot.com/2011/03/remove-trojanransomware-uninstall-guide.html"]source[/URL] [/QUOTE]
Insert quotes…
Verification
Nawa warak dahaya keeyada? (Namaya wadi kireema dahaya)
Post reply
Top
Bottom