How to remove " ******* 0wnz y0u " virus / fake CS Cheat
What the virus / fake CS Cheat file do (once you execute/click the file):
1. Install itself as Microsoft Shell Extension Service, and will autostart every time you start Windows.
2. Copy itself to C:\Windows\System32\shellext32.exe . This file is an exact copy of the virus executable, and will be used to run fake Microsoft Shell Extension Service.
3. Force screen resolution changes to 648x480
4. Force mouse buttons reversed. Left click will become right click and vice versa.
5. Force mouse pointer moves at a very slow speed.
6. Changes the Windows Desktop layout, such as moving the Start button to right hand side, changes all title of windows/buttons to " ******* 0wnz y0u " Please refer to screenshot Fig. 1.
7. Windows will no longer able to execute any files ended with *.exe , since virus takes over that extension. Therefore infected Windows cannot open almost any programs. Even changing Desktop resolution is impossible. Attempting to do so will only give you a ShellExt32.exe error.
http://members.lycos.co.uk/dns2php/messedup-hack.jpg
Fig. 1 Resulting Desktop after executing the virus.
How to remove virus:
http://members.lycos.co.uk/dns2php/fix-hack-01.jpg
Download fixswen.inf , and then right click on it, choose "Install".
http://members.lycos.co.uk/dns2php/fix-hack-02.jpg
#
Search for "shellext32" , and delete anything you see. Make sure you empty the Recycle Bin as well.
# Reboot your PC.
# Reset your original resolution.
# Remove the fake Microsoft Shell Extension Service:
Browse to C:\Windows, and double click on regedit.exe
Press F3 key on your keyboard, and put shellext32.exe in the "Find what" field, then hit "Find Next".
When there is a match, delete the whole MS ShellExt Services by right click on the "MS ShellExt Services" folder, and choose "Delete".
http://members.lycos.co.uk/dns2php/fix-hack-03.jpg
5.
Press F3 again to search for other matches. Remove all the matches same way you did as in the last step.
Now the virus is disabled. Unfortunately I cannot verify if above step will remove all the harm done by this virus. If you can, please back up your data, format your PC and re-install everything. This is the most troublesome step, but it will get rid of the virus for sure.