How to remove the virus-extortionist Recently, one of the most common types of viruses have become so-called virus-extortionists.If your computer to "catch" a virus that appears on the screen banner demanding to send an SMS to a short number or to put money on a specific phone number through the terminal.It will be useful to know, how to remove the virus-extortionist .

To begin remember: send an SMS and replenish a foreign telephone number in any case can not be !No unlock code you will probably not send, and lose money.Sometimes banner extortionist could masquerade as a message from the police and threatened with criminal charges for possession and distribution of child pornography, if you do not pay the fine.Do not believe it is the same virus-extortionist, the Interior Ministry does not use such methods.

Previously remove banner extortionist could be relatively simple: it was enough to complete the process of the virus by using the Task Manager.Now viruses are more "advanced", they know how to block access to the registry, call the Ta

sk Manager, edit startup and boot into safe mode. They are written in the startup and "encouraging" you every time you turn on the computer and reboot .How to remove the virus-extortionist?

To get started, try to do "a little blood."If you have a working computer or gadget with Internet access, you can try using the free service unlock the computer by Dr.Web or Kaspersky Lab! - Noindex - & gt ;.You need to enter in a special field mobile number or purse, which requires a resource transfer money.The system will inform you of possible unlock codes, one of them can go.Then scan your computer Antivirus.

If this method did not remove the virus-extortionist, you can try to boot from the LiveCD.You can, for example, download Kapsersky Rescue Disk or Dr.Web LiveCD .After downloading the disk image from the official site, it must be burned to a CD or USB flash drive.In the BIOS set to boot from the disk or USB-drive and boot from the appropriate drive.Once downloaded, run the computer scan for viruses: the system will find the virus-extortionist and remove it.

Alternative LiveCD antivirus developers - LiveCD ERD Commander .When booting from LiveCD, you will be prompted to select the system folder of the operating system, do so.ERD Commander interface resembles the familiar desktop interface Windows.To remove the virus-extortionist, you can use several features of this package:

  1. Rolling back the system to the date when you have not had time to "catch" the virus .Click Start, then System Tools → System Restore.In the Restore Wizard, select the first item, click Next.In the calendar select the date up to which you want to roll back (to choose should be written out in bold date - it means that for that date created restore point).After the end of the recovery, restart the computer and boot normally.

  2. Editing the registry .Sometimes, the virus destroys the recovery point, in which case you may need manual editing of the registry.Click Start → Administrative Tools → Registry Editor.Then locate the branch HKEY_LOCAL_MACHINE \ Software \ Microsoft \ WindowsNT \ CurrentVersion \ Winlogon.Check parameter Shell: it should look like Explorer.exe;if it contains superfluous information, change the value to C: \ Windows \ Explorer.exe.Also check point value Userinit: if there is something extra, and change the value to C: \ Windows \ System32 \ userinit.exe.Restarting the computer, boot into normal mode.

After editing the registry desirable further scan your computer Dr.Web CureIt or any other free utility.By the way, in the same way you can edit the registry by using Kaspersky LiveCD or Dr.Web.

If the virus does not block safe mode, you can do without the LiveCD: simply boot into safe mode and complete the process of the virus in the Task Manager.The virus must be removed from startup and finally scan your computer anti-virus utility.

As you can see, there are several ways to get rid of the virus extortion , we hope at least one of them will help you.

How to remove the virus-extortionist
Comment