Guest chris Posted September 5, 2013 Share Posted September 5, 2013 Hi, I have been infected by the above scam. I tried reboot in safe mode and then run malware bytes whiich remove 3 threats. When i restarted in normal mode the lockout was still there. Now I cant reboot in safe mode at all without that opening screen. I tried to bootup with zip drive and hitman pro on it but my keyboard wont allow me to make a selection of 1,2 or 3 on its menu? Can someone please help. Thanks Chris (foxhole8@bigpond.net.au) Link to comment Share on other sites More sharing options...
Arakasi 549 Posted September 5, 2013 Share Posted September 5, 2013 (edited) Good day Chris, If your running Eset, you should be able to restart the computer and let it sit on that lockout screen for 5-10 min. Most processes will still run despite the full screen app keeping you from visually seeing your desktop. Eset should clear the virus. Restart again after prolonged period. If not, here are some manual instructions. Boot to safemode again. Open Control panel, and Folder options. Select view tab, and check mark "Show hidden files and folders" navigate to C:\ProgramData and look for suspicious executables or jscript files and delete. navigate to %userprofile%\Appdata\Local do the same navigate to %userprofile%\Appdata\Roaming do the same navigate to %userprofile%\Appdata\Local\Temp do the same navigate to %userprofile%\Downloads , Documents, and any other TEMP directories you may find. navigate to C:\Windows\Temp look for unrecognized exe's Open Regedit - and navigate to this key : HKCU\Software\Microsoft\Windows\CurrentVersion\Run & RunOnce Remove any executables or batches trying to run at startup. This should give you more leverage. Let us know if you found any files that you deleted or look malicious or that you did not install. Edited September 5, 2013 by Arakasi Link to comment Share on other sites More sharing options...
Recommended Posts