__________________________________________________________________________________
Easy way to defeat:
If on XP:
![](https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEjLVed66wIC2wDvzxBVs7FzLRSlEdJ9Hh6Qa6MuzT5LVE1PjOPCBEKx7m__BLM6BM0pD04rKS9I4Um76ZJ0iysuzlfeTVFkwIi5d7uiHpSYA9BkMIkw4AUlEfWa1oy9ZJ6VlAcHr5xBExY/s320/f8bootoptions_xp.png)
From the list, choose "Directory Services Restore Mode"
You should now be in a Windows Safe Mode with Networking capabilities. __________________________________________________________________________________
Download and install Malwarebytes from here.
Run a Quick Scan.
Ransom message should no longer appear.
Additional information:
This ransom does not extract additional files. It simply runs from itself hijacking this key:
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run
Creates a bad value here like "vasja" which paths to the one bad ransom file.
__________________________________________________________________________________
No comments:
Post a Comment