COMPUTER VIRUS PLEASE HELLPP?

ok so our sister weren’t doing something and abruptly a artificial virus thing called xp security heart 2011 jumped up along with blocked her internet.we looked at downloading something but we’re not able to because we can’t download stuff and also we attempted sending a antivirus out of my laptop or computer to your girlfriend computer by using a flash travel but they don’t let my family download them on the woman’s computer YOU SHOULD HELP US:(:(

I have got a fake antivirus popup upon my machine and it’s also not permitting me make use of programs as well as download antivirus methods (Win 7 Antivirus 2011, Earn 7 Complete Security 2011, EXPERIENCE Security 2011, all kinds of other variants these names)
—————————————

Start the slicer in Protected Mode (hit your F8 operate key as the machine shoes up, along with choose Harmless mode)

First download today’s feeting versions of the following.(If fat loss download, get it done on one more, clean appliance and burn off to DVD or copy to some USB memory space stick)

Malwarebytes:
http://www.malwarebytes.org/mbam.php
ComboFix
http://download.bleepingcomputer.com/sUBs/ComboFix.exe
FixNCR.reg
http://download.bleepingcomputer.com/reg/FixNCR.reg
RKill
http://www.bleepingcomputer.com/download/anti-virus/rkill – this internet page has many different different filenames that will download that will fool the herpes virus, which will try to prevent RKill via running.Remember your filename with the version an individual downloaded.
CCleaner (cleans available caches)
http://www.ccleaner.com
Avast! 5 Home:
http://www.avast.com/eng/download-avast-home.html

Download these towards your desktop and before running them, then modify the names with the malwarebyte and combofix documents toMalwarebytes:mblah.scr
ComboFix:comfix.exe

Follow most of these steps if you wish

Disappointment System Restore against your machine, but merely until you get this set – numerous trojans find copied into the System Bring back files, which anti-virus packages aren’t helped to touch as well as viruses could possibly reinstall themselves after that.My Laptop or computer > Homes > Method Restore.

The actual malware make an effort to blocks packages and resources, so prior to can start out cleaning, you should get this malware entries outside the registry, along with stop your malware’s existing processes via running.

Double-click FixNCR.reg to run it to scrub the registry
Now 2 bottle click this RKill record (whatever label you downloaded it as) to run it.Loose time waiting for it, it could actually take some time.If this fake antivirus course throws some sort of warning for the screen as well as blocks RKill, leave your warning on the monitor and operate RKill yet again.

Never reboot your pc If an individual reboot it’ll just weight the adware and in all over again.

Then function CCleaner (it’ll make scanning faster given it will delete a handful of temp information and conserve your from the need to scan these.) That the virus hinders CCleaner via running, go to the following step.

And then run Malwarebytes (mblah), along with clean almost everything it says.

And then run ComboFix (comfix), along with clean almost everything it says.If it claims to reboot a person’s machine through the process, can so quickly.

Then install and function Avast – tell Avast to undertake a boot-scan – mouse click on “schedule boot-scan” :and restart the computer

Allow it to needlessly start plus do this Avast start scan

And then turn Technique Restore back again on.

Now install the antivirus program of the choice to complete continuous checking, and you should keep it as much as date

Keep your House windows, web visitor and Java software updated – recurrent patches are released for you to plug reliability holes.

http://www.pcworld.com/article/149298/10_quick_fixes_for_the_worst_security_nightmares.html

download malewarebytes Yahoo and google that get it for you computer operate scan an entire scan when it wont permit you to go in order to safe setting and carry out soo….http://www.malwarebytes.org/

-trust us this clears any type of virus actually blue display of passing away witch can be a virus this shut an individual internet down and wont permit you to open applications.

Remove EXPERIENCE Security 2011 manually
Another approach to remove XP Security 2011 is to manually rub out XP Security 2011 files in the system.Detect plus remove this particular XP Reliability 2011 documents:
Processes
%Temp%\pw.exe
%UserProfile%\AppData\Local\pw.exe
%UserProfile%\AppData\Local\MSASCui.ex
%UserProfile%\Local Settings\Application Data\pw.exe
%UserProfile%\Local Settings\Application Data\MSASCui.exe
%AppData%\ave.exe
%Documents along with Settings%\UserName\Local Settings\Application Data\RANDOM CHARACTERS.exe
D:\Documents along with Settings\USERNAME\Local Settings\Application Data\ave.exe
Different Files
%UserProfile%\Start Menu\Programs\XP Safety measures 2011
%UserProfile%\AppData\Local\opRSK
%UserProfile%\Local Settings\Application Data\opRSK
%Temp%\RANDOM CHARACTERS
%Documents along with Settings%\UserName\Templates\RANDOM CHARACTERS
%Documents along with Settings%\AllUsers\RANDOM CHARACTERS
%Documents along with Settings%\AllUsers\Application Data\RANDOM CHARACTERS
D:\WINDOWS\Prefetch\AVE.EXE-3098ECAE.p
D:\Documents along with Settings\USERNAME\Templates\y7V11
D:\Documents along with Settings\USERNAME\Local Settings\Application Data\y7V11
D:\Documents along with Settings\USERNAME\Local Settings\Temp\y7V11
D:\Documents along with Settings\All Users\Application Data\y7V11
Registry Keys
HKEY_CURRENT_USER\Software\Microsoft\W “XP Safety measures 2011”
HKEY_CLASSES_ROOT\pezfile
HKEY_CURRENT_USER\Software\Classes\pez
HKEY_CURRENT_USER\Software\Classes\.ex-mate “(Default)” = “%UserProfile%\Local Settings\Application Data\pw.exe” /START “%1” %*
HKEY_CLASSES_ROOT\.exe\shell\open\comm “(Default)” = “%UserProfile%\Local Settings\Application Data\pw.exe” /START “%1” %*
HKEY_CLASSES_ROOT\pezfile\shell\open\c “(Default)” = “%UserProfile%\Local Settings\Application Data\pw.exe” /START “%1” %*
HKEY_CURRENT_USER\Software\Classes\pez “(Default)” = “%UserProfile%\Local Settings\Application Data\pw.exe” /START “%1” %*
HKEY_LOCAL_MACHINE\SOFTWARE\Clients\St “(Default)” = “%UserProfile%\Local Settings\Application Data\pw.exe” /START “C:\Program Files\Internet Explorer\iexplore.exe”
HKEY_LOCAL_MACHINE\SOFTWARE\Clients\St “(Default)” = “%UserProfile%\Local Settings\Application Data\pw.exe” /START “C:\Program Files\Mozilla Firefox\firefox.exe”
HKEY_LOCAL_MACHINE\SOFTWARE\Clients\St “(Defa

Leave a Reply