Forums65
Topics76,457
Posts1,033,917
Members14,831
|
Most Online44,182 Mar 18th, 2025
|
|
8 members (4 invisible),
5,319
guests, and
487
robots. |
Key:
Admin,
Global Mod,
Mod
|
|
M |
T |
W |
T |
F |
S |
S |
|
1
|
2
|
3
|
4
|
5
|
6
|
7
|
8
|
9
|
10
|
11
|
12
|
13
|
14
|
15
|
16
|
17
|
18
|
19
|
20
|
21
|
22
|
23
|
24
|
25
|
26
|
27
|
28
|
29
|
30
|
|
|
|
|
|
|
Joined: Oct 2008
Posts: 5,214
Forum Veteran
|
OP
Forum Veteran
Joined: Oct 2008
Posts: 5,214 |
This is on my granddaughter's laptop and I've been given the task of removing it or format the hard drive. Has anyone else had it and removed it ok. I'd be glad if you could post instructions or a link they used. Don't like the idea of googling for it in case it is a bogus site set up by them derek
|
|
|
|
Joined: Feb 2011
Posts: 1,385
Forum Addict
|
Forum Addict
Joined: Feb 2011
Posts: 1,385 |
Derek Can you boot your computer in Safe Mode with Command Prompt, and type msconfig in the Command prompt. This should start the Windows System Configuration tool. Go to the Start-up tab, and search for any suspicious or unknonw entries (random numbers or letter, ctfmon.exe and other suspicious entries) and uncheck them from start-up. Next boot your computer in regular mode and perform a scan with HitmanPro and Malwarebytes this is how I got rid of it on my ex laptop 
|
|
|
|
Joined: Nov 2003
Posts: 21,269 Likes: 4
Wiki Master
|
Wiki Master
Joined: Nov 2003
Posts: 21,269 Likes: 4 |
If your granddaughter's laptop is full of rubbish just do a factory reset which would remove any viruses as it also re formats the drive doing this.
How do you know its that virus? If you have anti virus software they can give you a link to removal instructions.
Ive just done a google and came up with this
[youtube]ig9RUYkEagU[/youtube]
Its a nasty one Derek my advice would be to reset or format it down.
|
|
|
|
Joined: Jan 2013
Posts: 48
Newbeee
|
Newbeee
Joined: Jan 2013
Posts: 48 |
DON'T FORMAT. Jeesus!
This particular virus is quite nasty to those without the knowledge.
Simply use another computer to go to Surfright.nl and download HitmanPro (Choose the correct bitrate for your Operating System) then once loaded, click the little man at the bottom of the program. It'll mention a Kickstart.
Kickstarter is a feature of HitmanPro that can kick every other unknown process out (Including the Met Police ransomware) and allow the user to perform a scan.
Once you've clicked the man, you'll be prompted to insert a USB stick. Do so. Once your stick shows up, click on it and then click next. This will 'burn' the program onto the stick. Only takes a few seconds.
Once that's done, leave the stick in and turn off the computer. Turn it back on again then boot via the USB stick (Most computers have an F12 boot key - if not, press F2 or Delete to enter the BIOS and change the boot priority order so that the USB drive is at the top)
Once that's done, you'll be presented with a black screen with white text on. Mentioning about Hitman Pro and Kickstarter. It'll ask you for two options. Press the 1 on the keyboard and the computer will appear to start normally. Let it run through it's entire process until HitmanPro forces itself to run.
Once HitmanPro is on, follow the onscreen instructions to proceed to scanning. Scans usually take about 15 minutes on an average computer.
Once the scan is complete, marvel at the fact that HMP has found the virus and then click next.
Then Activate your free 30 day license, click next and wait for all the entries to be removed.
After that's done, it'll ask you to restart the computer. Do it.
Enjoy your computer once more and more importantly, enjoy your data as it's still there.
|
|
|
|
Joined: Aug 2012
Posts: 2
|
Joined: Aug 2012
Posts: 2 |
Woah, Allot of detailed answers!
I found it removed simply with AVG anti-virus & running an up to date program called Spybot search & destroy.
(Unless the virus hid somewhere! but I never had any problem after running those two)
|
|
|
Click to View Topic.
|
|
Posts: 1,318
Joined: May 2011
|
|
There are no members with birthdays on this day. |
|
|
|