- Disable your anti-virus program, How To Temporarily Disable Your Anti-virus, Firewall And Anti-malware Programs
- Please disconnect any USB or external drives from the computer before you run this scan!
- Right-Click RogueKiller and select Run as Administrator.
- Wait until Prescan finishes.
- On the RogueKiller console, click the Registry tab.
- Then press the Delete button.
- IF and only if prompted for a reboot, then allow it.
- The log will be found as RKreport
Copy & Paste the contents into next reply.
Download TFC by OldTimer
to your desktop
Step 3Disable your AntiVirus and AntiSpyware
- Please double-click TFC.exe to run it. (Note: If you are running on Vista or Windows 7, right-click on the file and choose Run As Administrator).
- It will close all programs when run, so make sure you have saved all your work before you begin.
- Click the Start button to begin the process. Depending on how often you clean temp files, execution time should be anywhere from a few seconds to a minute or two. Let it run uninterrupted to completion.
- IF prompted to Reboot, reply "Yes".
NOTE: We want to be in Windows Normal mode, from here on out, as much as possible.
applications, usually via a right click on the System Tray icon. They may otherwise interfere with our tools
For directions on how, see How To Temporarily Disable Your Anti-virus, Firewall And Anti-malware Programs
Do NOT turn off the firewall
Please download Rkill
by Grinler and save it to your desktop.
- Link 2
- Double-click on the Rkill desktop icon to run the tool.
- If using Vista or Windows 7, right-click on it and Run As Administrator.
- A black DOS box will briefly flash and then disappear. This is normal and indicates the tool ran successfully.
- If not, delete the file, then download and use the one provided in Link 2.
- If it does not work, repeat the process and attempt to use one of the remaining links until the tool runs.
- If the tool does not run from any of the links provided, please let me know.
- If your antivirus program gives a prompt message, respond positive to allow RKILL to run.
- If a malware-rogue gives a message regarding RKILL, proceed forward to running RKILL
IF you still have a problem running RKILL, you can download iExplore.exe
, which are renamed copies of rkill.com, and try them instead.Step 4
1. Go >> Here <<
and download ERUNT
(ERUNT (Emergency Recovery Utility NT) is a free program that allows you to keep a complete backup of your registry and restore it when needed.)
2. Install ERUNT by following the prompts
(use the default install settings but say no to the portion that asks you to add ERUNT to the start-up folder, if you like you can enable this option later)
3. Start ERUNT
(either by double clicking on the desktop icon or choosing to start the program at the end of the setup)
4. Choose a location for the backup
(the default location is C:\WINDOWS\ERDNT which is acceptable).
5. Make sure that at least the first two check boxes are ticked
6. Press OK
7. Press YES to create the folder.Step 5
To show all files:
Step 6You will want to print out or copy these instructions to Notepad for offline reference!These steps are for member BCord only. If you are a casual viewer, do NOT try this on your system!
- Go to your Desktop
- Double-Click the Computer icon.
- From the menu options, Select Tools, then Folder Options.
- Next click the View tab.
- Locate and uncheck Hide file extensions for known file types.
- Locate and uncheck Hide protected operating system files (Recommended).
- Locate and click Show hidden files and folders and drives.
- Click Apply > OK.
If you are not BCord and have a similar problem, do NOT post here; start your own topic
Do not run or start any other programs while these utilities and tools are in use!
Do NOT run any other tools on your own or do any fixes other than what is listed here.
If you have questions, please ask before you do something on your own.
But it is important that you get going on these following steps.
Close any of your open programs while you run these tools.
On most all of the following programs and tools, you will need to do a right-click on the program link or shortcut or desktop icon (as appropriate) and then select "Run as Administrator
". Please remember that as you go along and use these tools, each in turn.If you have a prior copy of Combofix, delete it now
Download Combofix from any of the links below, and SAVE it to your Desktop. Link 1Link 2
**Note: It is important that it is saved directly to your Desktop and not run straight away from download **
Turn OFF your antivirus, otherwise it will interfere. How To Temporarily Disable Your Anti-virus, Firewall And Anti-malware ProgramsHave infinite patience during the run & scan by Combofix. It has many phases: some 50+ stages
It will display it's "stage" within the Command prompt window. Do NOT panic if it seems slow to change ! It has lots of work.
You may notice the desktop icons disappear. Do NOT panic, as that is expected behavior.
Combofix my take as little as 10 minutes and perhaps as much as 30-40 minutes. Time taken will depend on speed of your system and how much there is to scan & how much it needs to clean.If this is on a notebook system, make sure first the notebook is connected to wall-power (AC power)or a UPS system Important: Have no other programs running. Your Task Bar should be clear of any program entries including your Browser.
Right- click on Combo-Fix.exe on your Desktop
and select "Run as Administrator".
A caution - Do not run Combofix more than once.
- A window may open with a warning or prompts. Accept the EULA and follow the prompts during the start phase of Combofix.
When the scan completes Notepad will open with with your results log open. Do a File, Exit and answer 'Yes' to save changes.
Do not touch your mouse/keyboard until the scan has completed, as this may cause the process to stall or your computer to lock.
The scan will temporarily disable your desktop, and if interrupted may leave your desktop disabled.
If this occurs, please reboot to restore the desktop.
A file will be created at => C:\Combofix.txt
Do not mouseclick combofix's window nor run any program while Combofix is running.
That may cause it to stall.
Reply with a copy of the C:\Combofix.txt log, AND tell me, How is your system now?
Any further "rogue" ransomware ?
Re-Enable your antivirus.