"How to delete banners which require SMS"

"How to delete banners which require SMS"

Very often careless users catch malicious software, in other words, the viruses which are getting out then at them on desktops banners with a request to send SMS to certain number. Even if you will send SMS - there is no guarantee that as a result the picture will disappear from a desktop. Therefore do not do it at all!

It is required to you

  • The computer, connection to the Internet, antvirus (paid or free), the manager of processes (like Anvir Task Meneger).

Instruction

1. The easiest way:
Try to make rollback of a system: "Start-up" – "Programs" – "Standard" – "Office" – "System recovery" — "Recovery of earlier status of the computer".
Select date before that when there was a banner, but keep in mind that in this case all those programs can disappear that you installed after date of a recovery point. Unfortunately such way can not help if there is no earlier version of a recovery point. Then you come to the following option:

The key press of CTRL+ALT+DELETE open the Task manager and try to find the process bringing a banner to your desktop. If you are familiar with the majority of processes of Windows, then you will easily find suspicious. Usually it masks under the necessary processes of a system, but it can be distinguished on excess or similar characters in the name, for example, svnost.exe instead of svhost.exe or to distinguish in the place from where process is started, for example, the process of svhost.exe which is executed in the My Drawings folder is obviously harmful.

It is possible to look at information on processes here: http://wiki.compowiki.info/ProcessyWindows
If at you it turned out find and "kill" harmful process, then the banner will disappear, but again will appear at the following loading of a system. That it did not happen, delete the file of harmful process from a disk and record about its start in automatic loading, and start an antivirus better and carefully scan a system. Delete files of a virus.

2. Due to the huge flow of similar viruses, the anti-virus companies provide services of search of codes from banners. Look for the code necessary to you according to these links:
http://support.kaspersky.ru/viruses/deblockehttp://virusinfo.info/deblocker/http://esetnod32.ru/support/winlock.phphttp://www.drweb.com/unlocker/indexhttp://news.drweb.com/show/?i=304&c=5http://netler.ru/pc/trojan-winlock.htmAnd some provide even free utilities for removal of banners: http://support.kaspersky.ru/faq/?qid=208636281

Especially cunning viruses rewrite the hosts file in a system to demonstration of a banner so at the same time that you cannot use searchers and the websites of the anti-virus companies. In this case open a normal notepad the C:\WINDOWS\system32\drivers\etc\hosts ( в настройках просмотра директорий сделайте видимыми скрытые и системные файлы и папки file). Then delete from the hosts file all lines the lines 127.0.0.1 localhost following later - now as a result of this action you will be able to go on-line and to take the above-stated advice.

3. In hard cases the viruses rewrite the file location of hosts in the system registry so that you will not be able to find it to the address C:\WINDOWS\system32\drivers\etc\hosts. To find the etc folder it is necessary to look in the register where it is.
For this purpose come into the register (regedt or Win+R regedit command), further pass to the address ""HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\services\Tcpip\Parameters"" and you watch value in DataBasePath (there and it is specified where there is an etc folder in which there is a hosts file).

If the above actions did not help you in any way, use a heavy artilerriya (but the system does not need to be reinstalled!).
Option 1:
Download http://www.freedrweb.com/livecd/?lng=ru LiveCD here, write a disk image on CD, reboot, enter BIOS, specify loading with CD ROM in BIOSe, be loaded from the written CD and carefully scan the computer on viruses. If you have a laptop, then just make the boot USB stick and be loaded from it.
Option 2:
Switch off the computer, take out the hard drive and contact the friend with a good antivirus or the Internet where safely scan antivriusy the hard drive, find a virus on it and delete it.

Author: «MirrorInfo» Dream Team


Print