FBI Virus Removal
Description:
The “FBI Virus” is a ransomware that locks down a user’s profile. There are different ways to remove it, but try these steps.
To Resolve:
-
Try and get on another user account if you are locked out of yours. Try the local administrator account if you have one.
-
If that doesn’t work, try your account in safe mode.
-
Once inside of a user profile, Run =>
%userprofile%\appdata\local\temp
=> removerool0\_pk.exe
=> removeV.class
=> the virus can have names other thanrool0\_pk.exe
but it should look like it doesn’t belong and should have a create date/time the same as a.class
file if you sort by file mod/create time you’ll find it. -
Run =>
%appdata%\microsoft\windows\start menu\programs\startup
=> removectfmon (ctfmon.lnk)
this is what’s calling the virus on startup => also checkHKLM:\Software\Microsoft\Windows\CurrentVersion\Run
and make sure there’s nothing obvious there. -
If those still haven’t removed it, start running all the virus scans you have inside another profile.
-
Re-image your computer if infection still persists.
Comments