PCeU Ransomware

  lotvic 20:56 02 Dec 2012

If this ransomware blocks your screen when you start your computer in safe mode with networking, try starting your PC in safe mode with command prompt. from ClickHere - has screenshots

  1. During your computer starting process press F8 key on your keyboard multiple times until Windows Advanced Options menu shows up, then select Safe mode with command prompt from the list and press ENTER.

  2. In the opened command prompt type explorer and press Enter. This command will open explorer window, don't close it and continue to the next step.

  3. In the command prompt type regedit and press Enter. This will open the registry editor window.

  4. In the registry editor window you should navigate to HKEYLOCALMACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\

  5. In the right side of the window locate "Shell" and right click on it. Click on Modify. The default value data is Explorer.exe if you see something else written in this window remove it and type in Explorer.exe (you can write down whatever else was written in the value data section - this is a path of the rogue execution file) - use this information to navigate to the rogue executable and remove it.

  6. Restart your computer, download and install a legitmate anti-spyware software and perform a full system scan to eliminate any left remnants of Metropolitan Police scam.

If command prompt still won't open Windows, there are more ways to do remove the Ransomeware they are on the link I've posted and it tells you which files need to be deleted.

This thread is now locked and can not be replied to.

Elsewhere on IDG sites

Samsung Galaxy Book 2: Release date, price and specs

Adobe's groundbreaking prototypes of new features and apps for Creative Cloud

When is the next Apple event?

Les meilleurs VPN gratuits (2018)