Monday, October 8, 2012

An Garda Síochána. Ireland’s National Police Service Virus

An Garda Síochána. Ireland’s National Police Service is a warning notification that suddently appears on your computer and hijackes your desktop. You are not the only person who has such problem of a totally paralized PC by this alert. It is a problem of the international scale. People get easily nervous when this alert appears on their computers as it looks so legit. Generally, this kind of cyber scam locks your computer in the name of the country and asks certain fines from you to automatically unlock your computer in the next few hours or so. Have you already performed all steps asked by An Garda Síochána. Ireland’s National Police Service warning? Is your PC still blocked despite you have paid the asked amount of the fine? It happens so because this is fake warning notifications that has nothing to do with Ireland’s National Police. It is a handiwork of virus developers. They invented this method to scare you and steal your money. The chances where you can catch this infections are very high is you are an active Internet user. One can have a PC infected with this virus include visiting unknown hacked sites, downloading free malicious programs and opening spam emails. A small piece of Trojan virus hidden in these places could assist the infection of this alert. What’s worse, your antivirus has failed to detect its malicious invasion.Do not panic, we will tell you what to do if such unpleasant situation takes place. Go on reading.

An Garda Síochána unlocking instructions

1. Reboot the infected computer and get into safe mode with networking. When you have pressed the restart button, please keep pressing F8 on your keyboard until a black screen with several commands appears. Then use the arrow keys to select “Safe Mode with Networking” and press ENTER;

2. Install GridinSoft Trojan Killer. Press Ctrl+Alt+Del at the same time or right click on the Task Bar to open the Windows Task Manager;

3. End the process [An Garda Síochána.].exe;

4. Open Control Panel from Start menu and search for Folder Options;

5. Under View tab, tick Show hidden files and folders and non-tick Hide protected operating system files (Recommended) then click OK;

6. Open Registry Editor by pressing Windows+R keys;

7. Remove the files created by this nasty ransomware:

  • %AppData%\NPSWF32.dll
  • %AppData%\Protector-.exe
  • %AppData%\result.db
  • %CommonStartMenu%\Programs\ rnd.lnk

8. Remove the registry entries created by this nasty ransomware:

  • HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\{random}
  • HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Run Regedit32
  • HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run “Inspector”
  • HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\Current\Winlogon\”Shell” = “{random}.exe”
  • HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\System “DisableRegedit” = 0
  • HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\System “DisableRegistryTools” = 0

If all steps are carefully done, you recommended to scan your PC with the reputable anti-virus like GridinSoft Trojan Killer

SOURCE: http://remove-trojans.com/an-garda-siochana-irelands-national-police-service-virus/

No comments:

Post a Comment