Malware Removal Instructions

  • Subscribe to our RSS feed.
  • Twitter
  • StumbleUpon
  • Reddit
  • Facebook
  • Digg

Friday, 13 January 2012

Remove Guardia di Finanza Ransomware (Uninstall Guide)

Posted on 11:10 by Unknown
We're seeing some more localized ransomware which renders a computer unusable and then demands payment to make it usable again. This time we're looking at the "Guardia di Finanza" virus which targets residents of Italy. It's not that often that you see a ransom Trojan localized into Italian language. This scam warning campaign was widely covered by local media assuring that the Guardia di Finanza, an Italian Police force directly under the authority of the Minister of economy and finance, has absolutely nothing to do with this scam, and that they never ask people for money.
Guardia di Finanza
Insieme per la Legalità
Attenzione!!!
E’ stata rilevata attività illegale, il sistema è stata bloccata per una violenza delle Leggi della Repubblica Italiana.


This malware is distributed through drive-by downloads and social engineering tricks. Once again the Blackhole Exploit Kit is involved. This commercial crimeware kit checks a computer for the presence of software vulnerabilities on the system, including CVE-2010-0186, CVE-2011-2110 and several others. These are already know vulnerabilities, so keeping your software (especially Java and Adobe) will significantly reduce chances of infection. Once installed, the virus locks your computer and displays a scam message (see image above). It then goes on to ask for a payment of €100 within 24 hours over Ukash or Paysafecard; otherwise your computer will be wiped clean. However, it's not capable of doing this stuff. The bad news is however that this malware may download and install spyware modules on your computer. We came up with at least several variants of Guardia di Finanza ransomware which upon execution requests malicious files from the Internet.

If your computer is infected with this virus, do not follow the instructions on screen. Please follow the steps in the removal guide below to remove Guardia di Finanza ransomware from your computer. Please note, we've analyzed a variant of this malware which replaces Explorer.exe file. If you got infected with other variant, our removal guide may not work for you. If you need extra help removing this malware, please leave a comment below. Good luck and be safe online!


Guardia di Finanza malware removal instructions:

1. Reboot your computer is "Safe Mode with Command Prompt". As the computer is booting tap the "F8 key" continuously which should bring up the "Windows Advanced Options Menu" as shown below. Use your arrow keys to move to "Safe Mode with Command Prompt" and press Enter key. Login as the same user you were previously logged in with in the normal Windows mode. Read more detailed instructions here: http://www.computerhope.com/issues/chsafe.htm



2.  When Windows loads, the Windows command prompt will show up as show in the image below. At the command prompt, type regedit and press Enter. The Registry Editor opens.



3. Locate the following registry entry:

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\

In the righthand pane select the registry key named Shell. Right click on this registry key and choose Modify.



Default value is Explorer.exe.



Change value data to iexplore.exe. Click OK to save your changes and exit the Registry editor.



Go back into "Normal Mode". To restart your computer, at the command prompt, type shutdown /r /t 0 and press Enter.



4. When Windows loads, there will be no icons. Don't worry, we will fix this soon. First, press Ctrl+Alt+Del or Ctrl+Shift+Esc and fire up Task Manager. Click File → New Task (Run...)



Type in iexplorer and click OK or press Enter.



5. Now, you need to download clean explore.exe file and over-write the infected one. Please make sure you download the file for your version of Windows:
  • Windows XP SP2
  • Windows XP SP3
  • Windows Vista SP2
  • Windows 7 SP1
Click on the link to download the file. Choose Save. Then browse to C:\Windows folder and select existing explorer.exe file. Click Save to over-write the malicious explorer.exe file.



6. Open up Task Manager once again. Click File → New Task (Run...) as you previously did. Type in regedit and click OK to open Registry Editor.



Locate the same registry entry outlined in step 3 of this removal guide.

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\

In the righthand pane select the registry key named Shell. Right click on this registry key and choose Modify. Delete iexplore.exe and type in Explorer.exe as it was before. Click OK to save changes.



Close Registry Editor and restart your computer. That's it! I hope this helps! Don't forget to scan your computer with anti-malware software.

If your computer is still infected, please follow an alternate ransomware removal guide.

To learn more about ransomware, please read Remove Trojan.Ransomware (Uninstall Guide).
    Share this information with other people:
    Email ThisBlogThis!Share to XShare to FacebookShare to Pinterest
    Posted in Ransomware | No comments
    Newer Post Older Post Home

    0 comments:

    Post a Comment

    Subscribe to: Post Comments (Atom)

    Popular Posts

    • Remove ShopperReports (Uninstall Guide)
      ShopperReports is defined as adware or a potentially unwanted program that displays marketing related results in a side pane of the browser...
    • Trojan.MBRlock, Внимание! Ваш компьютер заблокирован
      Trojan.MBRlock is a very disturbing piece of malicious code which infects the master boot record (MBR) and prevents Windows from starting. ...
    • Remove RiskTool.Win32.BitCoinMiner (Uninstall Guide)
      RiskTool.Win32.BitCoinMiner is a risk tool or potentially unwanted application that may use your computer's resources to generate bitco...
    • What is wrtc.exe and how to remove it?
      wrtc.exe - by Perion Network Ltd. What is wrtc.exe? wrtc.exe is a part of IncrediMail software, digitally signed by Perion Network Ltd. This...
    • Remove Rattlingsearchsystem.com (Uninstall Guide)
      Rattlingsearchsystem.com is a ZeroAccess/Sirefef rootkit-related browser hijacker that redirects users to shady websites while searching on...
    • False Positive: Ikarus and Comodo detecting TDSSKiller as a Trojan horse
      This awkward moment when you realize that your favorite rootkit removal utility is detected as malware. I probably wouldn't even have no...
    • Remove TR/ATRAPS.Gen2, removal instructions
      Cyber crooks and third parties that buy stolen data are increasingly using more and more sophisticated techniques, in a variety of different...
    • Remove Ask Search and Ask Toolbar (Uninstall Guide)
      Ask Search and Ask Toolbar are very often incorrectly classified as virus/spyware that may cause search redirects. The majority of us pref...
    • Remove Windows Attention Utility (Uninstall Guide)
      Windows Attention Utility is a rogue security application that generates misleading warnings about nonexistent viruses and attempts to lure...
    • Remove "System Check" (Uninstall Guide)
      System Check is malicious software posing as Windows system utility. Although, it may look like a real thing, it isn't! You are actuall...

    Categories

    • Adware
    • Answers
    • Antivirus software
    • Browser Hijackers
    • Cloud Computing
    • Fake Alerts
    • Giveaways
    • Hoax
    • How-To
    • IaaS
    • Internet
    • Malicious websites
    • Malware
    • PaaS
    • Parental Controls
    • Passwords
    • Phishing
    • Process Information
    • Ransomware
    • Rogue programs
    • Rootkits
    • SaaS
    • Security Advisories
    • Spam
    • Spyware
    • Trojans
    • Viruses
    • Web Browsers
    • Worms

    Blog Archive

    • ►  2013 (173)
      • ►  December (6)
      • ►  November (13)
      • ►  October (11)
      • ►  September (20)
      • ►  August (4)
      • ►  July (17)
      • ►  June (31)
      • ►  May (25)
      • ►  April (15)
      • ►  March (17)
      • ►  February (7)
      • ►  January (7)
    • ▼  2012 (86)
      • ►  November (2)
      • ►  October (4)
      • ►  September (6)
      • ►  August (6)
      • ►  July (11)
      • ►  June (1)
      • ►  May (5)
      • ►  April (7)
      • ►  March (7)
      • ►  February (17)
      • ▼  January (20)
        • Youtube PREMIUM Player, Free Facebook Credits and ...
        • How to Remove Searchqu (Uninstall Guide)
        • Remove RiskTool.Win32.BitCoinMiner (Uninstall Guide)
        • Bitdefender Internet Security 2012 Giveaway! Hurry...
        • Antivirus Smart Protection and Malware Protection ...
        • Remove "Smart Protection 2012" (Uninstall Guide)
        • Remove "Internet Security 2012" Malware (Uninstall...
        • Temp:winupd.exe (Uninstall Guide)
        • Search.conduit.com (Uninstall Guide) - How To Remo...
        • PUP.CNET.Adware.Bundle (Uninstall Guide)
        • Remove Internet Security Guard (Uninstall Guide)
        • Remove Guardia di Finanza Ransomware (Uninstall Gu...
        • Remove Strathclyde Police Ransomware (Uninstall Gu...
        • Malicious Youtube Extension, YXH-youtube_player.xp...
        • Remove Audio Ads Virus (Uninstall Guide)
        • Msdcsc.exe Process Information
        • Remove EoRezo Adware/PUP (Uninstall Guide)
        • Remove BasicScan (Uninstall Guide)
        • Be A Guest Writer
        • Remove Tidserv Activity 2 (Uninstall Guide)
    • ►  2011 (239)
      • ►  December (8)
      • ►  November (18)
      • ►  October (21)
      • ►  September (24)
      • ►  August (28)
      • ►  July (32)
      • ►  June (16)
      • ►  May (23)
      • ►  April (15)
      • ►  March (16)
      • ►  February (9)
      • ►  January (29)
    • ►  2010 (2)
      • ►  December (2)
    Powered by Blogger.

    About Me

    Unknown
    View my complete profile