How to Manually Remove Windows Antipiracy Ukash Ransomware
Step 1: Restart your infected computer and press the function key F8 repeatedly until the Windows Advanced Options Menu screen comes out. Use the arrow key to select the “Safe Mode with Networking” option and press Enter to proceed.
Step 2: Press Ctrl+ Alt+ Del together and enter the Windows Task Manager. Select the tab of Processes start tp ind out the processes related to Windows Antipiracy Ukash ransomware and terminate all of them.
Step 3: Open My Computer and go into the C drive. Find out and delete files associated with the ransomware as follows:
%AppData%[trojan name]toolbarstat.log
%AppData%[trojan name]toolbarversion.xml
%AppData%[trojan name]toolbarguid.dat
%AppData%[trojan name]toolbaruninstallIE.dat
%AppData%[trojan name]toolbarlog.txt
%AppData%[trojan name]toolbarstats.dat
%AppData%[trojan name]toolbarpreferences.dat
%AppData%[trojan name]toolbaruninstallStatIE.dat
%AppData%[trojan name]toolbardtx.ini
%AppData%[trojan name]toolbarversion.xml
%AppData%[trojan name]toolbarguid.dat
%AppData%[trojan name]toolbaruninstallIE.dat
%AppData%[trojan name]toolbarlog.txt
%AppData%[trojan name]toolbarstats.dat
%AppData%[trojan name]toolbarpreferences.dat
%AppData%[trojan name]toolbaruninstallStatIE.dat
%AppData%[trojan name]toolbardtx.ini
Step 4: Press the Windows Key+ R together. When the Run command box appears, type “regedit” in the blank and press Enter. In the Registry Editor, search for and remove all the related registry entries listed below:
HKEY_LOCAL_MACHINESOFTWAREClasses[trojan name]IEHelper.DNSGuardCurVer
HKEY_LOCAL_MACHINESOFTWAREClasses[trojan name]IEHelper.DNSGuard.1
HKEY_LOCAL_MACHINESOFTWAREMicrosoftInternet ExplorerToolbar “[trojan name]”
HKEY_LOCAL_MACHINESOFTWAREClasses[trojan name]IEHelper.DNSGuard
HKEY_LOCAL_MACHINESOFTWAREClasses[trojan name]IEHelper.DNSGuardCLSID
HKEY_LOCAL_MACHINESOFTWAREClasses[trojan name]IEHelper.DNSGuard.1
HKEY_LOCAL_MACHINESOFTWAREMicrosoftInternet ExplorerToolbar “[trojan name]”
HKEY_LOCAL_MACHINESOFTWAREClasses[trojan name]IEHelper.DNSGuard
HKEY_LOCAL_MACHINESOFTWAREClasses[trojan name]IEHelper.DNSGuardCLSID
Step 5: Reboot your computer in normal mode after you complete the steps above.
Note: The manual removal is a complicated and risky task which should only be attempted by advanced computer users. If you are less-experienced in computer operation, please download and use a powerful removal tool to remove the ransomware right now.
No comments:
Post a Comment