Unlocking Windows: How to remove the Windows lock banner? Windows is blocked, what to do with the banner

Greetings, dear readers! Today I will tell you how to remove the “Windows blocked” ransomware banner. This problem, unfortunately, arises for many, because no one is protected from this danger. But very few people know how to get rid of this banner. Today we will correct this situation, because after reading this article you can easily remove such a banner. So, since you have landed on this page, then most likely you have already received a ransomware banner on your computer. So there is no point in talking about what it looks like and what it is. The only point that must be mentioned is Do not send them SMS under any circumstances . The money will, of course, leave you, but the banner will not disappear, this happens, if not in all, then in 90% of cases. It’s also worth considering the reasons why this banner could have gotten onto your computer, so that you understand your mistake and don’t end up in the same situation a second time.

Where did the banner come from?

1. Installing pirated applications. Installing extraneous pirated software from unverified sources, you immediately expose your computer to serious risk. I advise you never to download or install programs from suspicious, unverified sources. 2. Suspicious sites. Here we're talking about not about normal information sites, like mine :) But about sites that are fraudulently trying to lure you to their place. For example, this could be the site “Flash player update” or “Your browser is out of date.” Don't be fooled by such messages because neither your browsers nor your flash players will notify you of anything in such an intrusive manner. These are the main vulnerabilities, try not to fall for the tricks of scammers. Now let’s move on to the most important thing - removing the “Windows is blocked” banner

How to remove a banner from Windows?

The best, 100% and easiest way to get rid of the banner showing that Windows is locked and requiring you to send an SMS is, of course, reinstalling Windows entirely. Everything will be lost here: banners, viruses, and your files. But if this method does not suit you, then you can remove the banner in another way, and it’s completely free. So, restart your computer, and while booting up, press the F8 key. A page will open in which we need to select the item “ Safe mode with the support command line" The mouse does not work here, you will have to select it using the up and down arrows:
When you select this item, press Enter. Then the desktop will open, everything is as usual, but the banner has not yet been deleted. Now use the hot combination Win keys+ R to open Run (Win is the key that either says "Win" or has a Windows icon). The program will open, in the line of which you need to write “regedit” and press Enter:
The registry will open. Here you need to be careful, follow everything strictly according to my instructions, otherwise you can completely ruin everything. So, in the registry we look at the left column and move along the following path:

HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\Current Version\Winlogon

After you click on the last way(Winlogon), parameters that can be changed will open in the right column. Here we check the following values: 1. Opposite “Shell” there should be “explorer.exe”; 2. Opposite “Userinit” there should be “C:\Windows\system32\userinit.exe,”:
To change a parameter, select it and click on it right click mouse and select "Edit". After this, the banner should leave your computer!

If something goes wrong and something doesn’t work out for you, then you can try the second method. I’ll say right away that it is much more complicated.

Kapersky Anti-Virus has written new utilities to remove the ransomware banner. Here is the link .

So, you need to download the ransomware banner removal file by clicking on this button:

The Internet is very interesting place, where a lot of information is hidden on the most different topics, that's why it's so popular. Many users can no longer live a day without looking online for at least a few minutes. But The World Wide Web It is also fraught with many dangers: viruses, Trojans, and worms attack users’ computers from all sides.

IN Lately ransomware banners have appeared: they block the system and require you to send it to specified number or transfer to it a certain amount money. may differ slightly in appearance and content of the text, but the essence is the same: the system is blocked and entry into it is impossible. Blocker program Trojan.Winlock copies itself, and its clones are registered in different places, occupy startup, disable the task manager, and paralyze the computer.

What to do to remove the Windows blocked banner

The hacker asks to send an SMS or some amount to his phone number. Trusting users, even knowing that they have never visited pornographic sites and have not violated the Criminal Code of Russia, they rush to comply with the requirements and transfer money or send SMS. A decent amount of money leaves their account, and in the end - minus balance in four-digit figures, and the banner flaunts in the same place, because this Trojan horse, disguised as system message. You can remove the blocking in two ways: by involving a specialist or by yourself.

Unlocking Windows

There is a very funny solution to this problem. The unlocking code is hidden in the banner itself; it is encrypted in the phone number to which you want to transfer money. If you discard the first and last digits, then all the remaining ones will be the code. But such an easy solution is not applicable to all banners. Then you should try the following methods.

1 way

The most effective way to combat any viruses that have entered your computer is reinstallation operating system . If for someone it is easier to reinstall the OS than to use other methods of removing the banner, then this is the most the best option, just too troublesome.

2 way

Banner ransomware is special program viral in nature, which completely blocks access to operating room controls Windows systems for the purpose of extorting money for unlocking access by sending money to a phone number or online wallet intruders. Despite the fact that the main wave of the influx of virus banners passed a couple of years ago, we still periodically have to deal with cases of computers being damaged by this dirty trick. This mainly happens to users who have not bothered to protect their PC from viruses. If you don't have it installed normal antivirus, then one fine day, instead of the usual desktop, you will see a banner that, in order to be deleted, will require you to send an SMS to the number mobile phone supposedly to get an unlock code. This is a complete deception and no matter how much money you send, of course there will be no answer! Now I will give 3 ways to remove ransomware banner from a Windows computer. If they don't help, then only complete reinstallation operating system.
There are 3 ways in which you can remove a banner in Windows:

The first way to remove a banner

Try using your phone, tablet or other computer to search the Internet for the unlock code using your phone number. Code generators for unlocking the ransomware virus are posted on the websites of the most large companies developing antivirus software. For example, Kaspersky Lab, DrWeb and Deblocker. There you usually need to enter a phone number to which the attackers demand you send money and SMS, or a number electronic wallet. In response to this, you will receive a code that will help you deactivate the blocker.
The only unpleasant thing is that this method works on the oldest and simplest ransomware banners. On a more cunning, complex and advanced “infection” this trick no longer works and to treat it you will need to use the following two methods.

The second way to unblock a banner on your computer

Take advantage Kaspersky utility WindowsUnlocker from Kaspersky Lab.

It is part of Kaspersky Rescue Disk. This is great free tool, which will help you quickly and easily remove the ransomware banner virus from your Windows 10 computer.

The third way to remove a Windows blocker virus

1. You need to boot the system in safe mode. In Windows 7, you need to press the F8 button at startup to do this. In Windows 10 or Eight you will need installation disk or flash drive. More details are well written in the article Windows 10 Safe Mode.
2. Next, you need to open the registry editor. To do this, press the Win+R key combination and enter the command in the “Run” window regedit.
3. In the registry editor we find the branch:

HKEY_LOCAL_MACHINE\ SOFTWARE\ Microsoft\ Windows NT\ CurrentVersion\ Winlogon

It will contain the entry “Shell”. Double-click on it and write standard conductor Windows - explorer.exe
If the explorer is already registered in the “Shell” entry, then open the branch:

HKEY_LOCAL_MACHINE\ SOFTWARE\ Microsoft\ Windows NT\ CurrentVersion\ Image File Execution Options

Unfold it and study it carefully. If there is a subsection “explorer.exe” there, simply delete it by right-clicking and selecting the “Delete” menu item.
4. Reboot the computer. Windows should boot normally. After this, be sure to check your computer good antivirus. For example, free DrWeb CureIT.

On this topic from another author, which is very outdated. In this article I will give you universal methods eliminating the virus. On own experience I became convinced that there are a lot of victims of such viruses. And most people solve the problem radically - reinstall Windows, although in 99.9% of cases you can get by" little blood", i.e. remove the virus without reinstalling the system and, accordingly, losing many programs and settings.

Attention! The article will contain a large abundance of computer terms and technical information. If you are new to computers, then give it to a non-newbie friend who, after reading the article, will fix your computer and gain knowledge himself. Or visit the computer forum http://www.hardforum.ru/t21083/, where you can learn a lot about computers and computer terms and also ask for advice knowledgeable people. However, I will still try to describe the problem and ways to solve it in understandable language.

What kind of virus is this?

As a rule, viruses of this type are called Trojan.winlocker or simply Winlock. However, such viruses often change their structure and type of operation, and therefore they are usually called the general term “Ransomware” (translated roughly as “viruses that demand a ransom”).

The virus looks something like this

The virus works this way: a banner like this pops up in front of you, which cannot be closed or removed standard means. At the same time, such a virus blocks the entire toolbar and interface. You only see the banner on top of the desktop wallpaper.

The banner says that you did something bad that violated the law. It may be written that you have pirated windows, or that child pornography was found on your computer, etc. And to remove the banner, you either need to send an expensive SMS to short number(then you will receive an unlock password), or you are asked to top up your mobile phone account in the amount of about 500 rubles (like then you will see a code on the payment receipt). Needless to say, this is all a deception and a scam. Even if you have licensed Windows, even if you don’t have anything indecent on your computer and you haven’t watched anything indecent on the Internet, the virus will still show you such a banner.

In addition, the banner will say that if you do not enter the password/code, then all your data on the computer and BIOS will be deleted. As a rule, you are given a period of 24 hours. And again, this is a deception. Such a banner will not delete anything on your computer (and even more so the BIOS - this is impossible). Therefore, if you find such a banner in your home, calmly turn off your computer and follow the advice in this article.

By the way, even if you pay/send an SMS, there is a 90% chance that the code received will not work (or most likely the code will not arrive at all). However, the code may work, but the virus will not be removed, which means it will appear again in a week.
Although there are also “honest viruses” to which the code will be suitable and they will delete themselves, but, I repeat, in 90% of cases this will not happen and the money you spend will not change anything on the computer.

How to get rid of the virus?

Try just rebooting. Yes, yes... old and undeveloped modifications of the virus (written by crooked people) are still circulating on the Internet. If after rebooting the computer starts normally, check the computer with antivirus software.

Method 2: Safe Mode

Most modern blockers also run in safe mode, but it’s worth a try. Turn off your computer and press F8 when starting up. However, on all computers the key to launch such a menu is different. Therefore, when you turn on the computer, start pressing all the buttons from F1 to F9 in a row. In general, this window should appear in front of you:

Next, use the Up and Down keys to select “Safe Mode”. If the system boots normally, then check your computer with antivirus software. If not, then select the “Safe Mode with Command Line Support” mode. If everything starts normally, then enter regedit. Next follow Method 3.

Method 3: Editing the registry

If you manage to log into the system, bypassing the virus, then press two Win + R keys simultaneously. In the window that appears, enter regedit. After which, a window for editing the registry will open.

This window is similar to Explorer. In the left panel you can select registry branches (as you select subfolders). The virus registers itself in certain branches of the registry, allowing it to run even in safe mode.

HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Winlogon
In this thread we look at two parameters Shell and Userinit.

The Shell value should be written explorer.exe, and the Userinit value should be userinit.exe, (necessarily with a comma). To rewrite a value, you need to double-click on it. If something else is written instead of the required values, then this is the name of the virus. We remember the name of the virus so that later we can find it with a regular search and remove it.

By the way, the virus can replace some letters with Cyrillic ones. For example, e x plorer.exe, where instead of the English x (x), there is a Russian x. Therefore, enter these values ​​again anyway.

However, those passed happy times, when the virus was registered only in these branches. Therefore, if everything is fine in the above branches, then look at these branches:
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run and
These branches indicate programs that start when the system starts. If you find something strange, delete it.

Plus you can also watch

If the banner is not blocked by Windows, but Internet browser Explorer, then clean up the thread
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\

Also look for suspicious names in threads:
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\ Windows\CurrentVersion\RunServices\
HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\Program_name\
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\ CurrentVersion\Image File Execution Options

If you got rid of the banner, but the registry editor is blocked and the task manager does not work, then look at the thread
In this thread we are looking for the following values:
And assign them the value 0.

Method 4. Live disk. Live flash drive

You can run from a live disk or from a flash drive and also edit the registry, as in Method 3.
If you are too lazy to look for a disk image that suits you and download it, you can use the utility Kaspersky Rescue Disc. Using this link you can read all the instructions and download everything you need. As a result, you will create bootable USB flash drive. The website tells you how to start the system from it. After starting the system from a flash drive, you can scan your computer for viruses, and at the same time select the Kaspersky utility Registry Editor. This is the same registry editor, so follow Method 3.

Method 5. Search by name

If you have two systems installed on one computer, or manipulations with the registry did not help. If the live disk and antiviruses didn’t even help you, then there is a childish method.

Most banners do not cover the entire desktop. Therefore, if you try to call the task manager using the Alt+Ctrl+Del keys, it will appear for a split second and then disappear. Therefore, you simply hold down these three keys and the task manager will begin to blink. You will not be able to perform any manipulations with it, but you will be able to see a suspicious process. Remember this suspicious name. Then boot from another system or from a live disk/flash drive and enter this name in the regular file search menu. If found, delete it.

True, there are also viruses that work as follows. Attached to the virus is a dll - a library that constantly creates executable file virus under different names. In this case, the name of the virus will always be different.

Method 6. Search by date

If you can't find it by name, then search by date. Boot from a live disk/flash drive and set an empty search, but in special conditions indicate the date of modification. Those. In the date of change we write the day of infection. After the search is completed, the system will show you many files. We are looking for suspicious people. Suspicious ones carry the extension .exe or .swf. Suspicious files have also long titles. Most viruses have the form 0.nnnnnnnn, where n is any number. Sometimes it's just a long string of letters and numbers.

By the way, you can delete all the files that the search gave you. System files will not be among them.

Method 7. Unblocker

You can go to the Dr. Web or Kaspersky websites, where you can use the phone number indicated on the banner or the photo to select a deactivation code. And only then, after deactivation, check with an antivirus or follow method 3.

Method 8. ERD Commander and AntiWinlocker

These are special images with even understandable to a simple user interface. Download and install them on a disk or flash drive, boot from them and follow the instructions.
http://www.antiwinlocker.ru/download.html - AntiWinlocker
ERD Commander you can find it on trackers.

Method 9. Legal

As a lawyer, I simply have to tell you a method that will not only save you from the virus, but will also cause a lot of trouble for the creators.
The main disadvantage for the blocker developer is the phone number indicated in the banner. If you are asked to deposit money on someone's number or asked to send an SMS, you can file a police report indicating this number. If the police do not accept the report, then call telephone operator who owns this phone. “Bull” and threaten the operator with court - the operator must give you either contact information for further proceedings, or he will file a statement with the police together with you. If you were sent there, then file an application with the prosecutor’s office, file a lawsuit, file a complaint with the police. In general, submit applications to all authorities.

IN this method there are many disadvantages. First, you will have to leave the virus on your computer as evidence. Secondly, the process will take a long time and it is not certain that it will be resolved. Thirdly, are you ready to spend a lot of free time for the sake of a “stupid” virus? That is why no one is simply looking for the creators of such viruses. The users themselves with a passive civic position are to blame for such an abundance of blockers.

Method 10. MBR

There are viruses that write themselves into a special boot area on the hard drive. Thus, the virus is launched even before the system itself. Those. on a black screen, the same thing will be written in white letters as in conventional blockers. However, such a virus cannot be removed using standard registry manipulations. You need the disk from which you installed Windows. If this is not the case, then download the image from the Internet. that Windows, which you have, and burn the image to a disk or flash drive. Insert the Windows disc. Go to the recovery console (usually the R key) and write fixmbr. Then to agree, press “Y” (Yes), then press Enter. Thus, your boot area will be restored to normal.

Bottom line

Protecting yourself from blockers is both difficult and simple. On the one side, modern views blockers are skipped by almost all antiviruses. Moreover, due to the vulnerabilities of most browsers, you can catch a virus even on trusted and popular sites.
To protect yourself, you need to limit your rights. If you have Windows 7/Vista installed, then enable UAC (Control Panel - Accounts users - Changes to control parameters). After enable UAC, before each of your actions the system will require your consent. Now the virus will not go away! But again, it’s not that simple. Most users will simply get tired of giving a separate permission to the system before each action. In addition, UAC assumes that users will have to make suspiciously responsible decisions. For example, if the blocker decides to start, UAC will display messages like “The application systemf.exe is trying to start” and will prompt you to start it or cancel it. Do you think there will be people who will launch it? Of course they will. Regular user will not identify the virus based on its name.
You can also install a browser plugin that will block scripts from running on websites. For example, a plugin for Firefox is NoScript. And again, a problem. After installing the plugin, you will not be able to access your favorite sites, since the plugin blocks all scripts by default! This means you will have to spend precious time on fine tuning.

Is it worth becoming paranoid for the sake of full protection your computer - it's up to you.

And on this cheerful note I end!
Thank you for your attention!

