Windows is blocked by a virus, what should I do? Windows is blocked, what should I do with the banner? Simple service from Dr.Web

Many Windows users have experienced that the computer sometimes locks up. Messages like “Your Windows is locked” can appear in several cases. And this is not always associated specifically with viral exposure. The fact is that the system itself can issue notifications of this kind. Next, it is proposed to familiarize yourself with possible situations and basic methods for eliminating such a problem.

Your Windows computer is locked: possible reasons for this phenomenon

So, let's start with the root causes of blocking the operating system itself, the registration record, the disk, or access to some applications. In general, there may not be many situations when it is reported that a Windows computer is blocked.

Among all the problems that occur most often, the following problems can be identified:

  • the system is blocked due to lack of activation;
  • access to programs is limited by the security system or administrator;
  • The system is blocked by ransomware viruses.

What to do if Windows 7 is locked after installation?

It is no secret that for all systems of this family, including the previously freely distributed tenth modification, a special license key must be entered during the installation process. However, in any installer you can skip this step, postponing activation of the operating system until later. The system will work, but its use is usually limited to thirty days.

If you do not enter the activation code during this time, a permanent notification will appear on the screen in the system tray stating that, for example, Windows 7 is blocked. In other words, it will be impossible to use it fully. As is already clear, to correct the situation it is necessary to carry out activation. After the procedure is successfully completed and rebooted, the system notification that the Windows system is locked will disappear. Many users, unfortunately, constantly postpone registration, leaving this procedure for later, and do not at all monitor the expiration dates of the trial period. Thus, ordinary inattention leads to the fact that the entire system at one point stops working.

Using the activator

However, not all users strive to purchase official copies of the system and do not always have the necessary activation keys available. It is clear that in this case a message will again be displayed stating that Windows is blocked. What to do in such a situation?

There is a solution, although it can be attributed to some illegal actions on the part of the user that violate international law. However, this never stopped our user. If you want to activate the system without a key, just use utilities like KMSAuto Net, which perform this procedure automatically. The only thing you should pay attention to is the agreement to enter the reactivation process into the “Task Scheduler” (re-registration will be carried out every ten days). In addition, the file itself cannot be deleted. If an antivirus or the protection system of the OS itself (Defender and firewall) is triggered, the object must be added to the exclusion lists of all tools that monitor system security. In the firewall, you can immediately add a program to the list of allowed ones or create a new rule to run it. Exactly the same actions are performed in antiviruses.

Administrator rights

But both the computer administrator and the system administrator can block access to Windows if network modifications are used. In this case, we are talking not only about limiting the use of programs or system tools, but even about the fact that logging in at the registered user level will simply be impossible.

So, if the administrator has blocked Windows 10 from logging in, the solution is obvious - you need to contact him to restore access. If you know the administrator username and password, the solution looks even simpler. Simply log in as an administrator, go to account management, select your registration and set the necessary rights or remove the lock. By the way, setting the appropriate rights to change system parameters or disabling control of “accounts” can also be useful if Windows 10 blocked the program, considering it unreliable when trying to install or when starting after its installation.

The simplest solution seems to be one that can be accessed through the Windows search engine (so as not to rummage through various menus for a long time). In the settings window, you just need to move the slider to the lowest position, save the settings and restart. You can also disable the firewall and the TrustedInstaller service. If some applet has blocked Windows, you can unblock it, but by setting it to always run as administrator. To do this, use the properties section of the executable file or its shortcut with a check mark on the corresponding line so that the application always starts with the rights the user needs, and the system does not issue constant requests for trust. By the way, the same applies to the TrustedInstaller service, which can be disabled in the simplest way through the services section, where in the parameters it is first deactivated, and then the disabled start option is set for it in the startup type.

Blocking by viruses: options to correct the situation

Finally, one of the most common situations is the inability to log into the system, when a constantly hanging banner appears on the screen during the loading process notifying that the computer is blocked (Windows is blocked) due to visits to some dubious sites on the Internet or the distribution of unwanted content, which allegedly originates from your address.

In fact, the operating system itself does not provide for such a blocking, and the user is dealing with an ordinary ransomware virus, which, in addition to everything, also issues a requirement to pay a certain amount, after which the system should seem to return to normal. Do not even think about transferring anything to the specified details. You can get rid of this kind of virus using simpler methods:

  • restore the system from a checkpoint;
  • remove virus keys from the system registry;
  • use antivirus software.

System Restore

Let's consider a situation where, for example, Windows XP is blocked. The system does not start, and at the stage of loading the “Desktop” the above banner appears.

To begin with, you can try to forcefully turn off your computer or laptop, then turn it on again and see if automatic recovery starts. If for some reason this does not work, turning it on and off will need to be done several times for the system itself to determine that an incorrect shutdown was performed.

If the recovery still does not work, the system does not boot, or at startup it turns out that the Windows account is blocked, you can use the classic method of selecting the boot type by pressing the F8 key at startup (in Windows 10 this option does not work, and you can use removable media). Here you simply choose to load the last working configuration and see how the system behaves.

If this does not help, try starting in safe mode, and then entering the system recovery settings through the “Control Panel” and performing a rollback using the checkpoint that preceded the virus’s penetration into the system (if there is no such point, click on link to show other points).

Using Registry Editor in Safe Mode

But let's assume that this had no effect. Again we see a situation where Windows is blocked by a virus application. What to do in this case?

First, you should boot into safe mode with command line support, and then call the registry editor through the console (regedit command). Now comes the most important part.

First of all, you need to find the Shell and Userinit keys in the HKLM branch, which are located in the Winlogon directory. For the first entry (without options), the value explorer.exe must be specified, and for the second, the full path to the executable file userinit.exe, which is located in the System32 system folder of the Windows root directory in the system partition (usually on drive C).

After that, you should check the similar section in the HKCU branch. Here in the same directory the above keys should not exist at all. If they are present, they must be removed. Then, to be sure, you need to check the Run and RunOnce directories in the HKLM and HKCU branches. In these sections you need to get rid of all suspicious entries in which the current values ​​are set to links to executable EXE files, the names of which consist of a meaningless set of characters (if for some reason you doubt whether to delete a certain key, just go to edit parameters by double-clicking and set the value to one - this will disable the execution of the application, and if necessary, the value can be returned to its previous state after eliminating the main problems with the operating system itself, but after it has been restarted in working order).

The next step if your Windows drive is locked is to clean it up. To do this, the same command line is used, but the abbreviation cleanmgr is written in it. In the window that appears, you need to check the boxes on all the lines that are present in the list, with the exception of the item for deleting backup files.

After editing the registry and the cleaning procedure, you can restart the computer and see how the boot will proceed. If for some reason starting is impossible again, enter explorer.exe in the command console, go to the Users folder, in your directory go to the AppData folder and in subdirectories delete files with the names that you got rid of in the registry.

If, when performing the specified actions with the registry and system partition, it is not possible to call the command line via start in safe mode, you will have to boot from removable media (installation or recovery disk/flash drive) and then perform similar procedures. The command console in this case can be activated in the fastest way through the combination Shift + F10.

AntiWinLocker application

But what should you do if even after this it turns out that your Windows computer is blocked by a viral application? This is where specialized utilities will come to the rescue. One of the most interesting is the described boot program, which allows you to start by being recorded on an optical or USB drive.

After starting the program, you must accept the license agreement and select automatic launch. Next, this tool will perform a full scan of the computer system and indicate where exactly the viruses are located. You can delete them immediately or leave such actions for later, but after the restart you will additionally need to launch some kind of anti-virus scanner. In theory, the system should boot in normal mode.

If the previous solution did not help, and again it turns out that your Windows computer is locked, you can use the equally effective Kaspersky Rescue Disk utility, which also starts from removable media.

After launching the utility, you first need to select the language and preferred interface (graphical is best). After this, you can either scan for viruses or go directly to unlocking the system. For the first option, all disks and partitions are marked, after which the scanning process starts.

For the second option, use the terminal line, called through the main menu button (like “Start” in Windows), and enter the line windowsunlocker in the console that appears. After this, a black window similar to a command console will appear, where three options will be offered. To instantly unlock, enter one, after which all you have to do is wait for the process to complete. However, even if an immediate scan is carried out and a virus is detected and it is removed or neutralized, starting the operating system will be possible. By the way, this particular program allows you to detect and eliminate almost all known threats, so its use in case of deep infection is as effective as possible.

AVZ program

Now there is another situation in which it turns out that Windows is blocked. The AVZ program or some kind of portable scanner can be used, so to speak, for a control shot - checking the system and/or restoring it and eliminating detected problems.

The application starts when the system starts from removable media or in safe mode, after which the recovery option is selected from the file menu. Mark everything you need and click the button to perform the selected actions. But it’s too early to rejoice. Next, you need to go to the built-in “Troubleshoot Wizard”, select system problems and the “All” item, mark all the lines and perform the necessary steps to scan and fix the faults found. After this, you need to use the browser settings and tweaks section in the same way, and then through the service menu go to the Explorer extensions editor, where you uncheck all the items marked in black. Next, through the same service menu, you need to go to the Internet Explorer extension manager and delete all the lines that appear in the settings window.

When your Windows computer is locked, running this application in Safe Mode may not work. If you want to use this particular option for starting the utility, you can use the system boot menu (F8) and select to first launch the recovery tool, and then use the command line, from which you need to launch standard Notepad by entering the notepad command. In this program, you should open the AVZ.exe file, selecting “All” in the file type, and run the antivirus executable file through RMB with the selection of the line “Open” and not “Select”, since using the second item will only lead to a text representation of the compiled file will be shown, rather than starting it as an executable applet.

What to do if nothing helps?

As is already clear, viruses can block access to Windows quite simply. Typically, such situations are associated with outdated versions of XP, but it is far from a fact that later modifications cannot be subject to such effects.

However, returning to the main question, we can assume that none of the above solutions gave a positive result. What to do in such a situation? Here, as a last option, you can suggest removing the hard drive with the infected system, connecting it to an uninfected computer terminal and checking it for viruses using a portable antivirus launched from the computer to which your hard drive is connected. What to use? In principle, utilities like Dr. are a good idea. Web CureIt or KVRT from Kaspersky Lab. True, it will not be possible to mark the boot or hidden areas of the connected HDD in them, however, it is possible to use such a solution as a last option (of course, provided that no other measures help).

Instead of a total

That, in fact, is all that concerns the occurrence of problems when the system or some of its functions are blocked. If the operating system starts, you can immediately conclude that the bans are imposed due to lack of activation or represent security measures on the part of the system itself or the computer administrator. But in the case of messages appearing in the form of banners, this is a clear sign of viral influence.

As for eliminating problems and bringing the system into a normal working state, it is best to use KMSAuto Net for activation (the program is portable and does not require installation); to eliminate problems with prohibitions from the OS itself, disabling UAC control or granting yourself extended rights to change the system configuration or access to blocked programs. Well, in this case it can be impossible to fight viruses without utilities that start even before the main Windows modules are loaded.

Yes, and here's another thing. Even if the operating system starts in safe mode, under no circumstances is it recommended to use supposedly anti-virus programs like SpyHunter, since threats may be detected and will be, but it will be impossible to remove them or neutralize them without purchasing the main application. In addition, then getting rid of anti-virus applets of this type will be much more difficult than removing threats detected by other applications, for example, programs from Kaspersky Lab. So, if you are asked to download and install such utilities, it is better, as they say, not to take risks.

The Internet is a very interesting place where there is a lot of information on a variety of topics, which is why it is so popular. Many users can no longer live a day without looking online for at least a few minutes. But the World Wide Web is also fraught with many dangers: viruses, Trojans, and worms attack users’ computers from all sides.

Recently, ransomware banners have appeared: they block the system and, in order to unlock it, require you to send or transfer a certain amount of money to a specified number. may differ slightly in appearance and content of the text, but the essence is the same: the system is blocked and entry into it is impossible. Blocker program Trojan.Winlock copies itself, and its clones are registered in different places, occupy startup, disable the task manager, and paralyze the computer.

What to do to remove the Windows blocked banner

The hacker asks to send an SMS or some amount to his phone number. Trusting users, even knowing that they have never visited pornographic sites and have not violated the Criminal Code of Russia, rush to comply with the requirements and transfer money or send SMS. A decent amount of money disappears from their account, resulting in a negative balance in four digits, and the banner remains in the same place, because it is a Trojan program disguised as a system message. You can remove the blocking in two ways: by involving a specialist or by yourself.

Unlocking Windows

There is a very funny solution to this problem. The unlocking code is hidden in the banner itself; it is encrypted in the phone number to which you want to transfer money. If you discard the first and last digits, then all the remaining ones will be the code. But such an easy solution is not applicable to all banners. Then you should try the following methods.

1 way

The most effective way to combat any viruses that have entered your computer is reinstalling the operating system. If for someone it is easier to reinstall the OS than to use other methods of removing the banner, then this is the best option, but it is too troublesome.

Method 2

Do you want to be smarter than others? Earn more? Read also:

  • ? Or maybe you know the answer?
  • . Let's see, let's try.
  • . It will be useful on the farm.

This will be a great article on how to unlock your computer. In this article there will be three options, one of which will definitely help you unlock windows. 1 Option

The easiest way to cure your computer if it is infected with a “banner virus” is to take the following steps to restore the system to a working state, we will do it like this:

  1. Reboot the computer in Safe Mode with command line support
  2. At the command prompt, enter the command
  3. When you start the window with Windows recovery, select the date on which We want to restore our Windows, click next and wait a while until it restarts the computer and restores it for the period you selected (it is better to choose a recovery date no more than a week ago from the incident)
  4. But this method, being the simplest and most effective, has its drawbacks, for example, if you did not initially have “ System Restore", then when you enter the command c:\WINDOWS\system32\Restore\rstrui You will receive an error:

System Restore is disabled and cannot be started in Safe Mode. To restore the system, restart your computer in normal mode and run System Restore."

This method, unfortunately, is not for you. But this is not the end of the world, because we are moving on to Option 2.

Option 2
This morning they brought a laptop on which, when loading, a window immediately appeared saying that windows was blocked. This trojan winlock not the same as it was before i.e. in which you had to enter a code (it could be obtained on the Kaspersky and drweb websites). But let’s not go into theory, but let’s immediately move on to practice, i.e. to remove this crap.

    1. Initially we have winlock which blocked the computer with the following text:

Microsoft Security detected a violation of Internet usage Reason: You watched a movie containing gay porn. To unlock Windows you need to: top up your Beeline subscriber number 8-963-666-94-10 in the amount of 400 rubles. You can pay through the terminal for paying for cellular communications. After payment, on the issued terminal receipt. You will find your personal unlock code, which you must enter below.

Our next steps are:

  1. restart your computer in Safe Mode with Command Prompt support
  2. when the computer boots up and you see the command line, enter regedit and the registry editor starts for you
  3. We look for the item in the registry HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon
  4. and in it we look for the Shell line and check that we had only one entry there Explorer.exe(i.e. we delete everything Explorer.exe that is there!!!)
  5. Next, we reboot the computer and enjoy the loaded Windows

What problems could there be if this option did not work:

  1. If you did everything as I wrote, but nothing happens, then check the item in the same registry branch Userinit should only have one entry: C:\Windows\system32\userinit.exe, (we delete everything that is there)
  2. If it doesn’t work again, then you need to compare the userinit.exe file on the infected computer with the file on the working computer; it happens that another modification of the virus replaced the userinit.exe and Explorer.exe files. You need to check from a computer that has the same operating system (let’s say Windows xp SP3 is on a computer that caught the virus and compare files from a work computer that also runs Windows xp SP3). In order to have you in safe mode with command line support desktop loaded in the console (where you previously entered the regedit command) enter the command explorer, and then we look for the files userinit.exe which is located in the C:\Windows\System32\ directory and compare the files by size and creation date.

— if you still realized that these files were replaced, then I solved this problem like this:

1) these two files could be taken from the C:\Windows\System32\dllcache directory, or if you have a windows disk from which this operating system was installed, then it is located there in the I386 folder (under the name userinit.ex_ or just like there is userinit.exe)

2) replace the files and reboot the system.

I really hope that everything worked out for you by editing the registry and you didn’t have to fiddle with replacing files, there are just different situations and I immediately decided to describe all the methods.
Option 3

If you caught an SMS banner extorting money “for viewing and reproducing child pornography.” This type of banner is radically different from the one I described in Option 1, although the removal methods are partially similar

The banner text is:

Computer is locked

To remove the blocking, you need to pay a fine of 500 rubles to the Beeline phone number 89037310755. If you pay an amount equal to or exceeding the fine, an unlock code will be printed on the terminal’s fiscal receipt. You need to enter it in the field at the bottom of the window and click the “Unblock” button. After removing the blocking, you must remove all materials containing elements of violence and pedophilia. If the fine is not paid within 12 hours, all data on your personal computer will be permanently deleted, and the case will be sent to court for proceedings under Article 242 Part 1 of the Criminal Code of the Russian Federation. Restarting or shutting down your computer will immediately delete ALL data, including operating system code and BIOS, with no further recovery possible.

Removing this banner as I wrote above using the first option did not work, well, that’s good, because this method is very easy and simple.

Leaders in antivirus products such as dr.web and Kaspersky quickly responded to this situation and provided users with their assistance in removing this modification of the banner virus from their computers.

4 Option

There is a variety of this nasty thing that, after attempting to self-medicate the computer, launches a second virus that overwrites the boot area of ​​the disk and after rebooting you will see the following text on the black screen:

Which Windows installation would you like to log onto(To cancel, press ENTER) and I type 1 (or see the picture below)

Tips for protecting yourself from Trojan.Winlock

How to protect yourself from Trojan.Winlock?!?

To protect against this problem, and against problems in general with the computer, I can give a lot, but the most important ones that need to be observed for maximum computer protection are:

  1. Licensed copy of Windows-It is advisable that you have the operating system installed on your computer without various third-party tweaks and add-ons; it is better to use a licensed copy disk on which there is nothing other than Windows (i.e. those that are sold in stores).
  2. Antivirus— I take antiviruses very seriously and over the years only one brand has been recommended for me, this is Kaspersky. Yes, it sometimes slows down the computer, but it also makes up for its disadvantages with interest!
  3. Do not download programs from unknown sites - cracks, activations, audio books, games and other garbage, people without bothering start looking for them simply by typing a request into Yandex or Google and clicking on all the buttons where it says "download". My advice and I have already taught myself and everyone else too, if you want to download something, then use torrents, I use rutracker or nnm-club, there you can be at least half confident that the software there is proven.

Well, lastly, I will say that 90% of computer errors are located 50 cm from the monitor. Be vigilant and careful and you will never have problems. Good luck to everyone and write your questions if you can’t unlock windows, we’ll figure it out together.

Hello! Today I will write about how to remove a desktop blocker that appeared after the computer was infected with a virus that blocked Windows. And now you see a window in front of you that requires you to enter an unlock code, which you can buy by paying a certain amount after sending an SMS to the attackers’ number.

How to unlock Windows for free?

Nobody wants to pay money to unlock Windows. And if you pay money to the account indicated by the scammers, there is no guarantee that they will send you a Windows key that will be unlocked. Therefore, we will look at ways to unlock Windows for free:

Method 1 is to change the date in the computer's BIOS. For those who do not have a computer, I will try to explain how to enter the BIOS. There is a reboot button on the system unit - press it if the computer is turned on. If the computer is turned off, then turn it on. A couple of seconds after your computer starts booting, press and hold the DELETE key on your keyboard. If you have successfully logged in, the BIOS menu will appear on the screen with a blue background in English. In the BIOS you need to go to the Standard CMOS Features section, there will be a current date field, change the date to an earlier one. After changing the date, press Esc and you will be taken to the main menu. To save the data, select Save & Exit Setup, then press y to confirm saving. This method will help solve the problem with the windows blocker banner, but the virus still needs to be found and removed.

2nd method - go from your mobile phone or from another computer to the Doctor Web antivirus websites or Kaspersky and look in these sections for the unlock key.

The 3rd method is to find and remove the virus yourself. Sequence of actions: when loading Windows, press F8 and select boot in safe mode with command line support; a window will load into which we enter the regedit command, the registry will open, be careful DO NOT DELETE ANYTHING, go to the branch HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon and find the file on the right side called Shell; write down the path to it that is written there and click 2 times and erase this path; then enter explorere.exe into the command line and reboot, Windows will turn on without problems and without a blocking banner. Now follow the path that you wrote down and delete the file of this virus itself! This way you will remove the virus that has blocked Windows.

4th method - press F8 when loading Windows and try to start system recovery by selecting a restore point. After successful recovery, you need to remove the virus, run an antivirus program and scan the entire computer.

5th method - icons of these viruses are visible in the quick launch bar. When you hover the cursor over the icon, the file name is displayed, often consisting of a set of numbers. Use the search to find this file. You can't just delete a file like that. First, rename it, and then delete it, and don’t forget to empty the trash. And just in case, scan the system with an antivirus.

6th method - format the local disk on which Windows is installed. But this option will lead to the loss of data stored on the local disk. And this is the most radical way to deal with a system blocker; use it only if the above methods for unlocking Windows did not help.

How to remove the virus after unlocking? Download the cureit program, which removes Trojan blockers from Windows. Here is the link The virus is often registered in the C:\System Volume Information folder

As a rule, this is a Trojan from the Winlock family. It is easy to identify: if an image of a pornographic or, conversely, business nature appears on the screen, and the computer stops responding to commands, this is our client.

The banner often contains the message “Your computer is blocked” and an offer to send a paid SMS or deposit money to a specified account - supposedly only after this the harmful banner (and with it the blocking of the PC) will disappear. There is even a field in the image where you need to enter a special code, which should arrive after fulfilling the above requirements. The principle of operation of such malicious elements comes down to substituting Shell parameters in the operating system shell and leveling the functions of Windows Explorer

There are several generations of ransomware viruses. Some of them are neutralized in a couple of clicks, others require more serious manipulations. We will give methods that, using which, you can cope with any Trojan of this kind.

Method No. 1

Task Manager

This method will work against primitive Trojans. Try calling the regular task manager (key combination CTRL+ALT+DEL or CTRL+SHIFT+ESC). If this succeeds, find in the list of processes what should not be running and terminate it.

If the dispatcher is not called, you can also use the process manager via the Win+R keys. In the “Open” field, enter the word “notepad” and press ENTER - this will open the Notepad application. In the application window that opens, type arbitrary characters and briefly press the on/off button on your laptop or desktop PC. All processes, including the Trojan, will end immediately, but the computer will not turn off. While the virus is deactivated, you can find files related to it and eliminate them or perform an antivirus scan.

If you haven't had time to install antivirus software, you may ask: how to remove ransomware from your computer? In most cases, the offspring of the evil Winlock family sneak into the directories of some temporary files or temporary browser files. First of all, check the paths:

C:\Documents and Settings\directory containing username\ and

C:\Users\directory by username\AppData\Roaming\.

There, look for “ms.exe”, as well as suspicious files with a random set of characters like “0.277949.exe” or “Hhcqcx.exe” and delete them.

Method No. 2

Removing virus files in safe mode

If the first method did not work and Windows is blocked, what should you do in this case? There is also no need to get upset here. This means that we are faced with an advanced Trojan that replaces system components and blocks the launch of the Task Manager.

In this case, we will have to choose to work in safe mode. Restart your computer. When Windows starts, hold F8. From the menu that appears, select “Safe Mode with Command Line Support.”

Then in the console you should write: “explorer” and press ENTER - you will launch Explorer. After this, write the word “regedit” in the command line and press ENTER again. This will open the registry editor. In it you can find the records created by the Trojan, and also the place from where it autoruns.

The paths to the files of the malicious component will most likely be in the Shell and Userinit keys (in the first it is written explorer.exe, and in “Userinit” it can be easily identified by a comma). The next procedure is as follows: copy the full name of the detected virus file with the right button to the clipboard, write “del” in the command line, then put a space and paste the copied name. ENTER - and you're done. Now you know how to remove ransomware virus.

We do the same with other infectious files.

Method number 3

System Restore

We boot the system in safe mode, as described above. In the command line we write: “C:\WINDOWS\system32\Restore\rstrui.exe”. Modern versions will also understand simply “rstrui”. And, of course, ENTER.

The “System Restore” window will pop up in front of you. Here you will need to select a restore point, or rather, the date before the virus hit the PC. It could be yesterday, or it could be a month ago. In short, choose a time when your computer was 100% clean and healthy. That's all for unlocking Windows.

Method number 4.

Rescue disk

This method assumes that you have time to download the software from another computer or go to a friend to get it. Although, perhaps, you have already acquired it with the foresight?

Special software for emergency treatment and system recovery is supplied by many developers directly in anti-virus packages. However, the rescue disk can also be downloaded separately - free of charge and without registration.

You can use ESET NOD32 LiveCD, Comodo Rescue Disk, or . All of these applications work on the same principle and can be placed on a CD, DVD, or USB drive. They automatically load along with the integrated OS (most often Linux), block the startup of Windows and, accordingly, malicious elements, scan the computer for viruses, remove dangerous software, and disinfect infected files.