Service from Kaspersky to unlock Windows. Removing ransomware virus banners Can a computer banner be cured with Kaspersky

Winlocker (Trojan.Winlock) is a computer virus that blocks access to Windows. After infection, it prompts the user to send an SMS to receive a code that restores the computer's performance. It has many software modifications: from the simplest - "introduced" in the form of an add-on, to the most complex - modifying the boot sector of the hard drive.

A warning! If your computer is locked by a winlocker, under no circumstances should you send an SMS or transfer money to receive an OS unlock code. There is no guarantee that it will be sent to you. And if this happens, know that you will give the attackers your hard-earned money for nothing. Don't fall for tricks! The only correct solution in this situation is to remove the ransomware virus from the computer.

Self-removal of ransomware banner

This method is applicable to winlockers that do not block booting the OS in safe mode, the registry editor and the command line. Its principle of operation is based on the use of system utilities only (without the use of anti-virus programs).

1. When you see a malicious banner on your monitor, first turn off your Internet connection.

2. Reboot the OS in safe mode:

  • at the time of the system reboot, hold down the "F8" key until the "Additional boot options" menu appears on the monitor;
  • use the cursor arrows to select "Safe Mode with Command Line Support" and press "Enter".

Attention! If the PC refuses to boot into safe mode or the command line / system utilities do not start, try removing the winlocker in another way (see below).

3. At the command line, type the command - msconfig, and then press "ENTER".

4. The System Configuration panel will appear on the screen. Open the "Startup" tab in it and carefully review the list of elements for the presence of a winlocker. As a rule, its name contains meaningless alphanumeric combinations ("mc.exe", "3dec23ghfdsk34.exe", etc.) Disable all suspicious files and remember/write down their names.

5. Close the panel and go to the command line.

6. Type the command "regedit" (without quotes) + "ENTER". Upon activation, the Windows Registry Editor will open.

7. In the "Edit" section of the editor's menu, click "Find...". Write the name and extension of the winlocker found in autoload. Start the search with the "Find next ..." button. All entries with the name of the virus must be deleted. Continue scanning with the "F3" key until all partitions have been scanned.

8. Immediately, in the editor, moving along the left column, view the directory:
HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\Current Version\Winlogon.

The "shell" entry should be "explorer.exe"; the "Userinit" entry is "C:\Windows\system32\userinit.exe,".

Otherwise, if malicious modifications are detected, use the "Fix" function (right mouse button - context menu) to set the correct values.

9. Close the editor and go back to the command line.

10. Now you need to remove the banner from the desktop. To do this, enter the command "explorer" in the line (without quotes). When the Windows shell appears, remove all files and shortcuts with unusual names (that you did not install on the system). Most likely, one of them is the banner.

11. Restart Windows in normal mode and make sure you managed to remove the malware:

  • if the banner has disappeared - connect to the Internet, update the databases of the installed antivirus or use an alternative antivirus product and scan all sections of the hard drive;
  • if the banner continues to block the OS, use another removal method. It is possible that your PC was hit by a winlocker, which is “fixed” in the system in a slightly different way.

Removal using antivirus utilities

To download utilities that remove winlockers and burn them to a disk, you will need another, uninfected, computer or laptop. Ask a neighbor, friend or friend to use his PC for an hour or two. Stock up on 3-4 blank discs (CD-R or DVD-R).

Advice! If you are reading this article for informational purposes and your computer, thank God, is alive and well, still download the curing utilities discussed in this article and save them on disks or a USB flash drive. The prepared "first aid kit" doubles your chances of defeating the viral banner! Quickly and without unnecessary worries.

1. Go to the official website of the utility developers - antiwinlocker.ru.

2. On the main page, click the AntiWinLockerLiveCd button.

3. A list of links for downloading program distributions will open in a new browser tab. In the "Disk images for treating infected systems" column, follow the link "Download AntiWinLockerLiveCd image" with the number of the older (newer) version (for example, 4.1.3).

4. Download the ISO image to your computer.

5. Burn it to DVD-R/CD-R using ImgBurn or Nero using the "Burn disc image" function. The ISO image must be written in unpacked form in order to get a bootable disk.

6. Insert the disc with AntiWinLocker into the PC where the banner is rampant. Restart the OS and go into the BIOS (find out the hot key to enter in relation to your computer; the options are "Del", "F7"). Install the boot not from the hard drive (system partition C), but from the DVD drive.

7. Restart your PC again. If you did everything correctly - correctly burned the image to disk, changed the boot setting in BIOS - the AntiWinLockerLiveCd utility menu will appear on the monitor.

8. To automatically remove the ransomware virus from your computer, click the "START" button. And that's it! No other actions are needed - destruction in one click.

9. At the end of the removal procedure, the utility will provide a report on the work done (which services and files it unblocked and cured).

10. Close the utility. When you reboot the system, go back to the BIOS and specify the boot from the hard drive. Start the OS in normal mode, check its performance.

WindowsUnlocker (Kaspersky Lab)

1. Open the sms.kaspersky.ru page (Kaspersky Lab's official website) in your browser.

2. Click the "Download WindowsUnlocker" button (located under the inscription "How to remove the banner").

3. Wait until the boot disk image of Kaspersky Rescue Disk with the WindowsUnlocker utility is downloaded to the computer.

4. Burn the ISO image in the same way as the AntiWinLockerLiveCd utility - make a bootable disk.

5. Set the BIOS of the locked PC to boot from the DVD drive. Insert the Kaspersky Rescue Disk LiveCD and reboot the system.

6. To launch the utility, press any key, and then use the cursor arrows to select the interface language ("Russian") and press "ENTER".

7. Read the terms of the agreement and press the key "1" (I agree).

8. When the Kaspersky Rescue Disk desktop appears on the screen, click on the leftmost icon in the taskbar (letter "K" on a blue background) to open the disk menu.

9. Select "Terminal".

10. In the terminal window (root:bash) next to the "kavrescue ~ #" prompt, type "windowsunlocker" (without quotes) and activate the directive with the "ENTER" key.

11. The utility menu will be displayed. Press "1" (Unlock Windows).

12. After unlocking, close the terminal.

13. Access to the OS is already there, but the virus is still free. To destroy it, do the following:

  • connect the internet;
  • launch the "Kaspersky Rescue Disk" shortcut on the desktop;
  • update antivirus signature databases;
  • select the objects to be checked (it is desirable to check all elements of the list);
  • with the left mouse button, activate the "Perform object check" function;
  • if a ransomware virus is detected from the suggested actions, select "Delete".

14. After treatment, in the main menu of the disc, click "Turn off". At the time of restarting the OS, go to BIOS and set the boot from the HDD (hard drive). Save your settings and boot Windows normally.

Dr.Web Computer Unlock Service

This method is to try to force the winlocker to self-destruct. That is, give him what he requires - an unlock code. Naturally, you don't have to spend money to get it.

1. Copy the wallet or phone number that the attackers left on the banner to buy the unlock code.

2. Log in from another "healthy" computer to the Dr.Web unblocking service - drweb.com/xperf/unlocker/.

3. Enter the rewritten number in the field and click the "Search Codes" button. The service will automatically select the unlock code according to your request.

4. Rewrite/copy all codes displayed in the search results.

Attention! If these are not found in the database, use the Dr.Web recommendation to remove the winlocker yourself (follow the link posted under the message "Unfortunately, at your request ...").

5. On the infected computer, enter the unlock code provided by the Dr.Web service into the "interface" of the banner.

6. In case of self-destruction of the virus, update the antivirus and scan all sections of the hard disk.

A warning! Sometimes the banner does not respond to entering the code. In this case, you need to use another method of removal.

Removing the MBR.Lock banner

MBR.Lock is one of the most dangerous winlockers. Modifies the data and code of the master boot record of a hard disk. Many users, not knowing how to remove this type of ransomware banner, begin to reinstall Windows, in the hope that after this procedure, their PC will “recover”. But, alas, this does not happen - the virus continues to block the OS.

To get rid of the MBR.Lock ransomware, follow these steps (Windows 7 option):
1. Insert the Windows installation disk (any version, assembly will do).

2. Enter the BIOS of the computer (find out the hotkey for entering the BIOS in the technical description of your PC). In the First Boot Device setting, set "Cdrom" (boot from a DVD drive).

3. After the system restarts, the Windows 7 installation disk will boot. Select your system type (32/64 bit), interface language, and click the "Next" button.

4. At the bottom of the screen, under the "Install" option, click "System Restore".

5. In the "System Recovery Options" panel, leave everything as it is and click "Next" again.

6. Select the "Command Line" option from the Tools menu.

7. At the command prompt, enter the command - bootrec / fixmbr, and then press "Enter". The system utility will overwrite the boot record and thus destroy the malicious code.

8. Close the command line, and click "Restart".

9. Scan your PC for viruses with Dr.Web CureIt! or Virus Removal Tool (Kaspersky).

It is worth noting that there are other ways to treat a computer from a winlocker. The more tools you have in your arsenal to combat this infection, the better. In general, as they say, God saves the safe - do not tempt fate: do not go to dubious sites and do not install software from unknown manufacturers.

Let ransomware banners bypass your PC. Good luck!

Recently, computers have become infected with the so-called ransomware virus (Trojan.Winlock), to unlock which, it is proposed to send paid SMS. In this article, you will learn how you can get rid of this virus absolutely free. In situations where antivirus sites are not opening, download and run this utility.

1 way. For the case when Windows boots up and a banner appears on the screen.

The easiest way to get rid of a virus on your desktop is to go to the website of the antivirus software developer Kaspersky Lab and use the form to get an unlock key. A similar operation can be done by going to the Doctor Web website. After the banner disappears from the desktop, be sure to check your computer for viruses.

Sequencing:
  1. Go to the website of Kaspersky Lab or Doctor Web. and use the unlock key.

2 and the following methods, for cases where the UNLOCK KEY DOES NOT SUIT.

If a banner appears on the desktop when you turn on the computer, use the free virus treatment utility CureIt - Download, or the Kaspersky Virus Removal Tool Download These cleaning utilities can be run even if you already have another antivirus installed on your computer.

Sequencing:

Download and run the CureIt - Download utility, or Kaspersky Virus Removal Tool Download

3 way. For the case when Windows won't boot.

If, when you turn on the computer, instead of loading the operating system, an offer appears on the monitor screen to part with a couple of hundred rubles, boot the computer in safe mode. To do this, restart your computer and constantly press the "F8" key on your keyboard. After a few seconds, you will be prompted to select the Windows boot option. Select "Safe Mode with Networking". Next, get rid of the virus in one of the ways described above.

Sequencing:
  1. Boot in safe mode
  2. Delete using a key from one of the sites of Kaspersky Lab or Doctor Web.
  3. To restart a computer.
  4. Check your computer for viruses.

4 way. For the case when Windows does not boot in safe mode.

In a situation where you need to remove the banner from the desktop, and the operating system does not boot in either normal or safe mode, the best option would be either a second home computer or a neighbor's computer. If there are any, we do everything as in the "first or second method" Also, it will not be very bad if you have a LiveCD download LiveCD from Dr.Web, by booting from which you can check your computer for viruses. Almost all anti-virus programs with the latest updates cure the computer from the banner on the desktop.

Sequencing:
  1. Enter the unlock key using another computer, or by booting from LiveCD download LiveCD from Dr.Web, download LiveCD from Kaspersky Lab.
  2. Check your computer for viruses.

5 way to remove the banner.

For Windows 7: after pressing the Win + U keys, click on the link "Help with settings settings" - "Privacy Statement". Then go to step 5

  1. Once your computer starts, press the keyboard shortcut windows icon button + U
  2. Select the on-screen keyboard and click Launch.
  3. Click "Help" - "About"
  4. In the window that appears at the bottom, select "Microsoft Web Site"
  5. In the address field, rewrite http://devbuilds.kaspersky-labs.com/devbuilds/AVPTool/
  6. A save file window will pop up, save to your desktop.
  7. In the browser, click on the top "File" - "Open" - "Browse".
  8. Click "Desktop" on the left. At the very bottom "File type" - "All files"
  9. Find the downloaded program and run it.
  10. Select full scan.

6 way to remove the banner.

If the banner appears before the desktop loads, the screen is locked.

  1. Press Ctrl+Shift+Esc and hold until the task manager starts blinking.
  2. Without releasing the Ctrl + Shift + Esc keys, click on the task manager with the mouse " Remove task".
  3. In task manager, click "new task" and type " regedit"
  4. Go to HKEY_LOCAL_MACHINE /SOFTWARE/MicrosoftWindows NT/CurrentVersion/Winlogon
  5. Go to the right pane of the Registry Editor and check the two options “ Shell" And " userinit". The value of the Shell parameter must be " Explorer.exe".Userinit parameter - " C:\WINDOWS\system32\userinit.exe" (no spaces, always a comma at the end)!
  6. If the “Shell” and “Userinit” settings are OK, find the HKEY_LOCAL_MACHINE /SOFTWARE/Microsoft/Windows NT/CurrentVersion/Image File Execution Options key and expand it. If it contains a subkey explorer.exe, delete it (Right click => Delete).
  7. Restart your computer.
  8. Be sure to check your computer for viruses.

If unsuccessful, repeat this method in safe mode.

If none of the above methods helped you, you can contact our company by

How to unlock a computer from a banner? This question is asked by a huge number of users who have become victims of ransomware Trojans. A Winlock/MBRLock class virus blocks the operating system, accusing the user of distributing pornographic video content and offering to pay money (top up a certain account or mobile number) in exchange for Windows unlock code. Of course, there is no Windows unlock code on the receipt of the payment terminal and cannot be (that's why it's a scam). In order not to get into such a situation, you need to use licensed antiviruses from well-known laboratories (Kaspersky Lab, Dr.Web, Symantec), but since you are already in trouble, it will help you to select the Windows unlock code by the account / phone number displayed by the ransomware trojan.

Below are three online unlock services: Dr.Web and Kaspersky Lab. Also, a method for removing a ransomware banner using a boot disk with an antivirus is described in the case when Windows unlock code failed to pick up.

Dr.Web is a free computer unlocking service.

Online Windows Unlock Service.

The well-known Russian anti-virus laboratory Dr.Web offers free online computer unlock service. The Windows unlock code can be selected both by the account number and by the image of the ransomware banner window.

Windows Unlock Service provided by Kaspersky Lab

In addition to the highest quality anti-virus products, the Russian laboratory of Evgeny Kaspersky provides everyone, absolutely free of charge, with its computer unlock service Kaspersky Deblocker. I would like to note that users using the products of this anti-virus laboratory on their computer are reliably protected from any viruses and do not encounter the problem of infection or blocking Windows.

Pick up Windows unlock code on Kaspersky Deblocker

What to do if the service for unlocking computers did not help?

What to do, if computer unlock service couldn't help? Unfortunately, Windows unlock code it may not have been tritely installed by the developers of the virus, or, at the moment, it may not be known to anti-virus laboratories. In this case, the only way out is to treat the computer using a boot disk with an antivirus. In general, such a rescue disk can be recorded in advance and always be ready in case of infection with a ransomware Trojan. Indeed, on a locked computer it is no longer possible to visit anti-virus online services and pick up a Windows unlock code!

Kapersky Rescue Rescue Disk Desktop

If none computer unlock service did not help, the disk with the bootable antivirus Kaspersky Rescue Disk will help get rid of the annoying ransomware Trojan.

A similar article on the Dr.Web Live rescue boot disk is located.

And finally, the service for unlocking computers provided by the foreign laboratory Eset

One more computer unlock service provided by Eset Antivirus Lab, maker of the popular NOD32 antivirus. The Windows Unlock Service is available from the following link.

To get the code to unlock the computer, in the form proposed on the page, you must fill in the data: the phone number to which it is proposed to send sms and the text of the message displayed by the virus. Next, you need to click the "Choose code" button.

Download boot disk with NOD 32 antivirus.

If you could not find the Windows unlock code, use the NOD32 antivirus rescue disk.

Professional antivirus computer help

If you can’t unlock your computer from a virus, it will come to the rescue, which includes the visit of a specialist, infection analysis, removal of viruses and rootkits, system recovery and installation of a licensed antivirus.

Users who do not use reliable anti-virus protection for , may encounter the problem of blocking the loading of the computer or the Desktop by malware that need to send sms with text to a specific number to get an unlock code.

Never fall for sms scammers. The cost of a sent SMS is usually several hundred rubles, but the user does not always receive a code for this money (often SMS extortionists do not mean sending any codes at all), even more rarely the received code helps to unlock the system.

You can pick up such joy when browsing Internet pages of "doubtful" content, while you are invited to install a new version of the player or browser. The unsuspecting user agrees to the installation and thereby voluntarily installs the SMS virus on his computer.

Visually, these Trojans look like a f***ing banner window, a message about a pirated copy of your Windows, or a warning from the Ministry of Internal Affairs. Sample message text: " Windows is locked. To unlock, you need to send an SMS with the text 446412302876 to the number 3786. Attempting to reinstall the system can lead to the loss of important information and computer malfunctions”, often the user is simply intimidated by the collapse of the system and the loss of important data, which is not true. Trojan.Winlock also blocks the task manager, the system registry, the Internet (only access to anti-virus sites can be blocked).

Always install system components, codecs, browsers or programs only from official sources, for your convenience, our website contains special sections for downloading the necessary distributions from official sites.

So if you have a question: How to unlock a computer from a banner", then we offer you the opportunity to remove the banner from the desktop yourself. To do this, follow the links below to the special sections of anti-virus companies to get the code. On the site, when filling out the form, you will need to indicate what text you are asked to send, and to which number.

Windows unlock codes on antivirus company websites

  • Get an unlock code for a banner on the Kaspersky website;
  • Get the banner unlock code on the Doctor Web website;
  • Get the banner unlock code on the site NOD32

Update 2020

Unfortunately, the developers of these antiviruses have removed the ability to get a code to unlock a PC. Now, the actual way is to remove the ransomware banner using a bootable LiveCD. You can also use the Windows Unlocker utility on the Kaspersky Lab website.

Removing a banner with Windows Unlocker

Attention! Work Windows Unlocker may cause inoperability operating system.

Hello readers of the ComService company blog (Naberezhnye Chelny). In this article, we will look at ways to remove the banner from the desktop. This can occur not only because of visiting sites of erotic content, but also when using cracks or keygens downloaded from nowhere. Therefore, try to download software only from manufacturers' websites. If you got a suspicious file, do not be lazy and . Typically, such banners are called extortionists, as they require money from the user. It can be like sending an SMS to a short number or replenishing an account in an electronic payment system. Fraudsters usually write on such banners about the violation of the law by the user, for which they are required to pay a fine. In this article, we will tell you how to unlock your computer from such banners.

Article structure

Introduction

Using these services is easy, but there are no guarantees. You can spend a lot of time but still not unlock the system. But, you should definitely try.

To use, you need a device (other, tablet or phone) with Internet access. We go to any of the listed addresses. Let's take Kaspersky as an example.

In a special field, you must enter the phone number or account to which you want to transfer money. If you are required to send an SMS to a short number, then write down this number and the text to be sent separated by a colon. Then click Get Code

The search results will appear below. Choose your banner and try codes against it.

If you didn't find your banner, try Dr.Web or Eset. If this method did not help to remove the banner from the desktop, read on.

2. Use System Restore

The option is good if you have this feature enabled. If it was disabled, go to the next step.

In order to remove the banner from the desktop using system restore, restart the computer and press F8 several times when loading. If a list of devices from which boot is possible appears, select your drive ( or ) and continue pressing F8 again. You should see a similar picture below. You need to select System Troubleshooter highlighted by default

A window will open where you need to select the language, then the user. Next, there will be a window with a choice of several recovery options. Choose System Restore. Then select a restore point and return the state of the computer to that point in time. First, take the nearest restore point, if it doesn’t help, restore to an earlier one.

You can read more about how to use system restore.

3. Remove the banner from safe mode

Checking Dr.Web Cureit or equivalents

There are banners that are not active in . This must be used. To prepare for treatment, you need to download the Dr.Web Cureit utility on a healthy computer by opening the following link in your browser.

To remove the banner from the desktop by cleaning the registry, you need to check several points in the latter.

In the left part of the window, go to the address

HKEY_CURRENT_USER -> Software -> Microsoft -> Windows -> CurrentVersion -> Run

Go to the right side and delete all items except for one (Default) which has no value assigned. Right-click on the item and select Delete. With this action, we will remove the banner from Windows startup. (You can read how to manage the startup of Windows 7 and Windows 8 when the computer is in working order.)

All the above steps must be performed in the same section.

HKEY_LOCAL_MACHINE -> Software -> Microsoft -> Windows -> CurrentVersion -> Run

There are two more places to check.

HKEY_CURRENT_USER -> Software -> Microsoft -> Windows NT -> CurrentVersion -> Winlogon

In this, we check the absence of the Shell and Userinit items. If they are there, delete them.

HKEY_LOCAL_MACHINE -> Software -> Microsoft -> Windows NT -> CurrentVersion -> Winlogon

check the values ​​of the above items

shell=explorer.exe

Userinir = C:Windowssystem32userinit.exe, (comma required)

If the values ​​are different, we correct them for the correct ones.

We close the registry editor and, for reliability, we check the computer with a utility or if we did not check it before editing the registry.

After checking, we reboot in normal mode and check if the banner is removed.

4. We use Kaspersky WindowsUnlocker to remove the banner from the desktop

With this utility, you can disinfect all operating systems installed on your computer. It does automatically what we did manually in the previous paragraph. This utility is part of Kaspersky Rescue Disk.

You can download the image of Kaspersky Rescue Disk from the official website at the link

To write to a USB device, it is better to use the utility from the manufacturer

In the application window, use the Browse button to specify the path to the Kaspersky Rescue Disk image. Insert a USB drive into the computer and it immediately appears in the corresponding section. If it doesn't, select it manually.

Attention! Save all important data from your USB stick.

After all the settings, press the START button

The image will be written to the USB drive. If the process completes successfully, you will see the following window. Click OK and close the rescue2usb program

Now you need to boot from the prepared USB drive on the infected computer. To do this, insert the USB flash drive into the computer and reboot. When booting the computer, press F8 several times to call up a list of devices from which it can boot. Select the connected USB drive. (Maybe there will be two labels on this list suggesting booting from USB. Try one first, then the other). If you can’t boot from a USB flash drive, you need to set boot from a USB drive in the BIOS, You can read how to do this.

After all the settings, it will boot from the USB drive and you will see the following window. Any key must be pressed within 10 seconds

Select the desired language using the arrows on the keyboard

You must accept the license by pressing button 1 on the keyboard

Select the boot mode for Kaspersky Rescue Disk. If you do not have a mouse, choose text. In all other cases, select graphics mode

In the terminal, type windowsunlocker and press Enter

If you have selected text mode, then press F10 to close the menu that appears and type windowsunlocker in the line under the file manager. Press Enter

In order to remove the banner from the desktop, press 1

After all the manipulations, you must press 0 - Exit.

After unlocking the operating system, you need to update the Kaspersky Rescue Disk databases and run a full scan of your computer. To do this, open the main menu and select Kaspersky Rescue Disk. Click the Update tab and click Run Update. In this case, the Internet must be connected to computer

Go to the Object Check tab and select the checkboxes for all objects in the field 2. Click Run Object Check

Wait for the scan to finish and delete or disinfect found malicious files. Then reboot in normal mode and check if the banner is removed from the desktop.

5. Fix the boot record

If the virus is loaded immediately when you turn on the computer before the operating system logo appears, then this infection has changed the boot record of your drive.

You need to go to the Windows Recovery Console and try to restore the boot record.

To open the recovery console, you must press the F8 key at boot, as when choosing safe mode. When a window appears with a choice of download options. At the very top, the item selected by default will appear - Troubleshooting the system. Select this item by pressing Enter

A selection window will then appear. user and entering a password. Select a user and enter a password if any, and click Next.

Then a window with system recovery options will appear. There you can choose to restore the computer from an image (which is done in Windows) or execute (if it is enabled. See paragraph 3 of this article) and much more. You select the last item Command line.

In it, type BOOTREC.EXE /FixBoot

After you reboot and check if the banner is removed from the desktop.

6. Check the drive on a healthy computer

If you have the opportunity to check your drive on another computer do it.

Turn off your computer. Disconnect . In the off state, connect it to another computer. Boot up. Update the anti-virus databases and check the connected drive for viruses. I like this option the most because there is such an opportunity. If not, use the options above.

I hope it doesn't get to the point of reinstalling and it will help you which any of the items described above.

Conclusion

In this article, how to remove the banner from the desktop, we looked at a lot of ways to successfully unlock the operating system. The main thing we need to understand is that there is no need to send any SMS and replenish any accounts.

Of course, it is worth starting the unlocking process with the use of services provided by large antivirus companies. Such services are described in the first part of this article. The next best thing to use is System Restore to one, two, or three to go back. In general, the service can greatly help out in critical situations. I highly recommend turning it on and allocating a few gigabytes for it in the settings. If recovery did not work, then proceed to treatment at. Unless, of course, the virus blocks everything with its banner there.

If safe mode does not work, then Kaspersky WindowsUnlocker as part of Kaspersky Rescue Disk is an excellent solution. If possible, you can and should check your drive on a healthy car of your relative, friend or neighbor. Don't worry, the virus won't jump to another computer. If the virus has registered in the boot record, then try through the recovery console. If nothing helps (which is unlikely), then it is better to reinstall the operating system.

Video how to unlock a computer from a banner Thanks for sharing the article on social media. All the best!