The Guardia di Finanza virus - How to remove?
The Guardia di Finanza virus is a ransomware program that blocks computer systems and displays bogus message accusing you for some law violations. It was designed by cyber criminals in order to get money from computer users. The program completely locks the infected system and does not allow to run any programs there. The Guardia di Finanza message states that you have been involved into distribution of pornographic content and because of that you must pay a fine.
As you may guess from the name, the Guardia di Finanza virus attacks computers located in Italy. The message body comes in Italian as well. Basically, you will be asked to pay 100 euros using Ukash payment system and as the massage states your system will be unlocked. Even if you were actually involved into distributing some copyrighted content, police would never use such means to collect the fines. The Guardia di Finaza virus is just one more scam that is used to rip you off.
Beware that the program can affect your computer protection level as it can disable your security tools and leave your system open for other programs to infiltrate. The Guardia di Finanza virus is a harmful program that you should stay away from. Do not pay anything if you received this message on your computer. Instead you have to remove the Guardia di Finanza virus from your computer as soon as possible. Follow the steps below to get rid of this annoying program:
1. Restart your computer, press F8 while it is restarting
2. Choose safe mode with networking
3. Launch MSConfig
4. Disable startup items rundll32 turning on any application from Application Data;
5. Restart your computer again.
7. Scan with http://www.2-viruses.com/downloads/spyhunter-i.exe to find the file and remove it.
If you cannot use Safe Mode, try rebooting into safe mode with command prompt. Here are steps how to do it:
- Reboot into safe mode with command prompt. The Guardia di Finanza virus should not be launched this time.
- Run regedit. Search for Winlogon.
- There will be a key labeled Shell under Winlogon. It should refer to Explorer.exe or be blank. If there is something else referring an executable in one of users folders, replace it with explorer.exe.
- Save changes, reboot to safe mode with networking.
- Run msconfig and disable all unnecessary startup entries. You should be able to reboot normally.
- Install and run http://www.2-viruses.com/downloads/spyhunter-i.exe. Scan with it the PC and delete the Guardia di Finanza virus executables it finds.