ArtsAutosBooksBusinessEducationEntertainmentFamilyFashionFoodGamesGenderHealthHolidaysHomeHubPagesPersonal FinancePetsPoliticsReligionSportsTechnologyTravel

FBI VIRUS REMOVAL TUTORIAL using Rkill

Updated on August 12, 2013

Hello Lazy People!

You've got it. You've got the pesky little FBI Virus.

There's plenty versions out there, but the removal is simple.

Day to day I remove this virus from our client's computers about 3 to 4 times a day.

There is no word on where exactly this virus comes from, but it can be stopped.

Things you gonna need:

  • RKill - From BleepingComputer.com
  • Malwarebytes - From Malwarebytes.org
  • Remote software (if the machine is not with you)
  • Thumbdrive ( if the machine is with you)

Lazy Author Edit: (It seems the fastest, easiest way to remove this virus is to copy Rkill.exe to your startup folder on your pc, reboot, and it will run, this will stop the virus for you to scan and remove it.) Remember to remove Rkill from startup when you are done.


You are gonna need to go ahead and get Rkill over to the infected PC.

Remotely:

  1. Have the client reboot the machine into safemode with networking.
  2. Have the client go to teamviewer.com if you do not already have a remote access software installed on the machine. Install Teamviewer, have them give you the ID and Password. Transfer Rkill to their desktop.
  3. Run Rkill.
  4. Download Malwarebytes or Update and Run Malwarebytes
  5. Virus removed.

Locally:

  1. Copy Rkill.exe to a thumbdrive
  2. Start the machine in safemode
  3. Copy Rkill.exe to the desktop
  4. Run Rkill.exe
  5. Download or Update and Run Malwarebytes
  6. Virus Removed.

If the FBI virus is the special kind of stupid, and it blocks you from safemode.

You are going to have to use a bit of skill. I have run into instances, as a matter of fact just before posting this removal tutorial, I had the instance where the FBI Virus blocked safemode.

I logged into another profile on the computer and removed it with ease. However if you do not have another profile and you too have run into this occurrence. You can follow these special steps:


  1. Power the Machine off
  2. Insert your thumbdrive with Rkill.exe in it. Preferably not behind a folder So it appears as e:/rkill.exe
  3. Boot your machine into safemode with command prompt by hitting f8 at startup
  4. Log into your machine, the Command Prompt will open
  5. type "e:" which should be the default drive letter for the Thumbdrive you put in
  6. type "rkill.exe"
  7. Rkill will run
  8. After it is finished running, You may have to hit CTRL-C, if not the E:\> will be sitting there.
  9. Change directories by typing "C:"
  10. type "Explorer.exe"
  11. This will pop up something that asks you if you want to run in safemode press yes
  12. Okay, so the purpose of this was not to remove the virus per say. This was to get Rkill to where it can do it's job.. We can now continue.

Since you are in SM with Command Prompt, you cannot start the network again. We want to click start >programs > Right-click Startup and press open

  1. Copy Rkill.exe into the startup folder
  2. Click Start > Run, Type msconfig
  3. This will open the startup menu, click the startup tab
  4. Uncheck everything but Rkill
  5. Press ok, reboot into regular windows.
  6. Rkill will run,
  7. When its done, Download or run and update Malwarebytes
  8. Virus Removed :)


Just an FYI, Rkill works on virtually any virus, or known Malware. It updates frequently so keep this little dude on a thumbdrive or on your domain somewhere.

Rkill was made by a guy named Lawrence Abrams. He is a martyr to us all!

Can I please get an effin follower or a comment PLEASE!

Oh btw.. Post a virus you think is unremovable I shall download it, and post a tut on how to remove it for Lazy People.

Breakthrough

Some people have contacted me since the creation of this tutorial.

They have complained that rkill.exe gets blocked as well.. Either by using it in USB or through startup.

Here is another useful tip.

If the virus presents itself, by means of an icon, or by a program. Right click on the icon and go down to properties.

Find the name of the program, for instance, wmdefender.exe

Rename Rkill to wmdefender, double click Rkill, and boom there ya go!

Comments

    0 of 8192 characters used
    Post Comment

    • Ashleign profile imageAUTHOR

      Ashleign 

      4 years ago

      I do not fully disagree with you. However the FBI virus has been mutated in certain respects. Creating a temporary profile sometimes will not work. However, doing it this way will work every time. I wanted this how-to to be with as less BS as possible. Users that are not accustomed to removing viruses, do not need complicated answers.

    • profile image

      Curt 

      4 years ago

      Just FYI.. The FBI Virus and similiars attack profiles, so by creating a temporary one, you can bypass the safe mode and use windows. (if it is the one that blocks safe mode, run Rkiller.exe then proceed

    • Ashleign profile imageAUTHOR

      Ashleign 

      4 years ago

      This sounds like a laptop, if not, a desktop with a webcam. I would suggest removing all thumbdrives, usb devices, printers, or scanners from the PC. Rkill, is just so you can kill the virus process, then use a program like Malwarebytes to remove it. RKill does not remove the virus. So most likely the virus is still there causing damage. If you would like, I can give you my skype ID and I could try to remote into it and repair it for you.

    • profile image

      AussieChica 

      4 years ago

      Hi, I just followed your tutorial on removing ransomware from my computer (thanks to an 8yr old and minecraft lol) I followed everything, put rkill in the startup, unclicked everything else, rebooted. My problem is this - After rebooting and logging into windows I get a black screen and a windows screen asking me what video capture device to use. I thought this might be the virus trying to utilize flash again by working around the kill program. I left it blank and clicked ok and the virus is back up and blocking everything again. Any thoughts? Thanks for your time.

    • Ashleign profile imageAUTHOR

      Ashleign 

      5 years ago

      I would consider copying it into the startup Programs folder, then restart the machine, it should run up front. Rkill does not delete the malware it just stops it, then you would run mbam to clean it off. Let me know how that turns out, and we will work through it together.

    • profile image

      devioudonut 

      5 years ago

      Hi, great guide. Rkill seems like a great tool wish I had known about it before.

      However, in this case after running rkill from usb and then typing explorer.exe the virus manages to take over again. Any ideas?

    working

    This website uses cookies

    As a user in the EEA, your approval is needed on a few things. To provide a better website experience, hubpages.com uses cookies (and other similar technologies) and may collect, process, and share personal data. Please choose which areas of our service you consent to our doing so.

    For more information on managing or withdrawing consents and how we handle data, visit our Privacy Policy at: https://hubpages.com/privacy-policy#gdpr

    Show Details
    Necessary
    HubPages Device IDThis is used to identify particular browsers or devices when the access the service, and is used for security reasons.
    LoginThis is necessary to sign in to the HubPages Service.
    Google RecaptchaThis is used to prevent bots and spam. (Privacy Policy)
    AkismetThis is used to detect comment spam. (Privacy Policy)
    HubPages Google AnalyticsThis is used to provide data on traffic to our website, all personally identifyable data is anonymized. (Privacy Policy)
    HubPages Traffic PixelThis is used to collect data on traffic to articles and other pages on our site. Unless you are signed in to a HubPages account, all personally identifiable information is anonymized.
    Amazon Web ServicesThis is a cloud services platform that we used to host our service. (Privacy Policy)
    CloudflareThis is a cloud CDN service that we use to efficiently deliver files required for our service to operate such as javascript, cascading style sheets, images, and videos. (Privacy Policy)
    Google Hosted LibrariesJavascript software libraries such as jQuery are loaded at endpoints on the googleapis.com or gstatic.com domains, for performance and efficiency reasons. (Privacy Policy)
    Features
    Google Custom SearchThis is feature allows you to search the site. (Privacy Policy)
    Google MapsSome articles have Google Maps embedded in them. (Privacy Policy)
    Google ChartsThis is used to display charts and graphs on articles and the author center. (Privacy Policy)
    Google AdSense Host APIThis service allows you to sign up for or associate a Google AdSense account with HubPages, so that you can earn money from ads on your articles. No data is shared unless you engage with this feature. (Privacy Policy)
    Google YouTubeSome articles have YouTube videos embedded in them. (Privacy Policy)
    VimeoSome articles have Vimeo videos embedded in them. (Privacy Policy)
    PaypalThis is used for a registered author who enrolls in the HubPages Earnings program and requests to be paid via PayPal. No data is shared with Paypal unless you engage with this feature. (Privacy Policy)
    Facebook LoginYou can use this to streamline signing up for, or signing in to your Hubpages account. No data is shared with Facebook unless you engage with this feature. (Privacy Policy)
    MavenThis supports the Maven widget and search functionality. (Privacy Policy)
    Marketing
    Google AdSenseThis is an ad network. (Privacy Policy)
    Google DoubleClickGoogle provides ad serving technology and runs an ad network. (Privacy Policy)
    Index ExchangeThis is an ad network. (Privacy Policy)
    SovrnThis is an ad network. (Privacy Policy)
    Facebook AdsThis is an ad network. (Privacy Policy)
    Amazon Unified Ad MarketplaceThis is an ad network. (Privacy Policy)
    AppNexusThis is an ad network. (Privacy Policy)
    OpenxThis is an ad network. (Privacy Policy)
    Rubicon ProjectThis is an ad network. (Privacy Policy)
    TripleLiftThis is an ad network. (Privacy Policy)
    Say MediaWe partner with Say Media to deliver ad campaigns on our sites. (Privacy Policy)
    Remarketing PixelsWe may use remarketing pixels from advertising networks such as Google AdWords, Bing Ads, and Facebook in order to advertise the HubPages Service to people that have visited our sites.
    Conversion Tracking PixelsWe may use conversion tracking pixels from advertising networks such as Google AdWords, Bing Ads, and Facebook in order to identify when an advertisement has successfully resulted in the desired action, such as signing up for the HubPages Service or publishing an article on the HubPages Service.
    Statistics
    Author Google AnalyticsThis is used to provide traffic data and reports to the authors of articles on the HubPages Service. (Privacy Policy)
    ComscoreComScore is a media measurement and analytics company providing marketing data and analytics to enterprises, media and advertising agencies, and publishers. Non-consent will result in ComScore only processing obfuscated personal data. (Privacy Policy)
    Amazon Tracking PixelSome articles display amazon products as part of the Amazon Affiliate program, this pixel provides traffic statistics for those products (Privacy Policy)