FBI VIRUS REMOVAL TUTORIAL using Rkill
Hello Lazy People!
You've got it. You've got the pesky little FBI Virus.
There's plenty versions out there, but the removal is simple.
Day to day I remove this virus from our client's computers about 3 to 4 times a day.
There is no word on where exactly this virus comes from, but it can be stopped.
Things you gonna need:
- RKill - From BleepingComputer.com
- Malwarebytes - From Malwarebytes.org
- Remote software (if the machine is not with you)
- Thumbdrive ( if the machine is with you)
Lazy Author Edit: (It seems the fastest, easiest way to remove this virus is to copy Rkill.exe to your startup folder on your pc, reboot, and it will run, this will stop the virus for you to scan and remove it.) Remember to remove Rkill from startup when you are done.
You are gonna need to go ahead and get Rkill over to the infected PC.
- Have the client reboot the machine into safemode with networking.
- Have the client go to teamviewer.com if you do not already have a remote access software installed on the machine. Install Teamviewer, have them give you the ID and Password. Transfer Rkill to their desktop.
- Run Rkill.
- Download Malwarebytes or Update and Run Malwarebytes
- Virus removed.
- Copy Rkill.exe to a thumbdrive
- Start the machine in safemode
- Copy Rkill.exe to the desktop
- Run Rkill.exe
- Download or Update and Run Malwarebytes
- Virus Removed.
If the FBI virus is the special kind of stupid, and it blocks you from safemode.
You are going to have to use a bit of skill. I have run into instances, as a matter of fact just before posting this removal tutorial, I had the instance where the FBI Virus blocked safemode.
I logged into another profile on the computer and removed it with ease. However if you do not have another profile and you too have run into this occurrence. You can follow these special steps:
- Power the Machine off
- Insert your thumbdrive with Rkill.exe in it. Preferably not behind a folder So it appears as e:/rkill.exe
- Boot your machine into safemode with command prompt by hitting f8 at startup
- Log into your machine, the Command Prompt will open
- type "e:" which should be the default drive letter for the Thumbdrive you put in
- type "rkill.exe"
- Rkill will run
- After it is finished running, You may have to hit CTRL-C, if not the E:\> will be sitting there.
- Change directories by typing "C:"
- type "Explorer.exe"
- This will pop up something that asks you if you want to run in safemode press yes
- Okay, so the purpose of this was not to remove the virus per say. This was to get Rkill to where it can do it's job.. We can now continue.
Since you are in SM with Command Prompt, you cannot start the network again. We want to click start >programs > Right-click Startup and press open
- Copy Rkill.exe into the startup folder
- Click Start > Run, Type msconfig
- This will open the startup menu, click the startup tab
- Uncheck everything but Rkill
- Press ok, reboot into regular windows.
- Rkill will run,
- When its done, Download or run and update Malwarebytes
- Virus Removed :)
Just an FYI, Rkill works on virtually any virus, or known Malware. It updates frequently so keep this little dude on a thumbdrive or on your domain somewhere.
Rkill was made by a guy named Lawrence Abrams. He is a martyr to us all!
Can I please get an effin follower or a comment PLEASE!
Oh btw.. Post a virus you think is unremovable I shall download it, and post a tut on how to remove it for Lazy People.
- Bleeping Computer - Technical Support and Computer Help
A free web based community and technical support forum for answering Technical Support, Computer Help, and Security questions asked by the Novice Computer User
Some people have contacted me since the creation of this tutorial.
They have complained that rkill.exe gets blocked as well.. Either by using it in USB or through startup.
Here is another useful tip.
If the virus presents itself, by means of an icon, or by a program. Right click on the icon and go down to properties.
Find the name of the program, for instance, wmdefender.exe
Rename Rkill to wmdefender, double click Rkill, and boom there ya go!