How to remove ! My Picture.scr

! My picutre.scr (check the spelling of picutre) is a trogen which will infect your computer and pendrive easily and it is very hard to remove or detect by an antivirus or antimalwares. When my computer was infected by this virus i tried to remove it with MSE and malwarebytes but both can't even detect this malware. So i googled through some pages and i have found out some clever way to remove this trogen which i am sharing with you guys.

> First open your windows OS in Safe Mode with networking (press F8 [win 7]when booting or restarting your computer)

>To show hidden files and folders:go to explorer> organize>folder and search option>show hidden files folder and drives> uncheck below three hide options and click apply

>Open Run from start menu or press Windows key +R

> Type msconfig click ok

>Select Startup tab
Warning: Take proper precautions after this step dont delete or remove systems file or functions

> Uncheck start up items which have a command/location C:\Program data\system 32 (its not on program files)

>Also uncheck any items with random long value (example :3ae4g456ijgx2klaselfdc47fcdc) and its command/location will look something like this C:\Users\username\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\3ae4g456ijgx2klaselfdc47fcdc.exe ; (red username is your computer name)
 or
C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup\3ae4g456ijgx2klaselfdc47fcdc.exe

>Delete System32.exe from C:\Program data\system 32.exe (Warning: Only delete system32.exe in this location  and other system32.exe file you delete causes crashing and formatting of your system)

>Then delete  "! My picutre.scr" from all root drives; that is go to the drive C, D, E, F, G etc or even your pendrive and manually delete "! My picutre.scr" by selecting the file and Shift+Delete.

>After that go to the locations which were we found out using msconfig
eg: C:\Users\username\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup
and 
or
C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup\

and delete those executable with random looking letters eg:
3ae4g456ijgx2klaselfdc47fcdc.exe

Cleaning Registry 
> Now go to run Windows+R
Type regedit
>Press Ctrl+F
>Type ! My picutre.scr
>enable all check box and click find next
>delete all the keys with ! My picutre.scr
>repeat the steps for the random letter executable also eg: 3ae4g456ijgx2klaselfdc47fcdc.exe

Comments

Popular posts from this blog

Convert excel files to .vcf for transfer of contacts from Pc to Andriod device

Compare two columns and get values from third parallel column in excel

Files not showing in pendrive