use windows defender
windows malicious software remover (MRT) worked for me. You might be able to download it form Microsoft and update it. I like defender also.
Get a Mac. You won’t have this problem.
Watch where you go and what you download to remove this. For the past three years this type of extortion ware has been infecting computers with false spyware removal programs and fake Anti-virus programs. THe authors who seem to be in China also put up fake websites advertising removal tools that just re-infect the computer.
Normally you can find the removal instructions on Symantec, McAfee, Trendmicro, AVG, F-Secure or one of the other Anti-Virus vendor websites. Also Microsoft’s Malware removal tool has been known to remove this type of infection.
http://www.softwarepatch.com/windows/microsoftvirusremoval.html
This has interesting non-technical things you should do, in addition to getting the technical problem fixed: http://www.bleepingcomputer.com/forums/topic227700.html
You probably need to put the hard drive in an external case, and then attach via USB or Firewire to a second system. Then, mount your drive, go into the location, remove the file, etc.
If you know the day of the infection erase every file that was made that day.
3. It is important you rename Combofix during the download, but not after.
4. Please do not rename Combofix to other names, but only to the one indicated.
5. Close any open browsers.
6. Close/disable all anti virus and anti malware programs so they do not interfere with the running of ComboFix.
-----------------------------------------------------------
* Very Important! Temporarily disable your anti-virus, script blocking and any anti-malware real-time protection before performing a scan. They can interfere with ComboFix or remove some of its embedded files which may cause "unpredictable results".
-----------------------------------------------------------
* Close any open browsers.
* WARNING: Combofix will disconnect your machine from the Internet as soon as it starts
* Please do not attempt to re-connect your machine back to the Internet until Combofix has completely finished.
* If there is no internet connection after running Combofix, then restart your computer to restore back your connection.
-----------------------------------------------------------
7. Double click on combo-Fix.exe & follow the prompts.
8. Note: Do not mouseclick combo-fix's window while it's running. That may cause it to stall
9. Please restart your PC, check how its running.
I thought this was a thread about prez Obeyme....
Get Root !
Download.com has a couple hundred thousand free downloads. AVG free 8.5 is a good choice if you can find it. They want you to buy the other program but keep going to AVG free. I have used it for years and it is better than norton, and the others I have used.
The most recent updates for MalwareBytes are able to remove this. Be sure you download updates before you run MBytes.
Turn off System Restore
When I used to use Windows, I’d set up my computer specifically so I could just zap the whole install and start over whenever I needed to. I found this much easier than pounding my head against the wall every few months. When Windows started to slow down, or if I had a problem, I’d format the Windows partiion on the HD. Then, I’d put the Recovery Disks in and start over from the beginning. Really didn’t take that long to do and I knew that when I was finished, I’d have a healthy computer.
Most of my data stayed on a separate partition anyway, and I always had backup copies of any programs I used regularly.
Those days have long passed since I started using Ubuntu.
I’ve been using Linux for two years now. You can boot up your computer with a Linux “live CD”. It does nothing to your Hard Drive and you can then save all the important files you really need on memory sticks or an external hard drive. Once you’ve backed up all the data you really want reinstall Windows. (Or , if you like, stay with Linux and become pleasantly amused at all the hardship others are having when a better choice is free for the taking)