Very often lately, programs of this kind are encountered that display a large inscription "Windows is blocked" on the screen and ask to top up someone's account or something else - such viruses are called Winlocker, their development/distribution is punishable by imprisonment for up to 5 years.
However, these programs are primarily designed for people who know practically nothing about computers. Very often, such "viruses" can be terminated in the Task Manager.
However, there are also those that block the Task Manager.
Oddly enough, blocking the Task Manager is very easy and even a novice programmer can do it. And if you are facing a Winlocker that hasn't even bothered with the Task Manager, then it was most likely developed by a pseudo-programmer or came to the attacker through an acquaintance.
If such a program does not block the Task Manager, it can simply be terminated and removed from the system. This is done simply - Press the key combination CTRL+ALT+DEL, the Task Manager will appear, go to the "Processes" tab and try to find this virus there.
But do not rush to terminate it, first select the item "Open file location", then kill the process and delete this file in the opened folder. Also, we recommend you clean the startup, since it is quite possible that the virus starts to multiply and put its "clones" into startup.
This is easy to do, open the START menu, then select the item "Run", in the window that appears, enter the word "msconfig" and click "OK". The system configuration window will open.
Go to the "Startup" tab and click the "Disable all" button, then check only the programs you need in the startup list and click the "OK" button. That's it, most likely this pseudo-virus will cease to exist and you will not see it again.
However, there are also more serious lockers that are a bit more difficult to deal with. Such lockers, as a rule, block everything possible. In this case, we advise you not to waste your time and simply start Windows in "Safe Mode". In this mode, Windows loads only the most necessary drivers and processes, ignoring Startup, etc. Unplug the computer from the power outlet or hold the power button for about 10-15 seconds, after which your computer will turn off.
After that, turn it on and immediately after pressing the power button, start pressing the boot mode selection key, usually these are the F12 or F11 keys, depending on your computer. Try restarting the computer this way several times until you hit the spot. Press keys starting from F8 and ending with F12 keys, as well as the DEL key. One of these buttons will 100% bring up the Windows boot mode selection menu.
Unblock the task manager when Windows is blocked
After starting Windows in safe mode, clean your computer of unnecessary files, update your antivirus, and clean the startup. After that, simply restart your computer and you're done, the locker should disappear. In case you cannot remove this locker, do not send SMS or do what the locker asks under any circumstances. Immediately take the computer to specialists or simply reinstall Windows, if possible.
By performing the actions that the Winlocker requires, you are thereby encouraging the attacker to continue spreading this virus. In addition, it is not uncommon for the Locker to continue extorting money, and this can go on indefinitely. And sometimes it happens that after performing the actions it requires, the Locker simply disappears from the system on its own, destroying all its traces, including destroying the computer's operating system.
Programs for your computer's security:
Good luck!