Ransomware Help Needed!! - Locked Out of Computer

Discussion in 'Malware Help (A Specialist Will Reply)' started by cw88, Aug 16, 2012.

  1. cw88

    cw88 Private E-2

    Yesterday my laptop (running windows 7) got infected with what I've found out is Ransomware. It was either from a website or something I had downloaded, and a message popped up (filling the screen) with Confederation Suisse (I'm in Switzerland), and 'Polizei' 'Cybercrime Investigation Department' in the header, and then my IP and a message in German (which I don't understand) but says something like I've been visiting illegal websites and will have to pay 100CHF with Paysafecard to unlock it.

    From research I found variations of this from different countries, all with a similar looking message and wanting 100 dollars/euros/pounds (or the currency of the country they are in) to unlock it with Ukash or Paysafecard.

    I have not found any specific things about this Swiss version online, so have been following the UK/German/Ukash virus posts about it to try and remove it, but had no luck within the last day.

    So far from following instructions I've found I have:
    - Restarted in Safe Mode/ With networking: Both have the same message pop up after entering password and still locked out.

    - Gone into Safe Mode w/ Command Prompt, and checked the Shell folder, but it already says it's explorer.exe

    - I tried msconfig to see if something was running there, but also found nothing

    - I then managed to boot Windows Defender Offline from a cd - ran that and only found OpenCandy which I removed.

    - Managed to get into Command Prompt - ran explorer.exe and got the start menu etc.. I deleted everything in the Temp folder as suggested by someone and tried to restart but no luck. I did find some files which were created about the time it happened: Called 15599351loa24184.exe and then about 8 other files (at least one a .dll) all with bye9he10 in their name - but deleting them didn't seem to do anything.

    I then ran Malwarebytes, Avira and AVG overnight and again found nothing.

    - I have tried booting Kaspersky Rescue Disk 10 from a CD, but it was unable to update properly and said Databases were Corrupt, so was unable to scan using that.

    - I am just trying Dr. Web Live CD - booted from a CD but it doesn't seem to open the scanner when I click on it.

    I am now trying to find any other things I can use to boot from a CD to maybe help but not sure what the best ones are.

    Does anyone know how to get rid of this, or any other ways I can try and scan for it? It seems a bit different to all the similar posts I've found about it, as apart from those few files in the Temp folder nothing seems to be found.

    I'd appreciate any help anyone can give as I've been trying almost constantly for 1 day so far and it's really frustrating me now, and I need to be able to use my laptop.

    If I need to provide more information please let me know what to do.

    This is the screen that shows up:
    http://files.myopera.com/cwaddell27/albums/12458902/IMG_20120815_221204edt.jpg
     
  2. cw88

    cw88 Private E-2

    After about 30 hours of scans and trying to get rid of it, it seems to be gone now (fingers crossed). Eventually managed to remove it by running F-Secure Rescue CD which scanned the computer and found the infected file which let me start up normally (though a little slower than usual). I then ran Malwarebytes on Quick Scan which found 2 remaining files which were removed, and after restarting it still seemed ok. I'm now running a full scan to make sure it's gone. Hopefully this will be helpful to someone else if they get this.
     
  3. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Welcome to Major Geeks!

    We are happy to hear you were able to get it fixed.

    If you find that you still have any malware problems, please follow the instructions in the below link:

    READ & RUN ME FIRST. Malware Removal Guide
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds