Ransomware Virus: Your computer has been locked

September 2016


Ransomware Virus: Computer has been Locked

According to report, since 2013, this type of computer or file hijacking is on the rise.



What is Ransomware

Ransomware is a type of malware which restricts access to the computer system that it infects, and demands a ransom paid to the creator(s) of the malware in order for the restriction to be removed. Some forms of ransomware encrypt files on the system's hard drive, while some may simply lock the system and display messages intended to coax the user into paying.

Here are two window example:
  • Your PC is blocked due the violation of Copyright and Related Rights Law...

Cause of infections

  • These infections propagate through malicious advertisements (Malvertising) from streaming/downloads websites etc...
  • These ads lead to malicious exploits on websites to infect visitors.
  • Visitors running outdated software (Adobe Reader / Flash, Java) are prone to infection of these types.
  • Hence the importance of keeping up to date software.

A video of an exploit in action where the infection settles in simple visit to a Web site:


Disinfection


Microsoft Standalone System Sweeper Tool

Microsoft Standalone System Sweeper Tool is a tool provided by Microsoft that allows you to boot from a CD or USB stick and scan your computer with Windows Defender.This can be handy if Windows is locked by ransomwares/Trojan.Winlock.
  • Microsoft Standalone System Sweeper Tool can be downloaded from this link: http://connect.microsoft.com/systemsweeper
  • Tutorial Microsoft Standalone System Sweeper Tool: http://forum.malekal.com/microsoft-standalone-system-sweeper-tool-t36850.html
  • Download the program and run it.
  • Follow the instructions and choose if you want to install on CD or USB key.
  • When the USB key or CD is ready: Restart the computer and change the boot sequence (boot on Live CD or USB).
  • Proceed with scan
  • At the end of the scan, if you have detected items, click the "Clean PC".
  • Restart the computer normally to see if the infection is eradicated.

Kaspersky Live CD





Restoring the SafeBoot keys

If you are able to eradicate the infection, you must restore the SafeBoot, to be able to access Safe mode again:
Download and run this fix.

After disinfection

To remove other malware including adware or other unwanted programs that slow down the computer, it is recommended to:
Use AdwCleaner:
  • Download AdwCleaner (from Xplode) on your desktop.
  • Run the program and click [Delete] and then wait the time of the scan.

Use Malwarebytes Anti-Malware:
  • Download and install Malwarebytes' Anti-Malware.
  • Update.
  • Make a quick scan and delete all detected items via the "Delete selection" button .


Malwarebytes Anti-Malware is relatively efficient and can be kept for occasional scans (compatabile free version with all antivirus).

Related :

This document entitled « Ransomware Virus: Your computer has been locked » from CCM (ccm.net) is made available under the Creative Commons license. You can copy, modify copies of this page, under the conditions stipulated by the license, as this note appears clearly.