Yahoo Answers is shutting down on May 4th, 2021 (Eastern Time) and beginning April 20th, 2021 (Eastern Time) the Yahoo Answers website will be in read-only mode. There will be no changes to other Yahoo properties or services, or your Yahoo account. You can find more information about the Yahoo Answers shutdown and how to download your data on this help page.

Anonymous
Anonymous asked in Computers & InternetSecurity · 8 years ago

Have ransomeware, it stopped appearing. Can no longer navigate to websites?

Got home from work and a dialogue box had popped up on my screen (i suspect someone was using my computer when i was away but that's another issue) it said something to the effect of "You must complete a survey to unlock your computer, after that everything will return to normal. See what happens if you don't" I at first didn't know what it was and tried to simply close it. It responded "This is warning number one, you only get two warnings, until your computer is unusable!" So i immediately went to the internet for an answer. I found out all about these "Ransomware" and how to get rid of them you must enter safe mode with networking by pressing f8 repeatedly on startup, then while in safemode download such programs as Malware bytes and avast. Yet despite having done this, the ransomware reappeared on my screen time and time again, i even went so far as to get Rkill, and restore my system to a backup from 7 months ago. (the only one i had lying around) Fed up i went to eat lunch. Upon my return i tried using all of the methods described at once in safe mode and then as soon windows logged in in "normal" mode i ran Rkill to stop the ransomware, but the website wouldn't load for me, and the ransomware pop up didn't reappear. I am still incapable of navigating to websites. My computer is now sluggish and unresponsive at times. So i am convinced other damage was done, but am incapable of fixing it. i have restarted my computer 2 more times and have yet to see that accursed ransomware pop up. So why cant i access any websites? Why is my cpu being consumed by just a couple of processes?

2 Answers

Relevance
  • 8 years ago
    Favorite Answer

    Since you can not access the Net with a browser - then seems useless to suggest downloading some removing software and/or website with removal information. Obviously you are using a friends PC to post this ?

    In your situation I would try a couple things but you will eventually probably need to use another computer to download some removal ware to run on it to attempt to regain the computer and clean it fully. There are a couple of antimalware downloads available that will run on a USB Drive that you install to that and then plug into the infected computer and run them to remove all malware. A USB Drive looks like the USB Media Stick that is just for like mp3 storage etc. You get the USb "Drive" that gives the capability to install and run software from it. Alternatively you could also burn to a DVD/CD and run from there. I will add links in the Sources section below.

    If you had real ransomware on your computer - it would have encrypted the entire disk with no way in except to install linux in dual boot and attempt to install legit encryption cracker software to try and bust the ransomware. Long shot at best. I have seen that software listing but would guess is extremely limited and probably not worth the try as what if the encryption, for fantasy example, is 100 bits and the linux ware is only 50. Out of luck. Real ransomware leaves a contact to get the code password or whatever to unlock the PC for a price they want. Whether true or not - rip off or not is a guess. What probably happened was a small payload package of a trojan or several possibly combined with a virus or several. Apparently you knocked some of the payload off, leaving some. Sounds like some fake ransomware type deal to dupe one. Ransomware goes after bucks like business people etc. It executes and encrypts the computer disk instantly and then pops up the instructions to regain the PC - period. That is a real ransomware successful attack. You don't get a second chance or are given some weirdo take a survey type game. That is what I mean - this is some type of really off-beat weird malware payload sounding like a prank if it was not dangerous malware though. http://www.microsoft.com/security/resources/ransom...

    Can you access PowerShell ? http://en.wikipedia.org/wiki/Windows_PowerShell

    Have you ever used the Command Prompt on Windows - DOS Command Prompt enviroment ? PowerShell is the next step up and Microsoft added not too long ago. Works about the same. Point is you may be able to install a quality antimalware and get rid all malware present. GET Emsisoft Antimalware - one of top 6 products in world no lie. Virtually always seen as detecting in the wild threats at VirusTotal.com - the 6 out of 33 top products worldwide - the rest miss. That's why I have used it for years and recommend it as a top performer.

    SEE

    http://www.howtogeek.com/138752/use-powershell-to-...

    Gives the idea of how to use PowerShell to install software just like you would from a browser.

    If not installed try here to install it from Microsoft:

    http://social.technet.microsoft.com/search/en-US?q...

    ADD http://www.hijackfree.com/en/

    BEST http://www.emsisoft.com/en/software/eek/

    SEE list of Portables here http://bluecollarpc.us/help-center/

    Good luck !

  • 8 years ago

    if all fails you may need a reinstall of windows or you can upgrade to win 7 or win 8 and install a good antivirus like kaspersky, cuz if you have ransomware on safemode you are doomed and this is your only option

Still have questions? Get your answers by asking now.