How do I know if I'm infected with the Ransomlock virus/Am I infected with the Ransomlock...

  • Thread starter Thread starter Vincent Bengtsson
  • Start date Start date
V

Vincent Bengtsson

Hi!

I was browsing on the internet when suddenly when I opened a page in a new tab, it changed into a web page that looked like it came from the Police.

It said that they've noticed illegal online activity from me and that all my information on my computer is taken. It also said that I needed to pay 1000 SEK in penalty. (About 100€)



I unplugged my internet, and made sure my PC got a new IP address before I gave it online access again. Then I started searching around about this while scanning my computer for viruses, and apparently the virus is supposed to lock me out from my computer unless I didn't pay, but after a restart and a scan in Safe Mode with Notron Power Eraser, no message about my computer being locked down showed up. The only anti-virus program that found anything was AdAware. It found four cookies that it treated as virus and removed them.



So how do I know if I am infected with the Ransomlock virus? And if I am, is there a way to fully remove it without having to wipe my harddrive?




Thanks in advance!




//Vincent Bengtsson




P.S: This is the log from AdAware:


<?xml version="1.0"?>


<Summary>

<ScanInfo EndTime="20140703T165302.037776" StartTime="20140703T164624.037776" ScanType="Full" ScanMode="Manual"/>


<InfectedObjects>

<InfectedObject ThreatName="Cookie.DoubleClick" ThreatType="Virus" ObjectStatus="Deleted" InnerObject="" ParentContainers="" ObjectPath="C:\Users\Vincent\AppData\Roaming\Microsoft\Windows\Cookies\Low\1IUVUVKB.txt" ObjectType="Cookie"/>


<InfectedObject ThreatName="Cookie.TribalFusion" ThreatType="Virus" ObjectStatus="Deleted" InnerObject="" ParentContainers="" ObjectPath="C:\Users\Vincent\AppData\Roaming\Microsoft\Windows\Cookies\Low\BGMF51NX.txt" ObjectType="Cookie"/>


<InfectedObject ThreatName="Cookie.Xiti" ThreatType="Virus" ObjectStatus="Deleted" InnerObject="" ParentContainers="" ObjectPath="C:\Users\Vincent\AppData\Roaming\Microsoft\Windows\Cookies\Low\DDZQIHBH.txt" ObjectType="Cookie"/>


<InfectedObject ThreatName="Cookie.Advertising" ThreatType="Virus" ObjectStatus="Deleted" InnerObject="" ParentContainers="" ObjectPath="C:\Users\Vincent\AppData\Roaming\Microsoft\Windows\Cookies\Low\M6EDYEIT.txt" ObjectType="Cookie"/>

</InfectedObjects>

</Summary>

Continue reading...
 
Back
Top