Results 1 to 3 of 3

Thread: Damsel in distress: West yorkshire police ransomware

  1. #1
    Junior Member
    Join Date
    Aug 2012
    Posts
    2

    Exclamation Damsel in distress: West yorkshire police ransomware

    To any knights or Ladies in shining armor:

    I am no pc whizz like some people here and ooh god i ask for help. I had the fright of my life as i was browsing suddenly this message just took over and locked my screen. it warned me that i had been watching illegal peado stuff and that the west yorkshire police had my IP number and locked down my pc. i had 4 hours to pay £100 fine via U-kash or my pc will burn in hell.
    So i freaked out a little inside of me (very unpleasant experience). As the work i do does not allow these sort of allegations - i'd be out of a career.

    so i called up the west yorkshire police... they were very kind and told me it is a ransom virus and not to pay anything. but that is were the help stopped. I have AVG 2012 (free version - up-to-date) and spybot and advanced systemcare (also up-to-date)- none of which have picked it up. i have downloaded 2 removal kits for this specific ransomware - they didn't work. i've downloaded hitman pro 3 and stopzilla (none detected it either). I have spent many hours installing, uninstalling and browsing the net for help. so i have followed instructions to manually delet it from 2 different websites (one being AVG)+ a youtube version- i couldn't find the registery file they were pointing out/looking for. but i deleted something that had the date implicated to when the pc got infected. nothing has worked.

    I have been told it looks like i have a newer version of this nasty piece of work. so now i'm waiting and hoping that an updated anti-virus version comes out.

    I can start the pc in safemode i don't know if my files (.doc, jpg, mov) have been encrypted.

    I have spent about 12 hours trying to solve the problem and it is a pain in the bum.

    is there anyone with an idea?

    Kind regards,
    A freakedout damzel Marie
    Last edited by tashi; 2012-08-11 at 20:54. Reason: Topic was moved from Security Alerts.

  2. #2
    Member of Team Spybot tashi's Avatar
    Join Date
    Oct 2005
    Location
    USA
    Posts
    30,961

    Default

    Hello magriff123,
    Quote Originally Posted by magriff123 View Post
    i have downloaded 2 removal kits for this specific ransomware - they didn't work.
    Downloading such one may pick up more infections from the malware authors.

    For someone to take a look at the system you could start a topic in the Malware Removal Forum and a volunteer analyst will advise when available.

    That is if you haven't requested assistance elsewhere and please bear in mind it is the weekend.

    First see that forum's FAQ which also includes instructions in post #2 on how to provide DDS/aswMBR logs, which are the logs used in the preliminary analysis.
    http://forums.spybot.info/showthread.php?t=288

    Quote Originally Posted by magriff123 View Post
    i've downloaded hitman pro 3 and stopzilla (none detected it either). I have spent many hours installing, uninstalling and browsing the net for help. so i have followed instructions to manually delet it from 2 different websites (one being AVG)+ a youtube version- i couldn't find the registery file they were pointing out/looking for. but i deleted something that had the date implicated to when the pc got infected. nothing has worked.
    If you start a new topic please provide a link back to this thread so that helpers are aware of that.

    Best regards
    Microsoft MVP Reconnect 2018-
    Windows Insider MVP 2016-2018
    Microsoft Consumer Security MVP 2006-2016

  3. #3
    Junior Member
    Join Date
    Aug 2012
    Posts
    2

    Default thanks

    thanks for the advice. will stop downloading and do what you have said. i know it is weekend and i hope you enjoy yours

Posting Permissions

  • You may not post new threads
  • You may not post replies
  • You may not post attachments
  • You may not edit your posts
  •