Help getting rid of ransomware?

Associate
Joined
18 Oct 2002
Posts
325
Location
North
My mrs' dad, in his infinite wisdom, handed his laptop over to a nice gentleman in India (via teamviewer) who promptly installed some lockscreen ransomware on it :rolleyes:

I've been trying all day to clean it - easiest way probably would've been a format and reinstall, I was trying to avoid that as I don't have a windows CD or his key (being a Dell I'm presuming there's a recovery partition?).

Anyway, all the Windows repair options didn't work (startup recovery, safemode, system restore etc) so I got into boot discs (USB). I've tried BitDefender rescue disc which connects to net and updates and scans but finds nothing. I've tried TrendMicro's ransomware tool but it wouldn't connect to internet. Also tried Hitman Pro but that likewise wouldn't connect to internet.
I'm able to access the HDD using the bitdefender disc (Linux) - don't know linux but was hoping there's something else I could try? I tried running the Hitman Pro from Linux (as the net connection works with that) but it obviously doesn't work with a windows program.

Been at this all day, any suggestions?
 
On a Dell, I think if you tap F8 as it's starting up, you should get a repair menu somewhere (under advanced?). IIRC you can reset to factory from there.

What version of Windows is it? We might be able to point you in the right direction to download a copy which will then activate automatically as Dells store the CD key in the bios.
 
Thanks Craig, I'd tried restoring factory settings first and it still didn't get rid somehow! :(
I didn't realise that (re. license).

It was win8 originally but upgraded free to 10.
I'm in Linux on it now, just downloaded ClamAV but, being totally unfamiliar with Linux, I've no idea how to run it!
 
Is it a syskey?

I repaired one last week and ended up guessing the password as ther restore points were cleared.
 
I think it was a custom prompt window, popped up post bios, before Windows.
Just did a format & reinstall and it's all fine now thankfully (after 15hrs work! :mad: ).
 
Back
Top Bottom