Malware Removal Instructions

  • Subscribe to our RSS feed.
  • Twitter
  • StumbleUpon
  • Reddit
  • Facebook
  • Digg

Thursday, 12 January 2012

Remove Strathclyde Police Ransomware (Uninstall Guide)

Posted on 16:31 by Unknown
Today we encountered ransomware that poses as a warning from the "Strathclyde Police" and asks to pay a fine for viewing illegal adult content. We believe this malware was created by the same group of cyber criminals who put some effort into distributing the Metropolitan Police ransomware. The back-end code is almost the same, except this time malware replaces explorer.exe instead of modifying Windows registry. And this time cyber crooks are targeting residents of Scotland. Upon execution, Strathclyde Police virus locks the computer and displays misleading warning claims you have been viewing adult content and asks you to pay a £100 fine via Ukash, Paysafecard or other legitimate online payment services.
Attention!!!
Under the laws of the United Kingdom and investigation of Metropolitan Police Service and Strathclyde Police Your computer is locked to prevent illegal activity in the network.

Your IP-Address "[removed]". From this IP address it was visited sites containing banned scenes of violence against people......Unsolicited Bulk messages was send from your computer's IP address and it was recorded by SpamHaus this month. The computer has been blocked to prevent your illegal activities on the Internet.


Ukash employees were already aware of such incidents and posted a short statement. They warned not to pay the 'ransom' by Ukash vouchers to remove virus and seek assistance from anti-virus companies and computer repair technicians. Ukash and Paysafecard are not in any way involved with this scam. We found out that Strathclyde Police ransom, as well as some other ransomware families were distributed using the Blackhole Exploit Kit. It seems to be the most popular crimiware kit nowadays.

Anyway, if your computer is infected with the Strathclyde Police ransomware, please do not follow the instructions on screen. To remove the virus from your computer, please follow the removal instructions below. The removal guide has been created to help you to remove this particular variant of Strathclyde Police ransom Trojan. Keep in mind that this removal guide may not work if you got updated of different variant of this malware. Just give it a try. If you have any questions, please leave a comment below. Good luck and be safe online!


Method 1: Strathclyde Police virus removal instructions using System Restore in Safe Mode with Command Prompt:

1. Unplug your network cable and manually turn your computer off. Reboot your computer is "Safe Mode with Command Prompt". As the computer is booting tap the "F8 key" continuously which should bring up the "Windows Advanced Options Menu" as shown below. Use your arrow keys to move to "Safe Mode with Command Prompt" and press Enter key.



2. Make sure you log in to an account with administrative privileges (login as admin).

3. Once the Command Prompt appears you have few seconds to type in explorer and hit Enter. If you fail to do it within 2-3 seconds, the Strathclyde Police ransomware will take over and will not let you type anymore.

4. If you managed to bring up Windows Explorer you can now browse into:
  • Win XP: C:\windows\system32\restore\rstrui.exe and press Enter
  • Win Vista/Seven: C:\windows\system32\rstrui.exe and press Enter
5. Follow the steps to restore your computer into an earlier day.

6. Download recommended anti-malware software (direct download) and run a full system scan to remove the remnants of Strathclyde Police virus.


Method 2: Strathclyde Police malware removal instructions:

1. Reboot your computer is "Safe Mode with Command Prompt". As the computer is booting tap the "F8 key" continuously which should bring up the "Windows Advanced Options Menu" as shown below. Use your arrow keys to move to "Safe Mode with Command Prompt" and press Enter key. Login as the same user you were previously logged in with in the normal Windows mode. Read more detailed instructions here: http://www.computerhope.com/issues/chsafe.htm



2.  When Windows loads, the Windows command prompt will show up as show in the image below. At the command prompt, type regedit and press Enter. The Registry Editor opens.



3. Locate the following registry entry:

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\

In the righthand pane select the registry key named Shell. Right click on this registry key and choose Modify.



Default value is Explorer.exe.



Change value data to iexplore.exe. Click OK to save your changes and exit the Registry editor.



Go back into "Normal Mode". To restart your computer, at the command prompt, type shutdown /r /t 0 and press Enter.



4. When Windows loads, there will be no icons. Don't worry, we will fix this soon. First, press Ctrl+Alt+Del or Ctrl+Shift+Esc and fire up Task Manager. Click File → New Task (Run...)



Type in iexplorer and click OK or press Enter.



5. Now, you need to download clean explore.exe file and over-write the infected one. Please make sure you download the file for your version of Windows:
  • Windows XP SP2
  • Windows XP SP3
  • Windows Vista SP2
  • Windows 7 SP1
Click on the link to download the file. Choose Save. Then browse to C:\Windows folder and select existing explorer.exe file. Click Save to over-write the malicious explorer.exe file.



6. Open up Task Manager once again. Click File → New Task (Run...) as you previously did. Type in regedit and click OK to open Registry Editor.



Locate the same registry entry outlined in step 3 of this removal guide.

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\

In the righthand pane select the registry key named Shell. Right click on this registry key and choose Modify. Delete iexplore.exe and type in Explorer.exe as it was before. Click OK to save changes.



Close Registry Editor and restart your computer.

7. Finally, download recommended anti-malware software (direct download) and run a full system scan. Remove found malware remnants and fix Windows errors. That's it! I hope this helps!

If your computer is still infected, please follow an alternate ransomware removal guide.

To learn more about ransomware, please read Remove Trojan.Ransomware (Uninstall Guide).
    Share this information with other people:
    Email ThisBlogThis!Share to XShare to FacebookShare to Pinterest
    Posted in Ransomware | No comments
    Newer Post Older Post Home

    0 comments:

    Post a Comment

    Subscribe to: Post Comments (Atom)

    Popular Posts

    • What is wrtc.exe and how to remove it?
      wrtc.exe - by Perion Network Ltd. What is wrtc.exe? wrtc.exe is a part of IncrediMail software, digitally signed by Perion Network Ltd. This...
    • Remove ShopperReports (Uninstall Guide)
      ShopperReports is defined as adware or a potentially unwanted program that displays marketing related results in a side pane of the browser...
    • Trojan.MBRlock, Внимание! Ваш компьютер заблокирован
      Trojan.MBRlock is a very disturbing piece of malicious code which infects the master boot record (MBR) and prevents Windows from starting. ...
    • False Positive: Ikarus and Comodo detecting TDSSKiller as a Trojan horse
      This awkward moment when you realize that your favorite rootkit removal utility is detected as malware. I probably wouldn't even have no...
    • Remove RiskTool.Win32.BitCoinMiner (Uninstall Guide)
      RiskTool.Win32.BitCoinMiner is a risk tool or potentially unwanted application that may use your computer's resources to generate bitco...
    • Remove Rattlingsearchsystem.com (Uninstall Guide)
      Rattlingsearchsystem.com is a ZeroAccess/Sirefef rootkit-related browser hijacker that redirects users to shady websites while searching on...
    • Remove TR/ATRAPS.Gen2, removal instructions
      Cyber crooks and third parties that buy stolen data are increasingly using more and more sophisticated techniques, in a variety of different...
    • Remove Ask Search and Ask Toolbar (Uninstall Guide)
      Ask Search and Ask Toolbar are very often incorrectly classified as virus/spyware that may cause search redirects. The majority of us pref...
    • How to remove 'TidyNetwork' adware virus from your computer
      As internet users most of us have seen those irritating little pop-up windows that are advertising something that we normally have little or...
    • Remove Windows Attention Utility (Uninstall Guide)
      Windows Attention Utility is a rogue security application that generates misleading warnings about nonexistent viruses and attempts to lure...

    Categories

    • Adware
    • Answers
    • Antivirus software
    • Browser Hijackers
    • Cloud Computing
    • Fake Alerts
    • Giveaways
    • Hoax
    • How-To
    • IaaS
    • Internet
    • Malicious websites
    • Malware
    • PaaS
    • Parental Controls
    • Passwords
    • Phishing
    • Process Information
    • Ransomware
    • Rogue programs
    • Rootkits
    • SaaS
    • Security Advisories
    • Spam
    • Spyware
    • Trojans
    • Viruses
    • Web Browsers
    • Worms

    Blog Archive

    • ►  2013 (173)
      • ►  December (6)
      • ►  November (13)
      • ►  October (11)
      • ►  September (20)
      • ►  August (4)
      • ►  July (17)
      • ►  June (31)
      • ►  May (25)
      • ►  April (15)
      • ►  March (17)
      • ►  February (7)
      • ►  January (7)
    • ▼  2012 (86)
      • ►  November (2)
      • ►  October (4)
      • ►  September (6)
      • ►  August (6)
      • ►  July (11)
      • ►  June (1)
      • ►  May (5)
      • ►  April (7)
      • ►  March (7)
      • ►  February (17)
      • ▼  January (20)
        • Youtube PREMIUM Player, Free Facebook Credits and ...
        • How to Remove Searchqu (Uninstall Guide)
        • Remove RiskTool.Win32.BitCoinMiner (Uninstall Guide)
        • Bitdefender Internet Security 2012 Giveaway! Hurry...
        • Antivirus Smart Protection and Malware Protection ...
        • Remove "Smart Protection 2012" (Uninstall Guide)
        • Remove "Internet Security 2012" Malware (Uninstall...
        • Temp:winupd.exe (Uninstall Guide)
        • Search.conduit.com (Uninstall Guide) - How To Remo...
        • PUP.CNET.Adware.Bundle (Uninstall Guide)
        • Remove Internet Security Guard (Uninstall Guide)
        • Remove Guardia di Finanza Ransomware (Uninstall Gu...
        • Remove Strathclyde Police Ransomware (Uninstall Gu...
        • Malicious Youtube Extension, YXH-youtube_player.xp...
        • Remove Audio Ads Virus (Uninstall Guide)
        • Msdcsc.exe Process Information
        • Remove EoRezo Adware/PUP (Uninstall Guide)
        • Remove BasicScan (Uninstall Guide)
        • Be A Guest Writer
        • Remove Tidserv Activity 2 (Uninstall Guide)
    • ►  2011 (239)
      • ►  December (8)
      • ►  November (18)
      • ►  October (21)
      • ►  September (24)
      • ►  August (28)
      • ►  July (32)
      • ►  June (16)
      • ►  May (23)
      • ►  April (15)
      • ►  March (16)
      • ►  February (9)
      • ►  January (29)
    • ►  2010 (2)
      • ►  December (2)
    Powered by Blogger.

    About Me

    Unknown
    View my complete profile