Australian Federal Police virus...

Hey guys, my PC is being blocked by Australian Federal Police virus and asks me to pay $100 in order to unlock my computer… What should i do…???
I searched this on google and got a site - (pcthreatremoval.net/australian-federal-police-virus-remove-australian-federal-police-from-pc-completely) which says it is fake and bogus kind of stuff… is it true…??? Why my Avst doesn’t blocked this one…??? Is this issue reallu serious…??? Plz help me out, i m really in a mess…

hi bob8585,

EDIT: Please remove the […] in your first post as it is a shortened invisible url to most users here; and has no safety reputation result from WOT (World Of Trust). If you wish to display the entire url in your first post, modify it to show hxxp://xxx.pcthreatremoval.net/australian-federal-police-virus-remove-australian-federal-police-from-pc-completely to make it inactive to protect other Avast users here. You do that by also removing the url brackets as well.

Whatever you do, do not pay the ransom. This rogue program is called ‘ransomware’ or ‘spyware’ and may be something a user may have installed thinking it was something else, and the authors of this program are in no way obligated to release or unlock your system should you decide to pay up.

IF you are able to enter ‘Safe Mode’ by tapping F8 repeatedly after the manufacturer screen just stops running and a blank screen appears with a blinking white cursor in the upper left corner of your screen, hitting F8 at that moment should get you to your admin account. Use the following programs to install there while in Safe Mode: Malwarebytes, OTL, aswMBR.exe, AdwCleaner.

Here: http://forum.avast.com/index.php?topic=53253.0

Read the entire topic to understand what you need to do, but start only with these four programs. Each will produce a log: attach each log using “Attachments and other options” below the reply/text box by clicking to open it.

Use your second computer to download and transfer the needed programs/logs to/from your sick computer. Using a USB flash stick will do this just fine for this purpose.

If you are not able to enter Safe Mode, do not worry, our malware experts have tricks up their sleeves you may never have heard of.

A malware expert has been notified. You may hear from him shortly or it may be a few hours. Please be patient.

thanks mchain for your help… ya, i didn’t paid this ransomeware… ya sure i will do the editing…

Thank you for removing the hidden url link. If I post a link here in the forum I think may lead to a possible infection for other Avast! users, I always modify that link. A good example of that would be: hxxp://www.avast.com where http is changed to hxxp to break the link. That is all that needs to be done.

If you can, logs are needed to prepare for the help you need. Help is forthcoming, and logs given ahead of time will help speed the cleansing process along.

What will happen is, when the malware expert steps in, he will be able to give you tasks to do using the programs you already have, to begin this process. Your fix will be unique and only safe to use on your system and no other. This specialised fix can only be done when the logs are provided. Even if you do succeed in removing the rogue software on your own, there is a high likelhood that malware still remains, and suggest submitting these logs to remove these remnants left over. Once the all clear is given, you can remove the downloaded software you got from here. Instructions for that will be given at the conclusion of your thread.

No Antivirus has 100% Detection or Protection…NO ANTIVIRUS!!! Not even avast…so dont fully rely on avast…have layered protection.

More ever,you must be self cautious of what you do and what you open and not to visit Porn sites. :slight_smile:

Tip:

Also you can use your computer via Safe Mode with command prompt.

then when a black CMD appears in safe mode type in explorer.exe and hit enter

Now you must be able to use the PC without the ransomware.

Monitoring, my recommendation would be to run RogueKiller first then follow up with OTL