Can't as the White Screen fills the whole screen you malwarebytes can't be started, and my variant has altered the HKLM Winlogon.
So the step didn't work, as I can't run programs while Windows is loaded. I am not going to use System Restore either as only like a couple of hours ago, I changed programs and data, I don't want the data reversed.
Don't worry, I will just repair the Windows registry key in question to have the path it is suppose to without loading Windows at all, The registry key is not to be deleted as doing so would make Windows useless.
I know why the White Screen appears, it is actually not meant to be like that even ehrn infected. It is because the Ransomware is trying to get to a web address to download the required UI, if it can't the user just get a White screen instead. Previous versions have other colours instead including Black or Blue.
Users with this are to please use a Malware removal guy to target and repair what is needed without altering the whole system. Just change what is required, leaving the rest if the system alone.
On testing one Ransomware variant I managed to screenshot, the White Screen lockout, this variant did not like my system so did not lock my system and deleted itself.
I ran Malware as advised on BS forum which picked up (Agent, Ransome & Vundo) trojans - my PC is running much better now. Thanks for the advice Quads (even if I did not follow it to the letter)
Can you tell me why Norton would not pick these up I have been running Norton for the past 5 years without a break.
Because you got it early on and the Ransomware in the wider family of Police Ransom (FBI, Met, Police, AFP, DOJ etc.) are not all Reveton, but also groups like Urausy and Uremtoo. Symantec for most would call Trojan.Ransomlock.**** (**** = the variant letter or gen).
All It takes is a timy change in the file make up to avoid detection by AV's, SONAR and Heuristics helps but you can't have a wide dertection otherwise I could imagine a lot more False Positives for legit / good files.
The same continual change of files has happened with Zeroaccess, TDSS (TDL) clones and mods.
This is not just one release of FBI ransom people have being seeing but may changes to files and even to the UI]
There is a FBI / Police thread by me in the Tech Outpost board on this forum showing a few different UI's that people see or have seen.