You are held hostage because this infection changes settings on your computer, so, when you launch an executable program, the infection launches instead! This happens, for example, when you try to launch Internet Explorer.
To overcome this, and remove the infection, try the following:
If the infection does not let you download files to the infected computer, download the files/programs requested below to a clean computer and then transfer them to the infected computer. You can use a USB flash drive, or other removable media (CD/DVD, external drive).
Please download FixNCR.reg:
Plug in the removable device into the infected computer and open the drive
Double-click on the FixNCR.reg file to open it
If prompted, allow it to merge with the Registry
You should now be able to run programs.
Now, download iExplore.exe, which is a renamed copy of RKill:
[If the file does not download, paste the following, >without the brackets<, in the address bar of your browser:
Save the file to the Desktop, and double-click on it.
Ignore any messages, and allow the file to run until the command window closes.
Without a reboot, download Malwarebytes’ Anti-Malware (black button with green and white icon) Save to the Desktop:
Double-click mbam-setup.exe and follow the prompts to install the program.
Run Malwarfebytes’ AntiMalware and update the program.
Once updated, select Perform Full Scan and click the scan button.
When the scan finishes, click OK in the message box, and you will see the results of the scan.
Click the Remove Selected button to get rid of the malware.
When Malwarebytes finishes, you may be prompted to reboot. If so, reboot.
Please post the >Malwarebytes log< in your reply so we can see where we are at, and plan any additional removal strategy.
Retired - Doin' Dis, Dat, and slapping malware.