I believe I became infected on 6/21/15. I remember looking at email from Big Lots, Swanson Products and Komando.com. I read the information guide on CTB-locker. I checked some rtfs and the file type was changed to nfrbbmh. I went to the Task Scheduler and deleted a job that pointed to a application file in the %TEMP% file which I also deleted. My questions are
Can I delete everything in the %TEMP% file. Is it all Unnecessary?
I used CCleaner, Malwarebytes (free version) and Windows Defender. They identified no viruses.
How can I delete the Ransom Screen? I did delete 2 files in the Document library.
I did the above on 6/22/15 and on 6/23/15, I got the Ransom Screen and see that the entries are back in the Document library. I got into my pc using safe mode to read more on this issue and post.