New computer virus - be on alert

Status
Not open for further replies.
Joined
Aug 13, 2011
Messages
2,392
Location
Waveland, MS
This might belong in computers but since more people frequent this forum I thought I might pass this along.

If you haven't heard of the 'FBI virus' it is extremely malicious. Our computer just got infected this morning but it seems there is a starter and a catalyst to get it into full motion. The starter is through vulnerable programs like outdated java, adobe, internet explorer, etc. For this reason you should get all of these programs up to date. The catalyst is a drive-by downloadable, which means you can click onto a website and without knowing it just with your click you have acknowledged to download the malicious software.

Mine was the uber-scary "FBI black screen of death". It literally erases everything on your screen and shows you this message. The software locks your computer and says "your computer has been locked!" and proceeds to tell you that you have downloaded illegal material involving children or copyrighted software. It says to pay a fine to unlock your computer using MoneyPak. DO NOT PAY THEM!! This is a fake FBI virus, although it scares the crud out of you when you see it. The virus can attatch itself to any website.

If you are a surfer or webcrawler please take special precautions. I think our laptop will be out of service for a long while until we can figure out how to erase it. To tell you the truth I jsut want to shoot the laptop because it is so screwed up that I'm afraid to turn it on. There are ways to get rid of teh virus but it evolves and morphs to hide itself and also shuts off and/or grenades your antivirus and anti-spyware softwares. It also steals files (both cookies and documents), logs keystrokes, and steals bank information.

If you have been infected, IMMEDIATELY SHUT OFF YOUR COMPUTER AND DISCONNECT IT FROM ANY INTERNET CABLES OR LAN. If you must start your computer, do so in safe mode or start it and disconnect the wireless adapter (laptop) or ethernet (desktop). The virus will morph and get stronger if the computer is not in safe mode so be wary. Change ALL OF YOUR online PASSWORDS immediately using a clean non-infected pc. This includes your facebook, hotmail, paypal, ebay, craigslist, etc. Notify your bank of possible monkey business and keep a close eye on your accounts. This virus can happen to anybody and the target is very broad.

This is a very serious virus that has just effected us and now we are pretty much out a laptop until we can figure out how to disarm it in safe mode. The virus and its files are hidden on my pc and I cannot find the files to delete it. I've heard of cases where you can't even boot up safe mode to stop it.

Some more information can be found here :

http://krebsonsecurity.com/2012/08/inside-a-reveton-ransomware-operation/

and here :

http://www.fbi.gov/news/stories/2012/august/new-internet-scam
 
I got this a while back. I suspected I was hit when a google search result was not what I thought it would be, but was some goofy other search engine.

Don't boot it again, period. You get 2 or 3 boots then it toasts itself completely. Get a linux live CD and back up your files to a jump drive, then isolate that jump drive for a month. Reinstall your OS, get the updates and antivirus up to date, then when daring scan that jump drive. The month is to give the antivirus people time to update their patches.
 
Originally Posted By: eljefino
Don't boot it again, period. You get 2 or 3 boots then it toasts itself completely. Get a linux live CD and back up your files to a jump drive, then isolate that jump drive for a month. Reinstall your OS, get the updates and antivirus up to date, then when daring scan that jump drive. The month is to give the antivirus people time to update their patches.


What do you mean 'toasts itself'? Like the computer dies? Or the virus mutates...? I've heard of people having success with doing command prompts and safe mode but as I said I cannot find the files to disarm them. How would I go about with this linux method?

I don't think I got a disc with my laptop with the software on it, how would I reinstall the O/S, or could I just reboot from a prev system restore?
 
Last edited:
depends on what loader you get.

some are extremely easily removed as in.. just booting in safe mode and deleting the files.

others are extremely challenging to remove. I've seen both

one infected svchost.exe and was running as a process and even when it was detected it would just reload itself. Next time you ran windows.

if you have a "svchost.exe *32" chances are you have some bad stuff.
 
There are a couple of variations of this that have been around for a month or two. They do not let you do much and want you to pay a $200 fine. One video's you and says they are recording it.

I have removed this a couple of times for others. My tried and true method is to pull the harddrive, attach it to my laptop and run ESET and Malwarebytes. I have the $10 adapter that allows me to connect desktop & laptop EIDE & SATA drives as USB.
 
Glad I don't use Windows. Yes, nothing is immune but I'd rather have a lower chance of getting something than the highest chance.
 
Originally Posted By: zerosoma
Originally Posted By: eljefino
Don't boot it again, period. You get 2 or 3 boots then it toasts itself completely. Get a linux live CD and back up your files to a jump drive, then isolate that jump drive for a month. Reinstall your OS, get the updates and antivirus up to date, then when daring scan that jump drive. The month is to give the antivirus people time to update their patches.


What do you mean 'toasts itself'? Like the computer dies?


It corrupts your data or file system or something.

A linux live CD, like ubuntu, will boot off the CD ROM. Not only is it a separate OS that virusses aren't designed for but it will connect to the internet or a USB drive and mount your internal hard drive, giving a chance to rescue your files.
 
I got this about a month ago - what worked for me was to boot into Safe Mode and then run System Restore from the Search System and Files Box under Start.

Perhaps this might be helpful/useful info as well. At the time the computer was infected, my wife was logged in on her account. The computer was pretty much froze, but I was able to Ctrl-Alt-Del and switch user to the Admin account. All was fine with this account. I then shut down, rebooted tapping the F8 key, then went to Safe Mode and logged into her account and ran System Restore. Nothing bad since.
 
Well it looks like it got the best of me. Did system restore in safe mode and now after a successful restore And log in all I get is a black screen. Does not connect to the Internet which is ok by me but safe mode still works fine with my original files. That means I can save my old files even if the computer doesn't work. I've been working at it all night and nothing but black shows up after I've logged in. Internet remains off - orange. There are programs running in the bkgrnd on the black screen seen with task manager but nothing overly suspicious. I can shut comp down and perform basic functions but desktop is gone. It destroyed my avast antivirus and spy bot did a thorough check and I saw it scanning TONS of malware... But only prompted me to remove Babylon and coupon printer. Our laptop physically is beat up pretty bad anyhow, and I spent too much time on it as it is. Maybe a blessing in disguise.
 
Last edited:
You'd think by now many of the security suite programs from the major players would have updated to block this virus...

Something else to remember...ALWAYS make sure you have ALL the WINDOWS security patches that arrive via windows update.... (not to be confused with your security suite updates!)

A LOT of folks ignore of forget about this thinking that as long as their security suite is up to date they are protected...NOT SO!
 
Interesting,glad I use Geswall on my XP computer,haven't used an antivirus program in 4 years now. All I do is once a month scan with Hitmanpro and Malwarebytes,both free by the way and never have any nasty stuff on my PC.
 
Originally Posted By: antiqueshell

Something else to remember...ALWAYS make sure you have ALL the WINDOWS security patches that arrive via windows update.... (not to be confused with your security suite updates!)


Lots of virusses cripple windows update, even if it's turned on go to http://windowsupdate.microsoft.com and go through it manually once in a while. If the installer says, jeez there's a problem and IDK what it is... you're infected.
 
System restore is not necessarily a safe solution to getting rid of viruses. In fact, there have been viruses known to live inside of your system restore points and restore themselves automatically if removed. One of the first things I do when I get a virus laden machine to fix is disable system restore and delete all restore points.

AVG makes a "rescue cd" that you can boot from and remove viruses without ever booting into windows or attaching your hard drive to another machine (risky).
http://www.avg.com/us-en/avg-rescue-cd
 
I got this virus and fixed my wife's laptop this am.

If you get it you can do a safe reboot and then create another admin account to work with your computer.

I tried Malware with no luck, restore point(no luck), Norton(no luck as it missed it), Norton extreme that built a bootable USB drive(no luck).

Finally installed Microsoft's free virus software and it took it off. Now back happy computing.
 
Status
Not open for further replies.
Back
Top