Announcement

Collapse
No announcement yet.

RCMP are after me!

Collapse
X
 
  • Filter
  • Time
  • Show
Clear All
new posts

  • RCMP are after me!

    well... to make my life already F-d... the wife turned on her laptop,
    when windows booted it skips right to a very authentic looking screen with a message from the RCMP
    saying that this computer is locked down due to violation of copyright protection laws and must pay the fine of 100$ to... drum roll....

    U-Kash.

    she called me at work cause there was an accompanied picture taken by what I thought was a deactivated webcam,
    of ME!! ... lying in bed all naked!!!

    what a freaky virus. http://www.brett-tek.com/?p=366

    this one looks like a total re-install of windows for this one.
    and maybe my wife should stop surfing porn... hehehe.
    HAF932 Mods
    C70 Mods

  • #2
    LMAO, now that is funny sorry bungs. poor attempt from that guy to get your money . as long as your spouce liked the picture and you format the pc you should be good
    Orange GT Build
    Orange V8 GT Build
    Ice Phoenix Build

    Comment


    • #3
      thats funny bungz

      you better cover up that webcam lmao

      Comment


      • #4
        I've never seen anything this pervasive... can't boot to safe mode.
        and bios won't even let me boot from CD or USB.

        BUT... physically removing the drive, plugging it into anther PC and giving her the full fisted format sure did the job.
        HAF932 Mods
        C70 Mods

        Comment


        • #5
          Bungz, you're having quite the run of bad luck lately man! Glad you got this one worked out!

          Comment


          • #6
            What A/V is running on that machine?
            Blue Dragon CM690 II an i7 - 960 x58 build
            OverKill HTPC - Red Team Build an AMD FX6100 with dual HD 5870's in crossfire.
            Canadian Amateur Modding Competition

            Comment


            • #7
              No anti virus can stop that Ransom ware.
              The new wave of it is pretty nasty.

              Comment


              • #8
                That sucks Bung, damn these nasty viruses
                "Casper B!"
                I7 3820 semi-k l Asus/Gigabyte R4E/X79-UP4 l 4x4gb Gskill Ripjaws Z 2133 l 2xGigabyte GTX670 Windforce OC l Asus Xonar DSX l Seasonic X1250 l XSPC D5/Daz D5 Vario l EX360 in p/p+2xCoolstream XTX 480 p/p/p l 2x560 AC Monsta p/p l 2xEK Uni-GPU Block Acetal l 2xBitfenix Recon 3D fan controller l Switch 810 matte black l
                50' Panasonic Viera Plasma ST50 l 7.1 Pioneer A/V Reciever l f@h 4 the future

                Comment


                • #9


                  Ah gosh. Boot kit / ransom ware.

                  I've dealt with many of these Bungz. If you're having a hard time getting rid of it feel free to PM me i'll give you some tricks and tools to get rid of it.

                  Alternatively , if you don't care about losing data secure erase the drive. It'll be okay.

                  Cheers man.

                  (my bad I just saw you wiped the drive.)

                  Also , after fresh install / restore go ahead and either install MSE "Microsoft Security Essentials" Or Ad-Aware Free

                  Both of these are free and work nicely for every day users *cough cough* ..women.
                  Last edited by Neo182; 05-25-2013, 11:55 PM.
                  Nova Stryker / Asus Z77 Sabertooth | Intel 3770K | Corsair Vengeance 1600mhz 32Gb | Crucial M5 240Gb | WD Black | Asus R9 390 Strix | CM Storm Stryker | BP Summit EF
                  Nova Polaris / Asus Maximus Gene VIII | Intel 6600K | Corsair Vengeance 3200mhz 16Gb | Intel M2 240Gb | Toshiba 2tb | EVGA GF 1070 | Fractal Node 804 | Swiftech Apogee XL2

                  Comment


                  • #10
                    ya, for some reason I had a 2010 version of Avast - so basically no A/V
                    I suspect this was another of those trojans attached to a fake adobe flash update.
                    Since I rarely use the lappy... I don't really care for it too well.

                    I am curious Neo what else you would have tried other than format.
                    HAF932 Mods
                    C70 Mods

                    Comment


                    • #11
                      Originally posted by bungwirez View Post
                      ya, for some reason I had a 2010 version of Avast - so basically no A/V
                      I suspect this was another of those trojans attached to a fake adobe flash update.
                      Since I rarely use the lappy... I don't really care for it too well.

                      I am curious Neo what else you would have tried other than format.
                      To remove this particular ransomware?
                      I've removed it by secure format.
                      I bypassed the activation with a flash website redirect (that has since been addressed by the original creator of this virus.)

                      Alternate (and simpler) methods
                      Rescue Disk via USB boot
                      Boot to safe mode (if you can re-worked version of this virus again...they might have changed the hook technique)
                      And remove it from msconfig + registry

                      Perhaps if this is your wifes or companions laptop and they don't do much actual important work on it you could opt to 'deep freeze' it.
                      Back in my highschool days when I was working the school network they used a program called deep freeze which would essentially do just that.
                      Anything you download / install would disappear upon reboot. You can set the date time of your choice So if you have email and the most recent windows updates and a good AV with latest def.
                      freeze it from that point , drop whatever files you want to keep onto an external or network attached storage solution.


                      Honestly , the best solution for you is probably just a clean install with latest updates , install Ad-aware free.
                      The phishing and hook techniques for Trojans and viruses today are very sophisticated.

                      From my end I understand the workings of javascript which is the most commonly used today to infect unsuspecting victims.

                      As you mentioned most of the time you get a pop up that says either "Java needs to be updated!" or "Flash needs to be updated click here to do that right now" and boom its all downhill from there.

                      Sometimes it even happens to me when im browsing tech websites , you get a flash banner that loads all by itself. BOOM! 2kb Trojan downloader wants to install.

                      So as you can see there's many ways that a single virus can 'defend' itself against 'attack' (removal)

                      That's why sometimes when you see a virus database you have 'variants'

                      Its essentially the same virus you started out with only with added code to become a little more sophisticated.

                      ie: complicate the users life and do everything to self replicate or deliver payload as intended - In this case make the person at the PC go get their wallet send them REAL money and get the credit card information and eventually steal that victims personal identity and so on...

                      That said , welcome to what I do for a living hahaha.

                      Virus removal and everything in between. Care to join me?

                      *laughs*
                      Nova Stryker / Asus Z77 Sabertooth | Intel 3770K | Corsair Vengeance 1600mhz 32Gb | Crucial M5 240Gb | WD Black | Asus R9 390 Strix | CM Storm Stryker | BP Summit EF
                      Nova Polaris / Asus Maximus Gene VIII | Intel 6600K | Corsair Vengeance 3200mhz 16Gb | Intel M2 240Gb | Toshiba 2tb | EVGA GF 1070 | Fractal Node 804 | Swiftech Apogee XL2

                      Comment


                      • #12
                        ok... thanks! good to know the Pro.
                        HAF932 Mods
                        C70 Mods

                        Comment


                        • #13
                          Originally posted by bungwirez View Post
                          I've never seen anything this pervasive... can't boot to safe mode.
                          and bios won't even let me boot from CD or USB.

                          BUT... physically removing the drive, plugging it into anther PC and giving her the full fisted format sure did the job.
                          Saw this thread too late, but FWIW:

                          Those that may encounter this issue you can do as what bungwirez did. Instead of formatting (if you have important data on your HDD), plug it into another PC and run a virus scan (make sure you update pattern files prior to the scan). It will pick up 1 or 2 (cannot remember the names) of the offending exe's and remove them. Once that is done, you can plug it back into your desktop/laptop and boot up into safe mode and perform a restore.

                          Restore your PC to a known date that it was still functioning from the list. Once that is complete, you can boot up back into normal mode and move all your important data. At this point you can actually use the desktop without any issues as the hooks will be removed and the virus non-functioning. BUT if you really want to have assurance then format the HDD once you've removed your important files off of it.

                          Cheers

                          Comment

                          Working...
                          X