Computer RansomwareThis is a discussion on Computer Ransomware within the Open Talk forums, part of the General Information category; Well this is a new one for me. My wife was on the computer last night and generally surfing the ...
(#1)
| | Forum Regular
Posts: 709 Join Date: Aug 2009 Location: grapevine, Texas Real First Name: eldon Camera: nikon Can Others Edit My Photos: Yes iTrader Rating: 1 LIKES Received: 9 LIKES Given: 16 | Computer Ransomware -
04-07-2010, 12:52 AM
Well this is a new one for me. My wife was on the computer last night and generally surfing the net. I ran to the convenience store. When I got home she sat frustrated in front of the computer not knowing what to do. She told me that she was pulling up stuff on the new exhibit at the ft worth zoo so that we could take the niece and nephew when they came to visit. She clicked on the wrong site tried to click out but it was one of those opposite click things. Any way now her screen is green and there is a notice that a program has been downloaded and it violates EU law but for $400 dollars it will dismiss a potential law suit. Her screen is totally locked. It will not leave this screen. I can get into the computer under my user name. I ran the virus scanner again it detected this program as a virus but could not quarantine it. Now how the Heck do you fix this one?
Last edited by shutterfire; 04-07-2010 at 01:06 AM..
| | | | | Sponsored Links | Premium Members do not see Google advertisements. SIGN UP today and help support our community.
|
(#2)
| | Senior Member
Posts: 410 Join Date: Feb 2009 Location: Austin, TX, Texas Real First Name: J Camera: Canon Can Others Edit My Photos: Yes iTrader Rating: 0 LIKES Received: 0 LIKES Given: 0 |
04-07-2010, 01:18 AM
sounds like a variant of the 'green av' (just a guess) First of all don't pay... that threat is just silly.
Try logging in as her... while you have the shift key held down, this should stop any of the regular startup programs during logging in. Try the Anti virus program again and hopefully it can clean it up. Else...
Ctrl+alt+del and find a running process with any suspicious names... (when you find a process by that name, remember that exactly). After you killed the process, do a search on your disk for that exact filename... when you find it, delete it. Also install this Mike Lin's Home Page run it and disable anything that rings a bell with that filename of what you just deleted.
If not, can you post the exact message it gives you. Did you try fully restarting the computer?
Last edited by dryicerx; 04-07-2010 at 01:25 AM..
| | | |
(#3)
| | Forum Regular
Posts: 709 Join Date: Aug 2009 Location: grapevine, Texas Real First Name: eldon Camera: nikon Can Others Edit My Photos: Yes iTrader Rating: 1 LIKES Received: 9 LIKES Given: 16 |
04-07-2010, 01:44 AM
When I do a Ctr alt del reboot it goes back to the green screen and is locked. so can I find it from my user window? | | | |
(#4)
| | Senior Member
Posts: 410 Join Date: Feb 2009 Location: Austin, TX, Texas Real First Name: J Camera: Canon Can Others Edit My Photos: Yes iTrader Rating: 0 LIKES Received: 0 LIKES Given: 0 |
04-07-2010, 01:57 AM
You said your virus scanner detected it as a virus... but couldn't quarantine it. What's it's name?
(should have been the first thing I should have asked) | | | |
(#5)
| | Uber Poster
Posts: 3,355 Join Date: Feb 2009 Location: Plano, Texas Real First Name: Mark Camera: Canon Can Others Edit My Photos: No iTrader Rating: 3 LIKES Received: 137 LIKES Given: 197 |
04-07-2010, 02:06 AM
-Warning, unexpert help ahead -
If you can get into the computer can you just uninstall the program?
Will a system restore solve this?
Good luck!
For general surfing needs we have an older computer that I installed Linux on along with the Firefox browser and the Adblock Plus add-on. Knock on wood, no problems. | | | |
(#6)
| | Forum Regular
Posts: 709 Join Date: Aug 2009 Location: grapevine, Texas Real First Name: eldon Camera: nikon Can Others Edit My Photos: Yes iTrader Rating: 1 LIKES Received: 9 LIKES Given: 16 |
04-07-2010, 02:06 AM
I will have to look when I get home. Im not sure. I came up to the office to research it so I can fix it. | | | |
(#7)
| | Uber Poster
Posts: 2,160 Join Date: Oct 2006 Location: Hurst, Texas Real First Name: David Camera: Canon Can Others Edit My Photos: Yes iTrader Rating: 10 LIKES Received: 45 LIKES Given: 52 |
04-07-2010, 07:31 AM
Go to Malwarebytes and install this anti malware program. ITs free, and dont pay any attention to all the other junk CNET wants you to try. Try running in safe mode if you have to. That should solve your problem | | | |
(#8)
| | Member
Posts: 238 Join Date: Mar 2010 Location: Midland, Texas Real First Name: Wayne Camera: Canon T2i Can Others Edit My Photos: Yes iTrader Rating: 0 LIKES Received: 5 LIKES Given: 36 |
04-07-2010, 08:30 AM
Quote:
Originally Posted by David Whatley Go to Malwarebytes and install this anti malware program. ITs free, and dont pay any attention to all the other junk CNET wants you to try. Try running in safe mode if you have to. That should solve your problem | I second David's suggestion. If you can log in under your account, download malwarebytes, make sure and update it. Then run it...but change the default to run a COMPLETE scan.
Also knowing what anti virus program you have and what virus it detected would be of great help. Good Luck. | | | |
(#9)
| | Account Closed Per User Request
Posts: 417 Join Date: Dec 2009 Location: texas, Real First Name: doc Camera: canon Can Others Edit My Photos: No iTrader Rating: 2 LIKES Received: 0 LIKES Given: 0 |
04-07-2010, 08:46 AM
Start computer in Safe mode with networking
Go to Malwarebytes, download install and run.
Go to Combofix, download install and run.
Go to Superantispyware, download install and run.
Go to Spy-Bot, download, install and run.
Go to CCleaner, download, install and run.
Defrag, clean disk.
Find the any registry files that are left that don't belong, wipe them out.
Restart and you should be good.
If combofix fails, your hard drive is shot.
Don't do anything I just said above, do what Rich said below. 
Last edited by DSL_PWR; 04-07-2010 at 03:21 PM..
| | | |
(#10)
| | Uber Poster
Posts: 2,742 Join Date: May 2006 Location: Keller, Texas Real First Name: Rich Camera: A disposable from CVS Can Others Edit My Photos: Yes iTrader Rating: 0 LIKES Received: 84 LIKES Given: 14 |
04-07-2010, 09:23 AM
I can fix it. PM me.
You have to boot to safe, clean it and clean it from the system restore.
You said that you can boot to your user.....how about take her pics, music etc to a new user. Save the trouble running all the cleaning programs.
I can tell you how to do it, but it is a PIA.
Safe bets for software: HijackThis and Malware bytes. I wouldn't do anything else.
I think the screen you see is an overwrite of your desktop. Basically the program told your computer to use the green as the desktop.
Last edited by Rson; 04-07-2010 at 09:43 AM..
| | | |
(#11)
| | Senior Member
Posts: 280 Join Date: Jun 2008 Location: Houston, Real First Name: - Camera: Nikon Can Others Edit My Photos: No iTrader Rating: 0 LIKES Received: 0 LIKES Given: 0 |
04-07-2010, 09:31 AM
I don't trust any spyware removal tools anymore. I had a somewhat innocent looking spyware that would hi-jack my google searches and running some of the mentioned programs- Malwarebytes, etc. and got my computer back to normal....so i thought. A couple of days later I tried to log into our work's bank account from firefox and after putting in my log-in information, it took me to a "verification" page.
For a brief second i thought maybe there was a deleted cookie and the bank thought I had a different computer (my personal bank detects changed IP addresses) and the address above WAS actually from the bank, but as soon as i saw the information it was asking for - name, ssn, mother's maiden name, etc. I knew something was very wrong so i called the bank and in 30 seconds they shut down every single account we had.
At that point I disconnected my laptop from the internet, backed up my data, and reformatted the hard drive. If you have recovery disks or the Windows DVD, I suggest you do the same...it will get rid of the junkware you've accumulated over time as well. | | | |
(#12)
| | Only visiting this planet
Posts: 344 Join Date: Nov 2008 Location: McKinney, Texas Real First Name: Steve Camera: Olympus stuff Can Others Edit My Photos: Yes iTrader Rating: 1 LIKES Received: 11 LIKES Given: 47 |
04-07-2010, 02:16 PM
MalwareBytes is the way to go, my wife and daugher have both gotten this (several times each) and every time I can clean it with MalwareBytes and then I blacklist the site in my router so they cant go there anymore. | | | |
(#13)
| | Account Banned
Posts: 1,984 Join Date: Aug 2008 Location: Plano, Real First Name: Richard Camera: Canon 20D iTrader Rating: 0 LIKES Received: 0 LIKES Given: 0 |
04-07-2010, 06:55 PM
After you get this straightened out, make sure that you do regular system restore points on your computer. That was the only way that I was able to kill a trojan that I picked up from boston.com. | | | |
(#14)
| | Member
Posts: 115 Join Date: Mar 2010 Location: Edgewood, Texas Real First Name: Ricky Camera: Sony SLT-A77 w Tamron 18-250 Can Others Edit My Photos: No iTrader Rating: 0 LIKES Received: 4 LIKES Given: 15 |
04-07-2010, 07:04 PM
Mcafee has a program called Mcafee stinger that will get rid of it. McAfee Threat Center | | | |
(#15)
| | Forum Regular
Posts: 709 Join Date: Aug 2009 Location: grapevine, Texas Real First Name: eldon Camera: nikon Can Others Edit My Photos: Yes iTrader Rating: 1 LIKES Received: 9 LIKES Given: 16 |
04-08-2010, 03:35 AM
After 2 days got it straightened out. Thanks to all the help of fellow TPFers . Updated anti virus clean sweep x 2, it was an av virus, that disguised its self in windows movie maker. | | | | | Thread Tools | | | | Display Modes | Linear Mode |
Posting Rules
| You may not post new threads You may not post replies You may not post attachments You may not edit your posts HTML code is Off | | | | Google Sponsors | Premium Members do not see Google advertisements. SIGN UP today and help support our community.
| |
Copyright ©2004 - 2011, Abel Longoria - www.Pixtus.com
Powered by vBulletin® Version 3.8.7 Copyright ©2000 - 2012, vBulletin Solutions, Inc. |