Follow us on Twitter!
Follow us on Facebook!
 

Go Back   Pixtus - Photography Forum, Photographers, Photo Tips > General Information > Open Talk


Computer Ransomware

This is a discussion on Computer Ransomware within the Open Talk forums, part of the General Information category; Well this is a new one for me. My wife was on the computer last night and generally surfing the ...

Reply
 
LinkBack Thread Tools Display Modes
  (#1) Old
Forum Regular
 
shutterfire's Avatar
 
Posts: 709
Join Date: Aug 2009
Location: grapevine, Texas
Real First Name: eldon
Camera: nikon
Can Others Edit My Photos: Yes
iTrader Rating: 1

Likes Received LIKES Received: 9
Likes Given LIKES Given: 16
Computer Ransomware - 04-07-2010, 12:52 AM


Well this is a new one for me. My wife was on the computer last night and generally surfing the net. I ran to the convenience store. When I got home she sat frustrated in front of the computer not knowing what to do. She told me that she was pulling up stuff on the new exhibit at the ft worth zoo so that we could take the niece and nephew when they came to visit. She clicked on the wrong site tried to click out but it was one of those opposite click things. Any way now her screen is green and there is a notice that a program has been downloaded and it violates EU law but for $400 dollars it will dismiss a potential law suit. Her screen is totally locked. It will not leave this screen. I can get into the computer under my user name. I ran the virus scanner again it detected this program as a virus but could not quarantine it. Now how the Heck do you fix this one?

Last edited by shutterfire; 04-07-2010 at 01:06 AM..
Reply With Quote
Sponsored Links

Premium Members do not see Google advertisements. SIGN UP today and help support our community.
  (#2) Old
Senior Member
 
dryicerx's Avatar
 
Posts: 410
Join Date: Feb 2009
Location: Austin, TX, Texas
Real First Name: J
Camera: Canon
Can Others Edit My Photos: Yes
iTrader Rating: 0

Likes Received LIKES Received: 0
Likes Given LIKES Given: 0
04-07-2010, 01:18 AM


sounds like a variant of the 'green av' (just a guess) First of all don't pay... that threat is just silly.

Try logging in as her... while you have the shift key held down, this should stop any of the regular startup programs during logging in. Try the Anti virus program again and hopefully it can clean it up. Else...

Ctrl+alt+del and find a running process with any suspicious names... (when you find a process by that name, remember that exactly). After you killed the process, do a search on your disk for that exact filename... when you find it, delete it. Also install this Mike Lin's Home Page run it and disable anything that rings a bell with that filename of what you just deleted.

If not, can you post the exact message it gives you. Did you try fully restarting the computer?

Last edited by dryicerx; 04-07-2010 at 01:25 AM..
Reply With Quote
  (#3) Old
Forum Regular
 
shutterfire's Avatar
 
Posts: 709
Join Date: Aug 2009
Location: grapevine, Texas
Real First Name: eldon
Camera: nikon
Can Others Edit My Photos: Yes
iTrader Rating: 1

Likes Received LIKES Received: 9
Likes Given LIKES Given: 16
04-07-2010, 01:44 AM


When I do a Ctr alt del reboot it goes back to the green screen and is locked. so can I find it from my user window?
Reply With Quote
  (#4) Old
Senior Member
 
dryicerx's Avatar
 
Posts: 410
Join Date: Feb 2009
Location: Austin, TX, Texas
Real First Name: J
Camera: Canon
Can Others Edit My Photos: Yes
iTrader Rating: 0

Likes Received LIKES Received: 0
Likes Given LIKES Given: 0
04-07-2010, 01:57 AM


You said your virus scanner detected it as a virus... but couldn't quarantine it. What's it's name?
(should have been the first thing I should have asked)
Reply With Quote
  (#5) Old
Uber Poster
 
texkam's Avatar
 
Posts: 3,355
Join Date: Feb 2009
Location: Plano, Texas
Real First Name: Mark
Camera: Canon
Can Others Edit My Photos: No
iTrader Rating: 3

Likes Received LIKES Received: 137
Likes Given LIKES Given: 197
04-07-2010, 02:06 AM


-Warning, unexpert help ahead -
If you can get into the computer can you just uninstall the program?
Will a system restore solve this?
Good luck!

For general surfing needs we have an older computer that I installed Linux on along with the Firefox browser and the Adblock Plus add-on. Knock on wood, no problems.
Reply With Quote
  (#6) Old
Forum Regular
 
shutterfire's Avatar
 
Posts: 709
Join Date: Aug 2009
Location: grapevine, Texas
Real First Name: eldon
Camera: nikon
Can Others Edit My Photos: Yes
iTrader Rating: 1

Likes Received LIKES Received: 9
Likes Given LIKES Given: 16
04-07-2010, 02:06 AM


I will have to look when I get home. Im not sure. I came up to the office to research it so I can fix it.
Reply With Quote
  (#7) Old
Uber Poster
 
David Whatley's Avatar
 
Posts: 2,160
Join Date: Oct 2006
Location: Hurst, Texas
Real First Name: David
Camera: Canon
Can Others Edit My Photos: Yes
iTrader Rating: 10

Likes Received LIKES Received: 45
Likes Given LIKES Given: 52
04-07-2010, 07:31 AM


Go to Malwarebytes and install this anti malware program. ITs free, and dont pay any attention to all the other junk CNET wants you to try. Try running in safe mode if you have to. That should solve your problem
Reply With Quote
  (#8) Old
Member
 
CtrlAltDel's Avatar
 
Posts: 238
Join Date: Mar 2010
Location: Midland, Texas
Real First Name: Wayne
Camera: Canon T2i
Can Others Edit My Photos: Yes
iTrader Rating: 0

Likes Received LIKES Received: 5
Likes Given LIKES Given: 36
04-07-2010, 08:30 AM


Quote:
Originally Posted by David Whatley View Post
Go to Malwarebytes and install this anti malware program. ITs free, and dont pay any attention to all the other junk CNET wants you to try. Try running in safe mode if you have to. That should solve your problem
I second David's suggestion. If you can log in under your account, download malwarebytes, make sure and update it. Then run it...but change the default to run a COMPLETE scan.

Also knowing what anti virus program you have and what virus it detected would be of great help. Good Luck.

---------------------------
http://www.waynestratton.com/
Reply With Quote
  (#9) Old
Account Closed Per User Request
 
DSL_PWR's Avatar
 
Posts: 417
Join Date: Dec 2009
Location: texas,
Real First Name: doc
Camera: canon
Can Others Edit My Photos: No
iTrader Rating: 2

Likes Received LIKES Received: 0
Likes Given LIKES Given: 0
04-07-2010, 08:46 AM


Start computer in Safe mode with networking
Go to Malwarebytes, download install and run.
Go to Combofix, download install and run.
Go to Superantispyware, download install and run.
Go to Spy-Bot, download, install and run.
Go to CCleaner, download, install and run.

Defrag, clean disk.
Find the any registry files that are left that don't belong, wipe them out.

Restart and you should be good.

If combofix fails, your hard drive is shot.


Don't do anything I just said above, do what Rich said below.

Last edited by DSL_PWR; 04-07-2010 at 03:21 PM..
Reply With Quote
  (#10) Old
Uber Poster
 
Rson's Avatar
 
Posts: 2,742
Join Date: May 2006
Location: Keller, Texas
Real First Name: Rich
Camera: A disposable from CVS
Can Others Edit My Photos: Yes
iTrader Rating: 0

Likes Received LIKES Received: 84
Likes Given LIKES Given: 14
04-07-2010, 09:23 AM


I can fix it. PM me.

You have to boot to safe, clean it and clean it from the system restore.

You said that you can boot to your user.....how about take her pics, music etc to a new user. Save the trouble running all the cleaning programs.

I can tell you how to do it, but it is a PIA.

Safe bets for software: HijackThis and Malware bytes. I wouldn't do anything else.

I think the screen you see is an overwrite of your desktop. Basically the program told your computer to use the green as the desktop.

Last edited by Rson; 04-07-2010 at 09:43 AM..
Reply With Quote
  (#11) Old
Senior Member
 
Coogie's Avatar
 
Posts: 280
Join Date: Jun 2008
Location: Houston,
Real First Name: -
Camera: Nikon
Can Others Edit My Photos: No
iTrader Rating: 0

Likes Received LIKES Received: 0
Likes Given LIKES Given: 0
04-07-2010, 09:31 AM


I don't trust any spyware removal tools anymore. I had a somewhat innocent looking spyware that would hi-jack my google searches and running some of the mentioned programs- Malwarebytes, etc. and got my computer back to normal....so i thought. A couple of days later I tried to log into our work's bank account from firefox and after putting in my log-in information, it took me to a "verification" page.

For a brief second i thought maybe there was a deleted cookie and the bank thought I had a different computer (my personal bank detects changed IP addresses) and the address above WAS actually from the bank, but as soon as i saw the information it was asking for - name, ssn, mother's maiden name, etc. I knew something was very wrong so i called the bank and in 30 seconds they shut down every single account we had.

At that point I disconnected my laptop from the internet, backed up my data, and reformatted the hard drive. If you have recovery disks or the Windows DVD, I suggest you do the same...it will get rid of the junkware you've accumulated over time as well.
Reply With Quote
  (#12) Old
Only visiting this planet
 
SJHester's Avatar
 
Posts: 344
Join Date: Nov 2008
Location: McKinney, Texas
Real First Name: Steve
Camera: Olympus stuff
Can Others Edit My Photos: Yes
iTrader Rating: 1

Likes Received LIKES Received: 11
Likes Given LIKES Given: 47
04-07-2010, 02:16 PM


MalwareBytes is the way to go, my wife and daugher have both gotten this (several times each) and every time I can clean it with MalwareBytes and then I blacklist the site in my router so they cant go there anymore.
Reply With Quote
  (#13) Old
Account Banned
 
Imagebuffet's Avatar
 
Posts: 1,984
Join Date: Aug 2008
Location: Plano,
Real First Name: Richard
Camera: Canon 20D
iTrader Rating: 0

Likes Received LIKES Received: 0
Likes Given LIKES Given: 0
04-07-2010, 06:55 PM


After you get this straightened out, make sure that you do regular system restore points on your computer. That was the only way that I was able to kill a trojan that I picked up from boston.com.
Reply With Quote
  (#14) Old
Member
 
texascbx's Avatar
 
Posts: 115
Join Date: Mar 2010
Location: Edgewood, Texas
Real First Name: Ricky
Camera: Sony SLT-A77 w Tamron 18-250
Can Others Edit My Photos: No
iTrader Rating: 0

Likes Received LIKES Received: 4
Likes Given LIKES Given: 15
04-07-2010, 07:04 PM


Mcafee has a program called Mcafee stinger that will get rid of it.

McAfee Threat Center
Reply With Quote
  (#15) Old
Forum Regular
 
shutterfire's Avatar
 
Posts: 709
Join Date: Aug 2009
Location: grapevine, Texas
Real First Name: eldon
Camera: nikon
Can Others Edit My Photos: Yes
iTrader Rating: 1

Likes Received LIKES Received: 9
Likes Given LIKES Given: 16
04-08-2010, 03:35 AM


After 2 days got it straightened out. Thanks to all the help of fellow TPFers . Updated anti virus clean sweep x 2, it was an av virus, that disguised its self in windows movie maker.
Reply With Quote
Reply

Tags
ransomware

Thread Tools
Display Modes

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is On
HTML code is Off
Trackbacks are On
Pingbacks are On
Refbacks are On



Visit Our Sponsors
 

Google Sponsors

Premium Members do not see Google advertisements. SIGN UP today and help support our community.

Copyright ©2004 - 2011, Abel Longoria - www.Pixtus.com
Powered by vBulletin® Version 3.8.7
Copyright ©2000 - 2012, vBulletin Solutions, Inc.