Glock Talk Welcome To The Glock Talk Forums.
 |
12-26-2012, 09:14
|
#1
|
|
Senior Member
Join Date: Aug 2007
Location: NC
Posts: 1,261
|
FBI virus
Couple of months ago, I heard about the dreaded FBI virus. Well my laptop got hit the other day. Everything boots up fine, then it gets to a point that it locks everything up and all you have is a white fbi screen and an audio message repeating"you have violated federal law, etc...."
So how would I go about getting to a point where I could clean it up, it's highjacked my computer.
Funny thing, the other pc's I have have not been effected and they run the avg free program. This one is paid mcfee. How can I prevent this from happening to my other ones>
thanks bsa
|
|
|
12-26-2012, 09:24
|
#2
|
|
Senior Member
Join Date: Mar 2005
Location: Falling into Crime's Dinner Party.
Posts: 1,316
|
Download Malwarebytes on one of your other computers and save the download file to a CD or thumb drive.
Boot up the infected computer into Safe Mode (hold down the F8 key while it is booting up). Once the computer is in safe mode, copy Malwarebytes onto the hard drive from your CD or thumb drive. Install and run Malwarebytes.
Reboot your computer.
posted using Outdoor Hub Campfire
|
|
|
');
document.write(' ');
};
//-->
12-26-2012, 10:11
|
#3
|
|
Senior Member
Join Date: Aug 2007
Location: NC
Posts: 1,261
|
Quote:
Originally Posted by The Fist Of Goodness
Download Malwarebytes on one of your other computers and save the download file to a CD or thumb drive.
Boot up the infected computer into Safe Mode (hold down the F8 key while it is booting up). Once the computer is in safe mode, copy Malwarebytes onto the hard drive from your CD or thumb drive. Install and run Malwarebytes.
Reboot your computer.
posted using Outdoor Hub Campfire
|
thankyou!
|
|
|
12-26-2012, 12:50
|
#4
|
|
Senior Member
Join Date: Jul 2008
Location: Robertsville, MO
Posts: 6,513
|
If it won't even boot up in Safe Mode, you might have to download a rescue disc, like Avira.
__________________
NASM-Certified Personal Trainer
MCSE, DCSE, A+
The single biggest problem in communication is the illusion that it has taken place. George Bernard Shaw
|
|
|
12-28-2012, 11:02
|
#5
|
|
Senior Member
Join Date: Sep 2007
Location: Bremen, GA
Posts: 2,606
|
you will most likely need to use a rescue cd or hook that hdd up to another computer to scan. Remote regedit could also be used to kill the startup key. If you can get into safemode and not have it boot you are extremely lucky. The last couple that i have removed had both regular and safemode totally locked down.
|
|
|
12-28-2012, 11:44
|
#6
|
|
Senior Member
Join Date: Nov 2011
Location: Chesapeake, VA
Posts: 1,176
|
One of our users in the office gets this one repeatedly. We do a system restore and its gone with no loss of user files. I keep asking my firewall administrator to block it at the firewall but he hasn't followed through on that yet.
__________________
To preserve liberty, it is essential that the whole body of the people always possess arms, and be taught alike, especially when young, how to use them. Richard Henry Lee
|
|
|
12-28-2012, 12:37
|
#7
|
|
Senior Member
Join Date: Dec 2005
Posts: 4,824
|
Quote:
Originally Posted by Chesafreak
One of our users in the office gets this one repeatedly. We do a system restore and its gone with no loss of user files. I keep asking my firewall administrator to block it at the firewall but he hasn't followed through on that yet.
|
^This seems like the easiest solution, if you can just restore it to a date prior to infection and then run a few scans to be sure after it has been restored.
|
|
|
12-29-2012, 05:36
|
#9
|
|
RIP Jack
Join Date: Jan 2001
Location: Indiana
Posts: 27,775
|
and if none of the above works
http://www.ubuntu.com
Sorry, I had to.
Good luck getting this fixed.
__________________
The NRA will fight for your rights in the halls of Congress.
The Second Amendment Foundation will fight for your rights in the courts.
The GOA will send out a fax or press release saying they will not compromise.
Join the NRA and SAF today!
|
|
|
12-29-2012, 06:21
|
#10
|
|
NRA Life Member
Join Date: Jan 2005
Location: New Jersey...sucks
Posts: 29,482
|
Quote:
Originally Posted by BSA70
Couple of months ago, I heard about the dreaded FBI virus. Well my laptop got hit the other day. Everything boots up fine, then it gets to a point that it locks everything up and all you have is a white fbi screen and an audio message repeating"you have violated federal law, etc...."
So how would I go about getting to a point where I could clean it up, it's highjacked my computer.
Funny thing, the other pc's I have have not been effected and they run the avg free program. This one is paid mcfee. How can I prevent this from happening to my other ones>
thanks bsa
|
I have gotten rid of the FBI virus twice, using nothing but online instructions (good to have 2 computers) and free software. It wasn't hard. I used the instructions here: http://www.bleepingcomputer.com/viru...pak-ransomware
__________________
I deserve to lose a gunfight if I ever take gunfighting advice from James Yeager.
|
|
|
12-29-2012, 11:31
|
#11
|
|
more ammo
Join Date: Sep 2002
Location: Indiana
Posts: 1,536
|
http://portableapps.com/apps
this site has some antivirus/antispyware software which can run from a usb thumb drive.
I would download it onto a thumb drive, update it, then copy it onto your harddrive and run it from the harddrive. that way you have it on both the usb and the hard drive.
__________________
.
.
Explosives were used because officials believed the whale was too large to shoot. /// "that's celebratory gunfire." /// It began, as it so often does, with a drum circle.
|
|
|
12-29-2012, 11:43
|
#12
|
|
Member
Join Date: Dec 2012
Posts: 25
|
Quote:
Originally Posted by Chesafreak
One of our users in the office gets this one repeatedly. We do a system restore and its gone with no loss of user files.
|
By far the easiest way to solve the problem. I did this on two different machines - the first time I spent hours trying to purge the problem before coming across the system restore idea, and it worked straight away. The second time, I didn't mess with anything else, system restore fixed it immediately.
|
|
|
12-29-2012, 14:19
|
#13
|
|
Senior Member
Join Date: Nov 2003
Location: Coastal SC
Posts: 4,220
|
Some of the latest versions of the trojan ransom prevent boot up in safe mode, prevent successfully doing a system restore, and will not allow the infected computer to perform any function that would enable a scan from a flash drive or CD.
At this point what is likely required for removal is to install the infected hard drive as a non boot drive in another computer and then performing a removal scan using malwarebytes for instance.
These trojans are getting nastier and tougher to remove all the time and are fully capable of blowing right by many of the top rated AV programs.
|
|
|
12-29-2012, 14:45
|
#14
|
|
Senior Member
Join Date: Nov 2011
Location: Chesapeake, VA
Posts: 1,176
|
Quote:
Originally Posted by IndyGunFreak
|
I just converted another person from Windows to Ubuntu after they got the FBI virus last week. They got tired of paying for virus removal and asked me how to stop it. The downside to how many people I have converted to Ubuntu is I lose money because they don't need me anymore.
__________________
To preserve liberty, it is essential that the whole body of the people always possess arms, and be taught alike, especially when young, how to use them. Richard Henry Lee
|
|
|
12-30-2012, 04:47
|
#15
|
|
Senior Member
Join Date: May 2003
Location: West Michigan
Posts: 3,717
|
Not sure if the OP still has the problem, but for the sake of future searches, try this:
http://www.selectrealsecurity.com/remove-ransomware
__________________
Mike - A forum post should be like a skirt. Long enough to cover the subject material, but short enough to keep things interesting.
"It's not about the odds, it's about the stakes." - quake
|
|
|
|
Sponsored Links
|
Advertisement
|
|
| Thread Tools |
|
|
| Display Modes |
Linear Mode
|
Posting Rules
|
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts
HTML code is Off
|
|
|
All times are GMT -6. The time now is 04:54.
|
|
|