Jump to content


Photo
- - - - -

The fake FBI froze my computer and demanded $200 ramson for phony cyber crime offenses!


  • Please log in to reply
30 replies to this topic

#1 Johnnie

Johnnie
  • Members
  • 151 posts
  • Location:North-Eastcoaster with shovels for blizzards

Posted 29 July 2012 - 08:35 AM

Here's what happened. Out of nowhere unexpectedly, my computer was frozen and locked down by a virus. Fortunately I found free virus-killer-programs through Youtube, and the programs got my computer unfrozen and got me back online to write this warning post. Read all about the virus on Youtube:




#2 addy1

addy1

    water gardener / gold fish and shubunkins

  • Members
  • 15869 posts
  • Location:Frederick, Maryland zone 6b-7a

Posted 29 July 2012 - 10:24 AM

I have malwares running all of the time, it has caught a few viruses trying to hit my lappy.

live feed to our pond ....To see the cameras you must be on IE, if using firefox right click-- copy the link location paste in IE browser... .... .... My pond build thread

Live every day as if it is your last, enjoy it to the fullest, because one day it will sure will be.
post-2547-0-36263200-1313748028_thumb.jp

a good read about pond chemisty, ph, hardness etc


Frederick.gif

 


#3 Johnnie

Johnnie
  • Members
  • 151 posts
  • Location:North-Eastcoaster with shovels for blizzards

Posted 29 July 2012 - 04:45 PM

I have malwares running all of the time, it has caught a few viruses trying to hit my lappy.


Me too. I have the McAfee security program running all of the time, but the ramson-virus sneaked through :-).

The virus attack may be a blessing in disguise for me. For decades I have relied on McAfee to catch and stop viruses from entering my computers.
However, after the ransom-virus-attack, now in addition to McAfee, I'm using these 2 free anti-virus programs:

This program will catch the ransom-virus and remove it from you computer. (Sadly McAfee failed to do its job even after I had McAfee to scan for the virus.)
http://www.techspot....ti-malware.html


This program will clean up the left-over "skeletons" after the virus is removed
http://www.piriform....leaner/download

To learn how to use the programs, watch the Youtube embedded in my first post.

#4 j.w

j.w

    I Love my Goldies

  • Members
  • 12326 posts
  • Location:Arlington, Washington

Posted 29 July 2012 - 06:29 PM

Yep I use both Ccleaner and Malwarebytes along w/ Norton as my security program. Also use spybot search and destroy and sometimes use Superantispyware free edition.
http://www.gardenpon.../7985-jws-pond/


Live and let live and let nature be your teacher, respect the life of your fellow creatures Posted Image

zone 7



Posted Image

#5 Johnnie

Johnnie
  • Members
  • 151 posts
  • Location:North-Eastcoaster with shovels for blizzards

Posted 29 July 2012 - 07:04 PM

Yep I use both Ccleaner and Malwarebytes along w/ Norton as my security program. Also use spybot search and destroy and sometimes use Superantispyware free edition.


It's better late than never. I wish you had told me about Ccleaner and Malwarebytes before the ramson-virus attack :-) I will look into your other anti-virus programs ASAP. Thanks. Oh well, I've learned of the problem the hardway; thus, I posted the warning and info to you ponder guys.

#6 j.w

j.w

    I Love my Goldies

  • Members
  • 12326 posts
  • Location:Arlington, Washington

Posted 29 July 2012 - 10:08 PM

I wish I would have known that you were gonna need them. Darn that's a shame but glad you figured it out!
http://www.gardenpon.../7985-jws-pond/


Live and let live and let nature be your teacher, respect the life of your fellow creatures Posted Image

zone 7



Posted Image

#7 Fishylove

Fishylove
  • Members
  • 800 posts
  • Location:Southern Indiana, US Zone 6b

Posted 05 August 2012 - 04:27 PM

Lol you guy are funny :)

#8 passthekoi

passthekoi
  • Members
  • 5 posts
  • Location:maryland

Posted 17 November 2012 - 07:59 PM

I have already tried to enter SAFE mode (all three types,) and it bluescsreens on me

any other way to get back into my PC?
I tried using my WinXP CD but couldn't remember the admin password for system repair

THis is what I put together for another tecchie website

my primary PC has blocked windows from me, I am using my #2 PC to request assistance.

My primary PC is a Dell T3500, quad processor, 12Gb RAM running WinXP x64, I use AVG2012 for my Antivirus with scheduled automatic scans, and last MS update was 15Nov.
I am the only user on these PCs and as such the only user logon at bootup is mine. [and yes that logon is the admin)
( I use ccleaner occasionally to clear cache and unwanted start-up apps)


Last night after clicking on a link from a google search , I believe my PC was hacked.

a fake webpage appeared demanding $200 to release my computer, showing that it had captured my browser data .


I took the PC offline and attempted some simple troubleshooting steps, but the START menu would only stay available for ~20 seconds.
my desktop icons never appear, (only the desktop background) so had to navigate as quickly as possible form the START menu to launch
was able to get ccleaner to complete a scan and clean, (before the primary monitor went blank {white} and the app and taskbar disappeared)
likewise when launching AVG, the app window would disappear before the scan completed and after few seconds #1 monitor would go white.
I tried launching in two different SAFE modes, but the bootup would result in a bluescreen.
Was likewise able to navigate to the RESTORE point screen and launch that, but in two efforts {1 day back and one week back)
both came back as "unable to perform restore" and when clicking OK to accept that fate, the screen went white again.


After these multiple efforts the START menu and TASKBAR started disappearing more quickly, like ~5seconds making it impossible to navigate quickly enough to perform anymore troubleshooting efforts.

Presuming now, I'll need a bootable option that will allow me to perform fixes outside my windows (profile) environment.

#9 addy1

addy1

    water gardener / gold fish and shubunkins

  • Members
  • 15869 posts
  • Location:Frederick, Maryland zone 6b-7a

Posted 17 November 2012 - 09:28 PM

Try password for the winxp cd password. or blank

live feed to our pond ....To see the cameras you must be on IE, if using firefox right click-- copy the link location paste in IE browser... .... .... My pond build thread

Live every day as if it is your last, enjoy it to the fullest, because one day it will sure will be.
post-2547-0-36263200-1313748028_thumb.jp

a good read about pond chemisty, ph, hardness etc


Frederick.gif

 


#10 j.w

j.w

    I Love my Goldies

  • Members
  • 12326 posts
  • Location:Arlington, Washington

Posted 18 November 2012 - 01:07 AM

Posted Image passthekoi
Sorry you are having computer headache problems
http://www.gardenpon.../7985-jws-pond/


Live and let live and let nature be your teacher, respect the life of your fellow creatures Posted Image

zone 7



Posted Image

#11 passthekoi

passthekoi
  • Members
  • 5 posts
  • Location:maryland

Posted 18 November 2012 - 02:28 AM

really getting frustrated here,
tried using windows 7 native image burner
no joy
tried imgburn
no joy
and finally
iso burner
and still getting nowhere
refuses to burn to etiher CDs or DVDs
from both my new Windows 7 machine and an old win XP (PIII machine)

#12 addy1

addy1

    water gardener / gold fish and shubunkins

  • Members
  • 15869 posts
  • Location:Frederick, Maryland zone 6b-7a

Posted 19 November 2012 - 10:48 AM

Here is some net info on how to fix

http://www.prlog.org...r-computer.html

This one tells you how to modify your registry, have it on a screen next to your pc and follow. I have modified my registry in the past, just have to be careful


http://www.zimbio.co...te+FBI+Moneypak

http://www.2-viruses...-fbi-ransomware

http://www.callnerds.com/fbi-virus/

live feed to our pond ....To see the cameras you must be on IE, if using firefox right click-- copy the link location paste in IE browser... .... .... My pond build thread

Live every day as if it is your last, enjoy it to the fullest, because one day it will sure will be.
post-2547-0-36263200-1313748028_thumb.jp

a good read about pond chemisty, ph, hardness etc


Frederick.gif

 


#13 passthekoi

passthekoi
  • Members
  • 5 posts
  • Location:maryland

Posted 19 November 2012 - 10:41 PM

Thanks for your input.
I ended up finding a reputable online tech service that was able to walk me through loading an external windows environment from a flash drive and fix the issue remotely VERY early Sunday morning.

for anyone else falling victim to this FBI ransomware virus.
it dumps a file called .directory into your desktop folder and likewise loads it into your startup list... which then of course usurps your desktop control as soon as the startup is launched.
It likewise disables task manager.
if you can get to the startup listing before the screen goes white, just select and delete the file from startup ... (hopefully it isn't savvy enough to reload itself) and then reboot and navigate to your desktop folder and delete the actual file. might also be worthwhile to edit registry [regedit] and do a specific search on that file name and delete the entire string.

My problem was after so many personal attempts at troubleshooting that required HARD COLD boots, my safe modes would come back as bluescreens indicating I needed to run chkdsk, which of course I had no access to perform. so with no safe mode all the usual fixes were moot in my situation

#14 addy1

addy1

    water gardener / gold fish and shubunkins

  • Members
  • 15869 posts
  • Location:Frederick, Maryland zone 6b-7a

Posted 19 November 2012 - 10:44 PM

Thanks for the info! I am going to print it out, cause if the computer is gone sure won't be able to read it! I have multiple layers of stuff protecting my puter, so maybe it won't make it here.........maybe

Can you share the online service? It would be nice to know a reputable group to get hold of it we have issues.

live feed to our pond ....To see the cameras you must be on IE, if using firefox right click-- copy the link location paste in IE browser... .... .... My pond build thread

Live every day as if it is your last, enjoy it to the fullest, because one day it will sure will be.
post-2547-0-36263200-1313748028_thumb.jp

a good read about pond chemisty, ph, hardness etc


Frederick.gif

 


#15 Johnnie

Johnnie
  • Members
  • 151 posts
  • Location:North-Eastcoaster with shovels for blizzards

Posted 31 December 2012 - 07:56 PM

Thanks for your input.
I ended up finding a reputable online tech service that was able to walk me through loading an external windows environment from a flash drive and fix the issue remotely VERY early Sunday morning.

for anyone else falling victim to this FBI ransomware virus.
it dumps a file called .directory into your desktop folder and likewise loads it into your startup list... which then of course usurps your desktop control as soon as the startup is launched.
It likewise disables task manager.
if you can get to the startup listing before the screen goes white, just select and delete the file from startup ... (hopefully it isn't savvy enough to reload itself) and then reboot and navigate to your desktop folder and delete the actual file. might also be worthwhile to edit registry [regedit] and do a specific search on that file name and delete the entire string.

My problem was after so many personal attempts at troubleshooting that required HARD COLD boots, my safe modes would come back as bluescreens indicating I needed to run chkdsk, which of course I had no access to perform. so with no safe mode all the usual fixes were moot in my situation



I'm sorry for failing to answer your posts because I have not seen your posts until now. Congrats for getting rip of the virus.


Anyway, I do 2nd Addy1's request. Please share with us the contact info of the reputable virus-buster/FIXER. I will need his service because my computer has gone "power off" automatically once awhile while I'm surving the net.