Posts: 8,423
Threads: 171
Joined: Dec 2011
Reputation:
46
Location: Portsmouth
Car Model/Spec: Black 3dr Dturbo
Thanks: 0
Given 1 thank(s) in 1 post(s)
25-03-2013, 03:07 PM
(This post was last modified: 25-03-2013, 03:09 PM by 4WayDiablo.)
So I turned the computer on to find this....
I'm fairly sure this is some kind of damn good virus of some sorts as it asks for you to pay £100 fine
Its completely blocked the Operating system meaning that can't do anything
Ctrl alt del does nothing but take me back to this
Tried to reboot in safe mode with command prompt but that doesn't do anything
Tried to get to system restore but couldnt
Anyone (Fooby Scott??) Got any ideas on this
Or do I get the match and lighter out. Trouble is there is many years of family photos on there
Some better quality pics...
Posts: 7,825
Threads: 465
Joined: Dec 2011
Reputation:
114
Location: Cullompton Devon
Car Model/Spec: Vauxhall
Thanks: 1
Given 98 thank(s) in 92 post(s)
ha ha phils been on the Porn again!
Posts: 5,024
Threads: 82
Joined: Dec 2011
Reputation:
27
Location: North Somerset
Car Model/Spec: E92 335i, GTi6, HDi S2
Thanks: 6
Given 22 thank(s) in 22 post(s)
Used to remove that virus daily of some sort or another.. what O/S is it running?
Posts: 7,825
Threads: 465
Joined: Dec 2011
Reputation:
114
Location: Cullompton Devon
Car Model/Spec: Vauxhall
Thanks: 1
Given 98 thank(s) in 92 post(s)
Posts: 571
Threads: 19
Joined: Dec 2011
Reputation:
5
Location: Cavan, Ireland
Car Model/Spec: Ph1 D-turbo(on going project)
Thanks: 0
Given 0 thank(s) in 0 post(s)
definately a virus, asks you to pay by some of the payzone Kash things i think
dunno how to remove though
Posts: 13,881
Threads: 476
Joined: Dec 2011
Reputation:
81
Location: Ipswich
Car Model/Spec: 306 Rallye
Thanks: 4
Given 104 thank(s) in 102 post(s)
yeh definitely a virus. Youd have to be watching more than porn to get that!
Posts: 8,749
Threads: 208
Joined: Jan 2012
Reputation:
60
Location: Wiltshire
Car Model/Spec: ph2 Gti6 / ph4 HDI Estate
Thanks: 1
Given 5 thank(s) in 5 post(s)
tut you know them sites are 18+ phill you shouldnt even be on them! how are you going to explain this to mum and dad eh??
Member of 99% warning or your nothing club!
Posts: 2,526
Threads: 143
Joined: Dec 2011
Reputation:
10
Location: South East London
Car Model/Spec: Ph3 XUD
Thanks: 1
Given 8 thank(s) in 8 post(s)
If you've got the Windows disc, assuming you're running windows, boot from that and do a system restore.
Posts: 14,208
Threads: 448
Joined: Dec 2011
Reputation:
51
Location: isle of wight
Car Model/Spec: Pov. Spec White '6
Thanks: 17
Given 18 thank(s) in 18 post(s)
Flol what have you been looking at! Tut tut
TEAM CONROD SHITTING RALLYE!
Posts: 663
Threads: 22
Joined: Jan 2012
Reputation:
6
Location: Herefordshire
Car Model/Spec: 306 HDi Stage 1
Thanks: 0
Given 0 thank(s) in 0 post(s)
(25-03-2013, 03:51 PM)bigcheez2k3 Wrote: If you've got the Windows disc, assuming you're running windows, boot from that and do a system restore.
and then back up all your photos etc to an external hard drive and CDR
We had a similar problem a few years ago and lost everything.......never again
Posts: 782
Threads: 18
Joined: Jan 2012
Reputation:
3
Thanks: 0
Given 0 thank(s) in 0 post(s)
Definately a virus. This may help, i use hitmanpro to get rid of this. Try this bud
http://malwaretips.com/blogs/pceu-virus/
Only you need a working computer to create a bootable USB
Posts: 1,135
Threads: 14
Joined: May 2012
Reputation:
7
Location: Sheffield
Thanks: 0
Given 5 thank(s) in 5 post(s)
Looks like a fairly complex piece of Scareware/Ransomware.
I hope you've got a backup, or means to backup your computer because the really well written stuff needs a format to remove.
Posts: 8,423
Threads: 171
Joined: Dec 2011
Reputation:
46
Location: Portsmouth
Car Model/Spec: Black 3dr Dturbo
Thanks: 0
Given 1 thank(s) in 1 post(s)
(25-03-2013, 03:12 PM)Midnightclub Wrote: Used to remove that virus daily of some sort or another.. what O/S is it running?
Windows vista or windows 7. I think its 7
Its the family computer but I rarely use it as I have my own. My brother used to use it shit loads and regularly caught him on dodgy sites
Cheers for the help
Posts: 1,497
Threads: 177
Joined: Dec 2011
Reputation:
3
Location: Highlands, Scotland
Thanks: 0
Given 0 thank(s) in 0 post(s)
25-03-2013, 04:21 PM
(This post was last modified: 25-03-2013, 04:24 PM by Daniel306.)
http://malwaretips.com/blogs/pceu-virus/
Seams like there is a few different virus that do this
Posts: 3,467
Threads: 186
Joined: Mar 2012
Reputation:
38
Location: Manchester
Car Model/Spec: MG ZR VVC
Thanks: 3
Given 21 thank(s) in 19 post(s)
Housemate got this but it was the "FBI" and he was blocked for looking at illegal material or something
Posts: 1,070
Threads: 115
Joined: Oct 2012
Thanks: 0
Given 0 thank(s) in 0 post(s)
God knows I've looked at some stuff (autopsies mainly) that if I didn't know any better I would shit myself if that came up
Posts: 15,646
Threads: 541
Joined: Dec 2011
Reputation:
124
Location: Aylesbury
Car Model/Spec: 320bhp Impreza WRX
Thanks: 7
Given 59 thank(s) in 58 post(s)
Definitely a virus mate, my mum got it last week and shes never illegally downloaded anything in her life.
There is some good guides on you tube to getting rid of it.
Its a scam that's been doing the rounds for months. Make sure you report it to the police.
Posts: 8,423
Threads: 171
Joined: Dec 2011
Reputation:
46
Location: Portsmouth
Car Model/Spec: Black 3dr Dturbo
Thanks: 0
Given 1 thank(s) in 1 post(s)
Managed to boot it in safe mode and get malware bytes which has isolated it but not removed it
Its a pretty good virus as I can see how people more vounerable would fall for it
It literally takes over the system
Cheers for the help and rep will be on the way to you all soon
Posts: 122
Threads: 18
Joined: Feb 2013
Reputation:
0
Location: Preston
Car Model/Spec: 306 Dturbo
Thanks: 0
Given 0 thank(s) in 0 post(s)
i had that come up once, was telling me that i was looking at fake creadit cards and some things that would make you got WTF, worked for me when i hit the power button and then turned back on :/ deffo a scam
Posts: 2,526
Threads: 143
Joined: Dec 2011
Reputation:
10
Location: South East London
Car Model/Spec: Ph3 XUD
Thanks: 1
Given 8 thank(s) in 8 post(s)
Another good thing to use with stuff like this is rkill. It scans the processes that are running and shuts off any that are known as malicious, usually ones that stop you from using anti-malware software.
Posts: 5,024
Threads: 82
Joined: Dec 2011
Reputation:
27
Location: North Somerset
Car Model/Spec: E92 335i, GTi6, HDi S2
Thanks: 6
Given 22 thank(s) in 22 post(s)
If you've deleted it using mbam, you may still have issues, it stores data in the registry sometimes so as soon as you reboot and removal it just redownloads all over again, i can't remember off hand which keys it effects i'm afraid :/
Posts: 8,298
Threads: 289
Joined: Nov 2011
Reputation:
92
Location: London
Car Model/Spec: Phase 17 R26
Thanks: 0
Given 1 thank(s) in 1 post(s)
Glad to hear you kind of have it sorted. Personally if a system has been compromised to that level, I would usually reformat and reinstall Windows, while not connected to the internet, and install some AV from a USB drive, before connecting. It might also be worth telling your brother to stop looking at so many dodgy sites, primarily warez sites as I'm assuming that's the sort of thing he was going on before.
Posts: 1,345
Threads: 119
Joined: Jan 2012
Reputation:
15
Location: Rotherham/Sheffield
Car Model/Spec: Ph1 Diablo DT
Thanks: 0
Given 1 thank(s) in 1 post(s)
It called ukash virus it encrypts all data on the system the rents had this the other month but couldn't remove it with anything at all so scrapped the hardware. After looking In to it malware bytes can isolate it
Perv 106 1.4 xs First Pug Love - Scrapped
Perv 306 1.6 5 Door Hore - Sold
110bhp 207 Hdi Sport - Used as a Brake
173bhp T25 Ph1 Diablo Dturbo - Scrapped
Thirsty Bitch Volvo 850 Estate - Sold
51bhp Berlingo Nad DT Van - Sold
Slow as f*ck Dispatch Work Horse
www.prestige-auto-care.co.uk
Posts: 8,423
Threads: 171
Joined: Dec 2011
Reputation:
46
Location: Portsmouth
Car Model/Spec: Black 3dr Dturbo
Thanks: 0
Given 1 thank(s) in 1 post(s)
What's a warez site? Lol
Will tell my parents it needs to be binned lol. Its a shame as its a pretty good computer
Posts: 8,298
Threads: 289
Joined: Nov 2011
Reputation:
92
Location: London
Car Model/Spec: Phase 17 R26
Thanks: 0
Given 1 thank(s) in 1 post(s)
Warez is a bit of a general term for file sharing, but I meant mainly if he's trying to download free versions of software, particularly software cracks or serial numbers.
No point binning it though, it can always be saved! What sort of spec is it?
Posts: 8,423
Threads: 171
Joined: Dec 2011
Reputation:
46
Location: Portsmouth
Car Model/Spec: Black 3dr Dturbo
Thanks: 0
Given 1 thank(s) in 1 post(s)
Quad core something? 2.8 iirc
6gb ram
"Overlockers" graphics card dunno what spec
Buts not exactly old and still pretty swift
Thing is though parents use it for internet banking as well as all their internet shopping of which they do a lot of
Posts: 5,024
Threads: 82
Joined: Dec 2011
Reputation:
27
Location: North Somerset
Car Model/Spec: E92 335i, GTi6, HDi S2
Thanks: 6
Given 22 thank(s) in 22 post(s)
You don't need to scrap it at all, worst worst case.. get a USB caddy and take out the HDD, put all your wanted data etc. on another PC or ext HDD etc. then as scott said, just wipe and reinstall windows. It'll be fine, must have removed it over 100 times, it can be persistent and usually the longer it stays on the machine the worse the infection gets, sometimes just a system restore and a MBAM scan with rkill will get rid of it, other times a complete wipe is required.
Posts: 8,298
Threads: 289
Joined: Nov 2011
Reputation:
92
Location: London
Car Model/Spec: Phase 17 R26
Thanks: 0
Given 1 thank(s) in 1 post(s)
(26-03-2013, 04:27 PM)4WayDiablo Wrote: Quad core something? 2.8 iirc
6gb ram
"Overlockers" graphics card dunno what spec
Buts not exactly old and still pretty swift
Thing is though parents use it for internet banking as well as all their internet shopping of which they do a lot of
Well they definitely need to stop using it until you've done a full reinstall and educated your brother on better browsing habits.
There's no need at all to scrap that, it's a decent PC. If I wasn't going away on Friday I'd do it for you over the weekend. If it's still not fixed by the time I get back then let me know and I'll help out.
Posts: 8,423
Threads: 171
Joined: Dec 2011
Reputation:
46
Location: Portsmouth
Car Model/Spec: Black 3dr Dturbo
Thanks: 0
Given 1 thank(s) in 1 post(s)
Cheers fella.
Get the pics off there then full system cleanse and reboot in order imo
Posts: 1,213
Threads: 92
Joined: Dec 2011
Reputation:
5
Location: Birmingham
Car Model/Spec: Subaru 20.d, GTi 6, 205 xs
Thanks: 0
Given 3 thank(s) in 3 post(s)
just boot the machine in safe mode and run combofix this will remove it then just run malwarebytes when you log back into windows, job done, its a common occurence at my work lol
Vehicle repair and servicing in the midlands pm for details
Current cars
Subaru Impreza 2.0d - Daily
306 1.8 - track whore soon to be GTI6
|