|
|
 |
|
11-05-2012, 08:25 PM
|
#1
|
|
Member
Join Date: Apr 2005
Posts: 104
|
Help With FBI Fake Virus - Malwarebytes Did Not Detect It
So my PC was locked up by that Fake FBI MoneyPack virus. Rebooted into safe mode and ran Malwarebytes using the latest updates (it was already installed at the time of the infection). Problem now is that it did not detect it.
Would really appreciate some help.
|
|
|
11-05-2012, 09:23 PM
|
#3
|
|
Elite Member
Join Date: Dec 2001
Posts: 23,211
|
Your safest action is to back your stuff up, and reformat the drive (including resetting the mbr).
If you visit risky sites, you should log in with a limited user account, use firefox with noscript, keep flash up to date, don't let the browser invoke adobe reader, and uninstall java if you don't need it.
|
|
|
11-05-2012, 11:00 PM
|
#4
|
|
Member
Join Date: Apr 2005
Posts: 104
|
Weird, I have WinPatrol installed which detects unwanted start Up programs and asks you if it's OK. When I booted into safe mode, the latest start up program entry was userinit.exe. I ran both Malwarebytes and SuperAntiSpyware, and both found nothing. I booted up in regular mode and the Fake FBI screen popped up again. I booted back into safe mode and deactivated the userinit.exe start up program in WinPatrol, and again booted up normally. The fake FBI screen has yet to return. Is it possible that the userinit.exe is also fake and related to this FBI malware? Every 5 minutes or so, WinPatrol warns me that it's trying to re-join the start up programs again.
Last edited by muskyx1; 11-05-2012 at 11:07 PM.
Reason: spelling
|
|
|
11-06-2012, 06:06 AM
|
#5
|
|
Senior Member
Join Date: Dec 2003
Location: Baltimore, MD
Posts: 297
|
I can easily assist, remove the virus from the startup folder and reboot windows, its a scareware and easy to remove.
|
|
|
11-08-2012, 10:10 PM
|
#6
|
|
Lifer
Join Date: Oct 1999
Location: London, Ontario Canada
Posts: 19,438
|
Quote:
Originally Posted by muskyx1
Weird, I have WinPatrol installed which detects unwanted start Up programs and asks you if it's OK. When I booted into safe mode, the latest start up program entry was userinit.exe. I ran both Malwarebytes and SuperAntiSpyware, and both found nothing. I booted up in regular mode and the Fake FBI screen popped up again. I booted back into safe mode and deactivated the userinit.exe start up program in WinPatrol, and again booted up normally. The fake FBI screen has yet to return. Is it possible that the userinit.exe is also fake and related to this FBI malware? Every 5 minutes or so, WinPatrol warns me that it's trying to re-join the start up programs again.
|
MSCONFIG is your friend at this point. Disable everything in Start Up and then reboot and see what happens.
Malwarebytes isn't perfect. You can also try MSE.
I bet Hitman Pro can remove this infection.
__________________
My Rigs
When I was four I gave myself a needle and the whole hospital said I got shot when I was 22 and asian. I drove a black honda. - catchphrase
Compare your lives to mine and then kill yourselves
|
|
|
11-09-2012, 01:35 AM
|
#7
|
|
Golden Member
Join Date: Aug 2001
Posts: 1,276
|
Emsisoft emergency kit.
|
|
|
11-10-2012, 06:39 AM
|
#8
|
|
Golden Member
Join Date: Jul 2001
Location: TN
Posts: 1,688
|
I would run rkill in safe mode with networking first. http://www.bleepingcomputer.com/download/rkill/ Then check your LAN settings in IE that proxy server is not checked. Then run MBAM.
http://www.fixpcyourself.com/how-to-...oneypak-virus/
If MBAM still does not detect it try this, run rkill first:
http://www.bleepingcomputer.com/viru...pak-ransomware
__________________
Asrock Z68 Extreme 4, i5-2500K @4.6 Ghz, 1.340V, Lian Li PC-7A Plus, Corsair A70, Corsair Force Series 3 120GB SSD, Samsung Spinpoint HD103SJ 1TB, 16GB Kingston HyperX DDR3 1600 @1.575V,Seasonic M12II 620W PSU, MSI GeForce GTX 650 Ti, Samsung SH-S223B, Win 7 Ultimate 64bit
Last edited by MadScientist; 11-10-2012 at 06:41 AM.
|
|
|
11-16-2012, 07:15 PM
|
#9
|
|
Senior Member
Join Date: Nov 2011
Posts: 261
|
Using MSCONFIG > Startup Tab > the second column shows manufacturer. Usually, illegitimate software will say Unknown.
|
|
|
11-24-2012, 03:36 AM
|
#10
|
|
Lifer
Join Date: Sep 2001
Location: Central California
Posts: 16,574
|
Offline detection and cleaning FTW. I always keep an external enclosure handy, for PATA and SATA, in both 2.5" and 3.5". Anyone comes to me with one of these nasty rogue programs, drive automatically goes into an external enclosure and I run three proggies on it from another computer; MSSE, MalwareBytes, and then a top AV product like Norton, BitDefender, or Kaspersky. Sure, it takes a while, but its not like you must sit there watching the progress indicator.
|
|
|
11-25-2012, 04:38 PM
|
#11
|
|
Senior Member
Join Date: May 2011
Posts: 502
|
still no work?
use combo fix but i do not recommend as it is advance and can mess up your pc. use at your own risk.
ps. can watch porn in linux ubunto live cd catch virus?
Last edited by NiceCold; 11-25-2012 at 04:41 PM.
|
|
|
11-26-2012, 05:32 AM
|
#12
|
|
Senior Member
Join Date: Nov 2010
Location: Norway
Posts: 626
|
Format.
Once you're infected there is no guarentee that you can completely scrub your system.
The aim of the game is to not get infected, once you are - Format!
|
|
|
11-27-2012, 01:35 PM
|
#13
|
|
Member
Join Date: May 2011
Location: chucktowm, sc
Posts: 29
|
I agree...full format only real cure!
|
|
|
11-29-2012, 07:42 PM
|
#14
|
|
Lifer
Join Date: Jul 2011
Location: Raleigh. NC
Posts: 11,294
|
I was able to get rid of it with malwarebytes.
__________________
E4300, 9800gt, 3.5gb RAM
I have a 660ti, but it won't fit in my case (Dell OEM POS)
Forever in debt to VirtualLarry, Jupiter57, Face2Face, Jfree
|
|
|
11-30-2012, 12:25 AM
|
#15
|
|
Senior Member
Join Date: Nov 2010
Location: Norway
Posts: 626
|
Quote:
Originally Posted by T_Yamamoto
I was able to get rid of it with malwarebytes.
|
What's your plan for not getting infected again?
Such a massive virus is bound to leave bits and pieces all over the place.
|
|
|
12-01-2012, 10:05 AM
|
#16
|
|
Golden Member
Join Date: Jul 2001
Location: TN
Posts: 1,688
|
Almost 90% of the computer repair work I do now is cleaning infected computers. I totally agree that the only sure way of getting rid of a virus is to format and re-install the OS, but I also agree with John's statement from his website.
"Ok, I'm infected. What about a fresh Windows install? If you reinstall the operating system then you'll need to reinstall Windows updates (unless you have a slipstreamed copy), drivers, assorted software, tweaks, and all of your other peripherals which could easily take several hours. You'll then need to figure out how you were infected in the first place in order to prevent it from happening in the future. This is one of the main reasons that I rarely recommend a clean install. As long as you take the time to learn how to clean an infected system a fresh Windows install should be a last resort (unless you have a recent known good image of your drive)." http://www.elitekiller.com/malware.htm
The only time I format and reinstall the OS is when the OS is beyond repair, or the person has a good image of the drive. I have yet to encounter the latter.
Most people, no matter how many times I tell them to do so, never backup their important files, i.e., music, pictures, documents. An infected computer I worked on this week had 92GB of music files on it.
To answer smakme7757's question. Quoting John again: "The fact is that no single antivirus or antispyware application can successfully remove all malware circulating around the internet. It's not unusual to resort to an arsenal of security products in an attempt to ensure that everything has been properly removed."
If your computer is infected go to John's website, download his rogue removal kit, unzip it and read his Readme.pdf file.
To keep your computer from being infected again read and follow mechBgon's "How (and why) to secure your Windows PC" http://www.mechbgon.com/build/security2.html
And as John points out: "Most of all I can't stress enough how important it is to use common sense!"
__________________
Asrock Z68 Extreme 4, i5-2500K @4.6 Ghz, 1.340V, Lian Li PC-7A Plus, Corsair A70, Corsair Force Series 3 120GB SSD, Samsung Spinpoint HD103SJ 1TB, 16GB Kingston HyperX DDR3 1600 @1.575V,Seasonic M12II 620W PSU, MSI GeForce GTX 650 Ti, Samsung SH-S223B, Win 7 Ultimate 64bit
Last edited by MadScientist; 12-01-2012 at 10:14 AM.
|
|
|
12-03-2012, 08:21 PM
|
#17
|
|
Lifer
Join Date: Jul 2011
Location: Raleigh. NC
Posts: 11,294
|
Quote:
Originally Posted by smakme7757
What's your plan for not getting infected again?
Such a massive virus is bound to leave bits and pieces all over the place.
|
Tell my brother (it was his lappy that got the virus) to use better judgement.
__________________
E4300, 9800gt, 3.5gb RAM
I have a 660ti, but it won't fit in my case (Dell OEM POS)
Forever in debt to VirtualLarry, Jupiter57, Face2Face, Jfree
|
|
|
12-03-2012, 11:54 PM
|
#18
|
|
Lifer
Join Date: May 2002
Location: Ohio
Posts: 11,463
|
Awful lot of "nuke happy" people on here
It IS quite possible to fully disinfect a PC, and in most cases it isn't that hard to remove any remaining traces. I do it at work all the time. Aside from some people who just can't stay away from the dark corners of the internet I rarely have a reinfection.
__________________
Heatware
CO2 is evil. Stop breathing
"I have never understood why it is greed to want to keep the money that you've earned, but not greed to want to take somebody else's money." - Thomas Sowell
|
|
|
01-15-2013, 03:53 PM
|
#19
|
|
Lifer
Join Date: Jul 2005
Posts: 17,738
|
Quote:
Originally Posted by jmarti445
I can easily assist, remove the virus from the startup folder and reboot windows, its a scareware and easy to remove.
|
Please describe in detail what you are talking about?
Many experienced users have had issues with the FBI warning virus....
__________________
JohnOfSheffield -- That said, Palestine will exist when they understand that Israel exists, it's that blatantly simple!
|
|
|
01-23-2013, 10:20 PM
|
#20
|
|
Lifer
Join Date: Aug 2001
Posts: 22,234
|
My friend just got this on his computer, while he was away for the day.
I asked him if he has Java installed, he said yes.
I told him it was probably a poisoned ad.
__________________
Rig(s) not listed, because I change computers, like some people change their socks.
|
|
|
01-24-2013, 02:39 AM
|
#21
|
|
Lifer
Join Date: Jul 2005
Posts: 17,738
|
Quote:
Originally Posted by VirtualLarry
My friend just got this on his computer, while he was away for the day.
I asked him if he has Java installed, he said yes.
I told him it was probably a poisoned ad.
|
Its quite a bit worse than a poisoned add.....if it is the FBI fake virus it locks your computer up......
Foe the people that have the real FBI virus its no laughing matter.....
I am sorry to inform you that you don`t get this virus by leaving and coming back to your computer...
__________________
JohnOfSheffield -- That said, Palestine will exist when they understand that Israel exists, it's that blatantly simple!
|
|
|
01-25-2013, 12:50 PM
|
#22
|
|
Lifer
Join Date: Aug 2001
Posts: 22,234
|
Quote:
Originally Posted by JEDIYoda
I am sorry to inform you that you don`t get this virus by leaving and coming back to your computer...
|
You can, if you leave a web page open, that has rotating ads, that come from an ad server that is hacked or otherwise distributing "poisoned" ads, and your local computer system has a currently-exploitable vulnerability, like current versions of Java.
__________________
Rig(s) not listed, because I change computers, like some people change their socks.
|
|
|
01-25-2013, 12:53 PM
|
#23
|
|
Lifer
Join Date: Aug 2001
Posts: 22,234
|
The sad irony is, if you've heard how this "FBI moneypak virus" works, the new "Six Strikes" system being implemented by ISPs around the country, in concert with demands from the RIAA/MPAA, is eerily similar.
Suddenly, whereever you browse on the internet, a page pops up, accusing you of something, and you either have to admit guilt, or pay a fine to contest it.
And your internet connection can be throttled, or cut off.
All without you actually doing something wrong.
__________________
Rig(s) not listed, because I change computers, like some people change their socks.
|
|
|
01-25-2013, 09:19 PM
|
#24
|
|
Lifer
Join Date: Jul 2005
Posts: 17,738
|
Quote:
Originally Posted by VirtualLarry
You can, if you leave a web page open, that has rotating ads, that come from an ad server that is hacked or otherwise distributing "poisoned" ads, and your local computer system has a currently-exploitable vulnerability, like current versions of Java.
|
I am sorry that will not happen if you are on a legitimate site and not some questionable porn site or other site.....
__________________
JohnOfSheffield -- That said, Palestine will exist when they understand that Israel exists, it's that blatantly simple!
|
|
|
01-26-2013, 03:12 AM
|
#25
|
|
Lifer
Join Date: Aug 2001
Posts: 22,234
|
Quote:
Originally Posted by JEDIYoda
I am sorry that will not happen if you are on a legitimate site and not some questionable porn site or other site.....
|
Even legit site's ad servers have been compromised. LegitReviews was compromised a few months back, and even these forums have had their ad servers compromised at least once in the past. What you say, simply isn't true.
__________________
Rig(s) not listed, because I change computers, like some people change their socks.
|
|
|
Posting Rules
|
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts
HTML code is Off
|
|
|
All times are GMT -5. The time now is 08:30 PM.
|