SmartFeedSmartFeed          



WELCOME - YOU ARE CURRENTLY VIEWING 419EATER AS A GUEST

By joining our community you will have the ability to post topics and access other forums reserved for members. Registration is quick, simple and absolutely free. Join our community today by clicking here.

ScamWarners.com - Internet Anti-Fraud Center - now open!

These forums are READ ONLY. Click here to register on our new forums - aff.419eater.com


 virus help needed

View next topic
View previous topic
 
This forum is locked: you cannot post, reply to, or edit topics.This topic is locked: you cannot edit posts or make replies.
Author Message
Klaasvaak
Baiting Guru


Joined: 11 May 2004
Posts: 2163


PostPosted: Fri Feb 20, 2015 3:58 pm Reply with quoteBack to top

My so emailed me the pic below of her laptop. She can't open any word files. She brought her laptop to some computerrepairguy (i'm still pissed about this) who said he probably cant do anything about it (even more pissed about this). and she will be missing her laptop this weekend (godd@#$!@#@#) Also now she can't do any work this weekend. (meltdown imminent banghead )

Any ideas what I'll be dealing with here?
She told me she didn't open any email attachments
Didn't open any dodgy facebook video who redirect you to some website.

Image

_________________
Easter 2015Elton Flying Monkey Pole Dancer
www.microsoft.com

View user's profileSend private message
B8er
Associate Boomdazzler


Joined: 16 Feb 2009
Posts: 13625
Location: In self-isolation practicing social distancing


PostPosted: Fri Feb 20, 2015 4:09 pm Reply with quoteBack to top

Its ransomware of some sort - the readme file would probably tell you which and you may find removal instructions on the web.

_________________
"I DENOUNCE THE MUFFIN MEN" - Ma Kim
"YOU ARE WALKING DEAD MAN. YOUR WOODEN COFFIN IS READY TO SWALLOW YOU AND YOUR DIRTY GENERATION"
"all chaps are ass-less by design otherwise they just be leather pants" - jose_cuervo
Safari x 5 Tattoo Golden Pig Easter 2015 Vcamera
United KingdomUnited StatesNigeriaMalaysiaNetherlandsThailandCanadaUnited Arab EmiratesUnited NationsAustraliaSenegalSpainBeninChinaDenmarkGhanaIvory CoastKorean FlagSouth AfricaSwedenBurkina FasoCambodia FlagcameroonGermanyHong KongIndonesiaJapanNew ZealandSwitzerlandTogoTurkeyUkraine x 335 Elite Ninja Team Member Whip 🚽
Cellphone x 4 Closed lad accounts x 1746 x 1904 - Fake cheques: $4,392,620.83
Safari Team Woody - Ghana to Singapore - 11535km
View user's profileSend private messageSkype Name
Roycropper
Baiting Guru


Joined: 14 Nov 2005
Posts: 7992
Location: Luxury Coffin


PostPosted: Fri Feb 20, 2015 4:12 pm Reply with quoteBack to top

Does this help?

http://www.idigitaltimes.com/cryptolocker-virus-removal-how-decrypt-or-restore-encrypted-files-and-remove-ransomware-malware-free

http://www.pcworld.com/article/2084002/how-to-rescue-your-pc-from-ransomware.html

_________________
the European Union has bounced on our freckles
COULD YOU IMAGINE WHAT HAPPENED WHEN I WENT TO THE BANK
our Agent is Completely broke, pocketless and stranded
I WLL SEND AN AFRICA WITCH TO ATTACH YOU BASTARD
You go die like bird
i started shouting HALLELUJAGOBBLE but none of them notice me immediately police arrested me due to the shouting
f*ck u asshole ur damn mother will loose ur fcuking skull brain ur brain is nothing to compare with rat f*ck ur u
MY FRIEND ALEX WAS DETAINED IN POLICE STATION
I am not happy due to the question i answered at money office. Let me tell you do not play with me ok.
Pith Helmet 10
x4 United Kingdom New Zealand Mortar Closed lad accounts Sand Timer 6Yrs Tattoo x6 Flying Monkey
View user's profileSend private message
Mattaz
Baiting Guru


Joined: 02 Jan 2015
Posts: 2075
Location: I'm on my way from happiness to misery with you


PostPosted: Fri Feb 20, 2015 5:03 pm Reply with quoteBack to top

I can recommend you to search for help at http://www.spywareinfoforum.com/

There are many volunteers who are specialized in removing all kinds of malware. Years ago I was one of them.
It takes some time because you have to follow the instructions they are giving you and you have to do all scanning and stuff by yourself, but it can save you a lot of money.
They will explain every step in detail so it is easy to do.

If you're from the lowlands I can recommend http://www.mivercon.be/forum/

_________________
🍰
"I am truly not a happy fellow at the moment." - Mr.George
View user's profileSend private messageSkype Name
Joker
*** BANNED ***


Joined: 26 Jul 2012
Posts: 1123


PostPosted: Fri Feb 20, 2015 8:23 pm Reply with quoteBack to top

That definitely looks like cryptolocker which is a nasty breed of ransomware. It would not shock me is that came with a variant of the Zeus platform known as game over as well. You can get this from dodgy files as well like word docs through a macro based vector.

Can you post up the contents of the text file? Mainly I'm curious what they have to say.

https://blog.malwarebytes.org/intelligence/2013/10/cryptolocker-ransomware-what-you-need-to-know/

I hope your SO was religious about making backups....

_________________
All warfare is based on deception - Sun Tzu, The Art of War
لئيم كافر
View user's profileSend private message
dwatina
Baiting Guru


Joined: 13 Feb 2010
Posts: 7164
Location: Home of the Orangemen! Friends call me Doc


PostPosted: Fri Feb 20, 2015 10:24 pm Reply with quoteBack to top

^^I year 'ya about back-ups. Even though I'm on a Mac--I do two complete backups every weekend (i.e., complete clones of my system). One to my 2nd internal drive, and the other to a firewire drive.

I use "Super Duper" for the Mac and the smart update--so it takes less than two hours total to do both clones.

_________________
Support bacteria. It's the only culture some people have. (my quote--not a lad's)
*****
Closed lad accounts x97 [I lost count years ago and don't keep track anymore]
United Kingdom x3 Mc Fry Easter Egg 2011 Elite Ninja Team Member Sand Timer
<a href="/forum/donate.php">[Click here to donate to 419Eater.com]</a>
x3 Safari : Femmy Bait w/Team Femmy
View user's profileSend private messageSend e-mailSkype Name
huskywowzer
Master Baiter


Joined: 03 Jan 2015
Posts: 204
Location: Where The Baiters Bait


PostPosted: Sat Feb 21, 2015 3:48 am Reply with quoteBack to top

You could always try wiping the computer fully and reinstalling Windows. Or you can install Ubuntu Linux from a USB drive. I had to do that with my last Ransomware virus. They are nasty buggers, aren't they?

_________________
"SIR,I HAVE VIEW THAT THE WESTERN UNION SLIP YOU ATTACHED IS FORGED AND NO PAYMENT WAS MADE.THANKS FOR YOUR CO-OPERATIONS AND CONGRATULATIONS." -JONAH OTUNLA
" i can't waste my time again over to you what hell are you talking about." Mr. William Betha
"You are making this whole thing difficult for our chemist" Bill Henderson
"make sure you make the payment as soon as possible for the Great Gugaga isn't that patient with new members." Illuminati Scammer
"I will be jailed for criminal activities, I am a knight in my church" - Clint


Easter 2015Closed lad accounts x10 United Kingdom x20 United Arab Emirates x3 Ghana x4 United States x8 Togo x2 South Africa Canada x2 France x2 Ivory Coast Hong Kong Thailand x3 Australia :flag_haggis: x2 misc. domains (no location) x7 Cellphone
View user's profileSend private messageSkype Name
Klaasvaak
Baiting Guru


Joined: 11 May 2004
Posts: 2163


PostPosted: Sat Feb 21, 2015 8:03 am Reply with quoteBack to top

Joker wrote:
That definitely looks like cryptolocker which is a nasty breed of ransomware. It would not shock me is that came with a variant of the Zeus platform known as game over as well. You can get this from dodgy files as well like word docs through a macro based vector.

Can you post up the contents of the text file? Mainly I'm curious what they have to say.

https://blog.malwarebytes.org/intelligence/2013/10/cryptolocker-ransomware-what-you-need-to-know/

I hope your SO was religious about making backups....


No she hasn't made a lot of backups she's a teacher and a lot of her university stuff is gone.


She gets her laptop back after this weekend. I will post try to post the txt but i can't do anything until then. We are still wondering how she got the virus

_________________
Easter 2015Elton Flying Monkey Pole Dancer
www.microsoft.com

View user's profileSend private message
B8er
Associate Boomdazzler


Joined: 16 Feb 2009
Posts: 13625
Location: In self-isolation practicing social distancing


PostPosted: Sat Feb 21, 2015 8:07 am Reply with quoteBack to top

^^^Does she ever get sent files by her students?

_________________
"I DENOUNCE THE MUFFIN MEN" - Ma Kim
"YOU ARE WALKING DEAD MAN. YOUR WOODEN COFFIN IS READY TO SWALLOW YOU AND YOUR DIRTY GENERATION"
"all chaps are ass-less by design otherwise they just be leather pants" - jose_cuervo
Safari x 5 Tattoo Golden Pig Easter 2015 Vcamera
United KingdomUnited StatesNigeriaMalaysiaNetherlandsThailandCanadaUnited Arab EmiratesUnited NationsAustraliaSenegalSpainBeninChinaDenmarkGhanaIvory CoastKorean FlagSouth AfricaSwedenBurkina FasoCambodia FlagcameroonGermanyHong KongIndonesiaJapanNew ZealandSwitzerlandTogoTurkeyUkraine x 335 Elite Ninja Team Member Whip 🚽
Cellphone x 4 Closed lad accounts x 1746 x 1904 - Fake cheques: $4,392,620.83
Safari Team Woody - Ghana to Singapore - 11535km
View user's profileSend private messageSkype Name
Klaasvaak
Baiting Guru


Joined: 11 May 2004
Posts: 2163


PostPosted: Sat Feb 21, 2015 8:09 am Reply with quoteBack to top

No. that's the first thing I asked. She said she didn't open any attachments

_________________
Easter 2015Elton Flying Monkey Pole Dancer
www.microsoft.com

View user's profileSend private message
Joker
*** BANNED ***


Joined: 26 Jul 2012
Posts: 1123


PostPosted: Sat Feb 21, 2015 7:41 pm Reply with quoteBack to top

Downloads, attachments, dodgy videos.... all par for the course with malware these days. There is a reason I say it probably came with the Game Over variant of Zeus. They tend to bind that to files on the web and on other people's computers. Start doing file sharing in the office and it gets spread like wild fire.

The malware operator sits there figuring out how to monetize his infected bots. If he can't spy and collect financial details (bank, CC, paypal, etc), they load CryptoLocker on the computer and hold it for ransom.

You can ask yourself what the attack vector was but these days, it really is boiling down to multiple with many malware operators very happy to sit back quietly for months at a time working nothing but spreading their gear. Once they feel they have a sufficient spread they hit the oldest infections not giving them financial data or already bled off of that data with stuff like this, while working newer infections to gain further coverage as they spread.

Don't beat yourself up over that one. It's seriously gone down to a very scary level these days.

_________________
All warfare is based on deception - Sun Tzu, The Art of War
لئيم كافر
View user's profileSend private message
Klaasvaak
Baiting Guru


Joined: 11 May 2004
Posts: 2163


PostPosted: Wed Feb 25, 2015 9:16 am Reply with quoteBack to top

Well the computerguy was able to delete the virus. But the documents are still encrypted Confused I don't know what the name of the virus was
We had a huge argument about this shit. Because 7 years of work is gone. Part of a book she was writing. wordfiles of a lawsuit. And stuff from university.

_________________
Easter 2015Elton Flying Monkey Pole Dancer
www.microsoft.com

View user's profileSend private message
Slightlyoutofit
Baiting Guru


Joined: 13 Feb 2007
Posts: 14310
Location: Foraging for Nuts.


PostPosted: Wed Feb 25, 2015 9:53 am Reply with quoteBack to top

She better have kept those wheelie bin photos or there'll be trouble.

_________________
Star pony pony pony Nurse Nastys Audi TT Purple Flower Whip
Safari Jolly Roger Mortar Closed lad accounts Cellphone United Kingdom

God will see you true for all this you have done to me you bastard. - Collins Kalu
MAY THE HAND THAT TYPE ON KEYBORD BECOME STRICKEN AND TRANSMIT VIRUS TO YOU ENTIRE BODY. - Dr Linda Akeem
oh what a mess its time cabbage punks like u will be expose for trully what they are. - David Cole
View user's profileSend private messageYahoo MessengerSkype Name
Klaasvaak
Baiting Guru


Joined: 11 May 2004
Posts: 2163


PostPosted: Wed Feb 25, 2015 9:55 am Reply with quoteBack to top

Do not worry I keep anything wheelie bin related on my own computer.

_________________
Easter 2015Elton Flying Monkey Pole Dancer
www.microsoft.com

View user's profileSend private message
Fryer
Baiting Guru


Joined: 15 Mar 2008
Posts: 2672
Location: Global Computer Mega Cafe


PostPosted: Wed Feb 25, 2015 9:10 pm Reply with quoteBack to top

Klaasvaak wrote:
she's a teacher and a lot of her university stuff is gone.


University networks = very scary!!

A bunch of kids who know very little about computing tied together via a mostly open configuration....

_________________
Easter 2015Whip Goat x 710 Closed lad accounts x N United States x 2 Nurse Nastys Audi TT Click here for a Sure Fire Pith Helmet Modality
YOU ARE A MOTHERFUCKER SCUMBAG AND AN EMPTY VESSEL
FUCK YOU AND YOUR ENTIRE FAMILY . YOU ARE SATAN. YOU ARE ANTI-CHRIST
guy nawaaa for you oooh
View user's profileSend private message
Joker
*** BANNED ***


Joined: 26 Jul 2012
Posts: 1123


PostPosted: Wed Feb 25, 2015 11:18 pm Reply with quoteBack to top

^ I would agree there. My university network was definitely a scary place as it was a tech uni. Aside from the crazy bastards in the computer science/engineering wanting to "test" ideas and an open university standard that encouraged the "hacker mentality" (if you want to go all Anonymous and media driven with the definition of that screw you as I am talking old school dev.... not this skid shit). Throw on the import students who I am sure were installing malware onto uni lab computers to sell off login credentials to their buddies back home.... yeah uni computers and networks are a scary place. Laughing

Flash drives are another angle. Plugged into an infected computer, they write a "spread file" to the drive and any computer that it gets plugged into... done deal. As someone said at an IT security conference once:

"You don't want me freely plugging my flash drive into your computer. You don't know where it has been, but I do." Laughing

_________________
All warfare is based on deception - Sun Tzu, The Art of War
لئيم كافر
View user's profileSend private message
Klaasvaak
Baiting Guru


Joined: 11 May 2004
Posts: 2163


PostPosted: Thu Feb 26, 2015 8:23 am Reply with quoteBack to top

well i've been reading about the Game over Zeus thing last few days, and thats some scary shit.

_________________
Easter 2015Elton Flying Monkey Pole Dancer
www.microsoft.com

View user's profileSend private message
Nanny Ogg
Baiting Guru


Joined: 19 Mar 2007
Posts: 2628


PostPosted: Thu Feb 26, 2015 1:34 pm Reply with quoteBack to top

That looks a nasty virus. I've had to remove ransomwarefrom one of my student offsprings laptop. Think it was that euro/metropolitain police one.Grrr.
Touch wood things have improved since I upgraded and installed Malwarebytes Premium, its been worth the money, you can install the Premium on up to 3 computers.

Through experience Ive learnt to back up files, upload precious pictures to flickr or picassa or even email myself important documents/pictures/files
View user's profileSend private message
windypops
Baiting Guru


Joined: 25 Jan 2005
Posts: 6059
Location: Planet X


PostPosted: Thu Feb 26, 2015 3:56 pm Reply with quoteBack to top

Klaasvaak wrote:
Well the computer guy was able to delete the virus.


The virus code would also include the encryption algorithm. If it's not on board you may never be able to decrypt the files as the key is missing.

*Edit to add* If the files are locked, you'll have to brute force them open first before even starting to unscramble the contents.

_________________
"No amount of semen donation will save this situation" Sanny Sanny
"We must disagree to agree" Raji Musa

If it's LADS you want. GoTo: http://www.yopmail.com/
and sign in with either ladmail or kentbrockman
View user's profileSend private message
Display posts from previous:      
This forum is locked: you cannot post, reply to, or edit topics.This topic is locked: you cannot edit posts or make replies.


 Jump to:   



View next topic
View previous topic
You cannot post new topics in this forum
You cannot reply to topics in this forum
You cannot edit your posts in this forum
You cannot delete your posts in this forum
You cannot vote in polls in this forum





All Content © 2003 - 419Eater.com : SEO Company
Powered by phpBB © 2001, 2002 phpBB Group :S5: FI Theme :: All times are GMT