Author Topic: Tablet infected by FBI MoneyPak Virus  (Read 17674 times)

0 Members and 1 Guest are viewing this topic.

tragicmat1

  • Guest
Tablet infected by FBI MoneyPak Virus
« on: August 19, 2013, 08:05:42 AM »
Hello,

Like the title says, my tablet has recently been infected by the FBI Moneypak Virus. Although Avast mobile recognizes it as malicious webpage (it's locked my browser), virus scan cannot find it. I do not know what steps I must take in order to rid the virus, so any help would be appreciated. Thank you!

Offline Ondra Cermak

  • AMS
  • Avast team
  • Full Member
  • *
  • Posts: 181
Re: Tablet infected by FBI MoneyPak Virus
« Reply #1 on: August 19, 2013, 09:50:11 AM »
If you visited a malicious page and avast! blocked it and you went away, then you are most likely fine and nothing has been downloaded to your tablet. Just to be sure, you can run full scan of the external memory/SD card, but if nothing is found, then you're okay.

tragicmat1

  • Guest
Re: Tablet infected by FBI MoneyPak Virus
« Reply #2 on: August 20, 2013, 02:17:14 AM »
Oh no, my tablet has already been infected. I had downloaded Avast AFTER, to see if the scan would do anything (but as I expected it wouldn't). Right now, it's impossible to use the browser on my tablet.

Offline Ondra Cermak

  • AMS
  • Avast team
  • Full Member
  • *
  • Posts: 181
Re: Tablet infected by FBI MoneyPak Virus
« Reply #3 on: August 20, 2013, 08:52:01 AM »
I'm not a virus analyst, but I thought that FBI Moneypak is a Windows malware, not Android. What exactly do you see in your Android browser?

tragicmat1

  • Guest
Re: Tablet infected by FBI MoneyPak Virus
« Reply #4 on: August 20, 2013, 09:16:42 AM »
It's basically the same as the windows version. It locks your browser, (though not the other functions), and automatically redirects you to the FBI moneypak scam, asking you for money. It lists your IP and location, and the whole fine will increase if not paid by a certain period (12 hrs).
« Last Edit: August 20, 2013, 09:18:26 AM by tragicmat1 »

Offline Ondra Cermak

  • AMS
  • Avast team
  • Full Member
  • *
  • Posts: 181
Re: Tablet infected by FBI MoneyPak Virus
« Reply #5 on: August 20, 2013, 05:06:01 PM »
I sent your issue to one of our Virus analysts, so hopefully he'll come for the rescue :)

tragicmat1

  • Guest
Re: Tablet infected by FBI MoneyPak Virus
« Reply #6 on: August 21, 2013, 04:24:50 AM »
Thanks a bunch!

svehlak

  • Guest
Re: Tablet infected by FBI MoneyPak Virus
« Reply #7 on: August 21, 2013, 12:03:59 PM »
Can you please share whic URL is it? Can not find any ransomware  for android devices.

tragicmat1

  • Guest
Re: Tablet infected by FBI MoneyPak Virus
« Reply #8 on: August 22, 2013, 07:49:26 AM »
It automatically redirects me to fbi.gov.id657546456-3999456674.a8764.com/?flow_id=2019&453640=45513/case_id=39994 .

It should also be noted, that I seem to now be able to use my browser after changing my homepage. But, I feel like as I didn't really do anything, the virus might still be lurking. But, I do not know what methods I have to go through in order to fix it.

svehlak

  • Guest
Re: Tablet infected by FBI MoneyPak Virus
« Reply #9 on: August 22, 2013, 05:31:43 PM »
Did you try to use another browser? This site has low reputation for sure, but there are no many ways, how to affect browser behavior. Is your tablet rooted? Also, you can use privacy advisor to see, which apps have privilige to use internet communication and change application behavior and may be you will find it..

tragicmat1

  • Guest
Re: Tablet infected by FBI MoneyPak Virus
« Reply #10 on: August 22, 2013, 09:17:13 PM »
Yes, if I use another browser, then I can get it to work and unlocked. But, I just wasn't sure if that was just the solution I should go with, or to actually try to get rid of the virus. Perhaps I should just uninstall the default browser? Also, I'm not entirely sure if there are other problems too, as I've avoided using the tablet ever since it has been infected.

Also no, the tablet is not currently rooted.
« Last Edit: August 22, 2013, 09:18:58 PM by tragicmat1 »

svehlak

  • Guest
Re: Tablet infected by FBI MoneyPak Virus
« Reply #11 on: August 23, 2013, 09:14:15 AM »
I suppose you will not be able to uninstall default browser, but you can try to find in system settings/applications and delete its data. It should be named something like "Browser" or com.android.browser.