Author Topic: Ransomware  (Read 2187 times)

0 Members and 1 Guest are viewing this topic.

TommyDuke

  • Guest
Ransomware
« on: September 02, 2013, 01:07:15 AM »
 >:( Got an instant hit by the DOJ ransomware stating my  computer is locked until I go to CVS and pay $300. Also; something to do with child porn...
I immediately restarted in the safe mode and ran a full Avast virus scan with no indications of a bug.
Returning to the regular boot-up, I attempted to get online again. Firefox 23, Win7 32bit. Same problem.
Thinking only the browser was affected, I uninstalled FF.
I'm using the Avast safe browser now.
When I attempt to re-install FF I get "XPCOM not found". I believe this is a DLL.
Right now I'm using the laptop (affected machine) and have a desktop at home to get any necessary downloads. It seems anything I attempt to download in this browser stays in it, and I am unable to access the download when the browser is closed.
Any suggestions?
Also, Avast AV never even noticed all that was going on!?

Offline Michael (alan1998)

  • Massive Poster
  • ****
  • Posts: 2768
  • Volunteer
Re: Ransomware
« Reply #1 on: September 02, 2013, 02:11:00 AM »
I would help you, but I'm not allowed to given my Age and stuff. Nor am I certified.

You do need to follow these Directions.. http://forum.avast.com/index.php?topic=53253.0

Adwcleaner, MBAM, OTL, AswMBR

VOLUNTEER

Senior Security Analyst; Sys Admin (Linux); Forensics/Incident Response.

Security is a mindset, not an application. Think BEFORE you click.

Offline essexboy

  • Malware removal instructor
  • Avast Überevangelist
  • Probably Bot
  • *****
  • Posts: 40589
  • Dragons by Sasha
    • Malware fixes
Re: Ransomware
« Reply #2 on: September 02, 2013, 07:29:35 PM »
With the safe zone browser you are unable to save anything as it is totally isolated from the rest of the system

Could you run this programme from safe mode

Download OTL  to your Desktop
Secondary link
  • Double click on the icon to run it. Make sure all other windows are closed and to let it run uninterrupted.


  • Select All Users
  • Under the Custom Scan box paste this in
netsvcs
BASESERVICES
%SYSTEMDRIVE%\*.exe
/md5start
services.*
explorer.exe
winlogon.exe
Userinit.exe
svchost.exe
/md5stop
dir "%systemdrive%\*" /S /A:L /C
CREATERESTOREPOINT


  • Click the Run Scan button. Do not change any settings unless otherwise told to do so. The scan wont take long.
    • When the scan completes, it will open two notepad windows. OTL.Txt and Extras.Txt. These are saved in the same location as OTL.
    • Post  both logs

TommyDuke

  • Guest
Re: Ransomware
« Reply #3 on: September 02, 2013, 09:50:26 PM »
This the only log that appeared (attached). I did nothing else but run the scan.



Offline essexboy

  • Malware removal instructor
  • Avast Überevangelist
  • Probably Bot
  • *****
  • Posts: 40589
  • Dragons by Sasha
    • Malware fixes
Re: Ransomware
« Reply #4 on: September 02, 2013, 10:36:51 PM »
This is a new variant as I can see no sign of ransom malware there

So I would like to run another programme


  • Download RogueKiller  and save it on your desktop.
     
    NOTE: If using IE8 or better Smartscreen Filter will need to be disabled

  • Quit all programs
  • Start RogueKiller.exe.
  • Wait until Prescan has finished ... 
  •     Click on Scan
   
 
  • Wait for the end of the scan. 
  • The report has been created on the desktop. 
  • Click on the Delete button.
     
  • The report has been created on the desktop.
  • Next click on the ShortcutsFix   

  • The report has been created on the desktop.
Please attach:    All RKreport.txt text files located on your desktop.

TommyDuke

  • Guest
Re: Ransomware
« Reply #5 on: September 02, 2013, 11:13:43 PM »
Ran RK, one suspicious file>deleted. Fixed shortcuts. Log attached...
BTW - Shortly I will be returning to home base and using the desktop. Any suggestions on avoiding
this ransomware in the future?
« Last Edit: September 02, 2013, 11:15:36 PM by TommyDuke »

Offline essexboy

  • Malware removal instructor
  • Avast Überevangelist
  • Probably Bot
  • *****
  • Posts: 40589
  • Dragons by Sasha
    • Malware fixes
Re: Ransomware
« Reply #6 on: September 03, 2013, 03:25:18 PM »
When you boot to normal mode are you still getting the ransom screen ?

TommyDuke

  • Guest
Re: Ransomware
« Reply #7 on: September 03, 2013, 05:08:27 PM »
No. All is normal now. When I saw the Dept of Justice ransom page, I turned off the computer manually (couldn't shut down normally). Rebooting in the safe mode I then removed FF with Revo uninstaller. No problems after that, except that I didn't have FF for a browser anymore; and couldn't download a new copy using the Avast safe zone browser.
Now I am back on my desktop and have got a copy of FF on a thumb drive to load into the laptop the next time I use it.
Thanks for all your help.

Offline essexboy

  • Malware removal instructor
  • Avast Überevangelist
  • Probably Bot
  • *****
  • Posts: 40589
  • Dragons by Sasha
    • Malware fixes
Re: Ransomware
« Reply #8 on: September 03, 2013, 06:26:50 PM »
Intriguing, that is something I need to bear in mind if it is now working from Firefox instead of the normal method(s)