Author Topic: Virus Avast doesn't find  (Read 4092 times)

0 Members and 1 Guest are viewing this topic.

Offline kyuuketsuki_kurai

  • Jr. Member
  • **
  • Posts: 88
Virus Avast doesn't find
« on: March 13, 2010, 06:32:16 PM »
There's a virus that locks you out of windows, that's going around in Russia. My father-in-law managed to get it (don't ask how), and Avast! did not pick it up. I have sent it to Avast, so they can put it in the next update.
The file involved is gftkcydl.exe, and it shows up on on Virustotal as having 5 detections.
It causes a very large red and white banner to show up and block most of the screen. This banner tells you to send an SMS to a number, which then charges you (reports claim it's about $10 a message), and send you the number to put in to unlock it. This will repeat itself everytime you restart until the virus is removed.
Housecall was able to remove it for me, so if you get it before it's put into Avast's definition, I'd recommend them.
Alienware 17, Windows 10, Intel Core i7-4700MQ, 8GB RAM, Avast 19.2, Chrome 72.0 64-bit

Offline essexboy

  • Malware removal instructor
  • Avast Überevangelist
  • Probably Bot
  • *****
  • Posts: 40589
  • Dragons by Sasha
    • Malware fixes
Re: Virus Avast doesn't find
« Reply #1 on: March 13, 2010, 06:55:09 PM »
Definitely new I will visit the Kaspersky website to see what data they have Ta

Offline Pondus

  • Probably Bot
  • ****
  • Posts: 37531
  • Not a avast user
Re: Virus Avast doesn't find
« Reply #2 on: March 13, 2010, 07:09:10 PM »

Offline DavidR

  • Avast Überevangelist
  • Certainly Bot
  • *****
  • Posts: 89053
  • No support PMs thanks
Re: Virus Avast doesn't find
« Reply #3 on: March 13, 2010, 07:39:26 PM »
This kind of ransom-ware isn't new, but the method does seem so.

There is no way I would send an SMS message, as for me that just gives them your mobile phone number and leaves you open to attack/fraudulent misuse on that too.

So what to do, I you aren't using hard disk imaging software, this is just another wakeup call to be able to restore your system in minutes from virtually any computer disaster, virus or otherwise. Make regular weekly drive images and do daily back-ups of your volatile data files.

If you fail to plan, then you plan to fail, a robust backup and recovery strategy can save your a**.
Windows 10 Home 64bit/ Acer Aspire F15/ Intel Core i5 7200U 2.5GHz, 8GB DDR4 memory, 256GB SSD, 1TB HDD/ avast! free 24.3.6108 (build 24.3.8975.762) UI 1.0.801/ Firefox, uBlock Origin, uMatrix/ MailWasher Pro/ Avast! Mobile Security

Offline essexboy

  • Malware removal instructor
  • Avast Überevangelist
  • Probably Bot
  • *****
  • Posts: 40589
  • Dragons by Sasha
    • Malware fixes
Re: Virus Avast doesn't find
« Reply #4 on: March 13, 2010, 07:56:02 PM »
Think i found it
http://forum.kasperskyclub.ru/index.php?showtopic=15995
I also found a reference in the closed forum and it was interesting reading - but at the moment it appears to be just two or three instances in Russia only

Onix

  • Guest
Re: Virus Avast doesn't find
« Reply #5 on: March 14, 2010, 01:15:31 AM »
You can get a code for unlocking here:
Dr.Web unlock service
Kaspersky unlock service


Offline kyuuketsuki_kurai

  • Jr. Member
  • **
  • Posts: 88
Re: Virus Avast doesn't find
« Reply #6 on: March 16, 2010, 05:12:36 PM »
I didn't send an SMS, the info I posted was based on research from Russian sites. I tried a couple of those unlock codes, but none of them had worked on the system in question.
Also, it only unlocks the system until next reboot, and really isn't much of a solution.
The computer that was infected had 5 users, and 3 of them were infected. It appears to use shared profiles as a way to spread, and stores itself in the profiles' app data folder.
If a computer has some uninfected users, the virus is reasonably easy to get rid of by deleting the file in question while on an uninfected user.
Alienware 17, Windows 10, Intel Core i7-4700MQ, 8GB RAM, Avast 19.2, Chrome 72.0 64-bit

Offline superhacker

  • Avast Evangelist
  • Advanced Poster
  • ***
  • Posts: 979
  • superhacker != super mario
re:
« Reply #7 on: March 16, 2010, 06:21:08 PM »
hips is also good,i think we should make keygens and cracks for those people"am kidding
Dreams don't die, they just fall asleep.