![]() |
![]() |
|
|||||||
| Register | Blogs | FAQ | Members List | Social Groups | Calendar | Mark Forums Read | Premium Memberships | Auto Loans |
![]() |
|
|
Share |
| Thread Tools | Display Modes |
|
|
#1 (permalink) |
|
Super Moderator
|
Getting rid of "FBI has locked your computer" ransomeware
Anyone done it?
One of the PC's in our office has it, and I can't get past it. Online says to boot into safe mode, but the screen comes up anyway, and it won't let me Ctrl/Alt/Del to get to the deskptop, or kill anything.
__________________
>David > 4x4Spot.com >It only hurts the first time you agree with me... >"A little nonsense now and then is cherished by the wisest men." |
|
|
|
|
|
#2 (permalink) |
|
Super Moderator
|
Oh yeah, Winxp machine if that matters.
__________________
>David > 4x4Spot.com >It only hurts the first time you agree with me... >"A little nonsense now and then is cherished by the wisest men." |
|
|
|
|
|
#3 (permalink) |
|
Rock God
Join Date: Nov 2005
Member # 57779
Posts: 1,300
|
I had it 2 days ago. Try booting into safe mode with command prompt. At the command prompt type
%systemroot%\system32\restore\rstrui.exe this will run the system restore. Restore to an earlier time. Once it has restored then run malwarebytes and combofix. If you have system restore disabled then i'm not sure what the next step would be |
|
|
|
|
|
#5 (permalink) | |
|
"Assault Clip"
Join Date: Jan 2006
Member # 66259
Posts: 5,610
|
Quote:
*unless it was a middle aged women, then it was from an email attachment.
__________________
07 FFL / SOT Last edited by spork2367; 08-03-2012 at 09:19 AM. |
|
|
|
|
|
|
#7 (permalink) |
|
Who stole my title?
Join Date: Apr 2006
Member # 70825
Location: Nacogdoches, Texas
Posts: 718
|
Look online and see if the files are listed that need to be removed.
Boot into safemode with command prompt and delete the files. Some malware gets stored in the temporary internet files folder. You may get lucky by deleting everything in there. If you have a sacrificial computer available you may try putting the infected hard drive in the other computer and scanning it that way. This could infect the other computer so use a computer that you can just format and reinstall when you're done.
__________________
Damn it feels good to be a Lannister. |
|
|
|
|
|
#9 (permalink) |
|
Rock God
Join Date: Apr 2006
Member # 70555
Location: Greensboro, NC
Posts: 1,604
|
Make sure you are disconected form the internet when you turn the computer back on.
I've taken it off three computers. If they are not conected to the web, it would not pop up even when just normal booting to windows. Then restore to an earlier time. |
|
|
|
|
|
#11 (permalink) |
|
Super Moderator
|
Nothing working so far. Booting into safe mode still gets the screen.
Nothing gets past the screen. Unplugging the internet only causes the screen to try and load - but never actually load... still can't get past that either.
__________________
>David > 4x4Spot.com >It only hurts the first time you agree with me... >"A little nonsense now and then is cherished by the wisest men." |
|
|
|
|
|
#12 (permalink) |
|
Registered User
Join Date: Jan 2001
Member # 2741
Location: Santa Rosa, CA
Posts: 2,098
|
Tried rkill yet? EDIT: You can't boot, so you can't try rkill...
__________________
[SIZE="2"][FONT="Arial Black"][COLOR="Wheat"]"The Constitution is not an instrument for the government to restrain the people, it is an instrument for the people to restrain the government." Patrick Henry "Courage doesn't always roar. Sometimes courage is the quiet voice at the end of the day saying 'I will try again tomorrow.'" Radmacher[/FONT][/COLOR][/SIZE] Last edited by Schly; 08-03-2012 at 09:50 AM. |
|
|
|
|
|
#14 (permalink) |
|
Super Moderator
|
Negative - attempting to boot to safe-mode with command ends up hanging, then eventually booting to regular windows safe mode.
__________________
>David > 4x4Spot.com >It only hurts the first time you agree with me... >"A little nonsense now and then is cherished by the wisest men." |
|
|
|
|
|
#15 (permalink) |
|
Rock God
Join Date: Nov 2005
Member # 57779
Posts: 1,300
|
ok they must have a new version out. I was always able to boot into safemode /command prompt.
I would just pull the drive and then install it in another machine and scan it with that machine. That should pull out enough to at least make the old drive bootable |
|
|
|
|
|
#16 (permalink) | |
|
Super Moderator
|
Quote:
![]() Seriously though - thanks for the tips guys... I just have to balance time/$$$ spent with going ahead and replacing an aging machine that was scheduled to be replaced before the end of the year anyway.
__________________
>David > 4x4Spot.com >It only hurts the first time you agree with me... >"A little nonsense now and then is cherished by the wisest men." |
|
|
|
|
|
|
#17 (permalink) |
|
Registered User
Join Date: Sep 2007
Member # 99025
Posts: 260
|
Sometimes you can boot into safe mode and bring up the task manager right away before the other shit can load. Then stop the "explorer.exe" process. Use the file/run option from the task manager to locate and delete the running file or to run a utility like combofix to remove it.
If that don't work then you can try making it a secondary drive in another computer, then locate and delete the infection manually. |
|
|
|
|
|
#18 (permalink) |
|
Rock God
Join Date: Jan 2004
Member # 25927
Location: Northeast TN
Posts: 2,161
|
Oh, that's an easy one.... format and reinstall!
__________________
Dana 60 or 14 bolt disk brake kits $315 shipped --> click here Dana 70 kits $300 --> click here . . Sterling 10.25 kits $390 --> click here Dana 60 front 3/4 ton kits $350--> click here |
|
|
|
|
|
#20 (permalink) |
|
Granite Guru
Join Date: Feb 2000
Member # 226
Location: Yakima, WA
Posts: 4,058
|
Try the Kaspersky rescue disk. http://support.kaspersky.com/faq/?qid=208282173
If this is one of the ones that attacks the MBR and creates its own boot partition you are in for a painful recovery. You can also try pulling the drive and connecting to a known good PC with a USB adapter to scan it offline. Be careful with this because you can infect the known good PC, use a thrasher box instead of your main PC. |
|
|
|
|
|
#23 (permalink) |
|
Newbie
Join Date: Dec 2003
Member # 24935
Posts: 15
|
Is this is the "Pay us or we will tell the cops you have kiddie porn" version?
If so much of the data on the hard drive has been encrypted and no cleaning will fix it. Did it say if you pay them they will give you a password? We had a customer with this last month. The solution was Format and restore from non connected backups. http://www.bleepingcomputer.com/forums/topic449398.html Good Luck Last edited by Typhoon; 08-03-2012 at 10:52 AM. |
|
|
|
|
|
#25 (permalink) | |
|
Registered User
Join Date: Feb 2007
Member # 86724
Posts: 4,647
|
Quote:
I just laughed, we do this about every 6 months cause he's a dirty old man, but he's honest about it. As to the problem. Kaspersky Rescue Disc. that will kill the files and such, which will let you get back into windows and unfuck it's registry settings. It does do the typical nonsense of disallowing certain executables. So I follow that up with Rkill, just to make sure, then malwarebytes to clean up the registry.
__________________
ko derf |
|
|
|
|
![]() |
| Thread Tools | |
| Display Modes | |
|
|