Recommended Posts

So my dad called me demanding I go to the house immidietly. He stated that he got the virus and I thought nothing of it. I thought I was just going to remove it like always. However, this time it was different. This was the most intrusive and threatening virus/malware that I called the police. They sent over a Cybercrimes Investigator within 20min. Like me, he was shocked as well. Not only did this attack blatantly COPY and imitate the Federal Government, but it went as so far as to name my dad, his address, SIC, and take his picture. Not only that, but it paralyzed the wireless network and the computer. I could not do anything. Due to the severity of this attack, the Police informed the RCMP and we force kicked the computer into windows where now I am running a new antivirus (Norton 360) and Malwarebytes to remove the threat.

I posted this to let everyone become aware of this new threat. The Virus was acquired from the Google Homepage. Download logs indicated that. Overall, what do you think and how can it be combated. We called the police because of the personal info security breach.

post-183823-0-30880400-1358906973.jpg

Link to comment
https://www.neowin.net/forum/topic/1132376-virusmalware-i-involved-the-police/
Share on other sites

You guys missed the part where the virus took the Social Insurance Card number. That's what concerned me. We didn't have that information on the computer... so where it get it?

Maybe your dad used it elsewhere? Cra SIN log in. Credit card sign up, credit check, etc...

Yes, you should notify your (or dads) bank, change all passwords/PIN numbers, get new cards and such., but involve the cops? Actually you should still do that, don't rely on the cops to do that for ya.

Don't see where it listed the Social Insurance Card number (or where you blanked it out) in the screenshot, just like the FBI one I posted.

That's an extreme reaction to a common threat. Wow, talk about overkill! Especially when it's so easy to remove in the first place! Are you sure your dad didn't give in and give them the info out of fear? I've seen this happen before....fake scare, better enter info, because hey....if it says police, it must be true, right? I think you might have over reacted. Now, if his credit cards had been used elsewhere, then yes, sure, call the authorities....but this is like literally the second time I've seen this...."Dad" got the fbi/police virus, now every time he boots up, he gets the scare....so to keep it quiet, he enters his details into this (obviously) fake scare screen.....only to have his identity stolen...only to reboot windows and the threat still be there. Research: it's better than jumping to conclusions any day. ;) Lesson learned.

  • Like 3

Well the authorities here have a cybercrime department. I didn't call 911, I called the specific department. The purpose of that department is simply to record and publish new threats, and help people who have had their identities stolen, etc. Yes, I did over react, but better safe than sorry regardless of how common it is. Like I said, I have not seen such a program before and I thought it was a legitimate threat.

I just received a call from the RCMP. They will publish a cyber bulletin on their website notifying people that there is a Canadian version of this virus.

Simon,

He called Cybercrimes to check it out so they will report it and probably track that person who created the virus/malware. So OP is making sure his dad is not a victim of identity theft.

Of course cops do not come to the house to remove crap for you... all they do is report and probably track someone down.

  • Like 2

"The Virus was acquired from the Google Homepage. Download logs indicated that."

then why would you claim something like that?

That is what the investigator told me once he checked the computer. He showed up, put some USB stick into the computer that ran a DOS program. Program scanned the computer and he wrote things down. He found out several things,

1. International IP

2. Program came from www.google.ca

3. International malware cannot be tracked by local police. He contacted RCMP and provided information from USB stick. RCMP will attempt to follow where the money is being transferred since Ukash is being used (without actually transferring money).

4. RCMP will publish warning.

I just wanted to inform people about this program. I did not know that some people already knew about it.

For everyone who is complaining he called the cybercrimes division, why not? Sure, he could have nuked the virus (since we are all well versed in this topic here), but let's assume for a moment that he did this. Then, it is shrugged off to be infected later on possibly and run through the same garbage.

When the cybercrimes division gets involved, they have the power to trace things back further than you might think via the ISP involved. They could trace back the records via a warrant (at least here), and find the originating source of the data. Then take action against that source or trace even further. And with the apparently alarming information contained in the virus such as his ultra private id numbers (social security type), then there is a reason to also call police as there might have been identity theft involved. (I have been a victim of Identity theft and it is not something you would ever want to go through -trust me), With a case number, they could probably give that to any parties involved later on down the road which might have been taken by his identification and bought a lot of things on his credit and never paid. Then it goes to collections/legal action - his Dad finds out later and then is sued. With that case number - it is sort of his insurance against being liable for those charges.

I am sorry this happened to your Dad, it is scary to see this type fo stuff come around especially as sophisticated they are lately.

I'm sure no porn was involved...{Rolls eyes}

Exactly. Every time I've seen this infection, it's never had anything to do with porn. </s> :rolleyes:

i highly doubt he got this from the google homepage btw

why do you highly doubt it? I saw someone at work get the FBI scam one from a google image search, after clicking on the image it went right to that via an exploit (we think it was a java exploit)

I got hit with something similar on Houzz.com, and that is not a malware site, it's a pretty large house design site...

This topic is now closed to further replies.
  • Recently Browsing   0 members

    • No registered users viewing this page.
  • Posts

    • Display Driver Uninstaller (DDU) 18.1.5.5 by Razvan Serea Display Driver Uninstaller (DDU) is a utility for completely removing AMD/NVIDIA/INTEL graphics drivers and related packages from your system, attempting to eliminate all leftovers (including registry entries, folders and files, driver store). Though AMD/NVIDIA/INTEL drivers can usually be removed via the Windows Control Panel, this uninstaller tool was created for situations where standard uninstall fails, or when you need to fully remove NVIDIA or ATI graphics card drivers. After using this driver cleaner, your system will behave as though it’s the first time you’re installing a new driver—similar to a fresh Windows installation. As with all such tools, we recommend creating a restore point beforehand, allowing you to undo changes if issues arise. If you're having trouble installing an older or newer driver, try it—there are reports that it resolves such problems. Recommended usage: The tool can be used in Normal mode but for absolute stability when using DDU, Safemode is always the best. Make a backup or a system restore (but it should normally be pretty safe). It is best to exclude the DDU folder completely from any security software to avoid issues. You do NOT need to uninstall the driver prior using DDU. Requirements: .NET Framework 4.8 Compatible with Windows 7, 8, 8.1, 10, and 11 (32-bit or 64-bit) Note: Using on Insider Preview builds is at your own risk. Display Driver Uninstaller (DDU) 18.1.5.5 changelog: Added 'Reset to recommended' button for the Options. General fixes and improvements. Download: Display Driver Uninstaller (DDU) 18.1.5.5 | 1.7 MB (Freeware) Download: DDU Portable | 1.2 MB Links: Display Driver Uninstaller Home Page | Screenshot Get alerted to all of our Software updates on Twitter at @NeowinSoftware
    • WACUP 1.99.51.24568 Preview by Razvan Serea WACUP (WinAmp Community Update Project) is a modern, enhanced version of the classic Winamp music player, designed for better stability, performance, and compatibility. Built for Windows, WACUP retains the familiar Winamp interface while adding 64-bit support, bug fixes, and new features like improved audio format support, customizable skins, and optimized playlist management. Unlike bloated alternatives, WACUP focuses on lightweight performance and regular updates, making it the best choice for fans of the classic Winamp experience. Basically, if you miss the good old days of Winamp and want a modern upgrade that doesn’t mess things up, WACUP is for you! WACUP key features: Classic Winamp Feel – Keeps the familiar interface and functionality. Bug Fixes & Stability – Fixes old Winamp issues and improves performance. 64-Bit Support – Works better on modern systems. More Formats & Plugins – Supports additional audio formats and third-party plugins. Customizable UI – Skins and tweaks for a personalized look. Better Library Management – Improved playlists, media organization, and search. No Bloat – Focuses on performance without unnecessary extras. Regular Updates – Community-driven development with new features and fixes. WACUP 1.99.51.24568 Preview changelog: Fixed a deadlock seen from the recent crash reports when doing some of the drag + drop actions within the media library window Fixed a loading crash seen related to a problem with some of the artwork cache image files being restored which should now be better handled allowing for the bad image to be removed without it failing Fixed a deadlock seen from the recent crash reports when the internal metadata cache clearing is triggered which could block the main ui thread for too long with this now being moved to a background thread Fixed some performance issues with some of the methods related to determining artwork support which mainly affected the local library import / refresh (this is still slower for some compared to other players because there's more data & artwork aspects being checked for which means doing more processing on a single file despite the best of attempts to reduce duplicate / heavy processing where possible) Fixed a crash with the JTFE based missing files hotkey which no one seems to have used for an age for this to appear (maybe it's time to seriously consider stripping out features that aren't being used) Fixed how some of the file types which use extra information to reference their sub-songs is handled which was preventing some from being correctly resolved back to their base file (noticed fixing above) Fixed an issue with the handling of files with underscores in their filepath which wasn't being correctly handled causing some of the filename to be lost when shown as the title if title reading is delayed Fixed a few things that might be behind NotSoDirect not being stable for some setups though am still not certain that the changes done for this are going to fully resolve the problem from the crash reports Fixed the OS toast handling when there's no prior shortcut in the OS start menu to now create the shortcut (needed to allow the yes/no buttons for the new build / post-release toast) to be done as a hidden one so it's less likely to cause annoyance for those not wanting to see it whilst still allowing this less than ideal OS api implementation requirement to be met to avoid toasts without the needed buttons Fixed a regression when moving from taglib1 to taglib2 which broke some of the handling in place to allow for external programs to still access files when wacup has a held open cached instance of the file Everything else Updated cppwinrt (gen_win10shell.dll) to 3.0.260520.1 (26 May 2026) Updated libcurl (libcurl.dll) to 8.2.1 (24 Jun 2026) Updated Monkey's Audio (in_ape.dll) to 13.15 (28 Jun 2026) Updated mpg123 (mpg123.dll) to 1.33.6 (6 Jun 2026) Updated OpenSSL (libcurl.dll) to 3.5.7 (9 Jun 2026) Updated pugixml to 1.16 (16 Jun 2026) Updated taglib (tag2.dll) to 2.3.0 (11 May 2026) Updated vgmstream (in_vgmstream.dll) to the latest Git commit from 28 Jun 2026 Download: WACUP 64-bit | 9.6 MB (Freeware) Download: WACUP 32-bit View: WACUP Website | Screenshots Get alerted to all of our Software updates on Twitter at @NeowinSoftware
    • "over a thousand engineering hours" and started selling it but could not take a couple of minuets to send an AI email to ask permission. What an expensive lesson.
    • just tested it yesterday, a simple page with autoloading ADS takes 60mb....just 1 page for 60 megabytes.   poor people with a limited internet never will visit neolose
    • Tor Browser 15.0.17 by Razvan Serea Protect your privacy. Defend yourself against network surveillance and traffic analysis. Tor is a network of virtual tunnels that allows people and groups to improve their privacy and security on the Internet. The Tor software protects you by bouncing your communications around a distributed network of relays run by volunteers all around the world: it prevents somebody from watching your Internet connection and learning what sites you visit, it prevents the sites you visit from learning your physical location, and it lets you access sites which are blocked. The Tor Browser Bundle lets you use Tor on Windows, Mac OS X, or Linux without needing to install any software. It can run off a USB flash drive, comes with a pre-configured web browser to protect your anonymity, and is self-contained. Tor Browser 15.0.17 changelog: All Platforms Updated Tor to 0.4.9.11 Updated NoScript to 13.6.25.1984 Build System / All Platforms Bug tor-browser-build#41821: Update gpg subkeys for boklm Bug tor-browser-build#41827: Update morgan's keychain with renewed key Download: Tor Browser (64-bit) | Tor Browser (32-bit) | 109.0 MB (Open Source) View: Tor Browser Website | Other Operating Systems Get alerted to all of our Software updates on Twitter at @NeowinSoftware
  • Recent Achievements

    • Reacting Well
      Wakeen1966 earned a badge
      Reacting Well
    • Rookie
      Almohandis went up a rank
      Rookie
    • Apprentice
      jahara21 went up a rank
      Apprentice
    • Reacting Well
      NovaEdgeX earned a badge
      Reacting Well
    • Week One Done
      NovaEdgeX earned a badge
      Week One Done
  • Popular Contributors

    1. 1
      +primortal
      530
    2. 2
      +Edouard
      266
    3. 3
      PsYcHoKiLLa
      148
    4. 4
      Steven P.
      99
    5. 5
      macoman
      55
  • Tell a friend

    Love Neowin? Tell a friend!