Recommended Posts

So my dad called me demanding I go to the house immidietly. He stated that he got the virus and I thought nothing of it. I thought I was just going to remove it like always. However, this time it was different. This was the most intrusive and threatening virus/malware that I called the police. They sent over a Cybercrimes Investigator within 20min. Like me, he was shocked as well. Not only did this attack blatantly COPY and imitate the Federal Government, but it went as so far as to name my dad, his address, SIC, and take his picture. Not only that, but it paralyzed the wireless network and the computer. I could not do anything. Due to the severity of this attack, the Police informed the RCMP and we force kicked the computer into windows where now I am running a new antivirus (Norton 360) and Malwarebytes to remove the threat.

I posted this to let everyone become aware of this new threat. The Virus was acquired from the Google Homepage. Download logs indicated that. Overall, what do you think and how can it be combated. We called the police because of the personal info security breach.

post-183823-0-30880400-1358906973.jpg

Link to comment
https://www.neowin.net/forum/topic/1132376-virusmalware-i-involved-the-police/
Share on other sites

You guys missed the part where the virus took the Social Insurance Card number. That's what concerned me. We didn't have that information on the computer... so where it get it?

Maybe your dad used it elsewhere? Cra SIN log in. Credit card sign up, credit check, etc...

Yes, you should notify your (or dads) bank, change all passwords/PIN numbers, get new cards and such., but involve the cops? Actually you should still do that, don't rely on the cops to do that for ya.

Don't see where it listed the Social Insurance Card number (or where you blanked it out) in the screenshot, just like the FBI one I posted.

That's an extreme reaction to a common threat. Wow, talk about overkill! Especially when it's so easy to remove in the first place! Are you sure your dad didn't give in and give them the info out of fear? I've seen this happen before....fake scare, better enter info, because hey....if it says police, it must be true, right? I think you might have over reacted. Now, if his credit cards had been used elsewhere, then yes, sure, call the authorities....but this is like literally the second time I've seen this...."Dad" got the fbi/police virus, now every time he boots up, he gets the scare....so to keep it quiet, he enters his details into this (obviously) fake scare screen.....only to have his identity stolen...only to reboot windows and the threat still be there. Research: it's better than jumping to conclusions any day. ;) Lesson learned.

  • Like 3

Well the authorities here have a cybercrime department. I didn't call 911, I called the specific department. The purpose of that department is simply to record and publish new threats, and help people who have had their identities stolen, etc. Yes, I did over react, but better safe than sorry regardless of how common it is. Like I said, I have not seen such a program before and I thought it was a legitimate threat.

I just received a call from the RCMP. They will publish a cyber bulletin on their website notifying people that there is a Canadian version of this virus.

Simon,

He called Cybercrimes to check it out so they will report it and probably track that person who created the virus/malware. So OP is making sure his dad is not a victim of identity theft.

Of course cops do not come to the house to remove crap for you... all they do is report and probably track someone down.

  • Like 2

"The Virus was acquired from the Google Homepage. Download logs indicated that."

then why would you claim something like that?

That is what the investigator told me once he checked the computer. He showed up, put some USB stick into the computer that ran a DOS program. Program scanned the computer and he wrote things down. He found out several things,

1. International IP

2. Program came from www.google.ca

3. International malware cannot be tracked by local police. He contacted RCMP and provided information from USB stick. RCMP will attempt to follow where the money is being transferred since Ukash is being used (without actually transferring money).

4. RCMP will publish warning.

I just wanted to inform people about this program. I did not know that some people already knew about it.

For everyone who is complaining he called the cybercrimes division, why not? Sure, he could have nuked the virus (since we are all well versed in this topic here), but let's assume for a moment that he did this. Then, it is shrugged off to be infected later on possibly and run through the same garbage.

When the cybercrimes division gets involved, they have the power to trace things back further than you might think via the ISP involved. They could trace back the records via a warrant (at least here), and find the originating source of the data. Then take action against that source or trace even further. And with the apparently alarming information contained in the virus such as his ultra private id numbers (social security type), then there is a reason to also call police as there might have been identity theft involved. (I have been a victim of Identity theft and it is not something you would ever want to go through -trust me), With a case number, they could probably give that to any parties involved later on down the road which might have been taken by his identification and bought a lot of things on his credit and never paid. Then it goes to collections/legal action - his Dad finds out later and then is sued. With that case number - it is sort of his insurance against being liable for those charges.

I am sorry this happened to your Dad, it is scary to see this type fo stuff come around especially as sophisticated they are lately.

I'm sure no porn was involved...{Rolls eyes}

Exactly. Every time I've seen this infection, it's never had anything to do with porn. </s> :rolleyes:

i highly doubt he got this from the google homepage btw

why do you highly doubt it? I saw someone at work get the FBI scam one from a google image search, after clicking on the image it went right to that via an exploit (we think it was a java exploit)

I got hit with something similar on Houzz.com, and that is not a malware site, it's a pretty large house design site...

This topic is now closed to further replies.
  • Recently Browsing   0 members

    • No registered users viewing this page.
  • Posts

    • The laptop in the bedroom is an Acer with i7-10510U CPU. Acer's website states they will not be upgrading it so I had little choice other than disable secure boot. I know next to nothing on these matters so hopefully it will be fine.
    • GitHub removes manual model selection from Copilot free and student plans by Karthik Mudaliar GitHub is removing the ability to manually select an AI model from its Copilot Free and Student plans, making its automatic routing system the default and only way to choose a model. This means users on these tiers will no longer be able to deliberately select a particular OpenAI, Anthropic, Google, or Microsoft model for a task. In its announcement, GitHub said Copilot Auto will dynamically choose what it considers the best model for each request. Free and Student accounts will retain access to models from multiple families, although the available selection will continue to depend on the restrictions attached to each plan. GitHub did not identify a fixed pool of models that Auto will always use, and its documentation warns that model availability can change over time. GitHub describes Auto as more than a random fallback system. On supported surfaces, its task-optimization technology evaluates the complexity of a request alongside real-time information about model health and availability. Straightforward prompts can be routed to faster and less expensive models, while more demanding coding tasks may be sent to higher-cost reasoning models. The company says this approach should reduce rate limiting, latency, and failed requests. Auto generally selects one model along natural prompt-caching boundaries rather than repeatedly switching models during a session, as GitHub found that mid-session changes increased costs without producing sufficient improvements in output quality. Users can still check which model generated a response. In Copilot Chat, the information appears when hovering over an answer, while Copilot CLI and the Copilot cloud agent display the selected model alongside their output. Auto is available in Copilot Chat, Copilot CLI, and the cloud agent, with the exact implementation and release status varying between supported development environments. The latest restriction follows several months of adjustments to Copilot’s individual plans. GitHub temporarily halted new Pro, Pro+, and Student subscriptions in April as it sought to manage demand and service reliability. It later introduced token-based billing and began gradually reopening individual-plan registrations on June 17. Alongside the picker change, GitHub is retiring the “Preview” label from Microsoft-developed models. It argues that the label is no longer necessary because Auto handles model routing and models are continuously updated behind the scenes.
    • Look up 'inflation' kid. Ask an AI for the numbers between both games.
    • Google reportedly set to lose two key Gemini and DeepMind researchers to Anthropic by Karthik Mudaliar Google is reportedly preparing to lose two more prominent artificial intelligence researchers, with Gemini contributors Jonas Adler and Alexander Pritzel planning to join rival AI developer Anthropic. According to a report from Bloomberg, both researchers are viewed internally as important contributors to Google’s flagship Gemini model family. Adler worked on Google’s AI coding efforts, while Pritzel was involved in the process used to train AI systems. Neither company has publicly confirmed the moves. The report also does not say when the researchers will formally leave Google or what positions they will hold at Anthropic. Training a large AI model requires decisions covering its architecture, data preparation, distributed computing infrastructure, and post-training methods that shape how the finished system behaves. Researchers with experience operating at the scale of Gemini are consequently difficult to replace quickly. Both Adler and Pritzel have previously contributed to Google DeepMind’s scientific research as well. They are listed among the authors of the company’s work on expanding AlphaFold protein-structure predictions across entire proteomes, alongside AlphaFold researchers including John Jumper. The reported departures arrive shortly after another important change within Google’s Gemini organization. Gemini co-lead Noam Shazeer is leaving Google for OpenAI, after returning to the search company in 2024 through its deal with Character.AI. Shazeer is particularly well known as one of the authors of the Transformer paper, whose architecture became the foundation for most modern large language models. Anthropic, meanwhile, has been recruiting recognizable figures from other leading laboratories. OpenAI co-founder and former Tesla AI director Andrej Karpathy joined Anthropic’s pre-training team in May. His move, followed by the reported recruitment of several Google researchers, suggests Anthropic is strengthening the research teams responsible for the core capabilities of future Claude models rather than concentrating solely on product and enterprise sales. The competition is complicated by the companies’ extensive commercial relationships. Anthropic competes directly with Google’s Gemini models, but it also relies on Google as an infrastructure partner. In April, Anthropic announced an expanded agreement with Google and Broadcom covering multiple gigawatts of next-generation Tensor Processing Unit capacity. TPUs are Google-designed accelerators used to train and run large AI models. via Bloomberg
  • Recent Achievements

    • One Year In
      Philsl earned a badge
      One Year In
    • Dedicated
      Scoobystu earned a badge
      Dedicated
    • First Post
      Tom Schmidt earned a badge
      First Post
    • One Month Later
      D0nn13 earned a badge
      One Month Later
    • Rookie
      +ChiefOfNeo went up a rank
      Rookie
  • Popular Contributors

    1. 1
      +primortal
      461
    2. 2
      +Edouard
      177
    3. 3
      PsYcHoKiLLa
      124
    4. 4
      Michael Scrip
      79
    5. 5
      Xenon
      76
  • Tell a friend

    Love Neowin? Tell a friend!