Recommended Posts

In the screenshot I didn't see where the SSN/SIC number was mentioned or blocked out, just a IP and City.

And curious minds want to know what the RCMP used to "check" the computer. Malwarebytes (pro or free version)?

More info was at the bottom, including how much needed to be paid, etc. I did not include it.

In the screenshot I didn't see where the SSN/SIC number was mentioned or blocked out, just a IP and City.

And curious minds want to know what the RCMP used to "check" the computer. Malwarebytes (pro or free version)?

I'd like to know the name of this supposed "dos" program, considering Windows hasn't used "dos" since....forever ago.

why do you highly doubt it? I saw someone at work get the FBI scam one from a google image search, after clicking on the image it went right to that via an exploit (we think it was a java exploit)

I got hit with something similar on Houzz.com, and that is not a malware site, it's a pretty large house design site...

sounds like "drive by downloads", usually happens because a machine is not fully patched. ;)

I'd like to know the name of this supposed "dos" program, considering Windows hasn't used "dos" since....forever ago.

sounds like "drive by downloads", usually happens because a machine is not fully patched. ;)

Command prompt.

Exactly. Every time I've seen this infection, it's never had anything to do with porn. </s> :rolleyes:

you can get this crap from infected sites that aren't porn, Houzz.com definatly isn't a porn site, and I got hit by it there..... our local newspaper got hit thanks to one of their stupid ad providers..... anyone who went to the paper site got something similar....

Command prompt.

LOLOLOLOL!!!!!! Too funny! :rofl:

you can get this crap from infected sites that aren't porn, Houzz.com definatly isn't a porn site, and I got hit by it there..... our local newspaper got hit thanks to one of their stupid ad providers..... anyone who went to the paper site got something similar....

Yeah, a drive by download....which happens to unpatched machines. Not my first time dealing with them. PatchMyPC(dot)net. Sure does help! ;)

I just had this happen to a co-worker on a company laptop (it's a POS, but anyways) and ended up just doing a format/clean install (was quicker/easier) all (needed) docs and such were on the server (and if they weren't, lesson learned).

And that lesson was:

1) Use a better AV,

2) Disable Java

3) Backup anything not on the server

My brother guy the exact same one, he was so panicked it was hilarious, I made fun of him good for it, I suspect he got it from

using one of those websites that let you watch TV shows for free, and using a java exploit, so I removed the trojan and Java.

OP:

Take the time to make sure his PC is up to date, browsers updates, everything.

As for his browsers,

if he's using Firefox: Make sure to install AdBlock Plus, and NoScript.

if he's using Chrome: install Adblock, and Disconnect.

if he's using IE9/10: Install the FanBoy and EasyList adblocking TPLs. Also make sure that SmartScreen filter is running.

Should help him in the future. They'll prevent arbitrary code from running. Also make sure any and all unneeded addons are eliminated.

Also, if possible, remove him from the default administrator account. If he's going to keep calling you for help, just set yourself up as the administrator. Lol. It's what I did for my parents, and as annoying as it was for them, it worked. They couldn't run anything without my permission.

LOLOLOLOL!!!!!! Too funny! :rofl:

Yeah, a drive by download....which happens to unpatched machines. Not my first time dealing with them. PatchMyPC(dot)net. Sure does help! ;)

unpatched machine? you mean a patch for something like Java which DIDN'T have a patch out, and is something that is actually required in a lot of business environments at the browser level?..... please tell me how it could of been more pached then the latest patches out there by Oracle and Microsoft....

I just finished removing the virus using Malwarebytes. 117 Infections in total. Oy. Machine was Windows 7 fully patched. I ran the updates 2 days ago. I will be installing Win8 this weekend. Oh, and he was using a Guest Account named Family. Not an administrator account.

I just finished removing the virus using Malwarebytes. 117 Infections in total. Oy. Machine was Windows 7 fully patched. I ran the updates 2 days ago. I will be installing Win8 this weekend. Oh, and he was using a Guest Account named Family. Not an administrator account.

How the heck is arbitrary code running on a guest account?

How the heck is arbitrary code running on a guest account?

Beats me, I was surprised.

Edit: http://social.msdn.microsoft.com/Forums/en-US/windowssecurity/thread/800a69df-8312-4105-b70e-235500ab5421

Looks like viruses can still install on a guest account and run, but are not system wide and thus will not affect other users. This is how I was able to remove it. I ran Malwarebytes on the admin account.

Someone I work with got the FBI one, and, wait for it, she PAID IT!!!! She came to work talking about how the FBI made her pay $300 for "something" or they wouldn't unlock her computer. We could not believe how stupid that was. Obviously she or her spouse is a little guilty of something...

Someone I work with got the FBI one, and, wait for it, she PAID IT!!!! She came to work talking about how the FBI made her pay $300 for "something" or they wouldn't unlock her computer. We could not believe how stupid that was. Obviously she or her spouse is a little guilty of something...

of being a idiot. They must've had more dollars than sense.... now they have a little less... of both.

AND that's EXACTY the people they prey on. The uninformed/non-neowinian type (we all know better...right?)

i just removed this one from a friends laptop the other day. From what i could tell, it came from putlocker and/or skype, but could have other delivery methods. the girl that i removed it for actually thought it was real at first.

I don't see any identifying details even removed by yourself from the screen shot. How do you know details were stolen.

Sounds like a case of a parent who doesn't know enough about the Internet, trying to do something and not realising it's unsafe and giving away details.

Hello,

A fairly common scam/piece of malware, I've seen it called Win32/Reveton or simply "Moneypak." It displays fake "announcements" from various law enforcement agencies around the world. Here are a couple of articles about it:

I have heard of FBI (US), Garda (Ireland) and Metropolitan Police (UK) versions of this, but this is the first time I can recall hearing about an RCMP-specific version.

It is very likely your anti-malware/security vendor's technical support department is quite familiar with removing this, and can give additional instructions on securing the machine.

For example, one might want to check the hosts file on the computer and/or the DNS servers being used, in case they were involved in what looks like a redirection of Google's web site.

Regards,

Aryeh Goretsky

My Sister in laws friend has this aswell so it must be doing the rounds

there are lots of different versions of it for different Countrys

https://www.botnets....dex.php/Reveton

and also removal instructions

http://www.f-secure.com/v-descs/trojan_w32_reveton.shtml

This topic is now closed to further replies.
  • Recently Browsing   0 members

    • No registered users viewing this page.
  • Posts

    • outside of the AI and embedded spyware, I think windows 8 is by far the worse version of windows. Or maybe windows ME could be worse.
    • All that hype about Android apps on PC and then nothing because of that stupid Amazon App Store partnership.
    • hands down the worst version of Windows to date and sadly I think it's only downhill from here
    • I've never known a release to have so much pressure than this one. There is so much riding on the whole games industry because of everything that's changed in the past five years. That if this is a complete flop then I think the whole games industry is done unless something radically changes.
    • Windows 11 is now five years old by Taras Buria Windows 11 is now half a decade old. Five years ago, on June 24, 2021, Microsoft announced its latest operating system, designed to "bring you closer to what you love." Today, Windows 11 celebrates its fifth birthday. The launch of Windows 11 was interesting. Rumors about Microsoft introducing a Windows 10 successor popped up weeks before the public announcement, and a few days later, an entire preview build leaked online, allowing everyone to take a peek at what Microsoft was preparing. A few weeks later, Microsoft confirmed that Windows 11 was a thing and officially unveiled its next-gen operating system. Early versions of Windows 11 promised quite a lot. A redesigned, more modern user interface, a brand new Start menu and taskbar, improvements to virtual desktops and window snapping, Android app support, Teams integrated into the taskbar, Windows Widgets, a new version of the Microsoft Store, improved security, and more. Some of those features were welcomed, while others were received with heavy criticism. Besides missing taskbar and Start menu features, many disliked the steep hardware requirements, which kicked out PCs that were back then still perfectly fine. TPM and Secure Boot became mandatory, causing a spike in sales of dedicated TPM chips for motherboards. Double-layered context menus were disliked as well, and it is something that Microsoft still has to fix. Additionally, with time, some of Windows 11's exclusive features were simply killed. Microsoft removed the Teams integration and discontinued Android app support. During the early days of Windows 11, Microsoft was quite unwilling to address things that users criticized most. After four years on the market, management changes, and heated competition from the Mac camp, Microsoft finally decided to give in and take its operating system back to the drawing board to fix everything users had been complaining about for years. Microsoft is now redesigning the Start menu, adding missing taskbar features, improving Windows Update, fixing Windows 11's context menu, and more. Some believe all that warrants a new Windows 12 release, but for now, it appears that Windows 11 will stick around for a while. With Microsoft now listening to its core audience and acting upon received feedback, fans can finally expect a much better version of Windows 11 than what was available five years ago. Here is to five more years, Windows 11!
  • Recent Achievements

    • Week One Done
      Wavespace earned a badge
      Week One Done
    • One Year In
      OHI Accounting earned a badge
      One Year In
    • First Post
      Almohandis earned a badge
      First Post
    • Rookie
      DaviKar went up a rank
      Rookie
    • Dedicated
      HidekoYamamoto94 earned a badge
      Dedicated
  • Popular Contributors

    1. 1
      +primortal
      463
    2. 2
      +Edouard
      176
    3. 3
      PsYcHoKiLLa
      122
    4. 4
      Michael Scrip
      81
    5. 5
      Xenon
      75
  • Tell a friend

    Love Neowin? Tell a friend!