Forum Home
Press F1
 
Thread ID: 134256 2013-06-15 00:58:00 Name this scam...? bazmeister (3216) Press F1
Post ID Timestamp Content User
1345778 2013-06-15 00:58:00 Out of town friends have had their computer badly infected after finding this scam....

On starting up they found a message from the NZ Police advising them that as they had been watching porn, their PC had been immobilised pending
them forwarding $100 via a payment method they outlined. Their local techie wanted $150 as he stated it would take a complete re-load, but they decided that due to the age and condition of their gear that they would buy a new one. NZ Police seem to know all about it when contacted, as did the salesman who sold them their new kit. The general consensus seem to be that the "jam up" is extensive and managing
to get thru most AV programs...they had Nortons.

I would like to research this a bit more. Does this issue have a virus type name I could Google...?
bazmeister (3216)
1345779 2013-06-15 01:09:00 Moneypak / Ukash. There is also an Aussie one and an FBI one. And a Metro Police one. They're called ransomware. This may remove it (support.norton.com)

One of the bootable AV isos may also remove it (Kaspersky / AVG). Once you get the ISO / burn it, then boot from it
Speedy Gonzales (78)
1345780 2013-06-15 02:03:00 Thanks Speedy, I've forwarded this to them and hopefully they might get a result from it.
Much obliged.
bazmeister (3216)
1345781 2013-06-15 04:01:00 No probs :) Speedy Gonzales (78)
1345782 2013-06-15 07:48:00 Have a read of this as well (www.bleepingcomputer.com) Speedy Gonzales (78)
1345783 2013-06-15 10:09:00 Has a friend caught out by that, it was fantastic :D

Total hoax but rather convincing...
Chilling_Silence (9)
1345784 2013-06-15 23:34:00 Thanks for the info...

The people who received this were initially concerned, but fortunately not fooled, by this one.

The senders have obviously upgraded from the FBI version, to a NZ Police one, complete with correct looking logos and headings.

They have now installed (and are trying to get up to speed) on a new PC with Win8. Somehow I doubt that
they will get around to trying to fix this which is a pity....I'd love to have a crack at fixing it myself but the PC is in the other
Island.

It appears that this scam is currently being run so if nothing else, this may help someone else....
bazmeister (3216)
1345785 2013-06-16 03:41:00 They can either reinstall windows. Or use something like this (www.avg.com)or this (support.kaspersky.com)

You need a blank cd obviously and a cd/dvd burner. Then boot from it. If it can boot into safe mode / networking OK, then you could log into it remotely with teamviewer. Then scan the system
Speedy Gonzales (78)
1345786 2013-06-16 06:21:00 If the pc has more than one logon user you should be able to get it running through that. Most but not all of the bad stuff is i n the user/appdata/temp directory. YHou wil lfind the police logos along with lots of other ones like avg and other anti-virus progs. You will need several anti lalware progs which can be dowloaded free to get all the bits and pieces. Search for the ucash on google mal-ware forums there are some good talkthru's - just dont delete any windows essential prog unless you are certain!
Piva
piva (3796)
1345787 2013-06-16 22:37:00 Is $150 for a reinstall reasonable? I have no Idea but it takes me less than an hour of my time to install windows, not counting the time I leave it unattended doing it's thing well I do other stuff. If they've replaced it anyway it's not that difficult to boot off the windows CD and do a fresh install themselves, and it is the most effective method. I like to go all the way and reformat the C: drive while I'm at it.

I've fought with these type of infections before, more specificlly the fake antivirus software that takes over the PC and locks out everything except internet explorer. I managed to clean it out but honestly it took longer than starting over would have. If I set a PC up for someone now and have the option I set up the backup schedule to create a weekly image of the C: drive, saves so much time when the non PC savvy screw up their machines.
dugimodo (138)
1 2