| 
		
	
	
	
		
	Posts: 8,423 
	Threads: 171 
	Joined: Dec 2011
	
 Reputation: 
46 Location: Portsmouth 
 Car Model/Spec: Black 3dr Dturbo
 Thanks: 0Given 1 thank(s) in 1 post(s)
 
 
	
		
		
		25-03-2013, 03:07 PM 
(This post was last modified: 25-03-2013, 03:09 PM by 4WayDiablo.)
	
	 
		So I turned the computer on to find this....   
I'm fairly sure this is some kind of damn good virus of some sorts as it asks for you to pay £100 fine
 
Its completely blocked the Operating system meaning that can't do anything 
 Ctrl alt del does nothing but take me back to this 
Tried to reboot in safe mode with command prompt but that doesn't do anything 
Tried to get to system restore but couldnt 
Anyone (Fooby Scott??) Got any ideas on this  
Or do I get the match and lighter out. Trouble is there is many years of family photos on there
 
 
Some better quality pics...
    
		
	 
	
	
	
		
	Posts: 7,825 
	Threads: 465 
	Joined: Dec 2011
	
 Reputation: 
114 Location: Cullompton Devon
 Car Model/Spec: Vauxhall
     Thanks: 1Given 98 thank(s) in 92 post(s)
 
 
	
	
		ha ha phils been on the Porn again!
	 
		
	 
	
	
	
		
	Posts: 5,024 
	Threads: 82 
	Joined: Dec 2011
	
 Reputation: 
27 Location: North Somerset
 Car Model/Spec: E92 335i, GTi6, HDi S2
 Thanks: 6Given 22 thank(s) in 22 post(s)
 
 
	
	
		Used to remove that virus daily of some sort or another.. what O/S is it running?
	 
		
	 
	
	
	
		
	Posts: 7,825 
	Threads: 465 
	Joined: Dec 2011
	
 Reputation: 
114 Location: Cullompton Devon
 Car Model/Spec: Vauxhall
     Thanks: 1Given 98 thank(s) in 92 post(s)
 
 
	
	
	
		
	Posts: 571 
	Threads: 19 
	Joined: Dec 2011
	
 Reputation: 
5 Location: Cavan, Ireland
 Car Model/Spec: Ph1 D-turbo(on going project)
 Thanks: 0Given 0 thank(s) in 0 post(s)
 
 
	
	
		definately a virus, asks you to pay by some of the payzone Kash things i thinkdunno how to remove though
 
		
	 
	
	
	
		
	Posts: 13,881 
	Threads: 476 
	Joined: Dec 2011
	
 Reputation: 
81 Location: Ipswich
 Car Model/Spec: 306 Rallye
 Thanks: 4Given 104 thank(s) in 102 post(s)
 
 
	
	
		yeh definitely a virus. Youd have to be watching more than porn to get that!
	 
		
	 
	
	
	
		
	Posts: 8,749 
	Threads: 208 
	Joined: Jan 2012
	
 Reputation: 
60 Location: Wiltshire
 Car Model/Spec: ph2 Gti6 / ph4 HDI Estate 
 Thanks: 1Given 5 thank(s) in 5 post(s)
 
 
	
	
		tut you know them sites are 18+ phill you shouldnt even be on them! how are you going to explain this to mum and dad eh??
	 
![[Image: DSC_0190-Copy_zpsf093f84d.jpg]](http://i1038.photobucket.com/albums/a468/167gti8/DSC_0190-Copy_zpsf093f84d.jpg) Member of 99% warning or your nothing club! 
		
	 
	
	
	
		
	Posts: 2,526 
	Threads: 143 
	Joined: Dec 2011
	
 Reputation: 
10 Location: South East London
 Car Model/Spec: Ph3 XUD
 Thanks: 1Given 8 thank(s) in 8 post(s)
 
 
	
	
		If you've got the Windows disc, assuming you're running windows, boot from that and do a system restore.
	 
		
	 
	
	
	
		
	Posts: 14,208 
	Threads: 448 
	Joined: Dec 2011
	
 Reputation: 
51 Location: isle of wight
 Car Model/Spec: Pov. Spec White '6
 Thanks: 17Given 18 thank(s) in 18 post(s)
 
 
	
	
		Flol what have you been looking at! Tut tut
	 
![[Image: 20A1806D-891D-40FB-BD52-AD519177A607-734...391753.jpg]](http://i35.photobucket.com/albums/d196/mattbush/20A1806D-891D-40FB-BD52-AD519177A607-7340-0000058F46391753.jpg) TEAM CONROD SHITTING RALLYE! 
		
	 
	
	
	
		
	Posts: 663 
	Threads: 22 
	Joined: Jan 2012
	
 Reputation: 
6 Location: Herefordshire
 Car Model/Spec: 306 HDi Stage 1
 Thanks: 0Given 0 thank(s) in 0 post(s)
 
 
	
	
		 (25-03-2013, 03:51 PM)bigcheez2k3 Wrote:  If you've got the Windows disc, assuming you're running windows, boot from that and do a system restore. 
and then back up all your photos etc to an external hard drive and CDR
 
We had a similar problem a few years ago and lost everything.......never again
	 
		
	 
	
	
	
		
	Posts: 782 
	Threads: 18 
	Joined: Jan 2012
	
 Reputation: 
3 Thanks: 0Given 0 thank(s) in 0 post(s)
 
 
	
	
		Definately a virus. This may help, i use hitmanpro to get rid of this. Try this budhttp://malwaretips.com/blogs/pceu-virus/ 
Only you need a working computer to create a bootable USB
	
		
	 
	
	
	
		
	Posts: 1,135 
	Threads: 14 
	Joined: May 2012
	
 Reputation: 
7 Location: Sheffield
 Thanks: 0Given 5 thank(s) in 5 post(s)
 
 
	
	
		Looks like a fairly complex piece of Scareware/Ransomware.
 I hope you've got a backup, or means to backup your computer because the really well written stuff needs a format to remove.
 
		
	 
	
	
	
		
	Posts: 8,423 
	Threads: 171 
	Joined: Dec 2011
	
 Reputation: 
46 Location: Portsmouth 
 Car Model/Spec: Black 3dr Dturbo
 Thanks: 0Given 1 thank(s) in 1 post(s)
 
 
	
	
		 (25-03-2013, 03:12 PM)Midnightclub Wrote:  Used to remove that virus daily of some sort or another.. what O/S is it running? 
Windows vista or windows 7. I think its 7
 
Its the family computer but I rarely use it as I have my own. My brother used to use it shit loads and regularly caught him on dodgy sites
 
Cheers for the help
	 
		
	 
	
	
	
		
	Posts: 1,497 
	Threads: 177 
	Joined: Dec 2011
	
 Reputation: 
3 Location: Highlands, Scotland
 Thanks: 0Given 0 thank(s) in 0 post(s)
 
 
	
		
		
		25-03-2013, 04:21 PM 
(This post was last modified: 25-03-2013, 04:24 PM by Daniel306.)
	
	 
		http://malwaretips.com/blogs/pceu-virus/
Seams like there is a few different virus that do this
	 
		
	 
	
	
	
		
	Posts: 3,467 
	Threads: 186 
	Joined: Mar 2012
	
 Reputation: 
38 Location: Manchester 
 Car Model/Spec: MG ZR VVC
 Thanks: 3Given 21 thank(s) in 19 post(s)
 
 
	
	
		Housemate got this but it was the "FBI" and he was blocked for looking at illegal material or something
	 
		
	 
	
	
	
		
	Posts: 1,070 
	Threads: 115 
	Joined: Oct 2012
	
 Thanks: 0Given 0 thank(s) in 0 post(s)
 
 
	
	
		God knows I've looked at some stuff (autopsies mainly) that if I didn't know any better I would shit myself if that came up   
		
	 
	
	
	
		
	Posts: 15,646 
	Threads: 541 
	Joined: Dec 2011
	
 Reputation: 
124 Location: Aylesbury
 Car Model/Spec: 320bhp Impreza WRX
 Thanks: 7Given 59 thank(s) in 58 post(s)
 
 
	
	
		Definitely a virus mate, my mum got it last week and shes never illegally downloaded anything in her life.
 There is some good guides on you tube to getting rid of it.
 
 Its a scam that's been doing the rounds for months. Make sure you report it to the police.
 
		
	 
	
	
	
		
	Posts: 8,423 
	Threads: 171 
	Joined: Dec 2011
	
 Reputation: 
46 Location: Portsmouth 
 Car Model/Spec: Black 3dr Dturbo
 Thanks: 0Given 1 thank(s) in 1 post(s)
 
 
	
	
		Managed to boot it in safe mode and get malware bytes which has isolated it but not removed it
 Its a pretty good virus as I can see how people more vounerable would fall for it
 It literally takes over the system
 
 Cheers for the help and rep will be on the way to you all soon
 
		
	 
	
	
	
		
	Posts: 122 
	Threads: 18 
	Joined: Feb 2013
	
 Reputation: 
0 Location: Preston
 Car Model/Spec: 306 Dturbo
 Thanks: 0Given 0 thank(s) in 0 post(s)
 
 
	
	
		i had that come up once, was telling me that i was looking at fake creadit cards and some things that would make you got WTF, worked for me when i hit the power button and then turned back on :/ deffo a scam
	 
		
	 
	
	
	
		
	Posts: 2,526 
	Threads: 143 
	Joined: Dec 2011
	
 Reputation: 
10 Location: South East London
 Car Model/Spec: Ph3 XUD
 Thanks: 1Given 8 thank(s) in 8 post(s)
 
 
	
	
		Another good thing to use with stuff like this is rkill. It scans the processes that are running and shuts off any that are known as malicious, usually ones that stop you from using anti-malware software.
	 
		
	 
	
	
	
		
	Posts: 5,024 
	Threads: 82 
	Joined: Dec 2011
	
 Reputation: 
27 Location: North Somerset
 Car Model/Spec: E92 335i, GTi6, HDi S2
 Thanks: 6Given 22 thank(s) in 22 post(s)
 
 
	
	
		If you've deleted it using mbam, you may still have issues, it stores data in the registry sometimes so as soon as you reboot and removal it just redownloads all over again, i can't remember off hand which keys it effects i'm afraid :/
	 
		
	 
	
	
	
		
	Posts: 8,298 
	Threads: 289 
	Joined: Nov 2011
	
 Reputation: 
92 Location: London
 Car Model/Spec: Phase 17 R26
 Thanks: 0Given 1 thank(s) in 1 post(s)
 
 
	
	
		Glad to hear you kind of have it sorted. Personally if a system has been compromised to that level, I would usually reformat and reinstall Windows, while not connected to the internet, and install some AV from a USB drive, before connecting. It might also be worth telling your brother to stop looking at so many dodgy sites, primarily warez sites as I'm assuming that's the sort of thing he was going on before.
	 
		
	 
	
	
	
		
	Posts: 1,345 
	Threads: 119 
	Joined: Jan 2012
	
 Reputation: 
15 Location: Rotherham/Sheffield 
 Car Model/Spec: Ph1 Diablo DT
 Thanks: 0Given 1 thank(s) in 1 post(s)
 
 
	
	
		It called ukash virus it encrypts all data on the system the rents had this the other month but couldn't remove it with anything at all so scrapped the hardware. After looking In to it malware bytes can isolate it
	 
Perv 106 1.4 xs First Pug Love - Scrapped 
Perv 306 1.6 5 Door Hore - Sold  
110bhp 207 Hdi Sport - Used as a Brake 
173bhp T25 Ph1 Diablo Dturbo - Scrapped  
Thirsty Bitch Volvo 850 Estate - Sold  
51bhp Berlingo Nad DT Van - Sold 
Slow as f*ck Dispatch Work Horse
www.prestige-auto-care.co.uk
		
	 
	
	
	
		
	Posts: 8,423 
	Threads: 171 
	Joined: Dec 2011
	
 Reputation: 
46 Location: Portsmouth 
 Car Model/Spec: Black 3dr Dturbo
 Thanks: 0Given 1 thank(s) in 1 post(s)
 
 
	
	
		What's a warez site? Lol
 Will tell my parents it needs to be binned lol. Its a shame as its a pretty good computer
 
		
	 
	
	
	
		
	Posts: 8,298 
	Threads: 289 
	Joined: Nov 2011
	
 Reputation: 
92 Location: London
 Car Model/Spec: Phase 17 R26
 Thanks: 0Given 1 thank(s) in 1 post(s)
 
 
	
	
		Warez is a bit of a general term for file sharing, but I meant mainly if he's trying to download free versions of software, particularly software cracks or serial numbers. 
 No point binning it though, it can always be saved! What sort of spec is it?
 
		
	 
	
	
	
		
	Posts: 8,423 
	Threads: 171 
	Joined: Dec 2011
	
 Reputation: 
46 Location: Portsmouth 
 Car Model/Spec: Black 3dr Dturbo
 Thanks: 0Given 1 thank(s) in 1 post(s)
 
 
	
	
		Quad core something? 2.8 iirc6gb ram
 "Overlockers" graphics card dunno what spec
 Buts not exactly old and still pretty swift
 Thing is though parents use it for internet banking as well as all their internet shopping of which they do a lot of
 
		
	 
	
	
	
		
	Posts: 5,024 
	Threads: 82 
	Joined: Dec 2011
	
 Reputation: 
27 Location: North Somerset
 Car Model/Spec: E92 335i, GTi6, HDi S2
 Thanks: 6Given 22 thank(s) in 22 post(s)
 
 
	
	
		You don't need to scrap it at all, worst worst case.. get a USB caddy and take out the HDD, put all your wanted data etc. on another PC or ext HDD etc. then as scott said, just wipe and reinstall windows. It'll be fine, must have removed it over 100 times, it can be persistent and usually the longer it stays on the machine the worse the infection gets, sometimes just a system restore and a MBAM scan with rkill will get rid of it, other times a complete wipe is required.
	 
		
	 
	
	
	
		
	Posts: 8,298 
	Threads: 289 
	Joined: Nov 2011
	
 Reputation: 
92 Location: London
 Car Model/Spec: Phase 17 R26
 Thanks: 0Given 1 thank(s) in 1 post(s)
 
 
	
	
		 (26-03-2013, 04:27 PM)4WayDiablo Wrote:  Quad core something? 2.8 iirc6gb ram
 "Overlockers" graphics card dunno what spec
 Buts not exactly old and still pretty swift
 Thing is though parents use it for internet banking as well as all their internet shopping of which they do a lot of
 
Well they definitely need to stop using it until you've done a full reinstall and educated your brother on better browsing habits. 
 
There's no need at all to scrap that, it's a decent PC. If I wasn't going away on Friday I'd  do it for you over the weekend. If it's still not fixed by the time I get back then let me know and I'll help out.
	 
		
	 
	
	
	
		
	Posts: 8,423 
	Threads: 171 
	Joined: Dec 2011
	
 Reputation: 
46 Location: Portsmouth 
 Car Model/Spec: Black 3dr Dturbo
 Thanks: 0Given 1 thank(s) in 1 post(s)
 
 
	
	
		Cheers fella. Get the pics off there then full system cleanse and reboot in order imo
 
		
	 
	
	
	
		
	Posts: 1,213 
	Threads: 92 
	Joined: Dec 2011
	
 Reputation: 
5 Location: Birmingham 
 Car Model/Spec: Subaru 20.d, GTi 6, 205 xs
     Thanks: 0Given 3 thank(s) in 3 post(s)
 
 
	
	
		just boot the machine in safe mode and run combofix this will remove it then just run malwarebytes when you log back into windows, job done, its a common occurence at my work lol
	 
Vehicle repair and servicing in the midlands pm for details 
 Current cars
 Subaru Impreza 2.0d - Daily
 306 1.8 - track whore soon to be GTI6
 
		
	 |