Jump to content

err, child porn spam and virus?


loops

Recommended Posts

one of the lads at works' brother has turned his laptop on to find a black screen with the metropolitan police logo and a message in red letters saying that his laptop has been blocked because he has been watching child porn! and he has to enter his credit card/ bank account details to pay about a hundred quid to unblock it!!!!

The lap top has frozen on this screen, has anyone heard of spam that includes a virus (in order to make you pay?) and how can he get his lap top working again?

Link to comment
Share on other sites

My first thought would be to start it in safe mode ( assuming he's running windows ) and then run my virus program.

To get to safe mode, press f8 repeatedly as the computer is starting - you'll have an option screen to select different varieties of safe mode and normal start. Safe mode will boot the system with nothing more than the drivers required to start windows.

a couple of links:

Metropolitan Police virus. How to unlock infected PC

How to remove "Police Central e-crime Unit" ransomware?

Both use similar approaches but differently. Good luck, from the reading this is a particularly nasty little bug.

Another says to restore the computer to a point in time before the page appeared - don't that still leaves the virus on your system and it's entirely possible to reactivate it by doing something innocuous.

And while it's hopefully not child porn, he's apparently been visiting some sites he shouldn't have been ....

Edited by Al Jones
Link to comment
Share on other sites

OK follow these steps:

  1. Start Computer in "safe mode with networking" (As Al posted above, you should me able to get into safe mode using F8 whilst the computer is booting).
  2. Visit this site and download combofix ComboFix Download .. DO NOT download from elsewhere
  3. Run combofix. This will take a fair while to run. You will get warning to only use in extreme cases and if you know what your doing. In this case you def need to run it
  4. Once finished you should be able to boot into normal mode. YOU HAVE NOT FINISHED
  5. Download malwarebytes from here (free version is fine). Malwarebytes Anti-Malware Download
  6. Install Malwarebyte using default install
  7. Allow malwarebytes to update when you open it.
  8. Run Malwarebytes on FULL scan (Ahain will take a while)
  9. Once finished remove anything it tells you to (it make require reboot)
  10. Once you have done the above download CCleaner from here CCleaner - Download (again free version)
  11. Install with custom install. Remove any checkboxes when installing that ask if you want to install toolbars, however you do want to attach to recycle bin
  12. Right click on recyclebin and click on Run CCleaner

If you go through the above step by step it should take you a good few hours, however you should be well rid of the rubbish that has been installed on the machine.

Link to comment
Share on other sites

Don't worry Sarah my Mum used to say the husband may be the head of the Household but the wife is the neck and remember it's the neck that turns the head. But, gotta say where would we be without the wisdom of Marc.

hmmmm do you REALLY want me to answer that LOL!!! ;)

Link to comment
Share on other sites

  • 4 weeks later...
  • 1 year later...

This virus is now blocking Safe Mode. To remove it, one should launch malwarebytes or other scan from a separate bootble drive like USB or CD. Kaspersky offer live CD and many others. For those in need, Here is a good instruction on how to create a bootable USB with HitmanPro and clean your cpmputer: http://privacy-pc.com/how-to/police-central-e-crime-unit-pceu-ukashpaysafecard-virus-ransomware-analysis-and-removal.html

 

You don't need to buy Hitman, just scan, clean and uninstall.

 

It is always good to do regular system and file backups anyway :)

Link to comment
Share on other sites

Join the conversation

You can post now and register later. If you have an account, sign in now to post with your account.

Guest
Reply to this topic...

×   Pasted as rich text.   Paste as plain text instead

  Only 75 emoji are allowed.

×   Your link has been automatically embedded.   Display as a link instead

×   Your previous content has been restored.   Clear editor

×   You cannot paste images directly. Upload or insert images from URL.

×
×
  • Create New...

Important Information

By using this site, you agree to our Terms of Use and Privacy Policy , along with dressing your husky as a unicorn on the first Thursday of each month