Pelican Parts
Parts Catalog Accessories Catalog How To Articles Tech Forums
Call Pelican Parts at 888-280-7799
Shopping Cart Cart | Project List | Order Status | Help



Go Back   Pelican Parts Forums > Miscellaneous and Off Topic Forums > Off Topic Discussions


Reply
 
LinkBack Thread Tools Rate Thread
Author
Thread Post New Thread    Reply
1.367m later
 
KevinP73's Avatar
 
Join Date: Feb 2002
Location: small farm town Iowa..........at last
Posts: 6,357
Send a message via Yahoo to KevinP73
I've managed to catch a very nasty virus on my lap top.

So I've managed to catch the "moneyPak/FBI" virus on my lap top. Everything I've read says to boot in safe mode but running XP all I get is the MS BSOD. I've got the original XP disc and I guess I have to set my BIOS to boot from cd.
My hesitation is I've never done something like this and am very concerned about losing some/all of the my data. Is there anything I should do in advance to keep from losing anything?
Moral and Technical advice Invited and Welcomed.

__________________
non velox ad propitiare, verisimile non oblivisci
If it's not The Original Automotive Innovations and Restoration, then it's just hot AIR.
Old 05-14-2013, 04:09 PM
  Pelican Parts Catalog | Tech Articles | Promos & Specials    Reply With Quote #1 (permalink)
Registered
 
AFC-911's Avatar
 
Join Date: Aug 2004
Location: NYC
Posts: 1,859
If you can get to safe mode and follow the rest of the instructions, it's easy enough to remove (I know from experience)...

That said, I don't know how should deal with the Blue Screen of Death. Good luck.
Old 05-14-2013, 04:14 PM
  Pelican Parts Catalog | Tech Articles | Promos & Specials    Reply With Quote #2 (permalink)
Registered
 
Join Date: Oct 2006
Location: So-Cal
Posts: 428
Some of the latest virus's are hard to remove. If you get a boot sector virus or root kit type of virus it is very hard to remove even in safe mode.

I use a live cd (a bootable cd that has virus removal tools)

Do you have another computer?
__________________
1987 Carrera
Old 05-14-2013, 04:14 PM
  Pelican Parts Catalog | Tech Articles | Promos & Specials    Reply With Quote #3 (permalink)
1.367m later
 
KevinP73's Avatar
 
Join Date: Feb 2002
Location: small farm town Iowa..........at last
Posts: 6,357
Send a message via Yahoo to KevinP73
Quote:
Originally Posted by Radioactive View Post
Some of the latest virus's are hard to remove. If you get a boot sector virus or root kit type of virus it is very hard to remove even in safe mode.

I use a live cd (a bootable cd that has virus removal tools)

Do you have another computer?
Yes I've got a clean system I'm working from.
__________________
non velox ad propitiare, verisimile non oblivisci
If it's not The Original Automotive Innovations and Restoration, then it's just hot AIR.
Old 05-14-2013, 04:24 PM
  Pelican Parts Catalog | Tech Articles | Promos & Specials    Reply With Quote #4 (permalink)
Registered User
 
Join Date: Apr 2013
Location: Fritch, Tx
Posts: 144
Send a message via MSN to cruisin
If it's the virus that says your system is locked until you pay a fee to some site, Spy Hunter from the Enigma Software Group is very effective at getting rid of it. You will have to find a way to boot up in safe mode though. Once you've gotten into safe mode, get on the Internet and search for Spy Hunter or google the name of the virus warning crap and look for fixes.

Hitting the F8 key during start up will generally get you into safe mode options. Be sure to choose the option "with networking" so you have access to the net.
Old 05-14-2013, 04:35 PM
  Pelican Parts Catalog | Tech Articles | Promos & Specials    Reply With Quote #5 (permalink)
1.367m later
 
KevinP73's Avatar
 
Join Date: Feb 2002
Location: small farm town Iowa..........at last
Posts: 6,357
Send a message via Yahoo to KevinP73
If I hit the F8 key during boot up it will give me the option of four ways to proceed.
Boot Normal
Boot to last known good settings
Safe Mode with Network
Safe mode without network
No matter which I choose (with or without network) I'll see a bunch of code scroll up the screen and then I get a blue screen with text telling me Windows has encountered a problem and has shut down to avoid causing any damage to my system.
I've been told this is normal for XP Professional.
__________________
non velox ad propitiare, verisimile non oblivisci
If it's not The Original Automotive Innovations and Restoration, then it's just hot AIR.
Old 05-14-2013, 04:45 PM
  Pelican Parts Catalog | Tech Articles | Promos & Specials    Reply With Quote #6 (permalink)
 
Registered
 
Join Date: Oct 2006
Location: So-Cal
Posts: 428
safe mode with networking
__________________
1987 Carrera
Old 05-14-2013, 04:46 PM
  Pelican Parts Catalog | Tech Articles | Promos & Specials    Reply With Quote #7 (permalink)
1.367m later
 
KevinP73's Avatar
 
Join Date: Feb 2002
Location: small farm town Iowa..........at last
Posts: 6,357
Send a message via Yahoo to KevinP73
BSOD every time.
__________________
non velox ad propitiare, verisimile non oblivisci
If it's not The Original Automotive Innovations and Restoration, then it's just hot AIR.
Old 05-14-2013, 05:13 PM
  Pelican Parts Catalog | Tech Articles | Promos & Specials    Reply With Quote #8 (permalink)
Registered
 
Join Date: Apr 2002
Location: Clinton, NJ
Posts: 12,782
Just go to WalMart, buy the MoneyPak, and send them the code. Everything will then be okay.

Nahh, just kidding. I had the same thing occur, and called the guy we use for computer repair and such. It took him about an hour to get rid of it, and it did some other nasty stuff, like screwing with the the registry. It took him a while to get everything back to normal, but it was $100 well spent. Everything that I was able to find about the Malware(using the laptop) said that the best idea would be to call a pro to remove it. It turned out to be the best idea.
__________________
______________________________
Dave

1969 911T Coupe
1972 911E Targa
Old 05-14-2013, 06:24 PM
  Pelican Parts Catalog | Tech Articles | Promos & Specials    Reply With Quote #9 (permalink)
Registered
 
Join Date: Oct 2006
Location: So-Cal
Posts: 428
Download a boot cd

Burning Hiren’s BootCD | HBCD Fan & Discussion Platform
__________________
1987 Carrera
Old 05-14-2013, 06:29 PM
  Pelican Parts Catalog | Tech Articles | Promos & Specials    Reply With Quote #10 (permalink)
Max Sluiter
 
Flieger's Avatar
 
Join Date: Mar 2006
Location: So Cal
Posts: 19,644
Garage
I got rid of a rogue antivirus last year with spyware doctor. I broke down and paid for a year subscription. The free tools I tried wouldn't get rid of it and it only took a few minutes with the spyware doctor so it was worth it in my book.

I hope you have backed up your files.

Even with the virus gone there still were lingering problems that a local computer guy fixed (for a fee of course).

I have Vista, though. I was able to boot into SM with network and go online. I had to use IE, though because the virus was blocking Firefox even in Safe Mode.
__________________
1971 911S, 2.7RS spec MFI engine, suspension mods, lightened
Suspension by Rebel Racing, Serviced by TLG Auto, Brakes by PMB Performance
Old 05-14-2013, 06:42 PM
  Pelican Parts Catalog | Tech Articles | Promos & Specials    Reply With Quote #11 (permalink)
Registered
 
Join Date: Oct 2006
Location: So-Cal
Posts: 428
After you download and burn the boot cd, boot the computer from the cd.

Plug in a usb drive, copy all of your files off of the laptop before you attempt to fix.
__________________
1987 Carrera
Old 05-14-2013, 07:06 PM
  Pelican Parts Catalog | Tech Articles | Promos & Specials    Reply With Quote #12 (permalink)
 
1.367m later
 
KevinP73's Avatar
 
Join Date: Feb 2002
Location: small farm town Iowa..........at last
Posts: 6,357
Send a message via Yahoo to KevinP73
Quote:
Originally Posted by Radioactive View Post
After you download and burn the boot cd, boot the computer from the cd.

Plug in a usb drive, copy all of your files off of the laptop before you attempt to fix.
No love, it wouldn't boot to anything except the hd
__________________
non velox ad propitiare, verisimile non oblivisci
If it's not The Original Automotive Innovations and Restoration, then it's just hot AIR.
Old 05-14-2013, 07:52 PM
  Pelican Parts Catalog | Tech Articles | Promos & Specials    Reply With Quote #13 (permalink)
1.367m later
 
KevinP73's Avatar
 
Join Date: Feb 2002
Location: small farm town Iowa..........at last
Posts: 6,357
Send a message via Yahoo to KevinP73
Fixed it !! My sister brought over a Norton disc that we booted from and ran the virus checker. It found 131 suspicious entries in the registry and cleaned them out.
It's running fine again.
Thanks for all the suggestions.
__________________
non velox ad propitiare, verisimile non oblivisci
If it's not The Original Automotive Innovations and Restoration, then it's just hot AIR.
Old 05-14-2013, 08:24 PM
  Pelican Parts Catalog | Tech Articles | Promos & Specials    Reply With Quote #14 (permalink)
Moderator
 
Z-man's Avatar
 
Join Date: Feb 2001
Location: NJ, USA
Posts: 9,628
Garage
I hate these hackers who earn a 'living' by exploiting others through computer viruses and malware. Imagine if these folks actually did productive and helpful things instead of this?

My work lappy got hit with the FBI / Moneypak virus. They reloaded my profile and got me back.

If you are able to get into safemode, one way to get around this virus is to use a system restore from a time prior to the virus hitting your machine. (You should have your system automatically back itsealf up at least weekly). If may not get rid of all components of the virus, but it will get you going.

-Z-man.
__________________
2010 Cayman S - 12-2020 -
2014 MINI Cooper S Coupe - 05-17 - 05-21
1989 944S2 - 06-01 - 01-14
Carpe Viam.
<><
Old 05-14-2013, 09:04 PM
  Pelican Parts Catalog | Tech Articles | Promos & Specials    Reply With Quote #15 (permalink)
Registered
 
Join Date: Oct 2006
Location: So-Cal
Posts: 428
The nastiest malware virus I have found, had created its own partition on the hard drive. No matter what software you used to clean and remove the virus, it would reload itself from the hidden partition it had created on the hard drive. I finally found the small hidden partion with a linux live cd, and removed it, re wrote the boot code.

It was by far the most challenging virus I have ever had to remove.

If I had formatted and reloaded windows the virus would have still been there.
__________________
1987 Carrera
Old 05-15-2013, 05:45 AM
  Pelican Parts Catalog | Tech Articles | Promos & Specials    Reply With Quote #16 (permalink)
Registered
 
A930Rocket's Avatar
 
Join Date: Oct 2003
Location: Mount Pleasant, South Carolina
Posts: 14,214
My wife and daughter were watching a Neflix movie when a picture was taken of them on her laptop last night. Then a notice came up that her computer was locked because of porn and she needed to pay a fine.

My son fixed it by going back a fre days to restore it. Seems to be working ok now.
Old 05-15-2013, 08:24 PM
  Pelican Parts Catalog | Tech Articles | Promos & Specials    Reply With Quote #17 (permalink)
19 years and 17k posts...
 
azasadny's Avatar
 
Join Date: Jul 2002
Location: Dearborn, MI (Southeast Michigan)
Posts: 17,444
Garage
Paying for software to "fix" this stuff is just as bad as paying the hackers who extorting $ from you in the 1st place...
__________________
Art Zasadny
1974 Porsche 911 Targa "Helga" (Sold, back home in Germany)
Learning the bass guitar
Driving Ford company cars now...
www.ford.com
Old 05-16-2013, 02:08 AM
  Pelican Parts Catalog | Tech Articles | Promos & Specials    Reply With Quote #18 (permalink)
Registered
 
Join Date: Mar 2003
Location: SW Cheese Country
Posts: 13,555
Garage
Most times with these they are tied to your user profile and if you log in under a different one you can run your Malwarebytes or other software to clean them if safe mode doesn't work

We use keep a copy of Malwarebytes on our computers. Had that FBI one once and it was gone after a "quick scan".

__________________
Brent
The X15 was the only aircraft I flew where I was glad the engine quit. - Milt Thompson.

"Don't get so caught up in your right to dissent that you forget your obligation to contribute." Mrs. James to her son Chappie.
Old 05-16-2013, 08:15 AM
  Pelican Parts Catalog | Tech Articles | Promos & Specials    Reply With Quote #19 (permalink)
Reply


 


All times are GMT -8. The time now is 07:20 PM.


 
Powered by vBulletin® Version 3.8.7
Copyright ©2000 - 2025, vBulletin Solutions, Inc.
Search Engine Optimization by vBSEO 3.6.0
Copyright 2025 Pelican Parts, LLC - Posts may be archived for display on the Pelican Parts Website -    DMCA Registered Agent Contact Page
 

DTO Garage Plus vBulletin Plugins by Drive Thru Online, Inc.