Ukash virus
 #869440
 02/20/13 01:58 PM
02/20/13 01:58 PM
 | 
 
Joined:  Sep 2003
 Posts: 921 Hampshire, UK
petert
 
OP 
Settled Boomer
 | 
 
  
OP 
Settled Boomer 
 
Joined:  Sep 2003 
Posts: 921 
Hampshire, UK
 | 
We have just been done over by something which I now know is called (on this side of the pond) the Ukash Virus or Ukash scam. It manifested itself as an alleged Adobe update,which we declined, but the virus came in anyway. Apparently, it doesn't matter if you click Yes or No - it still infects the computer. It says that we have been downloading something illegal, and are liable for a huge fine, or prison. It generously offers, if we pay £100, to get us out of this predicament. The message purports to come from Cardiff Police, but the money has to be sent to London.Our laptop is now being cleaned up in the local shop, but what can be done to stop it happening again? Norton is an absolute waste of space - the virus just came straight through it.
  petert 
 
 |  
 
 | 
 
 
 | 
 
 
 
Re: Ukash virus
[Re: petert]
 #869442
 02/20/13 02:02 PM
02/20/13 02:02 PM
 | 
 
Joined:  Jul 2005
 Posts: 23,997 UK
Rushes
 
 
True Blue Boomer
 | 
 
  
 
True Blue Boomer 
 
Joined:  Jul 2005 
Posts: 23,997 
UK
 | 
My computer tech was telling me about this very same virus only yesterday.  Do you run the realtime Pro version of Malwarebytes, or SuperAntiSpyware?  Both of these catch a LOT of nasties before they can get through.  They run in conjunction with anti-virus software. 
 
  
"Bleat, Watson -- unmitigated bleat!"  ~  Sherlock Holmes
 |  
 
 | 
 
 
 | 
 
 
 
Re: Ukash virus
[Re: petert]
 #869447
 02/20/13 02:17 PM
02/20/13 02:17 PM
 | 
 
Joined:  Jun 2005
 Posts: 21,501 Near St. Louis, MO
Draclvr
 
 
Reviews Editor - Hints/Glitches Mod - Site Support
 | 
 
  
 
Reviews Editor - Hints/Glitches Mod - Site Support 
True Blue Boomer 
 
Joined:  Jun 2005 
Posts: 21,501 
Near St. Louis, MO
 | 
You were "gotten" by this very nasty "ransomware."  It morphs from country to country to make it look like something from the officials in a specific location. I have removed it from two computers belonging to friends.  The virus goes by several names, but at the center it's called the Revetron virus.  This is a very good article from PC Magazine that just came out recently.  Although they indicate a strong relationship with on-line porn, that's just not the case.  Both the infections I removed had nothing to do with porn or anything like it.     Ransomeware Article at PC Magazine   
 
  
When life gives you tomatoes, make Bloody Marys.
 |  
 
 | 
 
 
 | 
 
 
 
Re: Ukash virus
[Re: petert]
 #869485
 02/20/13 03:41 PM
02/20/13 03:41 PM
 | 
 
Joined:  Sep 2003
 Posts: 921 Hampshire, UK
petert
 
OP 
Settled Boomer
 | 
 
  
OP 
Settled Boomer 
 
Joined:  Sep 2003 
Posts: 921 
Hampshire, UK
 | 
Rushes: no, I don't use either of the programs you mention. When we bought the laptop which subsequently had the Ukash problem, my wife was right royally conned by the salesman at Currys/PCWorld. He gave her some drivel about banks refusing to pay up if villains accessed our online bank account,if we did not run a 'paidfor' anti-virus, and told her that Avast was useless under those terms. So we paid about £60 for this pile of useless cr*p called Norton.I did actually go back on the next day and had a go at the salesman, who was all slimy contrition, saying that they were taught this during their training. Anyway, perhaps I should try malware bytes. I did try Microsoft Security Essentials, on my PC, but that slowed it down to an abysmal crawl - it would take about 20 minutes to connect to the internet - so I got rid of it.
  petert 
 
 |  
 
 | 
 
 
 | 
 
 
 
Re: Ukash virus
[Re: petert]
 #869492
 02/20/13 04:21 PM
02/20/13 04:21 PM
 | 
 
Joined:  Jul 2005
 Posts: 23,997 UK
Rushes
 
 
True Blue Boomer
 | 
 
  
 
True Blue Boomer 
 
Joined:  Jul 2005 
Posts: 23,997 
UK
 | 
Here's a link to Malwarebytes: http://www.malwarebytes.org/The realtime version isn't free, but apparently you do get a short trial of it to see how you like it before paying up.  The free version isn't realtime and only runs scans if you think you have an issue, or just to use as a weekly/daily health check. I find Microsoft Security Essentials super-light on my PC's resources, which is strange when you say you had problems with it.  I had McAfee before that, and THAT monster slowed my poor PC down to a stagger.  
 
  
"Bleat, Watson -- unmitigated bleat!"  ~  Sherlock Holmes
 |  
 
 | 
 
 
 | 
 
 
 
Re: Ukash virus
[Re: petert]
 #869494
 02/20/13 04:24 PM
02/20/13 04:24 PM
 | 
 
Joined:  Jun 2005
 Posts: 21,501 Near St. Louis, MO
Draclvr
 
 
Reviews Editor - Hints/Glitches Mod - Site Support
 | 
 
  
 
Reviews Editor - Hints/Glitches Mod - Site Support 
True Blue Boomer 
 
Joined:  Jun 2005 
Posts: 21,501 
Near St. Louis, MO
 | 
The salesman LIED to you!  Microsoft Security Essentials should never cause PC slowdowns.  I have it on two computer here at home and at least a dozen computers that I work on with no slow-downs at all.  Not sure what was wrong there. Malwarebytes is something to run WITH an anti-virus program, not by itself.  You can get the free version which is very useful in running scans and getting rid of stuff that is already on your computer.  Malwarebytes Pro (roughly $25 US) runs in real time as Rushes said and will stop most nasties.  Whenever I see it on sale for $10 or $12, I always buy 2 or 3 copies.  You can just download it from their website and then pay with a credit card.  They send you an ID and a key code.   Malwarebytes   
 
  
When life gives you tomatoes, make Bloody Marys.
 |  
 
 | 
 
 
 | 
 
 
 
Re: Ukash virus
[Re: Draclvr]
 #869497
 02/20/13 04:32 PM
02/20/13 04:32 PM
 | 
 
Joined:  Mar 2004
 Posts: 1,871 Rockland, Ontario, Canada
Starcom
 
 
Addicted Boomer
 | 
 
  
 
Addicted Boomer 
 
Joined:  Mar 2004 
Posts: 1,871 
Rockland, Ontario, Canada
 | 
and to add what Draclvr mentioned about buying Malwarebytes, You buy it once and it is good for a Lifetime, here is an excerpt from their site:
  A one-time purchase of Malwarebytes Anti-Malware is a life-time license for free future updates!
 
  
Last edited by Starcom; 02/20/13 04:33 PM.
 
 
 |  
 
 | 
 
 
 | 
 
 
 
Re: Ukash virus
[Re: petert]
 #869547
 02/20/13 09:25 PM
02/20/13 09:25 PM
 | 
 
Joined:  Jun 2005
 Posts: 2,849 Michigan
Geo
 
 
Addicted Boomer
 | 
 
  
 
Addicted Boomer 
 
Joined:  Jun 2005 
Posts: 2,849 
Michigan
 | 
This virus,which uses an official looking FBI screen in the US,locks the computer so you cant get to malwarebytes to use it. The latest versions block getting into safe mode also so you cant get to it that way either.So the free version of malwarebytes wont help much. ---------------------------------------------- Edit: What I mean about not being abls to get into safemode is that you can get to the screen that gives you choices,1)safe mode,2)safe mode with networking,etc. but when you click on any of the choices it just boots into regular startup. 
Last edited by Geo; 02/21/13 05:23 AM. Reason: addition
 
 
 |  
 
 | 
 
 
 | 
 
 
 
Re: Ukash virus
[Re: petert]
 #869550
 02/20/13 09:42 PM
02/20/13 09:42 PM
 | 
 
Joined:  Jun 2005
 Posts: 21,501 Near St. Louis, MO
Draclvr
 
 
Reviews Editor - Hints/Glitches Mod - Site Support
 | 
 
  
 
Reviews Editor - Hints/Glitches Mod - Site Support 
True Blue Boomer 
 
Joined:  Jun 2005 
Posts: 21,501 
Near St. Louis, MO
 | 
In both cases when I've removed the FBI ransomware, luckily I was able to boot into safe mode.  I used the Emisoft recommended at Bleepingcomputer and it did the trick for one computer and a Malwarebytes scan got it on the other computer.  Both of these were infections in the last 2 weeks.  There is another download from Kaspersky that you put on a flash drive and it runs at boot before you get into the OS.  It is geared to infected boot loaders where the infection respawns every time you boot.  This particular virus didn't infect the boot loader though.   Remove FBI Ransomeware   
 
  
When life gives you tomatoes, make Bloody Marys.
 |  
 
 | 
 
 
 | 
 
 
 
Re: Ukash virus
[Re: Draclvr]
 #869622
 02/21/13 08:56 AM
02/21/13 08:56 AM
 | 
 
Joined:  Jan 2010
 Posts: 3,293 Rivellon
traveler
 
 
Addicted Boomer
 | 
 
  
 
Addicted Boomer 
 
Joined:  Jan 2010 
Posts: 3,293 
Rivellon
 | 
I've never had to try it, so I can't say if it works, but Malwarebytes has a tool you can download called Chameleon which is supposed to get it running if it's blocked by malicious programs.
  They also have Anti-Rootkit.  They are both free to download.
  Gil. 
 
  
"Best not to think about it.  I don't want to fall to bits 'cos of excess existential thought."
 |  
 
 | 
 
 
 | 
 
 
 
Re: Ukash virus/Adobe
[Re: monbron]
 #869623
 02/21/13 08:58 AM
02/21/13 08:58 AM
 | 
 
Joined:  Jan 2010
 Posts: 3,293 Rivellon
traveler
 
 
Addicted Boomer
 | 
 
  
 
Addicted Boomer 
 
Joined:  Jan 2010 
Posts: 3,293 
Rivellon
 | 
Adobe Flash is probably set to ask if you want to download updates, monbron.  Mine is.  In that case, you will get that popup.
  Gil. 
 
  
"Best not to think about it.  I don't want to fall to bits 'cos of excess existential thought."
 |  
 
 | 
 
 
 | 
 
 
 
Re: Ukash virus/Adobe
[Re: petert]
 #869647
 02/21/13 10:26 AM
02/21/13 10:26 AM
 | 
 
Joined:  Jun 2005
 Posts: 21,501 Near St. Louis, MO
Draclvr
 
 
Reviews Editor - Hints/Glitches Mod - Site Support
 | 
 
  
 
Reviews Editor - Hints/Glitches Mod - Site Support 
True Blue Boomer 
 
Joined:  Jun 2005 
Posts: 21,501 
Near St. Louis, MO
 | 
And you should ALWAYS install Adobe Flash updates as they are often security updates.  The are awful about including what is called "foistware" with the downloads, so make sure you uncheck the McAfee safe search or whatever they want to put on your computer.
  Thanks, Gil.  I will have to check those out - I've read about them, but never downloaded them.  The way things are going lately, I'm going to need them one of these days! 
 
  
When life gives you tomatoes, make Bloody Marys.
 |  
 
 | 
 
 
 | 
 
 
 
Re: Ukash virus/Adobe
[Re: Draclvr]
 #869665
 02/21/13 11:39 AM
02/21/13 11:39 AM
 | 
 
Joined:  Jan 2010
 Posts: 3,293 Rivellon
traveler
 
 
Addicted Boomer
 | 
 
  
 
Addicted Boomer 
 
Joined:  Jan 2010 
Posts: 3,293 
Rivellon
 | 
And you should ALWAYS install Adobe Flash updates as they are often security updates.  The are awful about including what is called "foistware" with the downloads, so make sure you uncheck the McAfee safe search or whatever they want to put on your computer.
  These days they want to install Chrome, as I recall.  Google has its tentacles in everything, as you'll notice if you have Ghostery. Gil.  
 
  
"Best not to think about it.  I don't want to fall to bits 'cos of excess existential thought."
 |  
 
 | 
 
 
 | 
 
 
 
Re: Ukash virus/Adobe
[Re: petert]
 #869670
 02/21/13 11:50 AM
02/21/13 11:50 AM
 | 
 
Joined:  Jun 2005
 Posts: 21,501 Near St. Louis, MO
Draclvr
 
 
Reviews Editor - Hints/Glitches Mod - Site Support
 | 
 
  
 
Reviews Editor - Hints/Glitches Mod - Site Support 
True Blue Boomer 
 
Joined:  Jun 2005 
Posts: 21,501 
Near St. Louis, MO
 | 
I use "do not track" from Abine in my Firefox and I see the same thing there - nine-tenths of the trackers are Google related. 
 
  
When life gives you tomatoes, make Bloody Marys.
 |  
 
 | 
 
 
 | 
 
 
 
Re: Ukash virus/Adobe
[Re: Draclvr]
 #869673
 02/21/13 11:58 AM
02/21/13 11:58 AM
 | 
 
Joined:  Jan 2010
 Posts: 3,293 Rivellon
traveler
 
 
Addicted Boomer
 | 
 
  
 
Addicted Boomer 
 
Joined:  Jan 2010 
Posts: 3,293 
Rivellon
 | 
I use "do not track" from Abine in my Firefox and I see the same thing there - nine-tenths of the trackers are Google related.  Wrong place for this, remove if you like, but since you said that, Google is reported to be favoring the new Internet security bill, CISPA, which would allow the government to get all your private information from businesses which would give it up willingly - and you would have no legal comeback.  Scary. Gil.  
 
  
"Best not to think about it.  I don't want to fall to bits 'cos of excess existential thought."
 |  
 
 | 
 
 
 | 
 
 
 
 |  
 
 |