Author Topic: Green Dot FBI virus  (Read 3777 times)

vaskidmark

  • National Anthem Snob
  • friends
  • Senior Member
  • ***
  • Posts: 12,799
  • WTF?
Green Dot FBI virus
« on: September 11, 2012, 03:29:30 AM »
Ransomeware.

Viscious.

Pernicious.

My computer geek friend has been trying to get rid of it on the other box o' wires since Friday morning. 

So far:  computer geek friend - 0
            Green Dot FBI virus - refuses to die

On Saturday afternoon I asked him to nuke the HD after recovering as many of my files as could be verified as not infected.  He said "No" because he expects that he will be seeing more of this and wants t know how to kill it.  So far the usual and mid-range esoteric virus killers have been no help.  The thing apparently mutates (or is mutated) fairly frequently.

AVG, Semantyc, Norton, Windows Security all are unaware of the little bugger.  There are probably a lot of other anti-virus programs that also do not protect against it.

When you go venturing into the intartubes, remember that some of the dragons are quite nasty and your shield is made of tissue paper.

stay safe.
If cowardly and dishonorable men sometimes shoot unarmed men with army pistols or guns, the evil must be prevented by the penitentiary and gallows, and not by a general deprivation of a constitutional privilege.

Hey you kids!! Get off my lawn!!!

They keep making this eternal vigilance thing harder and harder.  Protecting the 2nd amendment is like playing PACMAN - there's no pause button so you can go to the bathroom.

MikeB

  • friend
  • Senior Member
  • ***
  • Posts: 924
Re: Green Dot FBI virus
« Reply #1 on: September 11, 2012, 06:19:57 AM »
Combofix and or Rkill

http://www.bleepingcomputer.com/combofix/how-to-use-combofix
http://www.bleepingcomputer.com/download/rkill/

I only recommend getting these from the bleepingcomputer.com site.

These two usually clean/kill anything, though I usually run MS Security Essentials and/or Malwarebytes afterwords. Run Rkill before Combofix if Combofix doesn't clean it on it's own.

BryanP

  • friendly hermit
  • friend
  • Senior Member
  • ***
  • Posts: 2,808
Re: Green Dot FBI virus
« Reply #2 on: September 11, 2012, 06:22:26 AM »
Depending on what you use the box for, I'd nuke it anyway. I tend not to trust PC's that are infected until they've been wiped and reinstalled.
"Inaccurately attributed quotes are the bane of the internet" - Abraham Lincoln

geronimotwo

  • friend
  • Senior Member
  • ***
  • Posts: 3,796
Re: Green Dot FBI virus
« Reply #3 on: September 11, 2012, 07:00:06 AM »
any idea what porn site it came from?
make the world idiot proof.....and you will have a world full of idiots. -g2

Chester32141

  • friend
  • Senior Member
  • ***
  • Posts: 642
Re: Green Dot FBI virus
« Reply #4 on: September 11, 2012, 07:13:10 AM »
What are the symptoms ?
"The best argument against democracy is a 5 minute conversation with the average voter...... "

Photos
CBs Hawg Sauce


zahc

  • friend
  • Senior Member
  • ***
  • Posts: 5,803
Re: Green Dot FBI virus
« Reply #5 on: September 11, 2012, 07:37:38 AM »
Does this affect users of Linux systems?
Maybe a rare occurence, but then you only have to get murdered once to ruin your whole day.
--Tallpine

Tuco

  • Fastest non-sequitur in the West.
  • friends
  • Senior Member
  • ***
  • Posts: 3,122
  • If you miss you had better miss very well
Re: Green Dot FBI virus
« Reply #6 on: September 11, 2012, 08:15:19 AM »
Que comments from the Apple savants.
7-11 was a part time job.

AJ Dual

  • friends
  • Senior Member
  • ***
  • Posts: 16,162
  • Shoe Ballistics Inc.
Re: Green Dot FBI virus
« Reply #7 on: September 11, 2012, 09:37:06 AM »
Combofix and or Rkill

http://www.bleepingcomputer.com/combofix/how-to-use-combofix
http://www.bleepingcomputer.com/download/rkill/

I only recommend getting these from the bleepingcomputer.com site.

These two usually clean/kill anything, though I usually run MS Security Essentials and/or Malwarebytes afterwords. Run Rkill before Combofix if Combofix doesn't clean it on it's own.

This.

Haven't found anything it couldn't clean up yet. It ignores some lower level adware that kind of straddles the line but that's what Malwarebytes is for.

I promise not to duck.

lee n. field

  • friend
  • Senior Member
  • ***
  • Posts: 13,611
  • tinpot megalomaniac, Paulbot, hardware goon
Re: Green Dot FBI virus
« Reply #8 on: September 11, 2012, 09:45:40 AM »
Ransomeware.

Viscious.

Pernicious.

My computer geek friend has been trying to get rid of it on the other box o' wires since Friday morning.  

So far:  computer geek friend - 0
            Green Dot FBI virus - refuses to die

On Saturday afternoon I asked him to nuke the HD after recovering as many of my files as could be verified as not infected.  He said "No" because he expects that he will be seeing more of this and wants t know how to kill it.  So far the usual and mid-range esoteric virus killers have been no help.  The thing apparently mutates (or is mutated) fairly frequently.

AVG, Semantyc, Norton, Windows Security all are unaware of the little bugger.  There are probably a lot of other anti-virus programs that also do not protect against it.

When you go venturing into the intartubes, remember that some of the dragons are quite nasty and your shield is made of tissue paper.

stay safe.

I can understand his wanting to know how to fight it.  If it were a pay situation, there comes a time when it's better to bail out, back up his stuff and repave the system.  That's only becomes hard if there's funky customization, missing licenses or install media, etc.

This wouldn't be one where you get a full page screen claiming some federal infraction, "send two hunnerd dollar"?  (Dealt with that one a couple times.  AVG rescue CD, combofix and malwarebytes.)
In thy presence is fulness of joy.
At thy right hand pleasures for evermore.

grislyatoms

  • friends
  • Senior Member
  • ***
  • Posts: 3,740
Re: Green Dot FBI virus
« Reply #9 on: September 11, 2012, 09:46:14 AM »
"A son of the sea, am I" Gordon Lightfoot

grislyatoms

  • friends
  • Senior Member
  • ***
  • Posts: 3,740
Re: Green Dot FBI virus
« Reply #10 on: September 11, 2012, 09:57:48 AM »
This.

Haven't found anything it couldn't clean up yet. It ignores some lower level adware that kind of straddles the line but that's what Malwarebytes is for.


I have yet to run across anything that the "dynamic duo" of Malwarebytes and Spybot couldn't kill. Then again, I update and scan weekly and avoid suspect sites.

At work, we nuke and re-image. It's the only way to be sure. =D
"A son of the sea, am I" Gordon Lightfoot

vaskidmark

  • National Anthem Snob
  • friends
  • Senior Member
  • ***
  • Posts: 12,799
  • WTF?
Re: Green Dot FBI virus
« Reply #11 on: September 11, 2012, 10:27:32 AM »
Combofix and or Rkill

http://www.bleepingcomputer.com/combofix/how-to-use-combofix
http://www.bleepingcomputer.com/download/rkill/

I only recommend getting these from the bleepingcomputer.com site.

These two usually clean/kill anything, though I usually run MS Security Essentials and/or Malwarebytes afterwords. Run Rkill before Combofix if Combofix doesn't clean it on it's own.

I have yet to run across anything that the "dynamic duo" of Malwarebytes and Spybot couldn't kill. Then again, I update and scan weekly and avoid suspect sites.

At work, we nuke and re-image. It's the only way to be sure. =D

Did I mention that "the usual fixes" had been tried on Friday?

This crap was not phased by any of these super-powerful heroes. :'(

Those wanting to know what it looks like can go google it for themselves.  :P

AFAIK it came from a news site - either South African or Norwegian news, to be precise.  Had both open when everything went south.

stay safe.
If cowardly and dishonorable men sometimes shoot unarmed men with army pistols or guns, the evil must be prevented by the penitentiary and gallows, and not by a general deprivation of a constitutional privilege.

Hey you kids!! Get off my lawn!!!

They keep making this eternal vigilance thing harder and harder.  Protecting the 2nd amendment is like playing PACMAN - there's no pause button so you can go to the bathroom.

Stetson

  • friends
  • Senior Member
  • ***
  • Posts: 1,094
Re: Green Dot FBI virus
« Reply #12 on: September 11, 2012, 10:35:15 AM »
Fixed for a friend.  Restored to week prior, booted into safe mode, removed files recommended by a few diff sites ( I forgot the ones  used...CNET? I think), booted back to normal, works like a charm

win7 32 bit is the OS

Jim147

  • friends
  • Senior Member
  • ***
  • Posts: 7,604
Re: Green Dot FBI virus
« Reply #13 on: September 11, 2012, 10:42:27 AM »
I've fixed one of those without wiping it. Pulled the drive and ran scans from another computer. I'm not sure you can remove it from a booted drive.

jim
Sometimes we carry more weight then we owe.
And sometimes goes on and on and on.

BAH-WEEP-GRAAAGHNAH WHEEP NI-NI BONG

AJ Dual

  • friends
  • Senior Member
  • ***
  • Posts: 16,162
  • Shoe Ballistics Inc.
Re: Green Dot FBI virus
« Reply #14 on: September 11, 2012, 11:10:27 AM »
I have yet to run across anything that the "dynamic duo" of Malwarebytes and Spybot couldn't kill. Then again, I update and scan weekly and avoid suspect sites.

At work, we nuke and re-image. It's the only way to be sure. =D

IMO, Spybot and Malwarebytes are good indicators of infection.

Because when you can't run them, you know you're infected.  :rofl:
I promise not to duck.

BryanP

  • friendly hermit
  • friend
  • Senior Member
  • ***
  • Posts: 2,808
Re: Green Dot FBI virus
« Reply #15 on: September 11, 2012, 11:43:30 AM »
This sort of thing is why I'm also a fan of setups like the Lenovo laptops I got for my wife & stepdaughter. They have a hidden partition that you boot to with a separate power button.  It has a backup & restore utility and a "restore this thing to out-of-the-box config" option. 
"Inaccurately attributed quotes are the bane of the internet" - Abraham Lincoln

lee n. field

  • friend
  • Senior Member
  • ***
  • Posts: 13,611
  • tinpot megalomaniac, Paulbot, hardware goon
Re: Green Dot FBI virus
« Reply #16 on: September 11, 2012, 11:48:37 AM »


AFAIK it came from a news site - either South African or Norwegian news, to be precise.  Had both open when everything went south.

stay safe.

It couldn't have come from the future.  It might have come from the past.
In thy presence is fulness of joy.
At thy right hand pleasures for evermore.

MechAg94

  • friend
  • Senior Member
  • ***
  • Posts: 33,857
Re: Green Dot FBI virus
« Reply #17 on: September 11, 2012, 06:53:05 PM »
IMO, Spybot and Malwarebytes are good indicators of infection.

Because when you can't run them, you know you're infected.  :rofl:
That happened to me one time.  In the end I finally figured out the antivirus program I was using was blocking nearly all Internet traffic for some reason.  Installed norton instead along with spy bot and all was well.
“It is much more important to kill bad bills than to pass good ones.”  ― Calvin Coolidge

lee n. field

  • friend
  • Senior Member
  • ***
  • Posts: 13,611
  • tinpot megalomaniac, Paulbot, hardware goon
Re: Green Dot FBI virus
« Reply #18 on: September 11, 2012, 09:04:09 PM »
That happened to me one time.  In the end I finally figured out the antivirus program I was using was blocking nearly all Internet traffic for some reason.  Installed norton instead along with spy bot and all was well.

I've seen Norton's firewall be the culprit for that as often as any.  Reset to defaults.  If that don't work, scour out and reinstall (or replace).

I noticed the other day that Symantec has a downloadable tool specifically for removing Norton consumer products and then reinstalling them.
In thy presence is fulness of joy.
At thy right hand pleasures for evermore.

Sindawe

  • friend
  • Senior Member
  • ***
  • Posts: 2,938
  • Vashneesht
Re: Green Dot FBI virus
« Reply #19 on: September 12, 2012, 01:09:47 AM »
While I liked Symantec's Exchange AV back in the early part of this century, I've never been a fan of their AV products.  I had to get their support involved to install the thing on a coworkers PC a few months back.

My preference currently is Kaspersky products.  The consumer model paired with Malwarebytes has kept my system clean for several years now.

I've not seen the Green Dot FBI virus yet, 'probably just a matter of time until another coworker or someone in my family picks it up and comes to me to clean up the mess.  :facepalm:
I am free, no matter what rules surround me. If I find them tolerable, I tolerate them; if I find them too obnoxious, I break them. I am free because I know that I alone am morally responsible for everything I do.

vaskidmark

  • National Anthem Snob
  • friends
  • Senior Member
  • ***
  • Posts: 12,799
  • WTF?
Re: Green Dot FBI virus
« Reply #20 on: September 12, 2012, 06:58:23 AM »
Computer geek friend is still finding remnants of the thing, after thinking he finally had gotten rid of it.  Said he has scanned a total of six times (so far) after supposedly clearing it out of the box o' wires, each time coming up with bits and pieces of the virus program or changes it made to other parts.

Between he and his wife (another computer fixer person) they have put in almost 30 hours and still not completely cleaned the booger completely.  It has become a personal challenge for them.  Glad I could provide the entertainment.

stay safe.
If cowardly and dishonorable men sometimes shoot unarmed men with army pistols or guns, the evil must be prevented by the penitentiary and gallows, and not by a general deprivation of a constitutional privilege.

Hey you kids!! Get off my lawn!!!

They keep making this eternal vigilance thing harder and harder.  Protecting the 2nd amendment is like playing PACMAN - there's no pause button so you can go to the bathroom.

lee n. field

  • friend
  • Senior Member
  • ***
  • Posts: 13,611
  • tinpot megalomaniac, Paulbot, hardware goon
Re: Green Dot FBI virus
« Reply #21 on: September 12, 2012, 01:58:22 PM »
That's about 27 hours after I would have bailed. 
In thy presence is fulness of joy.
At thy right hand pleasures for evermore.

Marnoot

  • friend
  • Senior Member
  • ***
  • Posts: 2,965
Re: Green Dot FBI virus
« Reply #22 on: September 12, 2012, 02:14:32 PM »
My preference currently is Kaspersky products.

After reading this article in Wired I become mildly wary of using Kaspersky. Kaspersky has since vehemently denied that he has any Kremlin ties, so who knows. My current preference is for Microsoft Security Essentials and Malwarebytes; as that's worked so far I haven't had a need to purchase any non-free solutions.