ATTN: PaysafeCard / UKash Police Scam and Trojan.

Status
Not open for further replies.
Joined
Jun 19, 2011
Messages
334
Reaction score
18
Just a note to people, not sure whether I should've posted this in Announcements or not, but I'll post it here, it can be moved up there if needed.

There's a p. annoying virus going around where your computer locks up, a fullscreen programme takes over your screen and locks out out of your computer essentially, you can use the aero switch function in W7/Vista to scroll through open windows and still see other programmes, but for the most part Task Manager and all other functions are locked.

ukash.jpg

The information (for the UK, I know there are European variants) display a Strathclyde/Metropolitan Police logo and some bullshit reading about copyright acts / human rights acts and goes on for some reason regarding either graphic content depicting mutilation of humans and excessive violence on your PC, or pirated music files that you have been found guilty of downloading. It shows your IP and other easily-accessed information, in order to scare you and then says that you could face a fine/imprisonment for up to three years, your computer being confiscated, etc.

Essentially, they're holding your computer ransom due to them asking you for a sum of so-and-so amount in order to unlock your computer, what really starts to smell of bullshit is when they say that you can enter card details into this box and use the handy-dandy rip-off of Paypal known as PaysafeCard or UKash to process the payment. You can even enter your neat little coupons or vouchers that you might just have for the two payment services! How convenient!

This can be easily avoided by keeping an up-to-date and active anti-spyware programme running on your PC, as well as a good firewall and other security measures, however, if you're like me and only days ago re-installed windows and have yet to find all the components necessary for a good security system, they may catch you off guard.

If you are caught by this crappy scam, turn your PC off immediately.

1. Get on another PC / Laptop.
2. Get a USB Flash Drive.
3. Download a good trusted spyware software, put the installer on the flash drive.

(Not Trojan Killer, it's all free until you remove the files and it asks you to pay for a license.)
http://shop.malwarebytes.org/lpa/342/3/7268/index_b.html?gclid=CP3kicOTx64CFeYhtAodb0hRBw is an okay one-time one.
Anyone who has good free anit-spyware suggestions, please list.


4. Turn on your PC and press F8 at the bios screen to load boot options and select "Safe Mode w/ Command Prompt"
5. When windows has loaded, just type "explorer" in the command box.
6. Now you have explorer open, go to My Computer, insert the flash drive into your PC.
7. Install the software, run a full scan and remove the threats as needed.

Restart your computer. Should work.

HOWEVER:

In recent iterations of the update, like the one I just had to fuck with, the virus screws with some of the memory units and other crap inside your PC, lord knows how, it could have just been a one-time thing but I've heard others have the problem too. Anyway, just in the rare case you get this, here's what to do.

I advise you make sure you know your way around the innards of a computer before doing this, or get someone with experience to do this bit:

1. Unplug all connections from your PC, switch off the mains and keep well away from other electrical crap.
2. Open up your PC, make sure you're grounded nicely so as not to electrocute yourself or explode your PC.
3. Find your CMOS Battery, this should be on the motherboard, near the cooling unit / CPU and looks like a small silver disc, like a watch battery.
4. Carefully take it out, now whilst it's out, press and hold your power button for a few seconds (about five should do it).
5. Insert the CMOS Battery and re-plug everything up and turn on your PC, hopefully thing should now run as normal.

Guides are pretty common, but the virus keeps making returns and with new "features" each time. So if you get anything similar, or helpful hints on how to defeat it, let me know.

This should also be stickied.
 
I had some stuff like this in the past. What you need to do -

1. Get any un-intalling program which allows you to manage autorun programs. (I use Revo Uninstaller)
2. Restart your PC and before windows loads press F5 (or F8).
3. Select Safe mode.
4. Once loaded, in autorun manager find a program which is going to look (most likelly) like explorer.exe. (Explorer does not need to be set to autorun , it is System default)(But it may be any other system process)
5. Remove the malignant program and find that file and delete it.

Hope this helps anyone with the simmiliar problem.
 
Is it possible to get this virus in the US? I hope not :c
 
That's a fucking winlock.
Computers are swarming with them in russia, but ive always thought that the same is happening in other countries.
 
why would anyone fall for a "government program" if the author of that thing can't even fucking spell.
 
while it's nice for OP to help everybody out with this along with having personal experience with it, I don't think anybody should over-dramaticize, these things come and go lol, tens of thousands of these sorts of things are released in to the internet daily

also, it's called malware
the definition of this type of malware is not "a virus" alone, it saves you a lot of trouble if you're explaining your computer issues to a person whilst using proper terminology
 
Though anyone that could be considered a computer person, and thus are qualified to be giving any advice at all to fix stuff like this, could easily figure out what he means and how irrelevant the semantics are. Stuff like this does come out every day, but when a certain one is on the rise, it's always good to warn people. We're probably all infected with conficker anyway!
 
I got a similar thing to this once. I didn't even give it a glance before I reformatted my whole pc lol
 
Status
Not open for further replies.

Users who are viewing this thread