Cheshire Police Virus Scam - I'm stumped !

Collapse
X
 
  • Time
  • Show
Clear All
new posts
  • tk007b
    Top Poster
    • Jul 2009
    • 131

    #1

    Cheshire Police Virus Scam - I'm stumped !

    Hi,

    I'm trying to get the Cheshire Police Virus scam off my father in law's laptop. However, I'm having difficulties.

    When it boots normally, I cannot get to anything other than the scammed website - fair enough
    When I boot in safe mode with networking it automatically shuts down as soon as it boots - Not so fair !
    I can get to safe mode with command prompt but can't do a lot to remove the virus.
    I did manage to run hitman pro spyware which identified the virus. However, I need internet access to activate the trial software but it cannot connect to the internet (even with a cable plugged in)

    Other than wiping it, I am pretty stuck.

    Any suggestions on how I can remove this.

    If I could enable the network port from SafeMode (command prompt) I could solve this.
    if I could get USB support from Safe Mode (command prompt) it would be easier.

    getting bored of burning anti spyware software packages to disk only to find they need the internet to get updates or activate !

    Many thanks

    TK
  • Canker_Canison
    V.I.P. Member
    • May 2010
    • 3904

    #2
    Remove the HDD from the laptop & plug into a fully protected PC. Then just run everything you have at it.
    Canker

    "Animal, vegetable or mineral... I'll do anything, to anything, with anything"
    - The Baby Eating Bishop of Bath & Wells
    [COLOR=Green]

    Comment

    • ajax2061
      DK Veteran
      • Nov 2012
      • 395

      #3
      heres how I go about it most the time

      Do a system restore from command prompt

      Hitman pro with kickstarter, download this on an other machine and install to a usb pen and boot from this Home - SurfRight
      that don't work hit it with ComboFix Download
      then just to make sure your clean hit with malwarebytes afterwards

      This malware scam is getting harder to clean but the above combo has not failed for me yet....

      Comment

      • tk007b
        Top Poster
        • Jul 2009
        • 131

        #4
        Thanks to both,
        Will try the combofix first and then get the drive out if that fails. I have already tried the Hitman- Pro KICKSTART USB solution but when it runs it looks for a network connection that's not there and fails. Also when I tried it (Hitman Pro) standalone, it found the malware/virus but would not delete it because I did not activate the trial software, which I couldn't activate it due to the lack of internet connection ! Arrgghh !
        Sometimes a clear head, or better still someone else's head, is the best way forward ... :-)

        Comment

        • tk007b
          Top Poster
          • Jul 2009
          • 131

          #5
          ComboFix did the trick for me,
          Great find !!
          Thanks to both
          :-)

          Comment

          • ajax2061
            DK Veteran
            • Nov 2012
            • 395

            #6
            glad to hear it

            Comment

            • wulbert2001
              Top Poster
              • May 2010
              • 110

              #7
              how did u pick up this virus...

              Comment

              • bossnt8
                Newbie
                • Jul 2013
                • 2

                #8
                One of the simplest ways this virus is downloaded to a PC/Laptop is a small pop up that tells you your version of Java is out of date. Generally and instinctively you click to get the latest version to run the page. Seconds later you PC desktop is hijacked. I work in IT and I was caught out. Only once though. There are some particularly nasty variants going around and the people that use this scam need hanging in my opinion. If your Java requires an update (I don't have auto update enabled on a WinXp syatem) the small official icon will appear in your start bar on the bottom right. I had an encrypted drive and none of the above worked because the virus is invoked as the desktop environment is loading, the drive is totally locked even to format due to the encryption.
                What I would suggest is having Malbytes Anti-Malware installed with the latest definitions. Anyone else gets this I can explain how you can remove it without using restore of any reformat of your HDD.

                Comment

                • bossnt8
                  Newbie
                  • Jul 2013
                  • 2

                  #9
                  One of the simplest ways this virus is downloaded to a PC/Laptop is a small pop up that tells you your version of Java is out of date. Generally and instinctively you click to get the latest version to run the page. Seconds later you PC desktop is hijacked. I work in IT and I was caught out. Only once though. There are some particularly nasty variants going around and the people that use this scam need hanging in my opinion. If your Java requires an update (I don't have auto update enabled on a WinXp system) the small official icon will appear in your start bar on the bottom right. I had an encrypted drive and none of the above worked because the virus is invoked as the desktop environment is loading, the drive is totally locked even to format due to the encryption.
                  What I would suggest is having Malbytes Anti-Malware installed with the latest definitions. Anyone else gets this I can explain how you can remove it without using restore of any reformat of your HDD.

                  Comment

                  Working...