Author Topic: ICCC virus  (Read 4499 times)

0 Members and 1 Guest are viewing this topic.

Offline silenthunder

  • Royal Highness
  • ****
  • Posts: 700
  • Cookies: 23
  • Anpan.
    • View Profile
ICCC virus
« on: December 30, 2012, 05:06:03 am »
Well it was either google or you guys, and I think I'd rather hear firsthand knowledge from you guys that know what to do right away.

My friend somehow got this virus on his computer and brought it to me to get fixed. Here is a description of the virus:

1: Turn on the computer (Windows 7)
2: Type in password to log on
3: Desktop starts to load, taskbar flashes a time or two, screen goes black for a few seconds
4: The screen fills with a warning from "Internet Crime Complaint Center/Department of Federal Bureau of Investigations"
5: A section of the warning reads: "You have been violating Copyright and Related Rights Law (Video, Music, Software) and illegally using or distributing copyrighted content, thus infringing Article" blahblahblah
6: "Fines may only be paid within 72 hours after the infringement." after the 72 hours im going to court blahblahblah
7: At the bottom there's a MoneyPak logo that's clickable and gives you steps on how to pay the $500 fine, which is also filled with terrible word choice: "Look for a MoneyPak in the prepaid section. Take it to the cashier and load it with a cash of $500" shit shit shit blahblahblah
8: The virus also activates the webcam and plays back a live feed of yourself.
9: I have no access to anything really, the CTRL+ALT+DEL command works but if I click taskmanager or anything, it's clear that it opens but the virus screen returns immediatly.

I've dealt with viruses before but I've never seen anything like this. All I would like help with is, how can I trick it or get around it to be able to view the desktop and stuff? I can probably handle it from there but tips are very appreciated :D.

Thanks


"Hacking is a lifestyle, a specific mindset, and it really is a lot of work." - Daemon

"Just wanted to state that this is just wicked social engineering at its best." - proxx

Offline fluxdaemon

  • Peasant
  • *
  • Posts: 104
  • Cookies: -7
  • Galatians 2:20
    • View Profile
Re: ICCC virus
« Reply #1 on: December 30, 2012, 05:07:34 am »
Boot into safemode, download and run this
It seems to work the best


http://www.bleepingcomputer.com/download/combofix/
« Last Edit: December 30, 2012, 05:08:12 am by fluxdaemon »

Offline silenthunder

  • Royal Highness
  • ****
  • Posts: 700
  • Cookies: 23
  • Anpan.
    • View Profile
Re: ICCC virus
« Reply #2 on: December 30, 2012, 05:14:03 am »
Boot into safemode, download and run this
It seems to work the best


http://www.bleepingcomputer.com/download/combofix/

Well, I've got time and nothing to lose, I'm goin for it.


"Hacking is a lifestyle, a specific mindset, and it really is a lot of work." - Daemon

"Just wanted to state that this is just wicked social engineering at its best." - proxx

Offline fluxdaemon

  • Peasant
  • *
  • Posts: 104
  • Cookies: -7
  • Galatians 2:20
    • View Profile
Re: ICCC virus
« Reply #3 on: December 30, 2012, 05:16:21 am »
I've seen this virus several times and so far, that's the only thing that's really got rid of it

Offline silenthunder

  • Royal Highness
  • ****
  • Posts: 700
  • Cookies: 23
  • Anpan.
    • View Profile
Re: ICCC virus
« Reply #4 on: December 30, 2012, 05:20:29 am »
+1, I didn't even think of safe mode. It's now in my memory banks and I think I'll get that combofix software anyways rather than just doing it myself, if it seems to work so well.


EDIT: This program seems to work very well actually, got rid of it rather quickly, thank you for the help.

EDIT: Damnit, it was going so well and it deleted 3 files but its still there.
« Last Edit: December 30, 2012, 05:45:17 am by silenthunder »


"Hacking is a lifestyle, a specific mindset, and it really is a lot of work." - Daemon

"Just wanted to state that this is just wicked social engineering at its best." - proxx

Offline Daemon

  • VIP
  • Baron
  • *
  • Posts: 845
  • Cookies: 153
  • A wise man fears a gentle mans anger
    • View Profile
Re: ICCC virus
« Reply #5 on: December 30, 2012, 06:26:38 am »
Malware bytes mate, boot into safe mode (should always do this) and make sure it's disconnected from the net as well (just a good habit) then run malware bytes on it. either install it to the comp or onto a flash drive. I'd personally go flashdrive, then after the computer is clean you can update it and then proceed to use it whenever this happens again.
This lifestyle is strictly DIY or GTFO - lucid

Because sexploits are for h0edays - noncetonic


Xires burns the souls of HF skids as a power supply

Offline fluxdaemon

  • Peasant
  • *
  • Posts: 104
  • Cookies: -7
  • Galatians 2:20
    • View Profile
Re: ICCC virus
« Reply #6 on: December 30, 2012, 06:29:35 am »
I haven't had much luck with malware bytes with this particular virus but you might as well try it. I'm surprised combo fix didn't get rid of it completely. It's always worked for me no problem
« Last Edit: December 30, 2012, 06:31:15 am by fluxdaemon »

Offline rasenove

  • Baron
  • ****
  • Posts: 950
  • Cookies: 53
  • ಠ_ಠ
    • View Profile
Re: ICCC virus
« Reply #7 on: December 30, 2012, 07:29:13 am »
Just go to msconfig and unmark strange contents from the startup tab, if it marks itself again. Then you will have to search for the virus files in safemode and delete them with cmd prompt.  This might help, 

www.evilzone.org/tutorials/become-an-antivirus/msg12115/#msg12115
« Last Edit: December 30, 2012, 07:29:57 am by rasenove »
My secrets have secrets...

Offline proxx

  • Avatarception
  • Global Moderator
  • Titan
  • *
  • Posts: 2803
  • Cookies: 256
  • ФФФ
    • View Profile
Re: ICCC virus
« Reply #8 on: December 30, 2012, 10:00:56 am »
That sounds like an awesome virus :)

Just indentify the files, bootup a linux live CD and remove it , easy as that.
While your at it install it :P
Wtf where you thinking with that signature? - Phage.
This was another little experiment *evillaughter - Proxx.
Evilception... - Phage

Offline techb

  • Soy Sauce Feeler
  • Global Moderator
  • King
  • *
  • Posts: 2350
  • Cookies: 345
  • Aliens do in fact wear hats.
    • View Profile
    • github
Re: ICCC virus
« Reply #9 on: December 30, 2012, 12:57:50 pm »
That's the FBI virus. I deal with it at work all the time. Google on FBI virus removal specifically. It will show you where the files are and all.
>>>import this
-----------------------------

Offline Kulverstukas

  • Administrator
  • Zeus
  • *
  • Posts: 6627
  • Cookies: 542
  • Fascist dictator
    • View Profile
    • My blog
Re: ICCC virus
« Reply #10 on: December 30, 2012, 03:25:34 pm »
lol I never heard of such a virus before. Scammers are getting clever :D before it was fake AV's (scareware) and now it's FBI virus... (still falls under scareware).

Offline Xtatics

  • Serf
  • *
  • Posts: 47
  • Cookies: 0
    • View Profile
Re: ICCC virus
« Reply #11 on: December 30, 2012, 04:02:37 pm »
I haven't done it in awhile but you can boot up a live linux cd like Proxx mentioned and get clamav going on the drive or manually remove them. Unfortunately it won't affect anything in the registry. With Clamav.
I play the role of a human on earth.

Offline techb

  • Soy Sauce Feeler
  • Global Moderator
  • King
  • *
  • Posts: 2350
  • Cookies: 345
  • Aliens do in fact wear hats.
    • View Profile
    • github
Re: ICCC virus
« Reply #12 on: December 31, 2012, 02:04:45 am »
lol I never heard of such a virus before. Scammers are getting clever :D before it was fake AV's (scareware) and now it's FBI virus... (still falls under scareware).

We call it ransomware at work if it asks for money.
>>>import this
-----------------------------

Offline silenthunder

  • Royal Highness
  • ****
  • Posts: 700
  • Cookies: 23
  • Anpan.
    • View Profile
Re: ICCC virus
« Reply #13 on: December 31, 2012, 03:35:44 am »
lol I never heard of such a virus before. Scammers are getting clever :D before it was fake AV's (scareware) and now it's FBI virus... (still falls under scareware).

This is more of ransomware or something along those lines, it wants you to dump $500 into a bank account to get rid of it.

We call it ransomware at work if it asks for money.

Sorry didn't see that post lol, now I'm not as dumb as I thought I was..anyways, my mom ended up googling it while I was at work and I think she's got the tut and will fix it for me..
« Last Edit: December 31, 2012, 03:37:32 am by silenthunder »


"Hacking is a lifestyle, a specific mindset, and it really is a lot of work." - Daemon

"Just wanted to state that this is just wicked social engineering at its best." - proxx

Offline Live Wire

  • Knight
  • **
  • Posts: 189
  • Cookies: 4
  • Up on your Net
    • View Profile
Re: ICCC virus
« Reply #14 on: December 31, 2012, 12:14:54 pm »
ransomeware lol. we should make hostageware while we're at it
"There is no right or wrong, there is only fun and boring."