Apprent Ransomware Attack On Colleague's Laptop

Discussion in 'Malware Help - MG (A Specialist Will Reply)' started by ftjr, Jun 10, 2016.

  1. ftjr

    ftjr Private E-2

    Helping out a colleague who's unfamiliar with PCs (she's a Mac user) with an apparent Ransomware attack on her personal laptop.

    From some other chatter online, this seems to be a known problem, the "(855) 267-8490 popup" It warns of a need to call that number because of a serious defect with Microsoft Edge and warns she must not reboot or turn off the system.

    Assistance with removal welcome. Thanks in advance.
     
  2. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Do not call!! IT is scam. What type of ransomware has she been infected with and are they demanding a ransom?
     
  3. ftjr

    ftjr Private E-2

    She called, but I handed her a piece of paper warning her it was a scam. She at first thought I was paranoid. Then they started talking about connecting her to their server. At that point she said she'd have to call them back and hung up. But presumably they now have her cellphone number. They have not called back and she isn't planning to call them again. No ransom demanded so far. She is unable to do anything with her browser, it's totally locked up. She has no security protections installed as far as I can tell. Is there a good way to tell exactly which malware package she has?
     
  4. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

  5. ftjr

    ftjr Private E-2

    So, we went through the steps as far as Malwarebytes (which found and cleaned 37 threats including two Malware items and a lot of PUPs) and Roguekiller (found at least 1 item, with Hkey in the name), but the system locked up while running Roguekiller. The system was totally unresponsive. She rebooted and the system is now failing to fully boot. This is a SurfacePro4 which has a facial recognition lock; it is now failing to recognize her, so she is unable to advance past that screen. Specifically, the camera used for the facial recognition is not coming on following the reboot.
     
  6. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    We need you to be able to boot fully. I suggest you post in the software forum for additional assistance, then come back here once you can boot up.
     
  7. ftjr

    ftjr Private E-2

    She had to leave for the day and left the computer with me, but I don't know her passwords (or have her face to be recognized). Won't be able to try this until Monday morning, so we'll back to it then.
     
  8. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    We will be here.
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds