Serious Malware Issue

Discussion in 'Malware Help (A Specialist Will Reply)' started by Dahemo, Apr 30, 2010.

  1. Dahemo

    Dahemo Private E-2

    Hi,

    Yesterday I managed to acquire the fake ICCP Foundation extortion malware, also known as Win32/Dottorrent. I'm running Windows XP on an Inspiron 6400 with up-to-date AVG Free (as much as that helped!). I noticed the icon appear on my desktop and was about to investigate when the warning screen appeared with dire threats of court, fines and jail time.

    I've investigated and it now appears that you should be able to exit this screen, to be met by repeated warnings as you use your computer. I, however, have not been so lucky. The warning screen is jumbled, with text and icons across the screen. in random assortment. I tried closing down the computer, but the screen re-appears immediately after logging on, blocking any Ctrl-Alt-Del commands (apparently by my administrator) and unresponsive to any Alt F4. It also appears to be blocking any other programs from running, as the links on the page simply provide non-functioning Internet Explorer pages.

    I've entered Boot Mode, running both "Windows Normally" and "Last Good Settings" to no avail, and I've also entered the startup menu and found no helpful settings in there. When I attempt to run Safe Mode, the computer simply prints many lines of DOS text then freezes.

    The fixes I have found online seem relatively straightforward but require my ability to use the laptop normally, which I cannot do. Any help would be greatly appreciated.
     
  2. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

  3. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Another possibility could be using the universal unlocking license code that has been published. See: http://blogs.zdnet.com/security/?p=6329

    If the license code unlocks it, then full malware cleaning procedures should be run afterwards.
     
  4. Dahemo

    Dahemo Private E-2

    Thanks for the help,

    Problem is resolved now, but it took some creativity. On the inactive IE pages, I right-clicked which allowed me to "Export to Excel", and from within Excel I used Open to Run anything I needed. I got an AVG full scan going which eventually found the problems and removed them, though the process took quite a while.

    My only issue now is that the virus has somehow locked me out of Task Manager, and I'm unable to open it using Ctrl+Alt+Del, when I try a warning appears telling me the function has been disabled by my administrator, despite my profile being the only administrator profile on the laptop. Anyone know how I can reactivate Task Manager? Not a priority but it would help as I like to get rid of useless background functions.

    Thanks for your help
     
  5. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member


MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds