Questions

FBI/DOJ virus, now locks out safe mode as well. Any ideas for removal?

+
0 Votes
Locked

FBI/DOJ virus, now locks out safe mode as well. Any ideas for removal?

Locrian_Lyric
The new version locks you out of windows safe mode with networking as well.

any ideas on how to block it long enough to run some removal programs to get it out, or some that I can boot into to get this darn thing off?
+
1 Votes
Clendanielc
Collapse -

I would remove the hard drive and use it as a secondary or external hard drive. I would then use malware tools, such as malwarebytes, and an antivirus software to scan the external drive. You might also have to Google this type of virus to delete the executables, registry paths, etc. yourself in order to get safe mode to work or Windows to boot.

If all else fails, get a new hard drive and restore everything from a backup. If you didn't backup the drive or its files, you can try to restore the files from the infected drive. Choose a group of files and scan them each time before you bring them to the new drive. You don't want to grab the virus that caused this issue to begin with.

I had a client that received this file once. Strange enough it was when he tried to download an episode of Criminal Minds off of a forum. He thought the FBI actually locked his PC. Too funny! Not for me though, it was a pain to get rid of. Luckily he only received the stage one of the virus which allowed safe mode. It seems it has adapted to the environment.

Good Luck!

+
0 Votes
Locrian_Lyric
Collapse -

Thanks, great idea!

+
1 Votes
dldorrance
Collapse -

Any experience removing this malware with with f-secure, kapersky or avira all available as bootable CDs hence obviating the need to use Windows as the OS?

+
0 Votes
Locrian_Lyric
Collapse -

I'll try that one too.

+
2 Votes
maggie5150
Collapse -

I use a bootable dvd which I would create on a safe pc. UBCD is a free boot cd utility that also comes bundled with antivirus/malware/rootkit utilities. These can be updated (prgram file+definition files) and then slipstreamed into the dvd image. So the burned image is bang up to date.

This can then be used to host a virtual OS complete with utilities to disinfect the problem computer. UBCD can be had from here http://www.ubcd4win.com/

+
0 Votes
Locrian_Lyric
Collapse -

THANKS!!!! That's GREAT!

+
2 Votes
OH Smeg
Collapse -

Try looking at this TR Blog Link from Michael Kassner. It covers exactly what you want to know here.

www.techrepublic.com/blog/security/rescue-cds-tips-for-fighting-malware/3803

Col

+
0 Votes
Locrian_Lyric
Collapse -

thanks

+
1 Votes
techie
Collapse -

Try using "Remove Fake Anti-virus" and then run "Combofix" running a search online and you will find both these tools. Has worked everytime for me.

+
0 Votes
Locrian_Lyric
Collapse -

thank you, I will try that.