| View previous topic :: View next topic |
| Author |
Message |
Pantera EFI
Joined: 12 Feb 2005 Posts: 1266 Location: So. California
|
Posted: Sat Jul 14, 2012 4:21 pm Post subject: Citadel Malware : WARNING |
|
|
OFF TOPIC<SURE>, my problem is REAL, a locked PC.
When one of my PC's allows for internet connection, it becomes LOCKED !
Then the .dll will ask for a payment of $200.00 USD, OR the FBI will come to my door, arrest me.
Citadel Malware infected, looks real (FBI.gov site ???)
MY FIRST thought "freeked-out", though a bit fishy.
I then went to the USA FBI.gov site a found the truth, a MONEY SCAM.
My next step will be to use a Malware Tool, some suggestions, please !
I need help, Lance |
|
| Back to top |
|
 |
John at J&S
Joined: 12 Nov 2005 Posts: 270 Location: GARDEN GROVE, CA
|
|
| Back to top |
|
 |
Buzzard
Joined: 14 Dec 2004 Posts: 160
|
Posted: Sun Jul 15, 2012 1:59 am Post subject: |
|
|
| Try MalwareBytes Anti malware |
|
| Back to top |
|
 |
Steve Arndt
Joined: 07 Jan 2005 Posts: 58 Location: Idaho
|
Posted: Sun Jul 15, 2012 1:09 pm Post subject: |
|
|
The best bet is an AVG boot CD. It is the full AVG virus scan setup, but it runs from a bootable CD. If you let windows load then the virus is already running. The key is booting and running the PC from the CD and scan from there, rather than running windows and attempting removal.
http://www.avg.com/us-en/avg-rescue-cd-download
Download and burn the ISO file to a CDR (from a clean PC). Then boot the CD and scan.
Steve |
|
| Back to top |
|
 |
El Verdugo

Joined: 15 Feb 2005 Posts: 502 Location: New Orleans
|
Posted: Sun Jul 15, 2012 3:53 pm Post subject: |
|
|
This forum has saved my laptop several times from malware and more serious infections.
http://tinyurl.com/6uuxu8p
Go there do the following procedure and download the necessary stuff to clean the PC.
The antimalware I use now is SuperAntiSpyware and Malwarebytes. Keep the definitions current and run a quick scan on a weekly basis and full scan every month on all my PCs. Good luck! _________________ Alberto I Correa, Jr.
EFI 101 Graduate 7-16-05
AEM EMS factory trained
www.corrperformance.com |
|
| Back to top |
|
 |
stevieturbo
Joined: 29 Aug 2006 Posts: 845 Location: Northern Ireland
|
Posted: Mon Jul 16, 2012 6:00 am Post subject: |
|
|
We've all been caught out by such things.
Perhaps a system restore might work ?
And it's always worth getting something like Acronis, and taking a backup image of your hard drive at regular intervals. Either weekly or monthly etc.
then in a scenario like that, just use the backup drive and things will be as they were when it was saved. _________________ LS1, V7 YSi
9.85 @ 144.75mph
202mph standing mile
http://www.youtube.com/watch?v=XgWRCDtiTQ0 |
|
| Back to top |
|
 |
Micky Fin
Joined: 24 Apr 2007 Posts: 69
|
Posted: Sat Jul 21, 2012 4:02 am Post subject: |
|
|
| Another way of removing virus is to take the infected drive and put in in another PC as a slave. Make sure the new PC has decent up to date antivirus software Microsoft Security Essentials is OK and then scan the slave drive |
|
| Back to top |
|
 |
Pantera EFI
Joined: 12 Feb 2005 Posts: 1266 Location: So. California
|
Posted: Mon Jul 23, 2012 9:02 am Post subject: Citadel Malware : WARNING |
|
|
Thanks all, my infected PC was repaired Monday last, for free.
The effort required using the AVG "boot disk", booting in Linux.
Three scans later AND only the newest definitions allowed the Trojan found.
The file Trojan.ransom.gen was removed from my disk.
The required effort was hours long, wasted time.
The two firewalls, several virus machines running allowed the infection to halt my machine.
I was NOT safe from the newest Malware.
I can only hope my story will help my friends at EFI101.
Lance |
|
| Back to top |
|
 |
Steve Arndt
Joined: 07 Jan 2005 Posts: 58 Location: Idaho
|
Posted: Mon Jul 23, 2012 2:07 pm Post subject: |
|
|
Glad to hear you got it repaired.
I've fixed a lot of machines with the AVG boot CD.
Steve |
|
| Back to top |
|
 |
nfn15037
Joined: 22 Dec 2005 Posts: 243 Location: Boston, MA
|
Posted: Wed Jul 25, 2012 1:31 pm Post subject: |
|
|
I use my tuning tuning computer at the p0rn sites  |
|
| Back to top |
|
 |
|