We’d like to remind Forumites to please avoid political debate on the Forum.

This is to keep it a safe and useful space for MoneySaving discussions. Threads that are – or become – political in nature may be removed in line with the Forum’s rules. Thank you for your understanding.

📨 Have you signed up to the Forum's new Email Digest yet? Get a selection of trending threads sent straight to your inbox daily, weekly or monthly!
The Forum now has a brand new text editor, adding a bunch of handy features to use when creating posts. Read more in our how-to guide

Computer taken over by scammers

grumpycrab
grumpycrab Posts: 5,042 Forumite
Part of the Furniture 1,000 Posts Name Dropper Bake Off Boss!
edited 26 April 2014 at 6:49PM in Techie Stuff
I've found somebody who allowed their computer to be remote controlled and locked and asked for £200 to unlock. Is this is reinstall job? If I put the hard drive in a caddy can data files be recovered? Thanks.

Comments

  • esuhl
    esuhl Posts: 9,409 Forumite
    Part of the Furniture 1,000 Posts Name Dropper
    As with all malware, you can probably get rid of it without reinstalling the OS, but at least with a reinstall you can be 100% sure.

    So long as the PC you connect the caddy to is up-to-date with an antivirus, etc. and you scan the files first, it shouldn't be a problem to access them that way.
  • grumpycrab
    grumpycrab Posts: 5,042 Forumite
    Part of the Furniture 1,000 Posts Name Dropper Bake Off Boss!
    Thanks. Guess I can try a malware program from a boot disk. Any recommended?
  • ossie
    ossie Posts: 354 Forumite
    Part of the Furniture 100 Posts Photogenic
    malwarebytes
  • Tiexen
    Tiexen Posts: 740 Forumite
    Part of the Furniture 500 Posts
    If its the Crypto Locker virus is not that it's hard to get rid of. It's that all your data files - pictures, documents, etc. will be encrypted, and are not able to be unencrypted without the key provided once you pay the ransom. It will also encrypt things on attached storage or network shares. Simply having an external USB drive connected with your data backed up on it won't be enough - those files will be encrypted also
  • grumpycrab
    grumpycrab Posts: 5,042 Forumite
    Part of the Furniture 1,000 Posts Name Dropper Bake Off Boss!
    Tiexen wrote: »
    If its the Crypto Locker virus...all your data files - pictures, documents, etc. will be encrypted,
    That's a !!!!!!. I'll get hold of the computer this week and check it out. Nasty.
  • aerostar
    aerostar Posts: 1,738 Forumite
    Part of the Furniture 1,000 Posts Name Dropper Combo Breaker
    Do NOT have any other computers on wireless or cabled and connected to the your network at the same otherwise you may well find those compromised as well !!!!
  • esuhl
    esuhl Posts: 9,409 Forumite
    Part of the Furniture 1,000 Posts Name Dropper
    grumpycrab wrote: »
    Thanks. Guess I can try a malware program from a boot disk. Any recommended?

    I wouldn't bother with a boot disk (unless the malware prevents you from using the system normally). But I'd definitely try several different anti-malware apps. Various different ones seem to pick up different things...

    My suggestions would be:
    Avast antivirus (or whatever antivirus is installed).
    MalwareBytes' Anti-Malware
    Spybot - Search & Destroy
    TDSSKiller
    adwCleaner
    ComboFix
    HijackThis
  • bluesnake
    bluesnake Posts: 1,460 Forumite
    this chap has put in quite a bit of effort in removing unwanted stuff, and you may find your fix there. However there are some items where the encryption is too good and you have to either pay up, or loose it

    https://www.youtube.com/results?search_query=britec09
  • closed
    closed Posts: 10,886 Forumite
    who did it, and how is it locked?

    The 'we're microsoft' scams usually don't do any damage, but pretend to have found virus problems which are really trivial event log errors, and charge to clean the logs

    kasperky rescue cd is often useful if it really is infected.
    !!
    > . !!!! ----> .
  • Sparx
    Sparx Posts: 909 Forumite
    Part of the Furniture Combo Breaker
    Boot into safe mode, run CCleaner (check startup items) and remove anything suspicious. Then run Malwarebyte's Anti-Malware and a full a virus scan.
This discussion has been closed.
Meet your Ambassadors

🚀 Getting Started

Hi new member!

Our Getting Started Guide will help you get the most out of the Forum

Categories

  • All Categories
  • 353.5K Banking & Borrowing
  • 254.2K Reduce Debt & Boost Income
  • 455.1K Spending & Discounts
  • 246.6K Work, Benefits & Business
  • 603K Mortgages, Homes & Bills
  • 178.1K Life & Family
  • 260.6K Travel & Transport
  • 1.5M Hobbies & Leisure
  • 16K Discuss & Feedback
  • 37.7K Read-Only Boards

Is this how you want to be seen?

We see you are using a default avatar. It takes only a few seconds to pick a picture.