So about a month ago I got the greatest scare I could have ever imagined. My trusted laptop that I use for research, tech work, and various other task came under the attack of a very annoying lockout virus/Trojan. I read through the text carefully then plugged in my trusty boot-able thumb drive, running the newest version of Ubuntu. After rebooting my laptop, I started researching what could have locked me out of my laptop. Using keywords like FBI, MoneyPak, ransom, and so on. I came across a few pictures that looked like the screen that had locked me out of my system so I began researching the title that was given on the webpage "FBI MoneyPak Ransom Virus". I went through a few websites that said to just run a virus scanner on a boot-able drive or other childish nonsense like paying the fee because it was from the FBI.
After a few days of running scans from all manners of different thumb drive sources none of which had any effect, which I still find odd, the system wasn't fixed. I decided to make a few attempts to log on to the computer and start a virus scan before the computer finished running through the boot-up process. On the last attempt I noticed that the wireless switch was in the off position on the laptop and since I hadn't tried this approach to fixing my issue I allowed it to fully boot. Ten minutes later the lockout virus/Trojan still hadn't popped up. This allowed me to understand the basic running of the virus/Trojan.
Basically:
- As soon as the computer attempts to connect to the internet it prompts the virus/Trojan to activate.
- Once a connection is established it runs the next portion which is to lock you out, but if the connection is not made it halts the virus.(This lets me know that the virus doesn't store IP information on infected system or if it does it needs an open connection to fully activate)
- Once active it blocks out all other programs to do anything but look pretty on the hard drive.
- This is very annoying and it has to be destroyed.
This whole story brings me to the easiest fix so far:
- Disconnect the computer from the internet so that when it attempts to connect it can't. Best thing to do is remove the wireless card, ethernet cable, flip the switch or any other means of a physically disconnecting from the internet. (This is so far the only quick means of getting through the boot process without being locked out.
- Next, open up network settings and proceed to remove the current connection settings from your system. For example if your at John Doe's house and his network connection information is saved under that name delete that information and then reconnect. This will reset your IP address. (fast and efficient for the moment).
- Search for a virus scanner online since you probably don't have one installed (I do now, I'm running malwarebytes free edition all I really need)
- Before the virus can catch up run a virus scan using your favorite scanner. The virus should pop up in the scanners result section. After that just go ahead and remove the virus from the system, allow the system to reboot and you're done.
As I said this happened to me about a month ago and my system is still running nicely which is why I am writing up this blog about it. If you know of anything better that would help out in the future please leave a comment. Please share this with your friends, techs, and just help to spread the knowledge.