Jump to content


 


Register a free account to unlock additional features at BleepingComputer.com
Welcome to BleepingComputer, a free community where people like yourself come together to discuss and learn how to use their computers. Using the site is easy and fun. As a guest, you can browse and view the various discussions in the forums, but can not create a new topic or reply to an existing one unless you are logged in. Other benefits of registering an account are subscribing to topics and forums, creating a blog, and having no ads shown anywhere on the site.


Click here to Register a free account now! or read our Welcome Guide to learn how to use this site.

Photo

FBI Warning


  • Please log in to reply
24 replies to this topic

#1 bob marley

bob marley

  • Members
  • 28 posts
  • OFFLINE
  •  
  • Local time:10:46 AM

Posted 23 December 2012 - 02:22 AM

Hello, I have a FBI warning that keeps popping up and not letting me do anything. It even shows up when I start my CPU in Safe Mode. I've tried Safe mde with networking and Command promt. The message instantly shows up and prevents me from doing anything. What should I do next? Thank You for your help!!

BC AdBot (Login to Remove)

 


#2 damando

damando

  • Members
  • 19 posts
  • OFFLINE
  •  
  • Gender:Not Telling
  • Location:Wisconsin
  • Local time:10:46 AM

Posted 23 December 2012 - 05:18 AM

Sounds like you have a virus attack. Check this out. Is this what you have ? "http://www.informationweek.com/security/vulnerabilities/ransomware-pays-fbi-updates-reveton-malw/240143047"

Go up to the top of the page here in the forums under "Tutorials" and check out the 1st one about the FBI Scam....."http://www.bleepingcomputer.com/virus-removal/remove-fbi-anti-piracy-warning-ransomware"

Edited by damando, 23 December 2012 - 05:38 AM.


#3 narenxp

narenxp

  • BC Advisor
  • 16,371 posts
  • OFFLINE
  •  
  • Gender:Male
  • Location:India
  • Local time:10:46 AM

Posted 23 December 2012 - 10:01 PM

what happens when you boot into safemode with command prompt?

Do you get a command prompt screen?

#4 bob marley

bob marley
  • Topic Starter

  • Members
  • 28 posts
  • OFFLINE
  •  
  • Local time:10:46 AM

Posted 23 December 2012 - 11:41 PM

If I start in safe mode/command promt. The FBI warning shows up before I can type in a command.

#5 bob marley

bob marley
  • Topic Starter

  • Members
  • 28 posts
  • OFFLINE
  •  
  • Local time:10:46 AM

Posted 24 December 2012 - 08:15 PM

The command promt screen comes up for about one second, then the FBI warning pops up.

#6 narenxp

narenxp

  • BC Advisor
  • 16,371 posts
  • OFFLINE
  •  
  • Gender:Male
  • Location:India
  • Local time:10:46 AM

Posted 25 December 2012 - 12:35 AM

Let me ask a malware response team member to help you

good luck

#7 bob marley

bob marley
  • Topic Starter

  • Members
  • 28 posts
  • OFFLINE
  •  
  • Local time:10:46 AM

Posted 26 December 2012 - 12:29 AM

thank you!

#8 bob marley

bob marley
  • Topic Starter

  • Members
  • 28 posts
  • OFFLINE
  •  
  • Local time:10:46 AM

Posted 26 December 2012 - 01:59 AM

I read on the internet that I need to type in explorer on the command promt real quick and hit enter before the "warning" pops up. I tried it, but only a second command promt line came up. Then the "warning" popped up. I tried typing regedit also, same result. Is there another command I can try? Or do I need to hit a different key then ENTER? Thought this info might be useful.

#9 narenxp

narenxp

  • BC Advisor
  • 16,371 posts
  • OFFLINE
  •  
  • Gender:Male
  • Location:India
  • Local time:10:46 AM

Posted 26 December 2012 - 10:05 AM

You can try this

net user test /add
net localgroup administrators test /add


Restart the PC and boot into TEST account and let us know.

#10 EnvyThis

EnvyThis

  • Members
  • 5 posts
  • OFFLINE
  •  
  • Local time:10:46 AM

Posted 26 December 2012 - 11:25 AM

I also cannot boot in any safe modes. If you find out how, please advise me.

#11 EnvyThis

EnvyThis

  • Members
  • 5 posts
  • OFFLINE
  •  
  • Local time:10:46 AM

Posted 26 December 2012 - 11:49 AM

Ok I got in safe mode via command prompt from my windows 7 boot disk. Glad I had that.

#12 bob marley

bob marley
  • Topic Starter

  • Members
  • 28 posts
  • OFFLINE
  •  
  • Local time:10:46 AM

Posted 26 December 2012 - 06:08 PM

It doesn't allow me enough time to type all that into the command promt. I've got 2 seconds before the FBI warning pops up. Enough time to type one word and hit enter.

#13 bob marley

bob marley
  • Topic Starter

  • Members
  • 28 posts
  • OFFLINE
  •  
  • Local time:10:46 AM

Posted 26 December 2012 - 06:11 PM

what about any of the other options under F8? Is there any other choices that might allow me to access my flash drive. I could then run antimalware programs.

#14 thisisu

thisisu

  • Malware Response Team
  • 2,525 posts
  • OFFLINE
  •  
  • Gender:Male
  • Location:USA
  • Local time:10:46 AM

Posted 28 December 2012 - 04:38 PM

Hello bob marley :)

I apologize for the delay. Do you still need assistance? If so, please try HitmanPro.Kickstart using this guide: http://www.surfright.nl/en/kickstart

Let me know how you progress.

#15 bob marley

bob marley
  • Topic Starter

  • Members
  • 28 posts
  • OFFLINE
  •  
  • Local time:10:46 AM

Posted 02 January 2013 - 08:08 PM

Hello and Happy New Year! Yes I still need your help and really appreciate it. It took me awhile to get another CPU to use so I could create the kickstart flash drive. I powered off the ransomed cpu and plugged in the flash drive like I was instructed in the video. I powered up the cpu and hit f12. I selected removable device, but the kickstart boot menu doesn't come up. Instead, windows starts up and then the FBI warning pops up. I am not allowed to do anything after that point as usual. I have tried using every usb port I have. Same result each time. The problem seems to be that the kickstart menu is not coming up for me. What do you suggest I try next? Thanks again for your help!!




0 user(s) are reading this topic

0 members, 0 guests, 0 anonymous users