Go Back   English Forum Switzerland > Help & tips > TV/internet/telephone
Reply
 
Thread Tools Display Modes
  #1  
Old 16.11.2011, 08:14
Junior Member
 
Join Date: Jul 2011
Location: Winterthur
Posts: 95
Groaned at 1 Time in 1 Post
Thanked 45 Times in 38 Posts
purple7374 has earned some respectpurple7374 has earned some respect
Computer virus

Just wanted to let you know that a computer virus has been going around for a week or so falsly saying that it comes from the Federal Department of Justice and Police.
http://www.ejpd.admin.ch/content/ejp...011-11-07.html

My home computer has been hit yesterday and nothing works anymore .

Whatever you do, do not pay the SFr150.- it asks you to. In the meantime I am still trying to figure out how to get rid of the virus on my home computer .
Reply With Quote
This user would like to thank purple7374 for this useful post:
  #2  
Old 18.11.2011, 11:22
oldmanc's Avatar
Senior Member
 
Join Date: Feb 2006
Location: 8058
Posts: 368
Groaned at 5 Times in 3 Posts
Thanked 382 Times in 157 Posts
oldmanc is considered knowledgeableoldmanc is considered knowledgeableoldmanc is considered knowledgeable
Re: Computer virus

We just got a warning about this EJPD Virus at work. Here is the fix in German from my colleagues:

Schritt 1:
Starten Sie Ihren Computer neu und drücken Sie dabei die Taste F8 bis das „Menu Erweiter-te Startoptionen“ eingeblendet wird. Wählen Sie anschliessend den Menupunkt „Abgesicher-ter Modus mit Eingabeaufforderung“:

Schritt 2
Das zu startende Betriebssystem wählen. Beispielsweise: „Microsoft Windows XP Home Edition“

Schritt 3
Eventuell ist noch eine Anmeldung (am besten als Administrator) erforderlich und es öffnet sich danach ein Konsolenfenster. Hier gibt man „regedit“ ein.

Schritt 4
Es öffnet sich der Registrierungseditor. Im Editor müssen folgende Einträge gesucht werden:
„HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Window s NT\CurrentVersion\Winlogon“
„HKEY_LOCAL_USER\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon“
Zu den Einträgen gelangt man durch Aufklappen der einzelnen Unterordner auf der linken Seite zum entsprechenden Eintrag. Ein Klick auf „Winlogon“ öffnet die gesuchten Einträge auf der rechten Seite. Ein Doppelklick auf den Eintrag „Shell“ auf der rechten Seite öffnet ein weiteres Fenster. In diesem Fenster wird ein Wert angezeigt, der mit dem String „new.exe“ endet. Dieser gesamte Eintrag muss durch „explorer.exe“ ersetzt werden. Die Änderung muss danach noch mit „OK“ bestätigt werden und der Registrierungseditor geschlossen wer-den.

4/4
Schritt 3
Eventuell ist noch eine Anmeldung (am besten als Administrator) erforderlich und es öffnet sich danach ein Konsolenfenster. Hier gibt man „regedit“ ein.
Schritt 4
Es öffnet sich der Registrierungseditor. Im Editor müssen folgende Einträge gesucht werden:
„HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Window s NT\CurrentVersion\Winlogon“
„HKEY_LOCAL_USER\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon“
Zu den Einträgen gelangt man durch Aufklappen der einzelnen Unterordner auf der linken Seite zum entsprechenden Eintrag. Ein Klick auf „Winlogon“ öffnet die gesuchten Einträge auf der rechten Seite. Ein Doppelklick auf den Eintrag „Shell“ auf der rechten Seite öffnet ein weiteres Fenster. In diesem Fenster wird ein Wert angezeigt, der mit dem String „new.exe“ endet. Dieser gesamte Eintrag muss durch „explorer.exe“ ersetzt werden. Die Änderung muss danach noch mit „OK“ bestätigt werden und der Registrierungseditor geschlossen wer-den.

Schritt 5
Computer mit dem Befehl „shutdown –r“ neu starten. Geben Sie hierzu diesen Befehl an der Konsole ein. Warten Sie anschliessend bis der 30 Sekunden Timer abgelaufen ist. Das Sys-tem sollte nun wieder ohne Blockierung starten.
Trotz einer erfolgreichen Entsperrung wird empfohlen, nach der Sicherung der Daten, das System neu zu installieren.

Everything AYOR - I have not done any of this myself.
__________________
-------------------------------------
Hüüt bin I Güet

Last edited by oldmanc; 18.11.2011 at 11:30. Reason: C+P fix
Reply With Quote
The following 2 users would like to thank oldmanc for this useful post:
  #3  
Old 18.11.2011, 13:54
Junior Member
 
Join Date: Jul 2011
Location: Winterthur
Posts: 95
Groaned at 1 Time in 1 Post
Thanked 45 Times in 38 Posts
purple7374 has earned some respectpurple7374 has earned some respect
Re: Computer virus

Quote:
View Post
We just got a warning about this EJPD Virus at work. Here is the fix in German from my colleagues:

Schritt 1:
Starten Sie Ihren Computer neu und drücken Sie dabei die Taste F8 bis das „Menu Erweiter-te Startoptionen“ eingeblendet wird. Wählen Sie anschliessend den Menupunkt „Abgesicher-ter Modus mit Eingabeaufforderung“:

Schritt 2
Das zu startende Betriebssystem wählen. Beispielsweise: „Microsoft Windows XP Home Edition“

Schritt 3
Eventuell ist noch eine Anmeldung (am besten als Administrator) erforderlich und es öffnet sich danach ein Konsolenfenster. Hier gibt man „regedit“ ein.

Schritt 4
Es öffnet sich der Registrierungseditor. Im Editor müssen folgende Einträge gesucht werden:
„HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon“
„HKEY_LOCAL_USER\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon“
Zu den Einträgen gelangt man durch Aufklappen der einzelnen Unterordner auf der linken Seite zum entsprechenden Eintrag. Ein Klick auf „Winlogon“ öffnet die gesuchten Einträge auf der rechten Seite. Ein Doppelklick auf den Eintrag „Shell“ auf der rechten Seite öffnet ein weiteres Fenster. In diesem Fenster wird ein Wert angezeigt, der mit dem String „new.exe“ endet. Dieser gesamte Eintrag muss durch „explorer.exe“ ersetzt werden. Die Änderung muss danach noch mit „OK“ bestätigt werden und der Registrierungseditor geschlossen wer-den.

4/4
Schritt 3
Eventuell ist noch eine Anmeldung (am besten als Administrator) erforderlich und es öffnet sich danach ein Konsolenfenster. Hier gibt man „regedit“ ein.
Schritt 4
Es öffnet sich der Registrierungseditor. Im Editor müssen folgende Einträge gesucht werden:
„HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon“
„HKEY_LOCAL_USER\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon“
Zu den Einträgen gelangt man durch Aufklappen der einzelnen Unterordner auf der linken Seite zum entsprechenden Eintrag. Ein Klick auf „Winlogon“ öffnet die gesuchten Einträge auf der rechten Seite. Ein Doppelklick auf den Eintrag „Shell“ auf der rechten Seite öffnet ein weiteres Fenster. In diesem Fenster wird ein Wert angezeigt, der mit dem String „new.exe“ endet. Dieser gesamte Eintrag muss durch „explorer.exe“ ersetzt werden. Die Änderung muss danach noch mit „OK“ bestätigt werden und der Registrierungseditor geschlossen wer-den.

Schritt 5
Computer mit dem Befehl „shutdown –r“ neu starten. Geben Sie hierzu diesen Befehl an der Konsole ein. Warten Sie anschliessend bis der 30 Sekunden Timer abgelaufen ist. Das Sys-tem sollte nun wieder ohne Blockierung starten.
Trotz einer erfolgreichen Entsperrung wird empfohlen, nach der Sicherung der Daten, das System neu zu installieren.

Everything AYOR - I have not done any of this myself.
Thank you for your help! We have tried some of the above steps but it didn't work as we didn't have the step by step guide that you've just provided. It looks like we gave up too soon as we brought the computer to a shop. Hope your computer manages to stay clear from this virus.
Reply With Quote
  #4  
Old 18.11.2011, 14:07
Newbie
 
Join Date: Nov 2011
Location: Neuchatel
Posts: 8
Groaned at 0 Times in 0 Posts
Thanked 3 Times in 2 Posts
Yukizora has earned some respectYukizora has earned some respect
Re: Computer virus

I would probably do it "SPARTAAAAA!" mode, if it still lets you access the bios (Which is likely true).
If you did backups, boot into a linux distribution, write random data all over the disk, reinstall, and done.
If you didn't, well, you'll have to get a backup medium and copy non-infected data on it before wiping the disk.

I'm sorry this is not a very suitable solution if you don't know computers a lot though
Reply With Quote
This user would like to thank Yukizora for this useful post:
  #5  
Old 18.11.2011, 14:16
Junior Member
 
Join Date: Jul 2011
Location: Winterthur
Posts: 95
Groaned at 1 Time in 1 Post
Thanked 45 Times in 38 Posts
purple7374 has earned some respectpurple7374 has earned some respect
Re: Computer virus

Quote:
View Post
I would probably do it "SPARTAAAAA!" mode, if it still lets you access the bios (Which is likely true).
If you did backups, boot into a linux distribution, write random data all over the disk, reinstall, and done.
If you didn't, well, you'll have to get a backup medium and copy non-infected data on it before wiping the disk.

I'm sorry this is not a very suitable solution if you don't know computers a lot though
Thank you. I personally don't know computers that well but know of someone who does. Luckily we have recently done a backup of everything. But this virus is definitely a reminder to do those backups on a regular basis, not just once every blue moon, which is regular too... .
Reply With Quote
  #6  
Old 18.11.2011, 14:32
TidakApa's Avatar
Forum Veteran
 
Join Date: Jun 2009
Location: Zurich
Posts: 1,601
Groaned at 13 Times in 12 Posts
Thanked 2,171 Times in 813 Posts
TidakApa has a reputation beyond reputeTidakApa has a reputation beyond reputeTidakApa has a reputation beyond reputeTidakApa has a reputation beyond reputeTidakApa has a reputation beyond reputeTidakApa has a reputation beyond repute
Re: Computer virus

I just got this spam message via the EF:

Quote:
Hallo
Wie geht's
Ich werde gern dein Freund sein
bitte senden Sie mir E-Mail an meine private Mail-Box
unter (laurencebenrose@ymail.com)
so dass ich Ihnen meine Bilder
warte auf Ihre Antwort auf meine Mail-Box
have a nice day
Dank
Miß Laurence
email deleted

Hi
how are you doing
i will like to be your friend
please send me email to my private mail box
at ( email deleted)
so that i will send you my pictures
am awaiting your reply to my mail box
have a nice day
thanks
Miss laurence
email deleted
If you thought the Police was a reliable source........ well, the EF is also just as unsafe.


GOLDEN RULE NUMBER ONE:
  • NEVER open an email attachment from someone you don't know
Never pay over the internet when you don't know the person.

The Police etc. will never contact you via email unless you consent to them first....... eg. How did they get your details?
(classic scam give away)


In the above example:

a) I don't know this person
b) ZERO POSTS
c) signed "Miss" Laurence...... but the email is ben laurence... classic gender fail

ROSEBEN does not want to be your friend

(just a warning)
Reply With Quote
This user would like to thank TidakApa for this useful post:
  #7  
Old 18.11.2011, 14:36
MacGregor's Daughter's Avatar
Forum Veteran
 
Join Date: Oct 2009
Location: Zug
Posts: 1,583
Groaned at 13 Times in 11 Posts
Thanked 1,226 Times in 579 Posts
MacGregor's Daughter has a reputation beyond reputeMacGregor's Daughter has a reputation beyond reputeMacGregor's Daughter has a reputation beyond reputeMacGregor's Daughter has a reputation beyond reputeMacGregor's Daughter has a reputation beyond repute
Re: Computer virus

Quote:
View Post
Just wanted to let you know that a computer virus has been going around for a week or so falsly saying that it comes from the Federal Department of Justice and Police.
http://www.ejpd.admin.ch/content/ejp...011-11-07.html

My home computer has been hit yesterday and nothing works anymore .

Whatever you do, do not pay the SFr150.- it asks you to. In the meantime I am still trying to figure out how to get rid of the virus on my home computer .
So do I get the virus when I click on your link
Reply With Quote
  #8  
Old 18.11.2011, 15:02
Junior Member
 
Join Date: Jul 2011
Location: Winterthur
Posts: 95
Groaned at 1 Time in 1 Post
Thanked 45 Times in 38 Posts
purple7374 has earned some respectpurple7374 has earned some respect
Re: Computer virus

Quote:
View Post
I just got this spam message via the EF:



If you thought the Police was a reliable source........ well, the EF is also just as unsafe.





GOLDEN RULE NUMBER ONE:
  • NEVER open an email attachment from someone you don't know
Never pay over the internet when you don't know the person.

The Police etc. will never contact you via email unless you consent to them first....... eg. How did they get your details?
(classic scam give away)


In the above example:

a) I don't know this person
b) ZERO POSTS
c) signed "Miss" Laurence...... but the email is ben laurence... classic gender fail

ROSEBEN does not want to be your friend

(just a warning)
Of course I don't open any attachments of an email from someone I don't know. I wasn't even accessing my email account that day or for that matter the days before that. This EJPD virus my computer is of a different kind. I was browsing the usual news pages on the internet when all of a sudden a window popped up with the message from 'EJPD'. From that point onward nothing did work anymore.
Reply With Quote
  #9  
Old 18.11.2011, 15:04
MacGregor's Daughter's Avatar
Forum Veteran
 
Join Date: Oct 2009
Location: Zug
Posts: 1,583
Groaned at 13 Times in 11 Posts
Thanked 1,226 Times in 579 Posts
MacGregor's Daughter has a reputation beyond reputeMacGregor's Daughter has a reputation beyond reputeMacGregor's Daughter has a reputation beyond reputeMacGregor's Daughter has a reputation beyond reputeMacGregor's Daughter has a reputation beyond repute
Re: Computer virus

Quote:
View Post
I just got this spam message via the EF:

If you thought the Police was a reliable source........ well, the EF is also just as unsafe.
I received a similar pm, somebody with 0 posts asking to be my friend
Reply With Quote
  #10  
Old 18.11.2011, 15:05
MacGregor's Daughter's Avatar
Forum Veteran
 
Join Date: Oct 2009
Location: Zug
Posts: 1,583
Groaned at 13 Times in 11 Posts
Thanked 1,226 Times in 579 Posts
MacGregor's Daughter has a reputation beyond reputeMacGregor's Daughter has a reputation beyond reputeMacGregor's Daughter has a reputation beyond reputeMacGregor's Daughter has a reputation beyond reputeMacGregor's Daughter has a reputation beyond repute
Re: Computer virus

Quote:
View Post
Of course I don't open any attachments of an email from someone I don't know. I wasn't even accessing my email account that day or for that matter the days before that. This EJPD virus my computer is of a different kind. I was browsing the usual news pages on the internet when all of a sudden a window popped up with the message from 'EJPD'. From that point onward nothing did work anymore.
Sounds pretty scary! You only looked at the pages you usually look at?
Reply With Quote
  #11  
Old 18.11.2011, 15:06
Junior Member
 
Join Date: Jul 2011
Location: Winterthur
Posts: 95
Groaned at 1 Time in 1 Post
Thanked 45 Times in 38 Posts
purple7374 has earned some respectpurple7374 has earned some respect
Re: Computer virus

Quote:
View Post
So do I get the virus when I click on your link
Ooops good point, I should have been more clear about the link I posted . The link is not the link to the virus! It is the link to the official EJPD website that talks about the virus... If you don't trust me then google it.
Reply With Quote
This user would like to thank purple7374 for this useful post:
  #12  
Old 18.11.2011, 15:11
Junior Member
 
Join Date: Jul 2011
Location: Winterthur
Posts: 95
Groaned at 1 Time in 1 Post
Thanked 45 Times in 38 Posts
purple7374 has earned some respectpurple7374 has earned some respect
Re: Computer virus

Quote:
View Post
Sounds pretty scary! You only looked at the pages you usually look at?
I know it is scary! And yes, I only browsed the usual pages, I promise. But don't panic, so far I only know of someone else who got the same virus. When I collected my computer from the shop today someone just came in with the EJPD virus on his computer.
Reply With Quote
  #13  
Old 18.11.2011, 15:16
Newbie
 
Join Date: Nov 2011
Location: Neuchatel
Posts: 8
Groaned at 0 Times in 0 Posts
Thanked 3 Times in 2 Posts
Yukizora has earned some respectYukizora has earned some respect
Re: Computer virus

Quote:
View Post
Sounds pretty scary! You only looked at the pages you usually look at?
Well, it happens. I don't know how the guys thought it was a good idea, posting their full bank account info. So much wasted potential
Windows is like the punching ball for any virus maker.
Reply With Quote
  #14  
Old 20.11.2011, 02:04
Newbie
 
Join Date: Sep 2011
Location: Fribourg
Posts: 8
Groaned at 0 Times in 0 Posts
Thanked 0 Times in 0 Posts
Beauty007 has no particular reputation at present
Re: Computer virus

Geez am i glad i saw this!! ive got this virus on my computer too and let me tell you for a second i thought i had to pay 150chf i have to say it looked very authentic....im still trying to get rid of it!! aaagghhhh .....
Reply With Quote
  #15  
Old 20.11.2011, 07:20
Forum Veteran
 
Join Date: Nov 2007
Location: Vaud
Posts: 825
Groaned at 46 Times in 26 Posts
Thanked 256 Times in 147 Posts
markalex has made some interesting contributions
Re: Computer virus

OK,

Already answered somebody on a private mail on this. The post office or indeed a bank would not agree/willing be part of what is nothing short of extortion. Not read the message, but sure this is one for the law.

Does Switzerland have a cybercrime unit perhaps? Anybody??
Reply With Quote
  #16  
Old 21.11.2011, 08:32
Junior Member
 
Join Date: Jul 2011
Location: Winterthur
Posts: 95
Groaned at 1 Time in 1 Post
Thanked 45 Times in 38 Posts
purple7374 has earned some respectpurple7374 has earned some respect
Re: Computer virus

Quote:
View Post
Geez am i glad i saw this!! ive got this virus on my computer too and let me tell you for a second i thought i had to pay 150chf i have to say it looked very authentic....im still trying to get rid of it!! aaagghhhh .....
I hope you manage to sort it out soon. Good luck.
Reply With Quote
  #17  
Old 22.11.2011, 01:04
Newbie 1st class
 
Join Date: Sep 2007
Location: Zurich
Posts: 15
Groaned at 0 Times in 0 Posts
Thanked 5 Times in 5 Posts
Brassmonkey has no particular reputation at present
Re: Computer virus

and just in case you need access to some very good but free and safe tools to remove the occasional trojan or whatever. I can happily recommend www.majorgeeks.com. The site is not for profit, has lots of bug free (tested) tools, and if you look on the right panel first a step by step guide to protecting and or cleaning your system. and no there is no hook, spin or anything!!

enjoy
Reply With Quote
This user would like to thank Brassmonkey for this useful post:
Reply


Currently Active Users Viewing This Thread: 1 (0 members and 1 guests)
 
Thread Tools
Display Modes

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is On
HTML code is Off
Trackbacks are Off
Pingbacks are Off
Refbacks are Off


Similar Threads
Thread Thread Starter Forum Replies Last Post
Warning Re: Mac Virus Textoch General off-topic 14 27.05.2011 14:05
Cell phone virus warning! Maria Complaints corner 0 16.12.2009 11:05
PC Virus Ian Nicol General off-topic 27 11.08.2009 00:07
Virus and anti-spyware recommendation cricketer General off-topic 12 01.01.2008 22:15


All times are GMT +2. The time now is 00:57.


Powered by vBulletin® Version 3.8.4
Copyright ©2000 - 2012, Jelsoft Enterprises Ltd.
LinkBacks Enabled by vBSEO 3.1.0