Translate

Sunday, January 27, 2013

Spotlight on malware: Reveton Trojan

The Reveton Trojan, also called the FBI MoneyPak Trojan, and the Police Trojan, is a screen locker Trojan that displays a warning from a "law enforcement agency" that claims that that user has preformed illegal activities such as downloading pirated software. This Trojan prevents you from doing anything on your computer until you pay the fine, up to $500, or remove the Trojan. The Trojan often demands payment though a prepaid, untraceable payment. Some recent versions show the view from your "webcam" and display your IP address to reinforce the claim that you are being watched. The "webcam" video shows up with no regard as to if you actually have a webcam or not. This Trojan is based on the Citadel Trojan, which is itself, based on the Zeus Trojan. There are several versions of this same Trojan which started out in the UK. These include versions for the FBI, the DOD, and the DOJ.

To remove, boot into Safe Mode with networking, go online and download Malwarebytes Anti Malware. Run the installer and say yes to all the regular options. Leave update and launch checked, and then it should start. After it has, choose Quick Scan, this quick scan will take anywhere from 1-15 minutes depending on how much stuff you have on your computer and how many files are infected.

4 comments:

  1. The fact that it shows up with webcam "footage" even though you do not have a webcam is rather funny. Are you sure that a quick scan is good enough for most computers?

    ReplyDelete
    Replies
    1. Some of the latest versions actually detect if you have a webcam or not. If you do, it just mirrors the webcam as if they are saying "There you are, we can see you!" And as far as a quick scan being enough, if you are speaking in terms of getting rid of the Trojan, yes, it is more then enough. If you mean just in general. Getting a ton of malware off of the computer, well maybe. It depends on how much malware is on the machine, it depends on a lot of things. But a quick scan is often the best place to start.

      Delete
    2. Thanks for the quick reply, I think I am going to run a full scan just to make sure that there is not any malware on my PC. Can you tell me how long that will take?

      Delete
    3. The speed of your computer does not matter that much because Malwarebytes does not take up that much in terms of system resources. A full scan is like going though your computer with a fine tooth comb, It can take anywhere from 1 hour to 24 hours depending on how much stuff you've got on the computer. If you just bought the computer and you do not have that much in the way of files on it, then it would be closer to 1 hour. This is an estimate, not an exact time of how long the scan may take.

      Delete