Department of Justice/F.B.I/ICE Dialogue Virus


“Department of Justice/F.b.I/Ice”: – associated dialogue Virus. This virus can in many forms a user can go through safe mode, and clean the virus out with a preferred virus scan ;or manually. However there is another version where safe mode is not an option in removing of this virus. Safe Mode will just reboot. This is my Tip instead of going to safe mode open up Command Prompt, a user will be able to type the command prompt C://Users/Windows/System32/Dir. In this DIR. towards the bottom is the newest installed files in System32 which this virus will be in FontCache.dat, and it will create a log file like winspeh.log. C://Users/Windows/System32/Dir/Del Fontcache.dat, and the log file.

Files Detected: 1
C:\Users\—–\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\33\23cdca1-7ae060b9 (Trojan.FakeMS.ED) -> Quarantined and deleted successfully.

Files Associated: 6
winspesh.log
2433f433.exe
dat1CD2
dat1E43
dat1FEF
dat2575

Files Affected: 1
FontCache.dat
Java

I am currently still going through log files, and registry files too see if any more files have been infected; or what other files may have been created. I will update this as I find more information. Malware-bytes Anti-Malware and AVG Anti-virus picked these files up with association.

Advertisements

About Eddie O.

Since 1998 I took interest in Computers, learning mostly about Virus removal; and security. Throughout the years I successfully completed A+, & N+ Prep Courses, for Computer Repairs; and Networking. Following the completion of them courses I enrolled into Online College for my Associates in Business Management, and my Bachelor in IT. I am considered a Free Lance Computer Technician, I specialize in Virus Removal, Rebuilding, and recovering Windows Operating Systems.
This entry was posted in Virus Info & Removal Help. Bookmark the permalink.

Leave a Reply

Please log in using one of these methods to post your comment:

WordPress.com Logo

You are commenting using your WordPress.com account. Log Out / Change )

Twitter picture

You are commenting using your Twitter account. Log Out / Change )

Facebook photo

You are commenting using your Facebook account. Log Out / Change )

Google+ photo

You are commenting using your Google+ account. Log Out / Change )

Connecting to %s