Windows 8 forum


DOJ Virus

by bk_msm / July 6, 2013 2:50 PM PDT

I recently experienced the DOJ virus on my Dell XPS12 tablet/laptop running Win 8. I went through the online scans of pctuneup and malwarebytes and pcmatic and everything else. They all come up with no malware found. At first, I could not browse the internet with chrome or firefox, but iexplorer was working. Now, no browsers will work, UNLESS the machine boots in safe mode. I disabled 'unknown' processes and am not sure what I should try next.
Please help if you have any information on this.

Discussion is locked
You are posting a reply to: DOJ Virus
The posting of advertisements, profanity, or personal attacks is prohibited. Please refer to our CNET Forums policies for details. All submitted content is subject to our Terms of Use.
Track this discussion and email me when there are updates

If you're asking for technical help, please be sure to include all your system info, including operating system, model number, and any other specifics related to the problem. Also please exercise your best judgment when posting in the forums--revealing personal information such as your e-mail address, telephone number, and address is not recommended.

You are reporting the following post: DOJ Virus
This post has been flagged and will be reviewed by our staff. Thank you for helping us maintain CNET's great community.
Sorry, there was a problem flagging this post. Please try again now or at a later time.
If you believe this post is offensive or violates the CNET Forums' Usage policies, you can report it below (this will not automatically remove the post). Once reported, our moderators will be notified and the post will be reviewed.

All Answers

Collapse -
I know I've got rid of attacks
by orlbuckeye / July 10, 2013 11:32 PM PDT
In reply to: DOJ Virus

by going to a restore point before the attack and do that restore. Then I ran Anti-Malwarebytes and did a scan with Norton 360. Other area's i look at are unknown toolbars and search engines.

Collapse -
Department of Justice Virus
by livepcexpert7 / July 15, 2013 5:19 AM PDT
In reply to: DOJ Virus

01. "Department of Justice Virus" is a very updated infection and keeps
updating its locations and file names hence it might be a little bit
critical to remove the infection

02. Try to perform a System Restore by the following process -
Swipe in from the right edge of the screen, and then tap Search.
(If you're using a mouse, point to the upper-right corner of the screen,
move the mouse pointer down, and then click Search.) Enter Recovery in the
search box, tap or click Settings, and then tap or click Recovery.
Tap or click Open System Restore, and follow the prompts.

03. If System Restore fails or if the issue is not resolved then proceed to
the next steps

04. Open Windows Start Menu, enter %appdata% into the search field, click

05. Go to: Microsoft\Windows\Start Menu\Programs\Startup.

06. Remove ctfmon (don't mix it with ctfmon.exe!).

07. Open Windows Start Menu, enter %userprofile% into the search field,
click Enter.

08. Go to Appdata\Local\Temp and remove rool0_pk.exeDelete [random
characters].mof file

09. Delete V.class

10. Restart the computer

11. The infection should have been removed

12. If the issue is not resolved then get back to us

Collapse -
doj virus
by paksam / August 21, 2013 10:31 PM PDT

i tried your instructions but stuck at appdata step. i cannot proceed further since i cannot locate the directory you indicated in your post. any idea? thanks

Collapse -
Another thing to try is to boot
by orlbuckeye / August 22, 2013 12:19 AM PDT
In reply to: doj virus

into safe mode. Some Virus are loaded at startup so Safe mode will not load then then go to the folder of your virus and run a scan which is usually scan.exe. If the viruses software is messed up i would download Antimalwarebytes on another machine and maybe avast (free version) and run those scans in safe mode and see if it removes stuff.

Collapse -
by paksam / August 22, 2013 1:01 AM PDT

i found the ctfMon file under the user folder, that file was created yesterday and that is the time i got the virus too. it is shown as an app file, okay to remove it? i also saw 2 more files were created about the same time. should i delete them too? they are exe files but your previous instruction said dont delete them. i am not good at using pc.
thanks for your help.

Popular Forums
Computer Newbies 10,686 discussions
Computer Help 54,365 discussions
Laptops 21,181 discussions
Networking & Wireless 16,313 discussions
Phones 17,137 discussions
Security 31,287 discussions
TVs & Home Theaters 22,101 discussions
Windows 7 8,164 discussions
Windows 10 2,657 discussions


Your favorite shows are back!

Don’t miss your dramas, sitcoms and reality shows. Find out when and where they’re airing!