Department of Justice Ransomware help

Discussion in 'Malware Help - MG (A Specialist Will Reply)' started by james250, Nov 11, 2013.

  1. james250

    james250 Private E-2

    I have a laptop that has The DOJ ransom ware. Safe mode does not work and I did not want copy a fix that might be intended for another machine.
    The laptop goes for the welcome screen to the Ransom screen and that's it.

    Os is vista.

    James
     
  2. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    [​IMG] For 32-bit (x86) systems download Farbar Recovery Scan Tool and save it to a flash drive.
    For 64-bit (x64) systems download Farbar Recovery Scan Tool x64 and save it to a flash drive.

    Plug the flashdrive into the infected PC.

    Enter System Recovery Options.

    To enter System Recovery Options from the Advanced Boot Options:
    • Restart the computer.
    • As soon as the BIOS is loaded begin tapping the F8 key until Advanced Boot Options appears.
    • Use the arrow keys to select the Repair your computer menu item.
    • Choose your language settings, and then click Next.
    • Select the operating system you want to repair, and then click Next.
    • Select your user account and click Next.

    To enter System Recovery Options by using Windows installation disc:

    • Insert the installation disc.
    • Restart your computer.
    • If prompted, press any key to start Windows from the installation disc. If your computer is not configured to start from a CD or DVD, check your BIOS settings.
    • Click Repair your computer.
    • Choose your language settings, and then click Next.
    • Select the operating system you want to repair, and then click Next.
    • Select your user account an click Next.
    On the System Recovery Options menu you will get the following options:
    • Select Command Prompt
    • In the command window type in notepad and press Enter.
    • The notepad opens. Under File menu select Open.
    • Select "Computer" and find your flash drive letter and close the notepad.
    • In the command window type e:\frst.exe (for x64 bit version type e:\frst64) and press Enter
    • Note: Replace letter e with the drive letter of your flash drive.
    • The tool will start to run.
    • When the tool opens click Yes to disclaimer.
    • Press Scan button.
    • It will make a log (FRST.txt) on the flash drive. Please attach this log to your next reply. (How to attach)
     
  3. james250

    james250 Private E-2

    Hey Kestrel13 Here's the scan Frst.text.
     

    Attached Files:

  4. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    NOTICE: This script was written specifically for this user, for use on that particular machine. Running this on another machine may cause damage to your operating system

    Attached is fixlist.txt
    • Save fixlist.txt to your flash drive.
    • You should now have both fixlist.txt and FRST.exe on your flash drive.

    Now re-enter System Recovery Options.
    Run FRST and press the Fix button just once and wait.
    The tool will make a log on the flashdrive (Fixlog.txt).
    Please attach this to your next message. (How to attach)


    Now see if you are able to complete these procedures: READ & RUN ME FIRST - Malware Removal Guide
     

    Attached Files:

  5. james250

    james250 Private E-2

    Hey Kestrel. DOJ still pops up. I was able to get to the desk top and it pops up. No luck in safe mode either.

    James
     

    Attached Files:

  6. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    Re run FRST again please, just a scan and attach log.
     
  7. james250

    james250 Private E-2

    Here's the scan.
     

    Attached Files:

  8. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    Hi James.

    NOTICE: This script was written specifically for this user, for use on that particular machine. Running this on another machine may cause damage to your operating system

    Attached is fixlist.txt
    • Save fixlist.txt to your flash drive.
    • You should now have both fixlist.txt and FRST.exe on your flash drive.

    Now re-enter System Recovery Options.
    Run FRST and press the Fix button just once and wait.
    The tool will make a log on the flashdrive (Fixlog.txt).
    Please attach this to your next message. (How to attach)

    Any luck booting normally or in safe mode now?
     

    Attached Files:

  9. james250

    james250 Private E-2

    That did it. I went through the read me first and only malwarebytes found a few things. All the the other scans were good.

    Funny thing the laptop has a paid subscription to Norton. I guess malware can get by it too.

    Thanks for the help. count me in for a T-shirt.

    James
     
  10. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    No problem James. I know you say things seem ok now but there may be some remnants left behind, if you want to attach all those logs from doing the R&R I would gladly review them all and ensure you're safe. :)
     
  11. james250

    james250 Private E-2

    Hey Kestrel. Here are the logs.
     

    Attached Files:

  12. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    Hi James.

    Uninstall the below:


    • [*]Ask Toolbar
      [*]Inbox Toolbar

    Now re run Hitman Pro and have it delete Potential Unwanted Programs.


    Please disable all anti-virus and anti-spyware programs while we do the following (re-enable when you are finished):

    Run C:\MGtools\analyse.exe by double clicking on it (Note: if using Vista, don't double click, use right click and select Run As Administrator). This is really HijackThis (select Do a system scan only) and select the following lines but DO NOT CLICK FIX until you exit all browser sessions including the one you are reading in right now:


    After clicking Fix exit HJT.


    Delete this:
    C:\Users\Just\AppData\Roaming\Microsoft\Windows\Templates\4iITLJ4W1AN7

    Now run the C:\MGtools\GetLogs.bat file by double clicking on it. (Right click and run as admin if using Vista, Windows7 or Win8) Then attach the new C:\MGlogs.zip file that will be created by running this.

    Let me know of any problems you may have encountered with the above instructions and also let me know how things are running now!
     
  13. james250

    james250 Private E-2

    Hey Kestrel. Everything worked. Here's the log.

    This laptop belongs to a friend of my wife. Her husband said it was a paper weight with the DOJ . Thanks to you're help it is running.

    THANK YOU.

    James
     

    Attached Files:

  14. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    Ah, you're all most welcome. :)

    You only attached the hjt log, I wanted the complete MGlogs.zip >>>
     
  15. james250

    james250 Private E-2

    Sorry got a little trigger happy.:-D

    I think this is what you ask for. It's a rescan.

    James
     

    Attached Files:

  16. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    Delete these:
    • C:\Users\Just\AppData\Roaming\Microsoft\Windows\Templates\1.bmp
    • C:\Users\Just\AppData\Roaming\Microsoft\Windows\Templates\1.jpg
    • C:\Users\Just\AppData\Roaming\Microsoft\Windows\Templates\4iITLJ4W1AN7
    • C:\Users\Just\AppData\Roaming\Microsoft\Windows\Templates\avG

    When you reboot, & navigate back, are they still gone? :confused
     
  17. james250

    james250 Private E-2

    They are gone. Pull the trigger now:-D

    Thanks
     
  18. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    OK :-D

    If you are not having any other malware problems, it is time to do our final steps:
    1. We recommend you keep Malwarebytes Anti-Malware for scanning/removal of malware.
    2. If we had you download any registry patches like fixme.reg or fixWLK.reg (or any others) and running MGclean.bat did not remove them, you can delete these files now.
    3. Renable your Disk Emulation software with Defogger if you had disabled it in step 4 of the READ & RUN ME.
    4. Go to add/remove programs and uninstall HijackThis. If you don't see it or it will not uninstall, don't worry about it. Just move on to the next step.
    5. If running Vista, Win 7 or Win 8, it is time to make sure you have reenabled UAC by double clicking on the C:\MGtools\enableUAC.reg file and allowing it to be added to the registry.
    6. Now goto the C:\MGtools folder and find the MGclean.bat file. Double click ( if running Vista, Win7, or Win 8 Right Click and Run As Administrator ) on this file to run this cleanup program that will remove files and folders related to MGtools and some other items from our cleaning procedures.
    7. Any other miscellaneous tools we may have had you install or download can be uninstalled and deleted.

    8. After doing the above, you should work thru the below link:
     
  19. james250

    james250 Private E-2

    Hey I did the final steps. Everything looks good.

    Thanks again.

    James
     
  20. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    You are most welcome.:)
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds