MajorGeeks Support Forums

Go Back   MajorGeeks Support Forums > ----------= PC, Desktop and Laptop Support =---------- > Malware Removal
Register FAQ Members List Calendar Casino Mark Forums Read

Malware Removal Malware removal forum. Please see the READ ME FIRST thread before you post. Forum is staffed by a small number of volunteers, please be patient.


Reply
 
Thread Tools Display Modes
  #1  
Old 09-21-12, 02:14
draftiebrah draftiebrah is offline
Private E-2
 
Join Date: Sep 2012
Posts: 24
Thanks: 3
Thanked 0 Times in 0 Posts
Default ukash virus help

Hi guys just recently I was hit with the ukash virus and now I cannot access anything at all. I can't seem to get into system restore to roll back, my computer is pretty much locked. How do I go about fixing this issue??
Thanks.
Reply With Quote
Sponsored links
  #2  
Old 09-21-12, 17:47
thisisu's Avatar
thisisu thisisu is offline
Malware Consultant
 
Join Date: Apr 2006
Location: Houston, TX
Posts: 8,179
Thanks: 270
Thanked 1,437 Times in 1,356 Posts
Default Re: ukash virus help

Hello draftiebrah,

Which operating system are you using?
__________________
Facebook . Twitter . Blog . VirusTotal
Reply With Quote
  #3  
Old 09-21-12, 18:35
thisisu's Avatar
thisisu thisisu is offline
Malware Consultant
 
Join Date: Apr 2006
Location: Houston, TX
Posts: 8,179
Thanks: 270
Thanked 1,437 Times in 1,356 Posts
Default Re: ukash virus help

If you are on Windows Vista or 7, try this:

Please download Farbar Recovery Scan Tool and save it to a flash drive.

Plug the flashdrive into the infected PC.

Enter System Recovery Options.

To enter System Recovery Options from the Advanced Boot Options:
  • Restart the computer.
  • As soon as the BIOS is loaded begin tapping the F8 key until Advanced Boot Options appears.
  • Use the arrow keys to select the Repair your computer menu item.
  • Choose your language settings, and then click Next.
  • Select the operating system you want to repair, and then click Next.
  • Select your user account and click Next.

To enter System Recovery Options by using Windows installation disc:
  • Insert the installation disc.
  • Restart your computer.
  • If prompted, press any key to start Windows from the installation disc. If your computer is not configured to start from a CD or DVD, check your BIOS settings.
  • Click Repair your computer.
  • Choose your language settings, and then click Next.
  • Select the operating system you want to repair, and then click Next.
  • Select your user account an click Next.
On the System Recovery Options menu you will get the following options:
Quote:
  • Startup Repair
  • System Restore
  • Windows Complete PC Restore
  • Windows Memory Diagnostic Tool
  • Command Prompt
  • Select Command Prompt
  • In the command window type in notepad and press Enter.
  • The notepad opens. Under File menu select Open.
  • Select "Computer" and find your flash drive letter and close the notepad.
  • In the command window type e:\frst.exe (for x64 bit version type e:\frst64) and press Enter
  • Note: Replace letter e with the drive letter of your flash drive.
  • The tool will start to run.
  • When the tool opens click Yes to disclaimer.
  • Press Scan button.
  • It will make a log (FRST.txt) on the flash drive. Please attach this log to your next reply. (How to attach)
__________________
Facebook . Twitter . Blog . VirusTotal
Reply With Quote
  #4  
Old 09-21-12, 19:23
draftiebrah draftiebrah is offline
Private E-2
 
Join Date: Sep 2012
Posts: 24
Thanks: 3
Thanked 0 Times in 0 Posts
Default Re: ukash virus help

Im running Vista SP2
Reply With Quote
  #5  
Old 09-21-12, 19:46
thisisu's Avatar
thisisu thisisu is offline
Malware Consultant
 
Join Date: Apr 2006
Location: Houston, TX
Posts: 8,179
Thanks: 270
Thanked 1,437 Times in 1,356 Posts
Default Re: ukash virus help

Quote:
Originally Posted by draftiebrah View Post
Im running Vista SP2
Great! Then try running the above set of instructions.
Let me know if you need help.
__________________
Facebook . Twitter . Blog . VirusTotal
Reply With Quote
Sponsored links
  #6  
Old 09-21-12, 20:02
draftiebrah draftiebrah is offline
Private E-2
 
Join Date: Sep 2012
Posts: 24
Thanks: 3
Thanked 0 Times in 0 Posts
Default Re: ukash virus help

Here is my FRST log.
Attached Files
File Type: txt FRST.txt (20.5 KB, 4 views)
Reply With Quote
  #7  
Old 09-21-12, 20:13
thisisu's Avatar
thisisu thisisu is offline
Malware Consultant
 
Join Date: Apr 2006
Location: Houston, TX
Posts: 8,179
Thanks: 270
Thanked 1,437 Times in 1,356 Posts
Default Re: ukash virus help

So you are able to boot into Safe Mode?
Which mode did you run FRST from?
__________________
Facebook . Twitter . Blog . VirusTotal
Reply With Quote
  #8  
Old 09-21-12, 20:17
draftiebrah draftiebrah is offline
Private E-2
 
Join Date: Sep 2012
Posts: 24
Thanks: 3
Thanked 0 Times in 0 Posts
Default Re: ukash virus help

Quote:
Originally Posted by thisisu View Post
So you are able to boot into Safe Mode?
Which mode did you run FRST from?
safe mode with command prompt. Any other way the white screen pops up and everything is locked again. If i go into system recovery the laptop just hangs.
Reply With Quote
  #9  
Old 09-21-12, 20:24
thisisu's Avatar
thisisu thisisu is offline
Malware Consultant
 
Join Date: Apr 2006
Location: Houston, TX
Posts: 8,179
Thanks: 270
Thanked 1,437 Times in 1,356 Posts
Default Re: ukash virus help

Quote:
Originally Posted by draftiebrah View Post
If i go into system recovery the laptop just hangs.
how many times have you tried entering system recovery options?

Quote:
Originally Posted by draftiebrah View Post
safe mode with command prompt
What happens if you type in explorer
in the command prompt window, and then press ENTER?

Are you able to see your desktop?
__________________
Facebook . Twitter . Blog . VirusTotal
Reply With Quote
  #10  
Old 09-21-12, 20:31
draftiebrah draftiebrah is offline
Private E-2
 
Join Date: Sep 2012
Posts: 24
Thanks: 3
Thanked 0 Times in 0 Posts
Default Re: ukash virus help

Quote:
Originally Posted by thisisu View Post
how many times have you tried entering system recovery options?

What happens if you type in explorer
in the command prompt window, and then press ENTER?

Are you able to see your desktop?
As for system restore even when i press F8 and it still bypasses it and boots up normally. But ive done it 3 times so far.*

Yes i do get to see the desktop
Reply With Quote
Sponsored links
  #11  
Old 09-21-12, 20:34
thisisu's Avatar
thisisu thisisu is offline
Malware Consultant
 
Join Date: Apr 2006
Location: Houston, TX
Posts: 8,179
Thanks: 270
Thanked 1,437 Times in 1,356 Posts
Default Re: ukash virus help

Quote:
Originally Posted by draftiebrah View Post
Yes i do get to see the desktop
In that case, complete as much of this as possible from Safe Mode with Command Prompt: Read and Run Me First - Malware Removal Guide.

If something doesn't run, just go to the next steps until you reach the very end.
__________________
Facebook . Twitter . Blog . VirusTotal
Reply With Quote
  #12  
Old 09-21-12, 21:42
draftiebrah draftiebrah is offline
Private E-2
 
Join Date: Sep 2012
Posts: 24
Thanks: 3
Thanked 0 Times in 0 Posts
Default Re: ukash virus help

Also when the time comes how do i save a log of RogueKiller??
Reply With Quote
  #13  
Old 09-21-12, 22:28
thisisu's Avatar
thisisu thisisu is offline
Malware Consultant
 
Join Date: Apr 2006
Location: Houston, TX
Posts: 8,179
Thanks: 270
Thanked 1,437 Times in 1,356 Posts
Default Re: ukash virus help

Quote:
Originally Posted by draftiebrah View Post
Also when the time comes how do i save a log of RogueKiller??
As soon as you press the Scan button, there will be a log on your desktop
__________________
Facebook . Twitter . Blog . VirusTotal
Reply With Quote
  #14  
Old 09-22-12, 00:51
draftiebrah draftiebrah is offline
Private E-2
 
Join Date: Sep 2012
Posts: 24
Thanks: 3
Thanked 0 Times in 0 Posts
Default Re: ukash virus help

Ok so here goes all logs required attached.
Many thanks again for the help provided. Really do appreciate it.
Attached Files
File Type: txt RKreport[3].txt (3.5 KB, 3 views)
File Type: log HitmanPro_20120922_1256.log (12.7 KB, 3 views)
File Type: txt mbam-log-2012-09-22 (12-41-56).txt (899 Bytes, 2 views)
File Type: zip MGlogs.zip (514.8 KB, 2 views)
Reply With Quote
  #15  
Old 09-22-12, 01:25
thisisu's Avatar
thisisu thisisu is offline
Malware Consultant
 
Join Date: Apr 2006
Location: Houston, TX
Posts: 8,179
Thanks: 270
Thanked 1,437 Times in 1,356 Posts
Default Re: ukash virus help

  • Open RogueKiller again.
  • Press Scan.
  • When the scan is finished, press the Delete button.
  • Attach the latest RogueKiller log to your next message.
__________________
Facebook . Twitter . Blog . VirusTotal
Reply With Quote
Sponsored links
  #16  
Old 09-22-12, 01:28
thisisu's Avatar
thisisu thisisu is offline
Malware Consultant
 
Join Date: Apr 2006
Location: Houston, TX
Posts: 8,179
Thanks: 270
Thanked 1,437 Times in 1,356 Posts
Default Re: ukash virus help

Fix items using OTL by OldTimer

Double-click OTL.exe to run. (Vista/7 right-click and select Run as Administrator)
Shut down your protection software now (antivirus, antispyware...etc) to avoid possible conflicts.
Copy the text in the code box below and paste it into the text-field.
Code:
:files
C:\Users\George\AppData\Roaming\msconfig.dat
C:\Windows\Installer\{b47899fd-dd8f-4aa9-60cf-c3e77067d3ab} /d
C:\Users\George\AppData\Local\{b47899fd-dd8f-4aa9-60cf-c3e77067d3ab} /d
C:\Windows\Assembly\GAC\Desktop.ini /d
:commands
[emptyjava]
[emptyflash]
[reboot]
Now click the button.
If the fix needed a reboot please do it.
Click the OK button (upon reboot).
When OTL is finished, Notepad will open. Close Notepad.
A log file will be located at C:\_OTL\MovedFiles\mmddyyyy_hhmmss.log, where mmddyyyy_hhmmss is the date of the tool run.
Attach this log to your next message. (How to attach)

__

Now download the latest MGtools.exe to the root of your c: drive.
  • Replace your existing MGtools.exe with this one.
  • Now run this new MGtools.exe by double-clicking it. (Vista/7 right-click and select Run as Administrator)
  • When it is finished, attach c:\MGlogs.zip to your next message. (How to attach)
__________________
Facebook . Twitter . Blog . VirusTotal
Reply With Quote
The Following User Says Thank You to thisisu For This Useful Post:
draftiebrah (09-23-12)
  #17  
Old 09-22-12, 02:07
draftiebrah draftiebrah is offline
Private E-2
 
Join Date: Sep 2012
Posts: 24
Thanks: 3
Thanked 0 Times in 0 Posts
Default Re: ukash virus help

that MGtools i downloaded seems to be the latest version. Im on a completely seperate laptop right now atm.

EDIT: just tried getting in again from safe mode with networking and issue still there
Reply With Quote
  #18  
Old 09-22-12, 02:30
thisisu's Avatar
thisisu thisisu is offline
Malware Consultant
 
Join Date: Apr 2006
Location: Houston, TX
Posts: 8,179
Thanks: 270
Thanked 1,437 Times in 1,356 Posts
Default Re: ukash virus help

Quote:
Originally Posted by draftiebrah View Post
that MGtools i downloaded seems to be the latest version. Im on a completely seperate laptop right now atm.

EDIT: just tried getting in again from safe mode with networking and issue still there
What happened with the previous steps? RogueKiller, OTL? Those should have removed the ransom.

Worry about MGtools last.
__________________
Facebook . Twitter . Blog . VirusTotal
Reply With Quote
  #19  
Old 09-22-12, 03:13
draftiebrah draftiebrah is offline
Private E-2
 
Join Date: Sep 2012
Posts: 24
Thanks: 3
Thanked 0 Times in 0 Posts
Default Re: ukash virus help

Quote:
Originally Posted by thisisu View Post
What happened with the previous steps? RogueKiller, OTL? Those should have removed the ransom.

Worry about MGtools last.
Thank You had some issues with the infected computer but as i did the OTL text fix, its worked. Now im going to run RK properly from the infected comp now.
Reply With Quote
  #20  
Old 09-22-12, 03:57
draftiebrah draftiebrah is offline
Private E-2
 
Join Date: Sep 2012
Posts: 24
Thanks: 3
Thanked 0 Times in 0 Posts
Default Re: ukash virus help

latest roguekiller log.
Attached Files
File Type: txt RKreport[5].txt (3.4 KB, 4 views)
Reply With Quote
Sponsored links
Reply

Thread Tools
Display Modes

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is On
HTML code is Off

Forum Jump

Similar Threads
Thread Thread Starter Forum Replies Last Post
ukash virus adamc Malware Removal 13 09-25-12 06:10
Damn UKASH virus Fence_ Malware Removal 11 08-10-12 12:19
It all started with Ukash! leelee77 Malware Removal 4 07-08-12 15:53
help with ukash virus newts Malware Removal 3 06-03-12 19:34
Bundespolizei Ukash virus Problem herbz100 Malware Removal 6 11-26-11 15:59


All times are GMT -5. The time now is 11:38.

MajorGeeks.Com Menu

MajorGeeks.Com \ All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ NEW! PC Games \ System Tools \ Macintosh \ Demonews.Com \ Top Downloads

MajorGeeks.Com \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds


All content Copyright MajorGeeks.com source code Powered by vBulletin® Version 3.8.4
Copyright © 2009 vBulletin Solutions, Inc. All rights reserved.
Ad Management by RedTyger