United States Department of Justice Ransom-ware

Discussion in 'Malware Help (A Specialist Will Reply)' started by Dollphinea, Jul 31, 2013.

  1. Dollphinea

    Dollphinea Private E-2

    Hi There,

    I have this malware on my sister's laptop which is an HP Pavilion running Windows 7, 64-bit software. At first, she said it was just showing the ransom screen with the pic it took, but I was able to run it in safe mode and sign on under different users other than the administrator today.

    After reading previous posts, I was able to run the Farbar Recovery Scan Tool and have attached the frst.txt. Would really appreciate your guys help for the next steps. I understand after this that I should still do the RUN & READ ME STEPS to make sure all is good.

    Thank you in advance for your help with this matter.
    You guys are great!! ;)
     

    Attached Files:

  2. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Save fixlist.txt to your flash drive.

    • You should now have both fixlist.txt and FRST.exe on your flash drive.

    Now reboot back into the System Recovery Options as you did previously.
    Run FRST and press the Fix button just once and wait.
    The tool will make a log on the flashdrive (Fixlog.txt).
    Please attach this to your next message. (See how to attach)

    Now boot into normal Windows can continue with the below.

    Running MGTools.
     

    Attached Files:

  3. Dollphinea

    Dollphinea Private E-2

    Hi Tim, :wave

    Thank you so much for responding. Attached is the next message I received after the fixlist.txt. I am running the MGTools now and will post that when complete.

    Doll ;)
     

    Attached Files:

  4. Dollphinea

    Dollphinea Private E-2

    I tried rebooting on to the software and the Ransom-ware was back and locked me up. Tried getting into the flash drive where I put the MGTools on it to transfer it to the C drive and could not. Should I rerun the fixlist.txt ? I am not sure what to do now??

    Thanks again.
     
  5. Dollphinea

    Dollphinea Private E-2

    I reran the farbar and attached the txt doc again just in case you need it. ;)
     

    Attached Files:

  6. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Hang in there. I need to consult my colleagues.
     
  7. Dollphinea

    Dollphinea Private E-2

    Im hanging in there...any news yet on how to proceed? ;)
     
  8. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    You need to run my fix as posted.

    Save fixlist.txt to your flash drive.

    • You should now have both fixlist.txt and FRST.exe on your flash drive.

    Now reboot back into the System Recovery Options as you did previously.
    Run FRST and press the Fix button just once and wait.
    The tool will make a log on the flashdrive (Fixlog.txt).
    Please attach this to your next message. (See how to attach)

    Now boot into normal Windows can continue with the below.

    Running MGTools.
     

    Attached Files:

  9. Dollphinea

    Dollphinea Private E-2

    Did that before but will try it again with this one and post again.
     
  10. Dollphinea

    Dollphinea Private E-2

    Okay downloaded file from you and had to change name for the fix to work. Ran it and please find attached the fixlog.txt. On to the MGTools wish me luck. :)
     

    Attached Files:

  11. Dollphinea

    Dollphinea Private E-2

    Okay I was able to run the MGTools and have attached the zip file. Also, wanted to let you know of a few issues while running this.

    1. I was using the USB flash drive and working off my computer previously. When I tried to copy the MGTools.exe from the USB to the C: drive the laptop(the one we are fixing) will not recognize the USB drives...it only recognized it during the system repair. But I was able to sign on the internet and download the exe file and use it.

    2. When I tried turning off the screen saver while the MGTools was running it said that my dll file was missing and will not allow me to adjust that.

    3. Other dll files were missing at first and wouldn't allow me to run notepad and a few other files, however this seems to be intermittent, so hopefully these next steps will fix them.

    I await your next instructions.
    Thanks for your continued help! :)
     

    Attached Files:

  12. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    You need to run CCleaner to clear out your temp folders.

    Now, let's do the below incase any system files were corrupted:

    Download Windows Repair by Tweaking.com and unzip the contents into a newly created folder on your desktop.

    • Now run Repair_Windows.exe by double clicking on it ( if you are running Vista or Win 7, use right click and select Run As Administrator)
    • Now select the Start Repairs tab.
    • The click the Start button.
    • Create a System Restore point if prompted.
    • On the next screen, click the Unselect All button to first deselect all repairs.
    • Now select the following repair options:
      • Reset Registry Permissions
      • Reset File Permissions
      • Register System Files
      • Repair WMI
      • Repair Windows Firewall
      • Remove Policies Set By Infections
      • Repair Winsock & DNS Cache
      • Repair Proxy Settings
      • Repair Windows Updates
      • Set Windows Services To Default Startup

    • Now on the lower right side check the box to Restart/Shutdown System When Finished
    • Then make sure the Restart System radio button is enabled.
    • Shutdown any other programs that you are running now before continuing.
    • Now click the Start button.
    • Be patient while the tool repairs the selected items.
    • It should reboot automatically when finished.


    Be sure to tell me how things are running now. Your logs are clean.
     
  13. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Actually you did not run the fix TimW gave you last time. You ran someone else's fix. It is quite obvious from the first fixlog.txt file that you did not run the fix TimW gave you. ;) The user accounts being shown are not even on your PC and nothing in that log was in the fix you had been given.
     
  14. Dollphinea

    Dollphinea Private E-2

    :-o Oh really my mistake then...I did download someones post at first but after further reading..realized i needed to post my own problem and so when Tim gave me the first attachment I must have copied the wrong file from to the USB... Doh!! :foolish Thanks for the clarification.
     
  15. Dollphinea

    Dollphinea Private E-2

    What about issue #2...any idea on that?

    Will run the CCleaner & Windows repair and let you know that feedback and I plan on doing the whole run & read me process afterwards as well...that always helps!

    Thanks much!!
     
  16. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Let me know how things are running after doing all that. We may need to send you to the software forum for further assistance with your screen saver issue.
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds