Boot issues/ransomware

Discussion in 'Malware Help (A Specialist Will Reply)' started by E1wood, Nov 27, 2013.

  1. E1wood

    E1wood Private E-2

    Hi,

    I think i have contracted a ransomware virus (metropolitan police etc etc). I tried to boot into safe mode/ repair windows and that just caused the machine to go dead.

    The machine will not even get to the safe mode selection screen now. It shows the bios screen and then goes to windows boot manager, and asks me to insert an installation disk for windows. Unfortunately I do not have a copy of this disk.

    Any advice or help would be most welcome.

    Thanks

    Elwood
     
  2. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    Hi there. :)

    What operating system is this please?
     
  3. E1wood

    E1wood Private E-2

    Sorry, forgot to mention that this is Windows 7
     
  4. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    http://img827.imageshack.us/img827/1263/frst.gif For 32-bit (x86) systems download Farbar Recovery Scan Tool and save it to a flash drive.
    For 64-bit (x64) systems download Farbar Recovery Scan Tool x64 and save it to a flash drive.

    Plug the flashdrive into the infected PC.

    Enter System Recovery Options.

    To enter System Recovery Options from the Advanced Boot Options:
    • Restart the computer.
    • As soon as the BIOS is loaded begin tapping the F8 key until Advanced Boot Options appears.
    • Use the arrow keys to select the Repair your computer menu item.
    • Choose your language settings, and then click Next.
    • Select the operating system you want to repair, and then click Next.
    • Select your user account and click Next.

    To enter System Recovery Options by using Windows installation disc:

    • Insert the installation disc.
    • Restart your computer.
    • If prompted, press any key to start Windows from the installation disc. If your computer is not configured to start from a CD or DVD, check your BIOS settings.
    • Click Repair your computer.
    • Choose your language settings, and then click Next.
    • Select the operating system you want to repair, and then click Next.
    • Select your user account an click Next.
    On the System Recovery Options menu you will get the following options:
    • Select Command Prompt
    • In the command window type in notepad and press Enter.
    • The notepad opens. Under File menu select Open.
    • Select "Computer" and find your flash drive letter and close the notepad.
    • In the command window type e:\frst.exe (for x64 bit version type e:\frst64) and press Enter
    • Note: Replace letter e with the drive letter of your flash drive.
    • The tool will start to run.
    • When the tool opens click Yes to disclaimer.
    • Press Scan button.
    • It will make a log (FRST.txt) on the flash drive. Please attach this log to your next reply. (How to attach)
     
  5. E1wood

    E1wood Private E-2

    I have downloaded the scan tool, but I am unable to get to the System Recovery Options. If I press F8 during the bios, it asks me what device to boot from. If I select the flash drive with the scan tool, the screen just goes black.

    If I do not press F8 during the bios, it tells me it has failed to start and that I should insert the installation disk.

    Thanks
     
  6. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    Where I have bolded out the type, do you not see that "repair your computer" anywhere?
     
  7. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

  8. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    Thanks Chas, nice link. :)
     
  9. E1wood

    E1wood Private E-2

    Unfortunately I don't see anything like step 3 in Chas' link.
     
  10. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    So you do not see the Advanced Boot Options screen? :confused (under step 3 of chas' link)
     
  11. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    It means the Recovery Environment was not installed on this PC. A Windows 7 Boot DVD will be needed or possibly the Kaspersky CD can be used as with Win XP.
     
  12. E1wood

    E1wood Private E-2

    Windows Vista came pre installed on the machine and I have the upgrade disk for windows 7 (home premium 64bit). Should I try booting with this disk inserted?

    Thanks
     
    Last edited: Dec 2, 2013
  13. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

  14. E1wood

    E1wood Private E-2

    I have downloaded the file, and can get into the kaspersky gui briefly (after a few seconds it goes black and I need to recreate the usb file from scratch in order to boot again).

    When I go to Terminal and try to start windowsunblocker, it says that the files don't exist (or something similar, there isn't much time to read ) before everything goes black and I have to start again.
     
  15. E1wood

    E1wood Private E-2

    I have also created a cd with the kaspersky unlocker. The same thing has happened as with the usb. It booted into the gui the first time and windowsunlocker could not be found.

    When I try a fresh reboot with the same cd, the screen goes black before the gui is loaded and does not recover.

    I'm starting to feel like this thing is learning from me...
     
  16. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    Seeking advice. Hang in there. :)
     
  17. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    One thing you could try would be to slave the hard disk onto another PC and see if any of the scans can find anything. This could also serve to allow important data to be backed up since you could be heading towards a reinstall/reimage.
     
  18. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Check this disk to see if you can boot from it. If not, do you have a friend with a WIn 7 Boot DVD?
     
  19. E1wood

    E1wood Private E-2

    I tried to boot from the disk and I have had differing results for different attempts (I think i did everything the same ech time). Most of the attempts (4out of 5 so far) all started to boot from dvd, got to a screen saying " windows is loading files " with a progress bar that almost filled before the screen went black and nothing further happened.

    The other attempt got further, showed the windows boot screen and gave me some options (radio buttons in dialogue boxes in a gui not text selection on black screen), one of which was repair windows. Selecting this flashed up a message (something along the lines of insert final repair disk or image to restore) before the screen went black and everything stopped again.

    I have looked through my old disks and have two other disks associated with this machine
    A vista "external recovery " disk
    What i believe to be a backup disk created sometime after the upgrade to windows 7 (I think) but of unknown time (probably a couple of years ago). This was created from an app preinstalled on the desktop by the supplier.
     
  20. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    You need to get a real Windows 7 Boot DVD from a friend if they have one so that you can see things like in the below:

    http://www.sevenforums.com/tutorials/668-system-recovery-options.html


    If your discs are not the correct ones, find a friend with a Windows 7 x64 PC and create the disc as in the below to try it to get to the Recovery Options screen:

    http://pcsupport.about.com/od/windows7/ht/system-repair-disc-windows-7.htm



    Your other choice would be to reinstall but if you do not have anything but an upgade disk, you may have to reinstall Vista ( if you have full reinstall disks for it or the factory recovery disks ) and then upgrade to Win 7 again.
     
  21. E1wood

    E1wood Private E-2

    I have tried with a friends boot dvd. Broadly similar results. The first time it got part of the way through the boot process into windows but got stuck on a message along the lines of c/boot corrupt when I tried to repair (i didn't copy down the exact message).

    Subsequent attempts didn't even get that far and just refused to boot into the windows dvd at all.

    I don't really understand why I get different results for different attempts.
     
  22. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Sorry but it does not look like we are going to be able to help you! Your problems are beyond malware. If you cannot even boot up the Windows DVD then something is physically wrong with either your mother board or your DVD drive. Booting the Windows DVD does not boot to Windows. It should boot you from the DVD to the type of screens we linked you to previously. If you are not getting those screens then perhaps you are not booting from the DVD but rather are still trying to boot from your hard disk.

    Are you 100% sure that you changed the BIOS boot order to boot from CD first and that you are booting from the DVD? If yes then you should either request help in the Software Forum for problems with this or you should just bite the bullet and reinstall from scratch. Not sure if you can even do that though if your DVD drive does not work properly. Perhaps you have a Factory Recovery partition on your hard disk that you can reimiage your drive from ( assuming your hard disk has not failed ).
     
  23. E1wood

    E1wood Private E-2

    Thanks for all your help so far. In the end I took the PC to a local repair professional and he got it up and running again. In case it helps anyone else, what he did was take out the hard drive and run check disk on it from another machine. This allowed it to boot and from there he could remove the virus.

    I have run the "Read and Run Me First" list. Please can you check that I am now infection free?

    I have noticed two issues (that I am not sure are related to malware or not) that are new:
    - I cannot save files to the C directory (I can save to sub folders). I am running as Administrator, and it allowed me to copy paste the MGTools from a different directory.
    - iTunes will not import (or play) CDs (it recognises the tracks, but crashes if you try to play the CD)

    Thanks again for your help, this hasn't been an easy one!
     

    Attached Files:

  24. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Yes this is something we will sometimes recommend to people if we know they have another PC and have the ability/knowledge to slave the drive into another PC.

    No! You are running as the user Jake who is a member of the administrator user group which is not the samething. ;)

    Can be quite normal for the permissions in Windows 7. Sometimes you cannot download directly to the root folder, but you can download to the Desktop which is why our procedures also give you this option.

    Not a topic for this forum as it is not a malware problem. Try uninstalling and then reinstalling iTunes. If that does not help, please post in the Software Forum.

    You have a little bit of junkware to remove.

    Copy the bold text below to notepad. Save it as fixme.reg to your desktop. Be sure the "Save as" type is set to "all files" Once you have saved it double click it and allow it to merge with the registry.
    Make sure that you tell me if you receive a success message about adding the above
    to the registry. If you do not get a success message, it definitely did not work.

    Now please download Junkware Removal Tool to your desktop.
    • Shut down your protection software now to avoid potential conflicts.
    • Run the tool by double-clicking it. If you are using Windows Vista or Seven, right-mouse click it and select Run as Administrator.
    • The tool will open and start scanning your system.
    • Note: That JRT may reset your home page to a google default so you will need to restore your home page setting if this happens.
    • Please be patient as this can take a while to complete depending on your system's specifications.
    • On completion, a log (JRT.txt) is saved to your desktop and will automatically open.
    • Attach JRT.txt to your next message.
     
  25. E1wood

    E1wood Private E-2

    Sounds like I need to learn more about user groups and administrators!

    I have run the Regedit4 and got a success message.

    I have attached the JRT log.

    Thanks

    Elwood
     

    Attached Files:

    • JRT.txt
      File size:
      5.5 KB
      Views:
      1
  26. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Looks good.


    If you are not having any other malware problems, it is time to do our final steps:
    1. We recommend you keep Malwarebytes Anti-Malware for scanning/removal of malware.
    2. Renable your Disk Emulation software with Defogger if you had disabled it in step 4 of the READ & RUN ME.
    3. Go to add/remove programs and uninstall HijackThis. If you don't see it or it will not uninstall, don't worry about it. Just move on to the next step.
    4. If running Vista, Win 7 or Win 8, it is time to make sure you have reenabled UAC by double clicking on the C:\MGtools\enableUAC.reg file and allowing it to be added to the registry.
    5. Now goto the C:\MGtools folder and find the MGclean.bat file. Double click ( if running Vista, Win7, or Win 8 Right Click and Run As Administrator ) on this file to run this cleanup program that will remove files and folders related to MGtools and some other items from our cleaning procedures.
    6. If we had you download any registry patches like fixme.reg or fixWLK.reg (or any others) and running MGclean.bat did not remove them, you can delete these files now.
    7. Any other miscellaneous tools we may have had you install or download can be uninstalled and deleted.
    8. If you are running Win 8, Win 7, Vista, Windows XP or Windows ME, do the below to flush restore points:
      • Refer to the instructions for your WIndows version in this link: Disable And Enable System Restore
      • What we want you to do is to first disable System Restore to flush restore points some of which could be infected.
      • Then we want you to Enable System Restore to create a new clean Restore Point.
    9. After doing the above, you should work thru the below link:
     
  27. E1wood

    E1wood Private E-2

    Thanks, that is great, your help is really appreciated.
     
  28. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    You're welcome. Surf safely!
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds