Cannot access computer

Discussion in 'Malware Help (A Specialist Will Reply)' started by mongooseba, Oct 4, 2013.

  1. mongooseba

    mongooseba Corporal

    Hi All,

    I have this fearful message from ICM that states that I have to pay $300 to unlock the computer. It even identified my IP address and service provider. I presume my computer has been hacked. What should I do? Cannot run any of the malware etc protocol. This initial screen takes over after logging in. How do I start disinfecting my computer and would appreciate it if I could have some initial steps for Wins 7 Pro.

    Thanks so much and await your assistance.

    Sincerely,
    Mongooseba
     
  2. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Please do the below so that we can boot to System Recovery Options to run a scan. There will be two options to choose from. One if you do not have your Windows 7 boot DVD and another when you have your DVD.

    For x32 (x86) bit systems download Farbar Recovery Scan Tool and save it to a flash drive.
    For x64 bit systems download Farbar Recovery Scan Tool x64 and save it to a flash drive.

    Plug the flashdrive into the infected PC.

    Option1: Enter System Recovery Options from the Advanced Boot Options:

    • Restart the computer.
    • As soon as the BIOS is loaded begin tapping the F8 key until Advanced Boot Options appears.
    • Use the arrow keys to select the Repair your computer menu item.
    • Select US as the keyboard language settings, and then click Next.
    • Select the operating system you want to repair, and then click Next.
    • Select your user account an click Next.

    Option2: Enter System Recovery Options by using Windows installation disc:

    • Insert the installation disc.
    • Restart your computer.
    • If prompted, press any key to start Windows from the installation disc. If your computer is not configured to start from a CD or DVD, check your BIOS settings.
    • Click Repair your computer.
    • Select US as the keyboard language settings, and then click Next.
    • Select the operating system you want to repair, and then click Next.
    • Select your user account and click Next.

    On the System Recovery Options menu you will get the following options:
    • Select Command Prompt
    • In the command window type in notepad and press Enter.
    • The notepad opens. Under File menu select Open.
    • Select "Computer" and find your flash drive letter and close the notepad.
    • In the command window type e:\frst.exe (for x64 bit version type e:\frst64) and press Enter
      Note: Replace letter e with the drive letter of your flash drive.
    • The tool will start to run.
    • When the tool opens click Yes to disclaimer.
    • Press Scan button.
    • It will make a log (FRST.txt) on the flash drive. Please attach this file to your next reply. (See: How to attach)
     
  3. mongooseba

    mongooseba Corporal

    Hi Tim W,

    Tried to enter the system recovery section but it failed with Option 1. It asked for an installation disk. I do not have it and have asked Dell to provide. They will send it out to me on Monday or Tuesday.

    I will then await for the Recovery USB to arrive. I presume I need to go into the BIOS on F2 to reset the boot sequence. Please advise. Thanks.

    Sincerely,
    Mongooseba
    :-o
     
  4. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Yes, hope you get the disc soon.
     
  5. mongooseba

    mongooseba Corporal

    Hi TimW,

    Tried Dell's USB stick and found that it was a recovery program that will wipe off every thing off the hard drive. Informed them that is not what I wanted and Dell will be forwarding me the actual Windows 7 Pro Installation disk. Thanks for your patience.

    Sincerely,
    Mongooseba:-D
     
  6. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    No problem.
     
  7. mongooseba

    mongooseba Corporal

    Hi TimW,

    I finally got the installation disks (Wins 7 Pro). I followed your instructions and could not get the installation disk to work on Recovery Mode. There was an error that mentioned the following:

    "Boot selection failed because a required driver is inaccessible".

    I tried to change the boot sequence to start the installation disk but I'm afraid all it does is to erase my data and start a new install.

    How should I proceed?
    Thanks.

    Mongooseba:-o
     
  8. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    If you can't run the procedures, I am afraid you are stuck. :(
     
  9. mongooseba

    mongooseba Corporal

    Hi TimW,

    Is there a way to activate the recovery mode on the installation disk without a full installation? I am able to boot the original WinPro7 disk.
     
  10. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    I am not familiar enough with Win7 options. I would suggest you ask that in the software forum.
     
  11. mongooseba

    mongooseba Corporal

    Hi TimW,

    Thanks for your reply. I disconnected the internet cable and was able to start the Win7. I tried to run C:\frst.exe but was not able to do so because the command prompt was blocked. Should I refer my problems to software forum?

    Should I download the programs that need to be run on a flash drive and start working on it.

    Thanks.

    Mongooseba
     
  12. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    How far can you get on a boot up? Yes, if you can download the tools to a thumb drive, try to run them.
     
  13. mongooseba

    mongooseba Corporal

    Hi TimW,

    Will try to download the programs on the USB. Any recommendation on AntiVirus? Is Avast all right?

    I did not understand the boot up. I am able to start Windows 7 normally and access in without the pop-up if I disconnect the internet. Did that help?
    Thanks.

    Mongoosebarolleyes
     
  14. mongooseba

    mongooseba Corporal

    Hi TimW,

    I'm making progress. I've installed the Avast Antivirus and it located 3 malware. These were 3ph7arm.exe, ohwao.exe, and soft.exe. All these files were quarantined successfully. Do you want me to remove them?

    Enclosed are the logs that you need.

    It took me some time to get the MGTools to work. It did not run on a particular user that had administrative rights. I also noticed the command prompt box did not work so MGTools failed. I used another administrative account to bypass this. How do I reactivate the cmd function on this user?

    The pop-up did not appear after the preliminary cleanup. I look forward to your advice.

    With much hope.
    Mongoosebarolleyes
     

    Attached Files:

  15. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Double-click RogueKiller.exe to run. (Vista/7 right-click and select Run as Administrator)
    When it opens, press the Scan button
    Now click the Registry tab and locate these detections:


    • [RUN][SUSP PATH] HKUS\S-1-5-21-1303847847-1858039322-440923383-1005\[...]\RunOnce : (cmd.exe /c rd /s /q "C:\Users\PD-XRay3\AppData\Local\Temp\joi6D.tmp" [x][x]) -> FOUND
      [RUN][SUSP PATH] HKUS\S-1-5-21-1303847847-1858039322-440923383-1005\[...]\RunOnce : join.me_joi6D.tmp_cleanup (cmd.exe /c del /f /q "C:\Users\PD-XRay3\AppData\Local\Temp\joi6D.tmp_cleanup.bat" [x][x]) -> FOUND

    Place a checkmark each of these items, leave the others unchecked.
    Now press the Delete button.
    When it is finished, there will be a log on your desktop called: RKreport[2].txt
    Attach RKreport[2].txt to your next message. (How to attach)
    Do not reboot your computer yet.

    Use windows explorer to find and delete:
    C:\ProgramData\3pln7arn

    Now reboot and rescan with RogueKiller and attach that log as well.

    Now run the C:\MGtools\GetLogs.bat file by double clicking on it (Note: if using Vista or Win7, don't double click, use right click and select Run As Administrator).

    Attach the new C:\MGLogs.zip.
     
  16. mongooseba

    mongooseba Corporal

    Hi TimW,

    I completed the tasks and enclosed are the three files that you need.
    Should I clear the quarantined virus chest?
    Thanks.

    Mongooseba:-o
     

    Attached Files:

  17. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Yes, you can empty the quarantine folder. What issues are you still having?
     
  18. mongooseba

    mongooseba Corporal

    Hi TimW,

    I still have problems with the cmd.exe file. It still woould not work with a particular user. Is there a setting that needs to be reconfigured? Otherwise the cmd.exe works on other profiles.

    Thanks.

    Mongooseba
     
  19. mongooseba

    mongooseba Corporal

    Hi TimW,

    Deleted all the viruses in the quarantined chest.
    Thanks.

    Sincerely,
    Mongoosebarolleyes
     
  20. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    You can pursue the cmd issue in the software forum.

    You're welcome.

    If you are not having any other malware problems, it is time to do our final steps:

    1. We recommend you keep Malwarebytes Anti-Malware for scanning/removal of malware.
    2. Renable your Disk Emulation software with Defogger if you had disabled it in step 4 of the READ & RUN ME.
    3. Go to add/remove programs and uninstall HijackThis. If you don't see it or it will not uninstall, don't worry about it. Just move on to the next step.
    4. If running Vista, Win 7 or Win 8, it is time to make sure you have reenabled UAC by double clicking on the C:\MGtools\enableUAC.reg file and allowing it to be added to the registry.
    5. Now goto the C:\MGtools folder and find the MGclean.bat file. Double click ( if running Vista, Win7, or Win 8 Right Click and Run As Administrator ) on this file to run this cleanup program that will remove files and folders related to MGtools and some other items from our cleaning procedures.
    6. Any other miscellaneous tools we may have had you install or download can be uninstalled and deleted.
    7. If you are running Win 8, Win 7, Vista, Windows XP or Windows ME, do the below to flush restore points:
      • Refer to the instructions for your WIndows version in this link: Disable And Enable System Restore
      • What we want you to do is to first disable System Restore to flush restore points some of which could be infected.
      • Then we want you to Enable System Restore to create a new clean Restore Point.

    8. After doing the above, you should work thru the below link:




    Malware removal from a National Chain = $149
    Malware removal from MajorGeeks = $0
     
  21. mongooseba

    mongooseba Corporal

    Hi TimW,

    Followed your steps and did the disable and enable system restore. I disabled it first and deleted the previous restore points. I then reenabled the "restore systems settings and previous versions of files". Did I do it correctly?

    Much appreciated.

    Mongooseba:-D
     
  22. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Yes, you did fine. ;)
     
  23. mongooseba

    mongooseba Corporal

    Hi TimW,

    All is well with the computer and every one is happy. You saved the day again with your expertise. Thank you for all your assistance and patience.

    Regards,
    Mongooseba:):):)
     
  24. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    You are most welcome.
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds