Ransomware

Discussion in 'Malware Help (A Specialist Will Reply)' started by jimpeel, Mar 15, 2011.

  1. jimpeel

    jimpeel Sergeant

    I have the antivirus ransomware "virus". I know how to kill it ... on an XP unit.

    Unfortunately, the unit it is on is a Windows 7 Home Premium unit.

    I need to know how in the h--- one gets the unit into safe mode. Once I am there I can fix this thing.

    Any help is appreciated.

    j
     
  2. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    Usually done by tapping F8 during start up. Is that not working for you?
     
  3. jimpeel

    jimpeel Sergeant

    Not at all. I tapped it every second through the entire startup and all it did was to start normally.
     
  4. jimpeel

    jimpeel Sergeant

    I tried holding the F8 key down through the entire setup and that didn't seem to work. I then restarted the thing and up popped the safe mode window so I was able to get into safe mode. I just haven't the foggiest idea of how I did it.
     
  5. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

  6. jimpeel

    jimpeel Sergeant

    Thank you. I already have all of that information and this is a ransomware that I am quite familiar with. I have removed it from several computers, some more than once.

    The common theme is these people all download music from download sites like iTunes, etc.

    My problem this time is that the computer has Windows 7 as the OS. I haven't much experience with Win7.

    How I managed to get into safe mode is beyond me but I am now running Ccleaner, Malwarebytes, Spybot, and SuperAntiSpyware. That has always cured the problem in the past. One simply cannot run any of the cleanup programs unless they are in safe mode because this malware will not let anything run. It also has false internet windows that it puts up, some of which are pornographic.

    Thanks.

    j
     
  7. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    Not to worry, as we can help with that. Attach logs when you are ready.
     
  8. jimpeel

    jimpeel Sergeant

    I was able to get into safe mode by happenstance. Can you tell me how that is done on a Win7 computer? I honestly do not know how I did it.

    I am in the process of cleaning the malware off of the computer. I am already able to boot into normal mode without incident.

    Thanks,

    j
     
  9. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    As I said, by tapping the F8 key.

    Getting into Windows Safe Mode.
    Attach logs when you are ready. :)
     
  10. jimpeel

    jimpeel Sergeant

    I tried "tapping" and that did not work. I tapped it every second throughout the entire boot process as I posted earlier.

    What seemed to work, which I also cited in a later post, was the instruction at http://windows.microsoft.com/en-US/windows7/Start-your-computer-in-safe-mode which stated:

    I did that BUT it still booted into the normal mode. I held the F8 key so long that my finger got tired and I had to change fingers; but here's the kicker. After it booted completely I then restarted it and lo and behold the selection window appeared which finally allowed me to boot into safe mode. I still have no idea how this process is supposed to work. As I stated prior, I managed this by happenstance, not by design.

    Yes, tapping the F8 key while booting into an XP OS works just swimmingly. This was my first excursion into the ethereal world of Win 7. Tapping simply didn't work. I tried several times to no avail. There has to be another set of rules for Win 7.

    I was able to get into safe mode, load and run the programs necessary to kill the malware, and the malware was successfully removed. This is a simple bug to kill and I have done it many times. I still don't know how I finally managed to get into the mode necessary to kill it. It was simply dumb, blind luck.

    Thanks for your help.

    j
     
  11. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    Hi there. Just to say, are you going to attach logs or not? If not then I can close the thread. :)
     
  12. jimpeel

    jimpeel Sergeant

    I'm sorry. Perhaps I have not been clear.

    The unit in question had malware (ransomware) which is quite common on machines which are used for music downloads.

    I know how to kill the malware; but before that can be done the infected unit has to be booted into safe mode.

    I am familiar with how to boot a unit with XP into safe mode but not a unit which has Win 7 as the OS. That is where I needed the help.

    I was able to finally boot the infected unit into safe mode and the infection has been removed pursuant to the READ & RUN ME FIRST. Malware Removal Guide which I am quite familiar with.

    There is no need to attach log files as the problem was always within my grasp to solve. Log files would also not tell us how I managed to get to safe mode. I followed instructions -- yours and Microsoft's -- and neither seemed to be much help. The unit kept booting into normal mode regardless of my efforts.

    It was only after I had tried one of the methods that it finally went to the proper screen, and that only after I restarted the machine. It did so on its own without any help on my part. It was all very strange.

    You may close the thread.

    PROBLEM SOLVED.

    Thank You.

     
  13. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Just an FYI for future reference. The safe boot mode registry keys sometimes get corrupted. It may occur due to malware or it may not be due to malware. Sometimes an easy fix is to repair the safe boot registry key. A manual registry patch can attempt to do this, but there is also a set of many builtin repair functions to SUPERAntiSpyware that you should take a look at the could come in handy. They include a fix for Safe Boot Mode. This does not mean that this would have definitely fixed your problem this time. There could be other reasons for inability to boot in safe mode than the registry key problem.
     
  14. jimpeel

    jimpeel Sergeant

    I was unaware that there is a registry key for that. Can you tell me what that key is and what the normal settings should be? I can then check that against the subject computer to see if it has a problem.

    I am using the free version of SUPERAntiSpyware; but I have the paid version on my wife's laptop. I will check out the repair options to see what they are and how they work.

    Thanks,

    j
     
  15. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    It is quite a long key ( HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot ). Not sure if it has exactly all the same parameters for Win 7 vs WinXP but they probably are. You can see defaults values in the C:\MGtools folder created by running MGtools. You will see a FixSBM.bat file which can be used to repair this key. It does this by loading the fixSBM.reg patch. What SUPERAntiSpyware does may be exactly the same.

    You don't need the paid version to use this fix. It is in the free version.

    If you did not have to repair this registry key and then just got into safe mode without making a fix then your problem was not this registry key. Some people just have problems getting into safe mode, hitting the key sequence is problematic for some people and sometimes it could also be some other non-malware problem with Windows having nothing to do with this key. If it is intermittant, like in your case then it was most likely not malware nor was it the registry key.
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds