UKash Ransomeware

Discussion in 'Malware Help (A Specialist Will Reply)' started by trogladyte, Dec 26, 2012.

  1. trogladyte

    trogladyte Private E-2

    Happy Xmas guys.

    It's a long shot that anyone will have time to help me right now, but here goes.

    My Father's Vista PC has the Metropolitan Police Ukash ransomeware. It has locked him out completely. He is not at all computer literate, and is totally freaked. He lives 150 miles away, but I am going there tomorrow. I will be there for 24 hours, and need to get him up an running in that time.

    Can anyone tell me what I should take with me? I'll be taking my own Vista laptop, and my Linux laptop, but are there any tools I should download now and have ready on USB or CD?

    And any clues as to where I should start when I get there will e really helpful!
     
  2. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    First, see if he can boot to safe mode. From there, try a system restore. If that doesn't work, you will need to try doing these instructions:

    Please do the below so that we can boot to System Recovery Options to run a scan. There will be two options to choose from. One if you do not have your Windows 7 boot DVD and another when you have your DVD.

    For x32 (x86) bit systems download Farbar Recovery Scan Tool and save it to a flash drive.
    For x64 bit systems download Farbar Recovery Scan Tool x64 and save it to a flash drive.

    Plug the flashdrive into the infected PC.

    Option1: Enter System Recovery Options from the Advanced Boot Options:
    • Restart the computer.
    • As soon as the BIOS is loaded begin tapping the F8 key until Advanced Boot Options appears.
    • Use the arrow keys to select the Repair your computer menu item.
    • Select US as the keyboard language settings, and then click Next.
    • Select the operating system you want to repair, and then click Next.
    • Select your user account an click Next.
    Option2: Enter System Recovery Options by using Windows installation disc:
    • Insert the installation disc.
    • Restart your computer.
    • If prompted, press any key to start Windows from the installation disc. If your computer is not configured to start from a CD or DVD, check your BIOS settings.
    • Click Repair your computer.
    • Select US as the keyboard language settings, and then click Next.
    • Select the operating system you want to repair, and then click Next.
    • Select your user account and click Next.
    On the System Recovery Options menu you will get the following options:
    • Select Command Prompt
    • In the command window type in notepad and press Enter.
    • The notepad opens. Under File menu select Open.
    • Select "Computer" and find your flash drive letter and close the notepad.
    • In the command window type e:\frst.exe (for x64 bit version type e:\frst64) and press Enter
      Note: Replace letter e with the drive letter of your flash drive.
    • The tool will start to run.
    • When the tool opens click Yes to disclaimer.
    • Press Scan button.
    • It will make a log (FRST.txt) on the flash drive. Please attach this file to your next reply. (See: How to attach)
     
  3. trogladyte

    trogladyte Private E-2

    Hi Tim. I have managed a system restore from safe mode. I now have access to the machine in normal mode. Norton went a bit mental performing a fix and now thinks it is cool. Where should I go from here to ensure we are clean?
     
  4. trogladyte

    trogladyte Private E-2

    Tim. I suppose you are busy. I am proceeding with the standard malware removal process. I have downloaded all the tools except MG Tools. This tells me that I do not have permission to save in that location (root of C: drive). Is there a way to give myself administrator privileges, or do I just need to save it somewhere else?

    Thanks so much for helping.
     
  5. trogladyte

    trogladyte Private E-2

    Tim

    RK report hopefully attached. Am now going to run MWB.
     

    Attached Files:

  6. trogladyte

    trogladyte Private E-2

    MWB didn't find anything. Log attached.
     

    Attached Files:

  7. trogladyte

    trogladyte Private E-2

    TDSSKiller didn't find anything. Log attached.
     

    Attached Files:

  8. trogladyte

    trogladyte Private E-2

    And finally, Hitman Pro. Can't run MG tools without your advice (see above). Would be good to hear what you make of the logs. Only RK appears to have found something.

    Hitman Pro log attached.

    Thanks again.
     

    Attached Files:

  9. trogladyte

    trogladyte Private E-2

    Well, I've now re-booted and the machine appears to be working normally. Will be out for a few hours this evening, but will keep an eye here for your reply. Would like to leave here tomorrow confident that the machine is clean.

    Thanks for your help.
     
  10. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    I just got in from digging out of a snow storm from the other night. Sorry for the delay, but I will look at your logs as soon as.......in the meantime, just download MGTools to your desktop and run it from there. Disable any AV software before you run it.;)
     
  11. trogladyte

    trogladyte Private E-2

    Thanks Tim. Hope you are out of the snow now!

    MGTools ran, but threw multiple errors saying that it couldn't create the MGlog.zip file.

    It reported the file was there at the end, and a copy was on the desktop, but there was no such file.

    I will only be here until about 11am GMT tomorrow. After that any further action would mean coaching my Dad through it, and that could be...challenging.

    In the mean-time, normal Windows functionality appears to be restored.
     
  12. trogladyte

    trogladyte Private E-2

    I've manually zipped all the .txt files in the MGtools directory. Hope this is what you need. Otherwise, please shout.
     

    Attached Files:

    • HJT.zip
      File size:
      184.1 KB
      Views:
      2
  13. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Ok, we're pretty much done. Just a few things to clean up.

    Use windows explorer to find and delete:
    C:\ProgramData\sfbpdjrechcojhr
    C:\ProgramData\zrnmmaptkojbgsd

    Now copy just the bold text below to notepad (Do not include any space above the word REGEDIT). Save it as fixME.reg to your desktop. Be sure the "Save as" type is set to "all files" Once you have saved it double click it and allow it to merge with the registry.
    Make sure that you tell me if you receive a success message about adding the above
    to the registry. If you do not get a success message, it definitely did not work.


    Let me know if he is having any other issues.
     
  14. trogladyte

    trogladyte Private E-2

    Many thanks indeed Tim.

    Sadly, I am now four hours drive away from the machine. Will it be safe to leave these final steps for a few weeks, or is it critical that I embark on the very considerable challenge of getting my elderly father to do it?
     
  15. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    The instructions are fairly simple. He should be able to carry them out. Let me know if he has issues with it.
     
  16. trogladyte

    trogladyte Private E-2

    I'm afraid I haven't managed to get my Dad to do this. You can't quite imagine how hesitant he is, and it's hard over the phone - he is 90, so I suppose he has an excuse.

    Could I perhaps send him the regedit text as an e-mail attachment, so he could just copy the whole document to his desktop, and run it?
     
  17. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Yes, save it as a text file ( use notepad ) and attach it to an email. Have him save the attachment to his desktop and then he only needs to click on it. Is he having any issue finding and deleting the two folders?
     
  18. trogladyte

    trogladyte Private E-2

    Thanks Tim. I haven't actually attempted that with him yet. I gave up when we failed on the cut and paste from the web page. I am guessing he can just type those file names into the search box, and then delete.
     
  19. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    No! That could prove disasterous.. something valid could end up killed. Be careful. Text file attachment in email is best way to go.
     
  20. trogladyte

    trogladyte Private E-2

    Hi Kestrel13 - Tim wanted to delete a couple of folders as well as registry edit - that's what i was referring to with the search and delete.

    I've sent the text file, and I'll be trying to get him to run it this evening. Fingers crossed.
     
  21. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    Good, best ot be safe and check! :)
     
  22. trogladyte

    trogladyte Private E-2

    Hi Tim
    Tried the e-mail attachment. Windows mail blocked it to start with, so I renamed the file and then changed it back. We got it onto the desktop, but when he double clicked it the message was "Windows cannot access the specified device, path, or file. You may not have the appropriate permissions to access the item."

    Any thoughts?
     
  23. trogladyte

    trogladyte Private E-2

    Any ideas guys?
     
  24. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    They aren't major concerns, but I guess you will have to wait until you can gain access to the computer again.
     
  25. trogladyte

    trogladyte Private E-2

    Thanks for your help, Tim. I really appreciate it.
     
  26. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Not a problem. ;)
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds