I've been trying to remove some Ransomware from a friends PC for about 24 hours now with little luck so I'm hoping someone might have a solution that I haven't thought of or found anywhere else.
The Ransomware is the typical "This is the Police, you've been a naughty boy so give us some money" rubbish. It appears we Windows starts up and can't be closed with Alt-F4, and task manager just gets hidden if you try and run it.
Obviously, I would normally boot up in Safe Mode and then remove the Malware, but when Windows starts in Safe Mode, it just gives the message shutting down, and the machine restarts before anything can be done.
I followed the instructions in BleepingComputer to remove Ransomware using a Kapersky rescue disk, but for some reason it is refusing to work in graphical mode (it gives a "File Exists" error). Text mode worked and after giving it 8 hours to scan the machine, the Ransomware was still there!
I also tried doing a System Restore by going into the Windows Repair Mode, but that failed with an unspecified error (0x8000ffff). Someone suggested this may be down to corrupted files so I used the Command Prompt to run chkdsk /r
And that's where I've got to.
My next plan, assuming that system restore won't work and even if it does I'm not sure it will get me to a state where I can get into Windows to fix it properly, was to use the command prompt, and use
wmic startup get caption,command
in order to see if I can find and delete the program which is giving me grief.
If anyone can suggest a better method, I'd love to hear it.
Edited by hamluis, 21 April 2013 - 10:50 AM.
Moved from Win 7 to Am I Infected - Hamluis.