Mod Edit: moved to better forum for assistance wit this ~~ boopme
Need help with FBI ransomware virus that affects regular mode and safemode. I see there is a post for that with some instructions, but I have a twist and am looking for assistance.
I am a former H/W service tech with limited experience in dealing with S/W and viruses.
A totally PC non-technical friend who lives out in the boonies 250 miles away is no where near any tech services, so he called me to help. I have alsways been able to help him before and I feel ignorant when dealing with this issue he came up with this time. He called me to help him remove the FBI ransomware that had locked up his computer with Windows XP Professional that had also affected safemode. I worked with him over the phone as we tried what I knew (no go), so then I started to research it on the internet.
I had him use another PC to download Hiren's Boot CD and he followed the instructions I found to fix it. It did remove a little bit of things, but continued to lock up when he he booted up. Safemode with command prompt did not allow him to use rstrui.exe to restore it to a known previous restore point. He has a backup on CD from the end of December, but nothing recent. The hard drive came preloaded with Windows XP Pro from the manufacturer and they did not give him his Windows CDs wehn he bought it, so formatting and reloading Windows and the rest of his programs from CDs is not possible.
In frustration, I asked him to send me the hard drive and told him I would work on it. I am now very sorry I volunteered to do this, but now that I have it, I need to get it cleaned up somehow and get it back to him. I have it connected to my desktop PC via an external HDD connector that connects it to a USB port. I booted up to my hard drive that is running fully updated Win XP with SP3, and ran MalwareBytes and Norton Antivirus on his drive from my C drive. It found and removed one thing, Trojan.Maljava, but I have found nothing that links that to the FBI virus, so I doubt the FBI virus was removed.
Is there a way for me to remove the FBI virus on his bad drive while using my PC? Once done with it, I will have to mail the drive back to my friend.
Thanks in advance!
Edited by boopme, 03 May 2013 - 04:00 PM.