Free Republic
Browse · Search
News/Activism
Topics · Post Article

To: Spirit of Liberty

A freeper on this thread explained how he got out of it in a comment, it had to do with restarting his computer in safe mode.

I had a problem on my last computer with the flash player plug in to IE browser.

It caused Norton to issue a ‘Norton intercepted and deleted a dangerous Trojan virus file’ alert popup every time I went to a new address with IE. Even my home page triggered it.

It was very frustrating and took a while for me to figure out what was causing it. I did the safe mode reboot for that.


101 posted on 12/26/2013 5:49:33 PM PST by sickoflibs (Obama : 'If you like your Doctor you can keep him, PERIOD! Don't believe the GOPs warnings')
[ Post Reply | Private Reply | To 100 | View Replies ]


To: sickoflibs; Spirit of Liberty

One method of tackling the problem is to bott into Safe Mode, restore to an uncontaminated Safe Point, reboot, and then use Malwarebytes and/or other malware removal tools to cleanup the malware. Unfortunately, some variants of Ransomware hide on the computer’s hard drive and/or BIOS/EUFI and restores itself after the cleanup, so when you go to boot the computer the next time or some later time the ransomware disables the computer even more by disabling Safe Mode. The computer either goes into a full boot and presents the ransomware message, or the computer cannot be booted into the operating system.

The next step is to use the BIOS setup utilities or another computer that can deal with malware infections to reformat the hard drive and reinstall the operating system. This will often remove the malware for awhile. However, in some instances the ransomware even managed to restore itself immediately after the hard drive had been reformatted and the operating system was reinstalled. Presumably, it did so by hiding enough code on a hidden sector of the hard drive not affected by the reformatting or in the system BIOS/EUFI to bootstrap itself back into the reinstalled operating system. The next attempt to remove this ransomware on these systems resulted in the ransomware blocking any and all efforts to bott the computer at all, whether it was to a full boot, boot to Safe Mode, or a boot to the system BIOS/EUFI.

The next step which has not yet been attempted is to use another used hard drive I can afford to lose and install it as a new hard drive on one of the affected computers. If the ransomware was hidden on an inaccessable area of the original hard drive, replacing the hard drive should be effective in removing the ransomware. However, if the ransomware is hidden in a corrupted BIOS/EUFI, I can expect to see the ransomware infect the replacement hard drive as well and hijack the operating system again, if it will allow the boot process to get even that far.

Your computer is probably repairable by reformatting the hard drive or at least by replacing the hard drive. But don’t be too surprised if you should be unlucky enough to have encountered one of the more vicious and persistent of the ransomware variants. In the worst case scenario with an infection of the BIOS/EUFI, you’ll have to find a means of restoring an uninfected BIOS/EUFI or abandon the ssytem board.


102 posted on 12/27/2013 6:49:20 AM PST by WhiskeyX ( provides a system for registering complaints about unfair broadcasters and the ability to request a)
[ Post Reply | Private Reply | To 101 | View Replies ]

To: sickoflibs
I got this after reading the original thread post and later trolling sports boards. It grabbed my browser and took over after restart. I brought up the task manager *, closed Firefox and then ran SUPERantiSpyware Free Edition. Worked just fine taking out this trash.

Haven't had to do this for a while but I once had some rather nasty malware that even took over during attempts to run the safe mode. Searches led me to this,

* Bring up Task Manager as soon as the computer will let you during startup. To do this, hold down Ctrl-Alt- and only just tap on the Del key. Holding the Del key down will restart the computer. Next you have to be quick with this. Try to identify the bad process. Many malwares have a letter + number combo. Highlight the bad process and hit the End Process button at the bottom right of the task manger box. May take a few tries. This should allow one to run junk removal programs. If you don't, most likely the malware will show back up after restart.

111 posted on 12/29/2013 6:51:27 AM PST by Hillarys Gate Cult (Liberals make unrealistic demands on reality and reality doesn't oblige them.)
[ Post Reply | Private Reply | To 101 | View Replies ]

Free Republic
Browse · Search
News/Activism
Topics · Post Article


FreeRepublic, LLC, PO BOX 9771, FRESNO, CA 93794
FreeRepublic.com is powered by software copyright 2000-2008 John Robinson