Rogue+no safe mode w/ cmd

Discussion in 'other security issues & news' started by Rico, May 19, 2013.

Thread Status:
Not open for further replies.
  1. Rico

    Rico Registered Member

    Joined:
    Aug 19, 2004
    Posts:
    1,699
    Location:
    Texas
    Hi Guys,

    I'm curing a PC with ransomware, where safemode with command prompt failed.

    I booted to KAV rescue disc 10, every 5 minutes or so, KAV rescue would, blank screen. Acting like a screen saver. The screen saver, interrupt could not be from windows, as it did not load.

    So does KAV rescue cd/usb have a built in screen saver?

    Throughout out the scan KAV said the machine was infected chose delete, upon completion, quarantine was empty. Seems rather awkward, is this just a Russian English thing?

    Also at KAV rescue > chose terminal > windowsunlocker <enter> 1 unlock windows > reboot > got into windows but did not have network, nor would MBAM load, then rogue re-appeared.

    Next reboot to KAV rescue 10 > terminal windowsunlocker > scan with KAV (about 3.5 hours)

    Next being skeptical > safemode with cmd prompt >create admin account remove virus > boot to remove virus > update & scan MBAM

    Have I missed something obvious, please critique with suggestions:

    Thanks
    Rico
     
  2. Nebulus

    Nebulus Registered Member

    Joined:
    Jan 20, 2007
    Posts:
    1,582
    Location:
    European Union
    The behaviour is normal. I didn't bother to see exactly if it's a screen saver (if it is, it's not the Windows one, of course) or the monitor's power saving feature, but it happens to me as well.
     
  3. ZeroDay

    ZeroDay Registered Member

    Joined:
    Jul 9, 2011
    Posts:
    693
    Location:
    Hogwarts.
    You could try Hitman pro kickstart.
     
  4. Rico

    Rico Registered Member

    Joined:
    Aug 19, 2004
    Posts:
    1,699
    Location:
    Texas
    Thanks guys,

    Kickstart -did not think of that one
     
  5. TheKid7

    TheKid7 Registered Member

    Joined:
    Jul 22, 2006
    Posts:
    3,469
    Did you have a look at the hard drive partitions with a bootable partition management software such as GParted?

    A few months ago I saw a video on Britec09's YouTube Channel which showed that a Rogue made a new partition and set the new partition as "Active". The Windows System Partition was still there and was no longer set as "Active".

    If it exists, could this Rogue "Active" Partition be contributing to your problems?
     
  6. Rico

    Rico Registered Member

    Joined:
    Aug 19, 2004
    Posts:
    1,699
    Location:
    Texas
    Thanks I'll check it out!
     
Loading...
Thread Status:
Not open for further replies.