Can't get past boot manager screen and computer won't access USB or DVD

Alien_Galaxy

New Member
Thread author
Verified
Apr 8, 2014
41
I am really hoping someone here can help me out. I will apologize now if by chance you come across a torrent file or 2, as I am unable to delete/access them at this point in time. Although, I believe they all should have been deleted a long time ago though.

Thanks, and I look forward to hearing from you.
 

TwinHeadedEagle

Level 41
Verified
Mar 8, 2013
22,627
Ok, we will burn required tools on your USB.


Please download the following tools on your Desktop:
  1. Farbar Recovery Scan Tool x64
  2. Rufus
  3. Windows 7 RC x64

  • Insert your USB and then start Rufus
  • Select the ISO file win7 64bit rc.iso on the desktop via the ISO icon.

16kbazl.jpg


  • Under the Device select your USB Flash.
  • Press Start
  • When the process is complete, copy Farbar Recovery Scan Tool x64 on this USB
  • Insert USB into infected computer and power on the computer. Now you need to set your computer to boot from USB. In order to do that, follow this guide.
  • When you boot from USB, you will see image like this:

2mo49iw.jpg


  • Click Repair your computer
  • Follow the prompt to enter keyboard input method, and then the prompt to enter a password. If the machine does not have a password, simply click Enter.
In the next menu, use the arrow keys on the keyboard to highlight Command Prompt and press Enter.
  • In the command window type in notepad and press Enter.
  • When notepad opens, click File and select Open.
  • Select "Computer" and find your flash drive letter and close the notepad.
  • In the command window type e:\frst64.exe and press Enter.
Note: Replace letter e with the drive letter of your flash drive.
  • The tool will start to run. When the tool opens click Yes to disclaimer.
  • Press Scan button.

It will make a log (FRST.txt) on the flash drive. Please attach it to your reply.
 

Alien_Galaxy

New Member
Thread author
Verified
Apr 8, 2014
41
Sorry it took me so long to get back to you. Things continue to go from bad to worse with every move I make. I was using my husband's laptop and was going to download those software links as you instructed but I encountered some problems. I had trouble accessing windows explorer and then the internet browsers would not even open. I tried a couple different browsers. My husband has all our computers and the printer networked so I am quite sure his system is probably infected too. I even think it may have came from him because he downloads a lot of movies. That is why I am replying to your post via my phone. I have 1 more computer but it is also networked, so I immediately uninstalled the Memeo Seagate Software which does our backups. It has been out of use for some time and has been powered off, so I am hoping that it will not be too infected since I just turned it on and booted it up today for the first time in a long time. I took the liberty of running an antivirus scan with the currently installed AV software. It had found 8 infiltrations at 95%. It's 98% done now.I wanted to check with you on how to disconnect from our network before I continue with the downloads.
 

TwinHeadedEagle

Level 41
Verified
Mar 8, 2013
22,627
Hi,


Here is what I would like you to do:
- Disconnect computers from network that you think are infected
- Tell me the names of "infiltrations" that were found
- Download and install this tool on your clean PC --> http://mcshield.net/ . It will protect you from USB spreading infections.
 

Alien_Galaxy

New Member
Thread author
Verified
Apr 8, 2014
41
Hi,
The computers have been disconnected from network. The following are the 8 infiltrations ESET had found so far. When I had gone to bed last night, it was at 99% (and had been at 99% for probably a couple of hours), but was definitely still scanning (btw, this is an older and VERY, VERY slow computer hence why it was not being used). When I woke up though, it was back at 32%, so I think it must have restarted scanning itself, as I don't see any other previous completed scan logs. The last scan date was from 2013, which was probably the last time the computer was in use. I should mention too that this isn't the most up-to-date version of ESET, It was only version 4. I am currently trying to update it to the most recent version (7). I have downloaded and installed the mcshield as well. Shall I try to continue on with your initial instructions now? Or, is there something further I should do before I do that?

C:\Users\Tanya\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\IVRYB2MP\Bitool[1].dll - Win32/Somoto.C
C:\Users\Tanya\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\N739CX1V\bi_downloader[1].exe >> NSIS >> bi_client.exe - Win32/Somoto.A
C:\Users\Tanya\AppData\Local\Temp\bitool.dll - Win32/Somoto.C
C:\Users\Tanya\AppData\Local\Temp\nssF2CB.tmp >> NSIS >> bi_client.exe - Win32/Somoto.A
C:\Users\Tanya\Downloads\cnet2_ip4200xp190bus_exe.exe - variant of Win32/InstallCore.D
C:\Users\Tanya\Downloads\DAEMONTools\ultra110-0103.exe >> NSIS >> Script.nsi - DownWare.L
C:\Users\Tanya\Downloads\glary utilities.exe >> NSIS >> Script.nsi - MSIL/Solimba.H
C:\Users\Tanya\Downloads\glary utilities.exe >> NSIS >> northstar.exe - a variant of MSIL/Solimba.I
 

Alien_Galaxy

New Member
Thread author
Verified
Apr 8, 2014
41
Okay, got it. Sorry that this is taking so long, but this computer is extremely slow... I think paint dries faster. :p Even with just 1 application running and very minimal processes, the CPU usage constantly runs at 100% (with no letting up). I have the Farbar Recovery Scan Tool and Rufus downloaded to my desktop, but the link for the Windows 7 RC x64 did not work... I just get a blank page (no error though). I will wait until I get a new link from you.
 

Alien_Galaxy

New Member
Thread author
Verified
Apr 8, 2014
41
Sorry to be the bearer of bad news... it was close, but no cigar. I followed your instructions. Downloads worked well. Inserted the USB and pressed F12. I received the following message (which was definitely new): "Press any key to boot from USB..." but it really didn't matter if you pressed a key or not, it was obvious that it was already predetermined what would happen... it was going to take you back to that Windows Boot Manager screen again where I got the same original error message. Pressing enter to continue no longer works and pressing ESC to exit no longer works. My only option here is powering off the computer. BTW, on the previous screen where you have a choice of F2 (for setup) or F12 (for boot options), F2 no longer works.
 

Alien_Galaxy

New Member
Thread author
Verified
Apr 8, 2014
41
I did press a key... in fact I tried every key eventually. None of the keys do anything. After a few seconds, the next screen appears regardless of what key is pressed.
 

TwinHeadedEagle

Level 41
Verified
Mar 8, 2013
22,627
It is better to upload it here --> http://tinypic.com/

Then just choose Forum format and copy the link here. I need to tell you that I tried myself method with USB just to be sure and boot was succesfull via USB. You probably did something wrong.
 

Alien_Galaxy

New Member
Thread author
Verified
Apr 8, 2014
41
Here are the images uploaded from TinyPic:

24l3j2q.jpg
[/IMG]
2dkegrt.jpg
[/IMG]
3304mx4.jpg
[/IMG]
2hrojk6.jpg
[/IMG]
muzt4w.jpg
[/IMG]
3311wer.jpg
[/IMG]

If you think I might have done something wrong I could go through the steps again. It should be much faster since I have got this other computer running much quicker now. There was a 'giftbox virus' that was slowing it down immensely. That's why it was running at 100% continually. I had thought this computer was clean, but it turns it out it was infected too. I wonder if it could have effected the downloads I did to the USB stick?
 

About us

  • MalwareTips is a community-driven platform providing the latest information and resources on malware and cyber threats. Our team of experienced professionals and passionate volunteers work to keep the internet safe and secure. We provide accurate, up-to-date information and strive to build a strong and supportive community dedicated to cybersecurity.

User Menu

Follow us

Follow us on Facebook or Twitter to know first about the latest cybersecurity incidents and malware threats.

Top