kuttus said:Are you getting ransom screen in safe mode?
No, the ransom screen is not appearing in safe mode.
kuttus said:Okay... Please run the following tool from the safe mode......
OK, just to clarify the ransom screen IS NOT showing in regular Safe Mode. However, in Safe Mode with networking the ransom screen IS showing.
Do you want me to run the utility from regular safe mode?
:OTL
[2013/03/13 12:08:23 | 000,000,004 | ---- | C] () -- Q:\Users\MichaelB\AppData\Roaming\skype.ini
[2013/05/23 08:11:41 | 000,000,153 | ---- | C] () -- Q:\ProgramData\ol2ocot.reg_old
[2013/05/23 08:11:41 | 000,000,057 | ---- | C] () -- Q:\ProgramData\ol2ocot.bat_old
[2013/05/23 08:11:38 | 095,023,320 | ---- | C] () -- Q:\ProgramData\ol2ocot.pad_old
[2010/04/24 18:24:03 | 000,007,597 | ---- | C] () -- Q:\Users\MichaelB\AppData\Local\Resmon.ResmonCfg
[2012/12/04 17:33:13 | 000,000,000 | ---D | M] -- Q:\ProgramData\34BE82C4-E596-4e99-A191-52C6199EBF69
[2012/09/06 07:47:23 | 000,000,000 | ---D | M] -- Q:\ProgramData\7531CC96E70B6025DB497545F875EF60
:commands
[emptytemp]
[reboot]
kuttus said:Yes.. Run it from Safe mode........
kuttus said:Okay... If you are still getting ransom screen Please try one more thing... Try to do a system restore from Safe Mode......
mbaynes said:kuttus said:Okay... If you are still getting ransom screen Please try one more thing... Try to do a system restore from Safe Mode......
Here are the logs after running the anit-rootkit program.
I've tried system restore but for some reason all the restore points are missing.
When trying to install the malware bytes software I get an access denied message.
kuttus said:Go to the Tab Logon and uncheck Everything in that Tab....... Unchecke all those Yellow Items also.
Reboot the computer and let me know what's happening now?