AVmedo

From: ANT_THOMAS 4 Feb 2013 13:31
To: ALL1 of 19
Trying to fix a virus ridden computer. Can't install or download any AV software. Got hold of a kaspersky rescue disk.

Popped it on a USB drive. But there's no BIOS option to get a boot menu.

Motherboard is an MSI PM8PM-V. Any ideas?

I've unplugged the hard drive and the rescue disk doesn't seem to have worked anyway. Any ideas?
EDITED: 4 Feb 2013 16:25 by ANT_THOMAS
From: Ken (SHIELDSIT) 4 Feb 2013 14:16
To: ANT_THOMAS 2 of 19
Can you use F10 or F12 to get to a boot menu selector?
From: ANT_THOMAS 4 Feb 2013 14:24
To: Ken (SHIELDSIT) 3 of 19
Neither work, been across the F keys. The manual says F8. I've managed to get Avast installed and it's finding all sorts of shit. Just odd that I don't have the F8 option. Nothing shows on the POST screen. There was an option in the BIOS to enable booting of other devices, that was off, but even when changed to on it didn't change anything.
From: graphitone 4 Feb 2013 15:30
To: ANT_THOMAS 4 of 19
Have you tried running the ultimate boot cd? S'good for diagnosing problems and contains a lot of start up/boot management tools.
      
From: ANT_THOMAS 4 Feb 2013 16:29
To: ANT_THOMAS 5 of 19
Right, best free Anti Virus please? I've scanned it with Avast and it found ~2500 infected files. "Repaired" those. Rebooted, running another scan because it keeps popping up about a malicious url being blocked. And there is an exe file that gets created in LocalSettings Temp folder that Avast deletes then it gets recreated every so often. It seems a root kit was found and some trojans. Booting into safe mode wasn't working before, but I'll give it another go. Any ideas on how to get rid apart from wiping the machine?
From: JonCooper 4 Feb 2013 16:30
To: ANT_THOMAS 6 of 19
sometimes BIOS access is the DEL key (and occasionally ESC)
From: ANT_THOMAS 4 Feb 2013 16:34
To: JonCooper 7 of 19
BIOS access is fine. It's access to the BIOS boot menu to select boot from USB etc.
From: JonCooper 4 Feb 2013 16:39
To: ANT_THOMAS 8 of 19
oh right, I don't think I've ever known that to be a problem once you're in
From: ANT_THOMAS 4 Feb 2013 16:44
To: JonCooper 9 of 19
Probably not explained myself correctly. When you boot there's often a message on the POST screen to press something like F8/F10/F12 which brings up a screen with a list of bootable devices. It's this message and option which seems to be missing.
From: Ken (SHIELDSIT) 4 Feb 2013 16:51
To: ANT_THOMAS 10 of 19
I've recently stopped using MSSE and started using Bit Defender (Free). Supposed to be one of the best you can get and it's very light.
From: koswix 4 Feb 2013 16:52
To: ANT_THOMAS 11 of 19
Go into BIOS and change boot order.
From: ANT_THOMAS 4 Feb 2013 16:53
To: Ken (SHIELDSIT) 12 of 19
I'll give that a go. Currently doing a startup scan with Avast. I feel like I'm going to kill the computer removing all these infected files that can't be repaired.
From: ANT_THOMAS 4 Feb 2013 16:53
To: Ken (SHIELDSIT) 13 of 19
Tried that, didn't seem to work for some reason, the USB drive wasn't an option. I tried with "bootable addon cards" first.
From: Ken (SHIELDSIT) 4 Feb 2013 16:56
To: ANT_THOMAS 14 of 19
Think that was for Kosser.
From: ANT_THOMAS 4 Feb 2013 16:57
To: ANT_THOMAS 15 of 19
Probably was. My quick reply box doesn't seem to be working today. Better clear my cache.
From: graphitone 4 Feb 2013 17:04
To: ANT_THOMAS 16 of 19
Found another boot disk image from a Mr. Hiren - with rootkit killers and AV on. However there doesn't seem to be anywhere to download it on their site. :C

Here's an alternative download.

Edit - 'Course this is assuming you've got an optical drive in the machine and it's setup to boot from it somewhere in the boot order before the hard drive.
EDITED: 4 Feb 2013 17:06 by GRAPHITONE
From: koswix 4 Feb 2013 17:05
To: ANT_THOMAS 17 of 19
Can you F8 to boot to a command prompt and then do format c:? that'd get rid of it!

(or from a Windows CD, as I imagine you probably can't format the drive the OS is running from.)
From: CHYRON (DSMITHHFX) 4 Feb 2013 18:16
To: ANT_THOMAS 18 of 19
I've generally found a clean reinstall is faster, easier and more reliable than trying to av through it. The severity of the issue suggests it may have been root kitted.
From: ANT_THOMAS 4 Feb 2013 19:54
To: CHYRON (DSMITHHFX) 19 of 19
I wanted to avoid that due to some software we probably don't have media for but I think tomorrow I'm going to wipe it and start from a clean install. My preferred option every time.