The Mother Board
How do I edit registry on a removed hard drive?

 
Post new topic   Reply to topic    The Mother Board Forum Index -> Virus/Spyware/Security
View previous topic :: View next topic  
Author Message
ed4586
Initiate
Initiate


Joined: 14 Nov 2006
Posts: 71
Location: Plattsburgh, NY

PostPosted: Wed Mar 13, 2013 7:36 pm    Post subject: How do I edit registry on a removed hard drive? Reply with quote

Have a friends hard drive with the FBI Money pack virus. Couldn't get in safe mode..so I removed the sata drive and ran AVG, Stinger, Malwarebytes etc via a laptop using an external USB adapter.

Located/deleted a bunch of malware, tojans etc..but it still has a virus. Can't locate anything in the Start/Startup files. I suspect it's in the registry.

Is there anyway to edit the registry in a slave drive that is not running the OS? Have full access to the files on the drive (as a slave)...just can't get past the virus when used as the Master.

It will be a last resort of course...Windows XP Pro 32 bit on the drive.

Thanks
Back to top
View user's profile Send private message Send e-mail Visit poster's website
evasive
Mobo-fu Master
Mobo-fu Master


Joined: 06 May 2001
Posts: 36699
Location: Netherlands, Breda

PostPosted: Thu Mar 14, 2013 12:13 am    Post subject: Reply with quote

Complete instructions are here. Malwarebytes in safe mode should take care of this one.

http://botcrawl.com/how-to-remove-the-fbi-moneypak-ransomware-virus-fake-fbi-malware-removal/#options

But I fear you have a rootkit in there as well which may or may not include a MBR infection.

http://malwaretips.com/Thread-MBR-check-tools
_________________
We hate rut, but we fear change.



System error, strike any user to continue...
Back to top
View user's profile Send private message Send e-mail Visit poster's website Yahoo Messenger MSN Messenger
ed4586
Initiate
Initiate


Joined: 14 Nov 2006
Posts: 71
Location: Plattsburgh, NY

PostPosted: Thu Mar 14, 2013 5:18 am    Post subject: Reply with quote

The PC will not open in Safe Mode....when selecting Safe Mode or any other options...it defaults to the FBI screen ...can't work in that environment at all. Can't run REGEDIT in the normal Windows environment ..was hoping to locate the registry file with drive as a slave.
Back to top
View user's profile Send private message Send e-mail Visit poster's website
Karlsweldt
Mobo-fu Master
Mobo-fu Master


Joined: 12 Nov 2003
Posts: 19012
Location: 07438

PostPosted: Thu Mar 14, 2013 8:58 am    Post subject: Reply with quote

If you cannot get any other start mode other than what is presented, then the MBR has indeed been infected. Try booting directly to the OS install disk recovery console, and command the Fixmbr process. You might be lucky.
Best is to mount the drive as a slave or secondary in a host case, or via a USB external case to a known-clean system.. and scan it with the host's antivirus program. Connect the drive after the OS has settled in, if external. A complete scan should clear up any unwanted entities. But if the virus has "taken root", then it could infect other system files.. and they too might be deleted. For reference, the Registry files are located in the Windows\System32\Config folder. But editing them outside of the parent OS (the one that created them) is near impossible. Only an experienced programmer should attempt it.
Yes, this "FBI Money Pack" virus is really nasty! Microsoft's Forum has hints on what to do. But don't expect a full recovery. You may have to rebuild the OS installation.
_________________
F@H.. to solve mankind's maladies.. in our lifetimes!
Back to top
View user's profile Send private message
Mr T
Enlightened Master
Enlightened Master


Joined: 14 Jun 2002
Posts: 16750
Location: England

PostPosted: Thu Mar 14, 2013 10:03 am    Post subject: Reply with quote

Are you booting into SAFE MODE via pressing F8 before the windows splash screen? Should get there to SAFE MODE and then use CTRL+ALT+DELETE to close processes down....

BUT.....

Before hand when the FBI warning screen is up in Normal mode, CTRL +ALT+DELETE and using task manager close it down virus process down. Then go to user accounts and create a new account with ADMIN status and password protect it. Set the other account to standard user then reboot into the new account and install Malwarebytes. From there you can reboot into SAFE MODE using the new Admin account run Malwarebytes to remove the nasty.

I highly recommend once the nasty is off, to remove any virus scanners and install Microsoft Security essentials, update and run it. Also download and run CCleaner using the registry fixer tool as well.

All these programs are free and can be down loaded from Filehippo.com.
_________________
I have been programming on computers since the ZX81.
I am an apprentice trained Electronics Engineer with qualifications to back it up.
I have been repairing computers since 1996.
Yet to some people I still know nothing...
Back to top
View user's profile Send private message
Hardware Junkie
Mobo-fu Master
Mobo-fu Master


Joined: 25 Jan 2001
Posts: 19397
Location: 00000h - 0000Fh

PostPosted: Thu Mar 14, 2013 11:23 am    Post subject: Reply with quote

How to edit the registry offline.

http://4sysops.com/archives/regedit-as-offline-registry-editor/

The only difference is you will need to specify full paths to the slave drive.
_________________
"Imagination is the only weapon in the war against reality." -Jules de Gautier

Back to top
View user's profile Send private message
securityguy
Pilgrim
Pilgrim


Joined: 13 May 2013
Posts: 1

PostPosted: Mon May 13, 2013 6:11 am    Post subject: Here is the step by step instructions to remove FBI Virus! Reply with quote

Norton Power Eraser does the job for me!
Back to top
View user's profile Send private message
Display posts from previous:   
Post new topic   Reply to topic    The Mother Board Forum Index -> Virus/Spyware/Security All times are GMT - 8 Hours
Page 1 of 1

 
Jump to:  
You cannot post new topics in this forum
You cannot reply to topics in this forum
You cannot edit your posts in this forum
You cannot delete your posts in this forum
You cannot vote in polls in this forum


Powered by phpBB © 2001, 2002 phpBB Group