• Hi there and welcome to PC Help Forum (PCHF), a more effective way to get the Tech Support you need!
    We have Experts in all areas of Tech, including Malware Removal, Crash Fixing and BSOD's , Microsoft Windows, Computer DIY and PC Hardware, Networking, Gaming, Tablets and iPads, General and Specific Software Support and so much more.

    Why not Click Here To Sign Up and start enjoying great FREE Tech Support.

    This site uses cookies. By continuing to use this site, you are agreeing to our use of cookies. Learn More.

Possible Boot Sector Virus

Status
Not open for further replies.
Hello,

I am unable to get into windows or even install it via a bootable drive due to an error message popping up when I get to the copying files part.

On top of this, whatever this virus is, it infected my entire networking system which includes my router & even my Mac, which if possible, I could really use help with after my PC (Mac is for work and has valuable files on it) but we can discuss this after.

I cleaned my router by performing a complete factory reset, changing my DNS server, IP addresses, disabling remote access, only allowing connection via https, re-enabling all security features etc.

My router is an Asus ROG Rapture AX1100

My MacBook is a 2017 MacBook Air (lowest variant)

My PC is custom built with the following :
I9-9900k
Nvidia 2080Ti FE
32gb G.SKILL Trident-Z RGB 3200Mhz RAM
Gigabyte Aorus Z370 Master
(2) WD Black 500gb NVME SSD's
(1) Samsung 500gb 970 EVO NVME SSD
(1) SanDisk 500gb SATA SSD
Gigabyte TITAN-RIDGE Thunderbolt 3 PCI-e card

Moving on....

I've noticed that GRUB is installed on my PC suddenly and I've never installed UBUNTU or LINUX on this PC.

On top of that, I've also noticed that some kind of script is running after I press F12 and select the USB drive to boot from. It happens right after I press the USB drive to boot and before the Windows loading screen comes on. This is how I have to access Command Prompt.

To explain further.... SFC can complete it's scan but Windows Resource Protection is unable to fix my issue.

I can't fix it with DISM either. It fails.

I've completely unallocated all of my drives.

I've used diskpart to fully clean my drives.

And this is where it gets weird: I've noticed that my PC supposedly has 5 physically mounted drives and 3 removable drives...

This is not true. I have (3) NVME drives and (1) SSD & finally the (1) removable bootable drive.

After going into my BIOS boot menu, I've noticed there are (3) storage devices
Generic-USB3.0 CRW -01.00
Generic-USB3.0 CRW -11.00
Generic-USB3.0 CRW -21.00

These are definitely NOT my drives. And I unplugged all other devices from my PC so im confident that these are malware somehow posing as USB drives. After doing a quick search via Google, I noticed that these Generic names are generally associated with the UBUNTU system.

I'm guessing those along with GRUB and various other items are pointing to the type of malware/virus here but I just don't know enough about them to be able to solve this myself and am hoping for some assistance.

By the way, I've tried deleting, unmounting, removing, flushing and every other command I could possibly find to remove these Generic drives but they mostly don't respond, access is denied etc. (I've been at this for almost 20 hours now so I've tried a lot)

I can't access safe mode. When I boot into Kaspersky Rescue Disk, I have no connection to the internet via either ethernet or wifi and if I add a connection it still won't work and also a scan reveals no malware and I'm certain that the malware takes control of Kaspersky on startup. KSD does not find any viruses and I think it's being stopped short with it's scan.

I could go on and on.

There is absolutely no data I want on these drives and whatever this virus is, I'm fairly sure it's probably corrupted my OneDrive also I know it at least tried to access it along with my personal vault (that had nothing in it)

Any help would be very much appreciated and if it makes it easier, I can provide a number to speak over the phone and also compensation for your time. I genuinely appreciate even the consideration to assist me, even if you can't.

Thank you!
 
Read through and follow the posting instruction in the Sticky Threads
Hello,

I actually read through it entirely before posting.

I understand you want me to post some logs but the problem is that I can't get to my desktop to scan at all. Not in safe mode or anything.
 
@jmarket
Then wait and see what the malware group has.
What? I don't understand your attitude. If you don't want to offer any guidance then that's fine, just say that but I don't see why you feel it's necessary to act like that when this is supposedly a forum to obtain assistance with this.........

After investigating this, I've found out that I've been infected using the BootHole exploit using GRUB2 and it has elevated system privileges along with access to the bootloader and can thereby, start with my PC.

It has infected my PC, MAC, ONEPLUS 7 PRO, SAMSUNG GALAXY TAB S7+, NVIDIA SHIELD and potentially my GOOGLE HOME but this is unconfirmed at this time.

So now that you see my issue, maybe you'll understand why I can't produce the logs your requesting.
 
Hello @JesseJamez55,

Rustys was in no way having an attitude, he was just tagging me so I could see your post. I apologize if it seemed like he was aggressive but he was only trying to help :)

I am curious how you came to the determination that you have been infected with a BootHole vulnerability. Also, is your Mac infected or no? If not, you need to air gap it for now. Next step will be to wipe the flash drive, format it, and create a fresh bootable Windows 10 USB drive using the Mac.
 
Status
Not open for further replies.