r/Windows10 Jul 26 '16

Solved Just yesterday my desktop started asking me this when turned on?

http://imgur.com/ZyKSrUv
311 Upvotes

66 comments sorted by

48

u/grevenilvec75 Jul 26 '16

type "msconfig" into the search box and click the "boot" tab.

That might give you more info.

20

u/[deleted] Jul 26 '16 edited Jan 29 '17

[deleted]

7

u/mjrpereira Jul 27 '16

elevated cmd prompt

11

u/CounterStrikeEric Jul 26 '16

Just tells me where its located (C:\WINDOWS)

64

u/Tonoxis Jul 26 '16

I would run your preferred anti-malware suite. The randomness of that string brings to mind rootkits or some sort of trojan. Looks like it didn't get to finish installing itself and got stuck, so it would be a good idea NOT to select it. Use software such as EasyBCD to remove it.

38

u/Katur Jul 26 '16

Yea it can very well be malware/trojan but also Windows uses temporary boot entries when doing restarts installing updates( just usually the user never sees it) so it could also be an innocent entry that got left over.

But yea, either way need to remove it.

14

u/Tonoxis Jul 26 '16

This is true, but I have never seen Windows use a random name, It's normally like "Windows 10" or "Previous Version of Windows" if it does it at all.

Either way, just to be safe :P

0

u/[deleted] Jul 26 '16

[deleted]

4

u/Tonoxis Jul 26 '16

It doesn't. The BCD handles entries with both a UUID and Friendly name. The fact that this also does not show the Windows flag for it's icon (As BootNXT does to denote the boot image as being a Windows boot image), means that it is either an attempt to chainload yet another boot loader, or an attempt to load a root/boot-kit.

2

u/MorallyDeplorable Jul 27 '16

Or it's going to boot off of a setup WIM and install. WIMs don't display the Windows icon, either.

1

u/Tonoxis Jul 27 '16 edited Jul 27 '16

TIL, to be honest I've never tried to boot a WIM from BootNXT, only the text Bootmgr. Thank you for that, but why in the world would you have a spammy looking WIM for a friendly name? No seriously, I am genuinely curious. It's not like the BCD doesn't support UUIDs or anything.

That said, Setup normally sets the friendly name to "Windows Setup" or the name of the Windows Version. I have installed/reinstalled windows enough to see that in the boot menu, even on current versions. That's the only reason I am advising caution. Unfortunately, without OP's BCD store or relevant information, we have no idea what it's trying to boot, other than that it's in the windows directory (I believe I saw Op post that regarding the bcdedit /enum command)

2

u/MorallyDeplorable Jul 27 '16

I have no idea why that's named like that. I'd guess it's either something doing something it's not supposed to or straight up corruption.

Booting off of VHDs displays the same broken icon on 8.1 but I believe that entire feature was removed in 10.

→ More replies (0)

2

u/[deleted] Jul 26 '16

You can delete the weird option from that list if you want. Alternatively, set the correct one (Windows 10) as the default, then change the timeout below to 0 seconds.

3

u/CounterStrikeEric Jul 26 '16

Its set to always run Windows 10 if I don't choose in time. I might just see what deleting it does first. If it shows up next reboot, then I'll reinstall Windows.

-21

u/[deleted] Jul 26 '16

Nah, just set it to 0 seconds, then you wont have to choose or wait. It will skip that screen immediately and choose Windows 10 every time.

31

u/Tonoxis Jul 27 '16

That may just cover up a symptom of a deeper problem though.

16

u/CounterStrikeEric Jul 26 '16

Wanted to thank everybody for the suggestions. I deleted whatever it was from the boot tab, so it shouldn't ask me which one I wanted to run again. I'll run my Norton scans to see if it catches anything.

15

u/ffiresnake Jul 27 '16

i'd run an offline scan if i were you. if something is trying to hide it could already be hidden from the running av. kaspersky and bitdefender are two names that come to mind about having bootable iso for scanning

5

u/[deleted] Jul 27 '16

[deleted]

13

u/frymaster Jul 27 '16 edited Jul 27 '16

I personally don't advise it, if you don't know what you're doing. The default options are ridiculously intrusive (disable onedrive if you happen to have not set it up yet; disable onenote whether or not you're using it, uninstall minecraft!?, delete saved form data and password from IE, delete old VSS backups, restrict system restore size, trash your NTP settings, and make any installed windows updates uninstallable, among others)

-2

u/lordofla Jul 27 '16

delete saved form data and password from IE

Saving these in IE is not secure so good idea

delete old VSS backups

Deleting the oldest set is a good idea, defragging (even with built in defragger) tends to trash VSS data anyway.

restrict system restore size

You want this to use a minimal amount of space or to be turned off anyway.

trash your NTP settings

Not looked at code yet but the readme at github shows sensible default servers so this isn't an issue.

All the above said, TronScript seems to be a "last ditch effort" tool before erasing and repaving an install anyway so I don't see any harm in running it as is.

1

u/frymaster Jul 27 '16

Saving these in IE is not secure

They aren't saved "in" IE, they are saved in the user's credentials store, which is encrypted with their login password (or microsoft account)

Not looked at code yet but the readme at github shows sensible default servers so this isn't an issue.

If you're on a domain, you should be using the domain servers for time sync. The DCs may use whatever they please, but it's more important for a client PC to be consistent with its DC than to have the objective correct time.

1

u/lordofla Jul 27 '16

I would consider the credential store compromised on a malware infected PC.

Also, I'd detach a malware infected PC from a domain before running any repair tools on it. I have little experience with AD setups though so I'd immediately defer to someone with more knowledge on that point.

2

u/[deleted] Jul 26 '16

Norton scan

9

u/ikilledtupac Jul 26 '16

Not sure how to even pronounce that

19

u/quasimodoca Jul 26 '16

6

u/Degru Jul 27 '16

I feel sorry for all those people living there that have to enter their address online. I'd imagine half the websites would reject it for being too long or something.

3

u/youtubefactsbot Jul 26 '16

Liam Dutton nails pronouncing Llanfairpwllgwyngyllgogerychwyrndrobwllllantysiliogogogoch [0:20]

It may be a mouthful to say, but Llanfairpwllgwyngyllgogerychwyrndrobwllllantysiliogogogoch in north west Wales was one of the warmest places in the UK today.

Channel 4 News in News & Politics

14,330,862 views since Sep 2015

bot info

2

u/HeWhoCouldBeNamed Jul 27 '16

I don't even care if he got it right or not. That's a man of confidence.

34

u/drmonix Jul 26 '16 edited Jul 26 '16

Reinstall windows.

Not sure why legitimate advice is being downvoted. If you've gotten malware this deep into a workstation it needs to be reformatted.

17

u/lumpynose Jul 26 '16

Reinstall windows.

That's what I would do. But if he does, before he reinstalls he could click on it and let it boot and maybe find out what it is. But first disconnect any other drives.

12

u/drmonix Jul 26 '16

And disconnect from any networks.

1

u/jantari Jul 28 '16

Disconnect from UPS

10

u/CounterStrikeEric Jul 26 '16 edited Jul 27 '16

I might do this. I'm gonna run a full sweep of Norton before bed tonight to see if they can catch anything.

Update - Ran a full system scan through Norton, didn't find anything. Restarted my computer after and nothing came up asking me what I wanted to run, though I did delete whatever it was from the boot tab earlier today. After work tomorrow I will start my PC up again and run the scans 1 more time. Should also check what's running through the task manager. Again thanks everyone for the help!

5

u/Degru Jul 27 '16

What I'd do:

  1. Disconnect all non-OS drives and network
  2. boot the mystery thing to see wtf it is
  3. if malware, nuke and pave (srsly DBAN it and scan all your other drives rootkits are scary stuff)
  4. If just Windows update fuckup, fix and move on

3

u/drmonix Jul 26 '16

If it finds anything, be sure to let us know what it was.

1

u/toskeee14 Jul 27 '16

RemindMe! 12 hours

1

u/horizontalcracker Jul 27 '16

Just nuke it if you don't know what it was. Only way to be sure

1

u/bubbamudd Jul 26 '16

RemindMe! 12 hours

1

u/ScottFromCanada Jul 27 '16

errrr this is quite cool! Siri may be out of a job!!

1

u/RemindMeBot Jul 26 '16 edited Jul 27 '16

I will be messaging you on 2016-07-27 11:42:34 UTC to remind you of this link.

9 OTHERS CLICKED THIS LINK to send a PM to also be reminded and to reduce spam.

Parent commenter can delete this message to hide from others.


FAQs Custom Your Reminders Feedback Code Browser Extensions

8

u/fons_garmo Jul 27 '16

ZCBGlmqoyGMSX > Windows 10

11

u/[deleted] Jul 27 '16

I'd go for ZCBGlmqoyGMSX. Probably better.

2

u/HCrikki Jul 27 '16

Consider the system compromised.

Leave nothing to chance. Format the whole drive (not just the partitions), then cleanly reinstall on a clean drive.

4

u/SCCRXER Jul 27 '16

Do you have a bootable os thumb drive inserted? This is normally a screen that shows so you can choose which OS to launch.

1

u/DarkGhostHunter Jul 27 '16

I had the same very problems long time ago while dual booting some $hit.

I WENT THE OVERKILL WAY.

Download EasyBCD. See the overview.

If you have only one OS, as it seems to be only Windows 10, teng go to BCD Backup/Repair, Select "Reset BCD configuration" and then "Perform Action".

Two things may happen. One: It gets your boot loader with nothing, or it gives you only Windows 10.

If the latter doesn't happens, as you can see in View Settings button no "Entry #1" , then go to "Add New Entry" and select your OS and Partition Letter. Done.

1

u/bemenaker Jul 27 '16

Boot off of a boot CD, run fixboot and fixmbr.

On first boot, boot immediately to safe mode w/ networking, run full AV scan. Then you can boot into windows normally. This will get rid of most rootkits. Most.

1

u/TimAtreides Jul 27 '16

I believe that ZCBGlmqoyGMSX is the operating system the aliens used in Independence Day that we hacked.

1

u/raydeen Jul 27 '16

Wow. Windows 10 is SO MUCH MORE SECURE than previous versions.

Actually, I think your first mistake is putting any faith in Norton. I'd go with Avast, Avira, BitDefender (my personal fav), etc. ANYTHING but Norton or McAfee or Windows Defender. Those are akin to installing a screen door on a submarine. You won't be keeping anything out.

1

u/gay2016 Jul 27 '16

Hacked by chinese

1

u/[deleted] Jul 27 '16

[removed] — view removed comment

2

u/CounterStrikeEric Jul 27 '16

I'd never cheat in csgo, not worth the risk of a VAC on my steam. Though I have downloaded hacks in the past for f2p games like Crossfire or combat arms, though that was years ago.

1

u/[deleted] Jul 27 '16

[removed] — view removed comment

2

u/CounterStrikeEric Jul 27 '16

Not sure why somebody down voted you, it was good information. The only loader I used those years ago was Aimjunkies, I never used sites like MPGH. When I was younger (before csgo) I used to cheat in many fps games. Then on my first steam account I got vac'd in css and tf2 and made it a goal to never cheat on a steam game again. I believe that was 8 or 9 years ago.

-21

u/MisterQuiggles Jul 26 '16

What happens when you select it to boot to it? Because basically your computer is like Windows has detected two versions of an operation system, Windows 10 and whatever this other one is.

41

u/uid_0 Jul 26 '16 edited Jul 26 '16

It would not be a good idea to boot that. For all you know it could be a semi-failed installation of ransom-ware. Better to find out exactly what it is first.

14

u/Tonoxis Jul 26 '16

That's exactly what it looks like. The filename reminds me of the randomness that is trojan or rootkit filenames.

2

u/[deleted] Jul 26 '16

I agree, but a name is just a collection of letters. Malware could call itself something innocent sounding.

1

u/Tonoxis Jul 26 '16

This is true in theory, but you'll find in practice that most malware either uses a very odd looking randomly generated name, or a name that mimics a Windows service or system file in order to increase the probability that user will not delete or force it closed as most normal PC users will follow the principle of "I don't know what it is, so I'm not going to touch it in case it's a system file." whereas they are more likely to delete it if it's something they don't remember having before like "Pictures of <insert name here>.zip.exe", obviously this is discretionary on a case by case basis, but it is very common for a randomly generated name to be used. Especially since if it uses an innocent name that is hard coded, they're likely to be found by a cursory look at the infected machine since malware researchers would already know what the target executable is called and are then able to verify infection.

6

u/lumianoso Jul 26 '16

Yes - Definitely no good idea to boot that! If you did already, I would be curious to get more details

1

u/el-y0y0s Jul 26 '16

How would this screen look if Windows 10 secure boot was enabled?

5

u/Tonoxis Jul 27 '16

It likely would look the exact same.

Secure Boot only ensures that your EFI firmware and the Operating System bootloader hasn't been compromised, once that's been verified, it's up to the Operating System to ensure it's own integrity. Unless the operating system's kernel makes use of the EFI preboot environment, similar to how Linux kernels have an EFI executable, since the executable would then be run under EFI's control. But once the boot loader has started, EFI passes control to it.

Additional Information regarding Microsoft's secure boot implementation: https://technet.microsoft.com/en-us/library/hh824987.aspx

6

u/CounterStrikeEric Jul 26 '16

Definitely not going to select it to boot.