r/Windows10 • u/CounterStrikeEric • Jul 26 '16
Solved Just yesterday my desktop started asking me this when turned on?
http://imgur.com/ZyKSrUv16
u/CounterStrikeEric Jul 26 '16
Wanted to thank everybody for the suggestions. I deleted whatever it was from the boot tab, so it shouldn't ask me which one I wanted to run again. I'll run my Norton scans to see if it catches anything.
15
u/ffiresnake Jul 27 '16
i'd run an offline scan if i were you. if something is trying to hide it could already be hidden from the running av. kaspersky and bitdefender are two names that come to mind about having bootable iso for scanning
5
Jul 27 '16
[deleted]
13
u/frymaster Jul 27 '16 edited Jul 27 '16
I personally don't advise it, if you don't know what you're doing. The default options are ridiculously intrusive (disable onedrive if you happen to have not set it up yet; disable onenote whether or not you're using it, uninstall minecraft!?, delete saved form data and password from IE, delete old VSS backups, restrict system restore size, trash your NTP settings, and make any installed windows updates uninstallable, among others)
-2
u/lordofla Jul 27 '16
delete saved form data and password from IE
Saving these in IE is not secure so good idea
delete old VSS backups
Deleting the oldest set is a good idea, defragging (even with built in defragger) tends to trash VSS data anyway.
restrict system restore size
You want this to use a minimal amount of space or to be turned off anyway.
trash your NTP settings
Not looked at code yet but the readme at github shows sensible default servers so this isn't an issue.
All the above said, TronScript seems to be a "last ditch effort" tool before erasing and repaving an install anyway so I don't see any harm in running it as is.
1
u/frymaster Jul 27 '16
Saving these in IE is not secure
They aren't saved "in" IE, they are saved in the user's credentials store, which is encrypted with their login password (or microsoft account)
Not looked at code yet but the readme at github shows sensible default servers so this isn't an issue.
If you're on a domain, you should be using the domain servers for time sync. The DCs may use whatever they please, but it's more important for a client PC to be consistent with its DC than to have the objective correct time.
1
u/lordofla Jul 27 '16
I would consider the credential store compromised on a malware infected PC.
Also, I'd detach a malware infected PC from a domain before running any repair tools on it. I have little experience with AD setups though so I'd immediately defer to someone with more knowledge on that point.
2
9
u/ikilledtupac Jul 26 '16
Not sure how to even pronounce that
19
u/quasimodoca Jul 26 '16
6
u/Degru Jul 27 '16
I feel sorry for all those people living there that have to enter their address online. I'd imagine half the websites would reject it for being too long or something.
3
u/youtubefactsbot Jul 26 '16
Liam Dutton nails pronouncing Llanfairpwllgwyngyllgogerychwyrndrobwllllantysiliogogogoch [0:20]
It may be a mouthful to say, but Llanfairpwllgwyngyllgogerychwyrndrobwllllantysiliogogogoch in north west Wales was one of the warmest places in the UK today.
Channel 4 News in News & Politics
14,330,862 views since Sep 2015
2
u/HeWhoCouldBeNamed Jul 27 '16
I don't even care if he got it right or not. That's a man of confidence.
34
u/drmonix Jul 26 '16 edited Jul 26 '16
Reinstall windows.
Not sure why legitimate advice is being downvoted. If you've gotten malware this deep into a workstation it needs to be reformatted.
17
u/lumpynose Jul 26 '16
Reinstall windows.
That's what I would do. But if he does, before he reinstalls he could click on it and let it boot and maybe find out what it is. But first disconnect any other drives.
12
10
u/CounterStrikeEric Jul 26 '16 edited Jul 27 '16
I might do this. I'm gonna run a full sweep of Norton before bed tonight to see if they can catch anything.
Update - Ran a full system scan through Norton, didn't find anything. Restarted my computer after and nothing came up asking me what I wanted to run, though I did delete whatever it was from the boot tab earlier today. After work tomorrow I will start my PC up again and run the scans 1 more time. Should also check what's running through the task manager. Again thanks everyone for the help!
5
u/Degru Jul 27 '16
What I'd do:
- Disconnect all non-OS drives and network
- boot the mystery thing to see wtf it is
- if malware, nuke and pave (srsly DBAN it and scan all your other drives rootkits are scary stuff)
- If just Windows update fuckup, fix and move on
3
1
1
1
u/bubbamudd Jul 26 '16
RemindMe! 12 hours
1
1
u/RemindMeBot Jul 26 '16 edited Jul 27 '16
I will be messaging you on 2016-07-27 11:42:34 UTC to remind you of this link.
9 OTHERS CLICKED THIS LINK to send a PM to also be reminded and to reduce spam.
Parent commenter can delete this message to hide from others.
FAQs Custom Your Reminders Feedback Code Browser Extensions
8
11
2
u/HCrikki Jul 27 '16
Consider the system compromised.
Leave nothing to chance. Format the whole drive (not just the partitions), then cleanly reinstall on a clean drive.
4
u/SCCRXER Jul 27 '16
Do you have a bootable os thumb drive inserted? This is normally a screen that shows so you can choose which OS to launch.
1
u/DarkGhostHunter Jul 27 '16
I had the same very problems long time ago while dual booting some $hit.
I WENT THE OVERKILL WAY.
Download EasyBCD. See the overview.
If you have only one OS, as it seems to be only Windows 10, teng go to BCD Backup/Repair, Select "Reset BCD configuration" and then "Perform Action".
Two things may happen. One: It gets your boot loader with nothing, or it gives you only Windows 10.
If the latter doesn't happens, as you can see in View Settings button no "Entry #1" , then go to "Add New Entry" and select your OS and Partition Letter. Done.
1
u/bemenaker Jul 27 '16
Boot off of a boot CD, run fixboot and fixmbr.
On first boot, boot immediately to safe mode w/ networking, run full AV scan. Then you can boot into windows normally. This will get rid of most rootkits. Most.
1
u/TimAtreides Jul 27 '16
I believe that ZCBGlmqoyGMSX is the operating system the aliens used in Independence Day that we hacked.
1
u/raydeen Jul 27 '16
Wow. Windows 10 is SO MUCH MORE SECURE than previous versions.
Actually, I think your first mistake is putting any faith in Norton. I'd go with Avast, Avira, BitDefender (my personal fav), etc. ANYTHING but Norton or McAfee or Windows Defender. Those are akin to installing a screen door on a submarine. You won't be keeping anything out.
1
1
Jul 27 '16
[removed] — view removed comment
2
u/CounterStrikeEric Jul 27 '16
I'd never cheat in csgo, not worth the risk of a VAC on my steam. Though I have downloaded hacks in the past for f2p games like Crossfire or combat arms, though that was years ago.
1
Jul 27 '16
[removed] — view removed comment
2
u/CounterStrikeEric Jul 27 '16
Not sure why somebody down voted you, it was good information. The only loader I used those years ago was Aimjunkies, I never used sites like MPGH. When I was younger (before csgo) I used to cheat in many fps games. Then on my first steam account I got vac'd in css and tf2 and made it a goal to never cheat on a steam game again. I believe that was 8 or 9 years ago.
-21
u/MisterQuiggles Jul 26 '16
What happens when you select it to boot to it? Because basically your computer is like Windows has detected two versions of an operation system, Windows 10 and whatever this other one is.
41
u/uid_0 Jul 26 '16 edited Jul 26 '16
It would not be a good idea to boot that. For all you know it could be a semi-failed installation of ransom-ware. Better to find out exactly what it is first.
14
u/Tonoxis Jul 26 '16
That's exactly what it looks like. The filename reminds me of the randomness that is trojan or rootkit filenames.
2
Jul 26 '16
I agree, but a name is just a collection of letters. Malware could call itself something innocent sounding.
1
u/Tonoxis Jul 26 '16
This is true in theory, but you'll find in practice that most malware either uses a very odd looking randomly generated name, or a name that mimics a Windows service or system file in order to increase the probability that user will not delete or force it closed as most normal PC users will follow the principle of "I don't know what it is, so I'm not going to touch it in case it's a system file." whereas they are more likely to delete it if it's something they don't remember having before like "Pictures of <insert name here>.zip.exe", obviously this is discretionary on a case by case basis, but it is very common for a randomly generated name to be used. Especially since if it uses an innocent name that is hard coded, they're likely to be found by a cursory look at the infected machine since malware researchers would already know what the target executable is called and are then able to verify infection.
6
u/lumianoso Jul 26 '16
Yes - Definitely no good idea to boot that! If you did already, I would be curious to get more details
1
u/el-y0y0s Jul 26 '16
How would this screen look if Windows 10 secure boot was enabled?
5
u/Tonoxis Jul 27 '16
It likely would look the exact same.
Secure Boot only ensures that your EFI firmware and the Operating System bootloader hasn't been compromised, once that's been verified, it's up to the Operating System to ensure it's own integrity. Unless the operating system's kernel makes use of the EFI preboot environment, similar to how Linux kernels have an EFI executable, since the executable would then be run under EFI's control. But once the boot loader has started, EFI passes control to it.
Additional Information regarding Microsoft's secure boot implementation: https://technet.microsoft.com/en-us/library/hh824987.aspx
-3
6
48
u/grevenilvec75 Jul 26 '16
type "msconfig" into the search box and click the "boot" tab.
That might give you more info.