eRecovery after Virus attack

lsd
lsd Member Posts: 3 New User

A friend has a Aspire M3641 thats been attacked by a virus and of course they never made a recovery disk.

 

And just to make things harder the system is in French

 

Alt F10 gives \windows\system32\winload.exe partion 2 /noexecute=optin command which just makes the display blink and then vista starts as normal

 

In Vista, erecovery does not work, no error messages ...etc

Uninstalled Empowering software and installed new downloaded ETF 2.5.4011

Running the Empowering icon tells me that this is not a Acer system ???

Using computer explorer and double cliking on erecovery in Acer/eRecovery dir does nothing.

The Virus is still active as I've seen it delete some of the eRecovery files as I'm viewing the folder !!

 

Odd bit is that I can see the hidden partion as PQService on drives K and L ???

Checking K (or L) drive for  windows\system32\winload.exe it does not appear and can't copy the C drive winload.exe

to the drive - Think the long error message means the drive is locked or special - not sure

 

Is there a boot disk/ISO I can download that will allow me to rebuild the machine from the PQService ?

 

Thanks

 

Leigh

Answers

  • gendrake93
    gendrake93 Member Posts: 29 New User

    i think you may hav gotten a virus that encrypts the entire HDD,but not for certain,if you have gotten one,you verry well may have to get anew computer,or wait till the entire OS is gone,Either way,i dont think you can recover it,ever,....one question though,the virus im talking about is calle ransomware,and it targets bussinesses,is your friends computer a bussiness computer?

  • lsd
    lsd Member Posts: 3 New User

    Thanks for taking te time to reply Gendrake93

     

    The people do use it for business but only use software like office, nothing fancy and its running Vista home edition

    There's no loaded gun asking for money, as yet anyway

     

    I tried to use some of the bootable anti virus disks around (Bitdefender/Kaspersky/Avira) but none of them could find the harddisk so looks like something has been done to the disk but not encryption.

     

    Was able to create a Acronis disk image to a external USB drive which I can load on another computer and view the files so no encryption involved.

     

    The basic problem is that eRecovery does not work using ALT F10 or the version on C drive

    If Acer produced a ISO disk that could be booted from (No virus or windows O/S involved) and use it to either to restore the factory image from the PQService files or make ISO images of the recovery disks that should have been created by the user ..grrr Don't you love users

     

    Any help from Acer on this problem ?

     

    Leigh

     

     

  • gendrake93
    gendrake93 Member Posts: 29 New User

    Have you contacted acer about this,you may have a virus,probably a speacialized trojan,ill try asking an acer about this,but from the looks of it,you may have to get a new hdd,as,if the trojan has somehow deleted the recovery system files,it may very well have cradhed you hdd.

  • lsd
    lsd Member Posts: 3 New User

    Not contacted Acer yet, especially as its a French machine :-)

     

    Would like to create the recovery disk(s), format the drive and run some tests to see if the drive is physically dammaged or not.

     

    I've always recommended ACER in the pass but I really hate this eRecovery process, just supply the recovery CD/DVD's like they use to in theold days but suppose ACER saves 20p a machine.

     

    The machine is over 5 years old so I think the client may just throw it in the bin and buy a new one in which case I'll format the drive and install Linux on it.

     

    All the best

     

    Leigh

This discussion has been closed.