Avatar of jhillbos
jhillbos
 asked on

get rid of ICE Cyber Locker Windows 7

I have been infected with the ICE cyber crime center malware.
I am running Windows 7 Pro 64 bit
I am unable to get into safe mode
I downloaded Bleeping computer's Hitmanpro, created a boot USB drive, but when I boot from it, I can never get to the point where hitmanpro  will run.
I cannot go back to a restore point (because I cannot get to c:\windows\system32\rstrui.exe before ICE Cyber runs again on me.

I have been working on this for 4 hours.  Can someone help me please!!
Feel free to ask any questions you need for clarification.
Microsoft Legacy OSWindows 7

Avatar of undefined
Last Comment
jhillbos

8/22/2022 - Mon
jhillbos

ASKER
As to hitmanpro, when I boot from the USB drive, I select option #1 'Bypass master boot record'.
Windows runs, I login, and hitmanpro does not run, but ICE Cyber locker does and hangs me up
Thomas Zucker-Scharff

jhillbos

ASKER
I am afraid not.  I get to the point where I can actually load restore points.  The first restore point that displays works, but the infection must have already been there, because it is still there after the restore is complete.  When I display previous restore points, I can try to restore back to 11/11/14.  It starts to work, It starts with preparing, goes to initializing, then goes to restoring files, then crashes with rstrui.exe application error.  "The instruction at 0xfb1bca referenced memory at 0c062c50bc.  The memory could not be read.  Click OK to terminate."  I have tried this on several restore points.

Are there specific files I could try to delete using the command prompt?
This is the best money I have ever spent. I cannot not tell you how many times these folks have saved my bacon. I learn so much from the contributors.
rwheeler23
jhillbos

ASKER
Also, according to the instructions from the youtube video, when I try to open the 'hive' and I find the 'software' key, it tells me the file is in use.

This is a real bugger!!
Thomas Zucker-Scharff

Have you ruled out a fresh reinstall?  Better yet do you have either an image to re-image the computer or you could combine a fresh install with recovering using a versioning file backup tool (assuming you were using one - like crashplan - not dropbox).  Dropbox is not a backup, but if that is all you had contact them and they will restore your files from an older version, although it takes them longer.
jhillbos

ASKER
That is the last thing I want to do.  It will take quite a while to get things back to where they were.  No more suggestions?  I do not have an image from the original install.
Get an unlimited membership to EE for less than $4 a week.
Unlimited question asking, solutions, articles and more.
Thomas Zucker-Scharff

I don't have more suggestions at this point for your current dilemma.  I do suggesst you invest in versioning backup in the future.  Like I was saying, it is much easier to recover from this type of problem, when you can go back as many versions as you wish.  We have successfully done this using CrashplanPROe. and I have done the same using Crashplan home version.  Note that with a tool like crashplan you can do this for free as long as you don't use the CrashPlan server (cloud) as a backup destination.  You can even designate multiple other destinations.

www.crashplan.com

Disclaimer:   I am not in any way affiliated with anything mentioned in this post - just a happy user.
ASKER CERTIFIED SOLUTION
jhillbos

Log in or sign up to see answer
Become an EE member today7-DAY FREE TRIAL
Members can start a 7-Day Free trial then enjoy unlimited access to the platform
Sign up - Free for 7 days
or
Learn why we charge membership fees
We get it - no one likes a content blocker. Take one extra minute and find out why we block content.
Not exactly the question you had in mind?
Sign up for an EE membership and get your own personalized solution. With an EE membership, you can ask unlimited troubleshooting, research, or opinion questions.
ask a question
Thomas Zucker-Scharff

Sorry to hear.  For our information - how much did it end up costing and did you get the decryption key?
jhillbos

ASKER
I tried multiple suggestions.  I guess by the time I got to the PC, it was to late to go back.  Could not accomplish anything.  Could not revert back to system restore points at all.
I started with Experts Exchange in 2004 and it's been a mainstay of my professional computing life since. It helped me launch a career as a programmer / Oracle data analyst
William Peck