Stop / remove / prevent Net Boot - Image deployment (rootkit or virus)

I am unable to clean install any version of Windows or Linux.  It appears that the operating system net boots / vlan boots ahead of any boot options available to me. Once an operating system is installed, it begins downloading and installing various packages (.Net, C++, Visual Runtime, Ect). Files and packages from Win XP through Win 10. It remotes the Registry, changes my administrator access to less than complete, and on and on, and on. I digress... For now I will be thrilled if anyone can help me with the Net Booting issue.

Pasting in uefi_vars for reference;

Boot variables are allowed on this system

***

Boot variables information:

***

---- 2 ----
Description: Hard Drive
Path: Unknown
GUID: Unknown
Partition number: Unknown
Begin: Unknown
Partition Size: Unknown

----------------

Additional data:
00041h 0004Dh 00047h 0004Fh 00041h 0004Dh 0004Eh 0004Fh 000B5h 00000h 00000h 00000h 00001h 00000h 00000h 00000h 0006Fh 00000h 00053h 00000h 00053h 00000h 00044h 00000h 00032h 00000h 00053h 00000h 00043h 00000h 00032h 00000h 00034h 00000h 00030h 00000h 00047h 00000h 00033h 00000h 0004Ch 00000h 00043h 00000h 00037h 00000h 00030h 00000h 00039h 00000h 00042h 00000h 00031h 00000h 00032h 00000h 00031h 00000h 0002Dh 00000h 00034h 00000h 00036h 00000h 00030h 00000h 00050h 00000h 00000h 00000h 00005h 00001h 00009h 00000h 00002h 00000h 00000h 00000h 00000h 0007Fh 000FFh 00004h 00000h 00002h 00001h 0000Ch 00000h 000D0h 00041h 00003h 0000Ah 00000h 00000h 00000h 00000h 00001h 00001h 00006h 00000h 00000h 00011h 00003h 00012h 0000Ah 00000h 00000h 00000h 000FFh 000FFh 00000h 00000h 0007Fh 000FFh 00004h 00000h 00001h 00004h 0003Eh 00000h 000EFh 00047h 00064h 0002Dh 000C9h 0003Bh 000A0h 00041h 000ACh 00019h 0004Dh 00051h 000D0h 0001Bh 0004Ch 000E6h 0004Eh 00000h 00050h 00000h 00032h 00000h 00059h 00000h 00031h 00000h 00031h 00000h 00030h 00000h 00034h 00000h 00030h 00000h 00030h 00000h 00035h 00000h 00030h 00000h 00030h 00000h 00031h 00000h 00036h 00000h 00035h 00000h 00034h 00000h 00030h 00000h 00030h 00000h 00032h 00000h 00000h 00000h 0007Fh 000FFh 00004h 00000h 00041h 0004Dh 00042h 0004Fh


***

---- 1 ----
Description: Windows Boot Manager
Path: \EFI\Microsoft\Boot\bootmgfw.efi
GUID: 6172FEA2-70BA-4CC2-A166-299BB67F60A3
Partition number: 1
Begin: 923648
Partition Size: 204800

----------------

Additional data:
00057h 00049h 0004Eh 00044h 0004Fh 00057h 00053h 00000h 00001h 00000h 00000h 00000h 00088h 00000h 00000h 00000h 00078h 00000h 00000h 00000h 00042h 00000h 00043h 00000h 00044h 00000h 0004Fh 00000h 00042h 00000h 0004Ah 00000h 00045h 00000h 00043h 00000h 00054h 00000h 0003Dh 00000h 0007Bh 00000h 00039h 00000h 00064h 00000h 00065h 00000h 00061h 00000h 00038h 00000h 00036h 00000h 00032h 00000h 00063h 00000h 0002Dh 00000h 00035h 00000h 00063h 00000h 00064h 00000h 00064h 00000h 0002Dh 00000h 00034h 00000h 00065h 00000h 00037h 00000h 00030h 00000h 0002Dh 00000h 00061h 00000h 00063h 00000h 00063h 00000h 00031h 00000h 0002Dh 00000h 00066h 00000h 00033h 00000h 00032h 00000h 00062h 00000h 00033h 00000h 00034h 00000h 00034h 00000h 00064h 00000h 00034h 00000h 00037h 00000h 00039h 00000h 00035h 00000h 0007Dh 00000h 00000h 00000h 00069h 00000h 00001h 00000h 00000h 00000h 00010h 00000h 00000h 00000h 00004h 00000h 00000h 00000h 0007Fh 000FFh 00004h 00000h


***

---- 3 ----
Description: UEFI: HL-DT-STDVDRAM SP80NB60
Path: Unknown
GUID: Unknown
Partition number: Unknown
Begin: Unknown
Partition Size: Unknown

----------------

Additional data:
00001h 00004h 00044h 00000h 000EFh 00047h 00064h 0002Dh 000C9h 0003Bh 000A0h 00041h 000ACh 00019h 0004Dh 00051h 000D0h 0001Bh 0004Ch 000E6h 00048h 00000h 0004Ch 00000h 0002Dh 00000h 00044h 00000h 00054h 00000h 0002Dh 00000h 00053h 00000h 00054h 00000h 00044h 00000h 00056h 00000h 00044h 00000h 00052h 00000h 00041h 00000h 0004Dh 00000h 00020h 00000h 00053h 00000h 00050h 00000h 00038h 00000h 00030h 00000h 0004Eh 00000h 00042h 00000h 00036h 00000h 00030h 00000h 00000h 00000h 0007Fh 000FFh 00004h 00000h 00041h 0004Dh 00042h 0004Fh


***

---- 4 ----
Description: Removable Drive
Path: Unknown
GUID: Unknown
Partition number: Unknown
Begin: Unknown
Partition Size: Unknown

----------------

Additional data:
00041h 0004Dh 00047h 0004Fh 00041h 0004Dh 0004Eh 0004Fh 000B9h 00000h 00000h 00000h 00001h 00000h 00000h 00000h 00077h 00000h 00048h 00000h 0004Ch 00000h 0002Dh 00000h 00044h 00000h 00054h 00000h 0002Dh 00000h 00053h 00000h 00054h 00000h 00044h 00000h 00056h 00000h 00044h 00000h 00052h 00000h 00041h 00000h 0004Dh 00000h 00020h 00000h 00047h 00000h 00050h 00000h 00034h 00000h 00030h 00000h 0004Eh 00000h 00042h 00000h 00034h 00000h 00030h 00000h 00000h 00000h 00005h 00001h 00009h 00000h 00001h 00000h 00000h 00000h 00000h 0007Fh 000FFh 00004h 00000h 00002h 00001h 0000Ch 00000h 000D0h 00041h 00003h 0000Ah 00000h 00000h 00000h 00000h 00001h 00001h 00006h 00000h 00002h 00015h 00001h 00001h 00006h 00000h 00000h 00000h 00003h 00005h 00006h 00000h 00003h 00000h 0007Fh 000FFh 00004h 00000h 00001h 00004h 00044h 00000h 000EFh 00047h 00064h 0002Dh 000C9h 0003Bh 000A0h 00041h 000ACh 00019h 0004Dh 00051h 000D0h 0001Bh 0004Ch 000E6h 00048h 00000h 0004Ch 00000h 0002Dh 00000h 00044h 00000h 00054h 00000h 0002Dh 00000h 00053h 00000h 00054h 00000h 00044h 00000h 00056h 00000h 00044h 00000h 00052h 00000h 00041h 00000h 0004Dh 00000h 00020h 00000h 00047h 00000h 00050h 00000h 00034h 00000h 00030h 00000h 0004Eh 00000h 00042h 00000h 00034h 00000h 00030h 00000h 00000h 00000h 0007Fh 000FFh 00004h 00000h 00041h 0004Dh 00042h 0004Fh 00041h 0004Dh 0004Eh 0004Fh 000B9h 00000h 00000h 00000h 00001h 00000h 00000h 00000h 00077h 00000h 00048h 00000h 0004Ch 00000h 0002Dh 00000h 00044h 00000h 00054h 00000h 0002Dh 00000h 00053h 00000h 00054h 00000h 00044h 00000h 00056h 00000h 00044h 00000h 00052h 00000h 00041h 00000h 0004Dh 00000h 00020h 00000h 00053h 00000h 00050h 00000h 00038h 00000h 00030h 00000h 0004Eh 00000h 00042h 00000h 00036h 00000h 00030h 00000h 00000h 00000h 00005h 00001h 00009h 00000h 00001h 00000h 00000h 00000h 00000h 0007Fh 000FFh 00004h 00000h 00002h 00001h 0000Ch 00000h 000D0h 00041h 00003h 0000Ah 00000h 00000h 00000h 00000h 00001h 00001h 00006h 00000h 00002h 00015h 00001h 00001h 00006h 00000h 00000h 00000h 00003h 00005h 00006h 00000h 00004h 00000h 0007Fh 000FFh 00004h 00000h 00001h 00004h 00044h 00000h 000EFh 00047h 00064h 0002Dh 000C9h 0003Bh 000A0h 00041h 000ACh 00019h 0004Dh 00051h 000D0h 0001Bh 0004Ch 000E6h 00048h 00000h 0004Ch 00000h 0002Dh 00000h 00044h 00000h 00054h 00000h 0002Dh 00000h 00053h 00000h 00054h 00000h 00044h 00000h 00056h 00000h 00044h 00000h 00052h 00000h 00041h 00000h 0004Dh 00000h 00020h 00000h 00053h 00000h 00050h 00000h 00038h 00000h 00030h 00000h 0004Eh 00000h 00042h 00000h 00036h 00000h 00030h 00000h 00000h 00000h 0007Fh 000FFh 00004h 00000h 00041h 0004Dh 00042h 0004Fh
Boot variables in Boot Order:

***

1 3 2 4

***
ospeng05Asked:
Who is Participating?

[Product update] Infrastructure Analysis Tool is now available with Business Accounts.Learn More

x
I wear a lot of hats...

"The solutions and answers provided on Experts Exchange have been extremely helpful to me over the last few years. I wear a lot of hats - Developer, Database Administrator, Help Desk, etc., so I know a lot of things but not a lot about one thing. Experts Exchange gives me answers from people who do know a lot about one thing, in a easy to use platform." -Todd S.

Casey WeaverManaged Services Windows Engineer IIICommented:
I'm not exactly sure what your question is. If you have a fresh install that is immediately getting infected, you need to get rid of the infected PC on the network. If you have a virus pushing an infected image by PXE boot, the booting PC should give the IP of the system it's receiving the image from. Trace down the PC and take it off the network. Otherwise disable PXE boot in the client PC's boot options?

Experts Exchange Solution brought to you by

Your issues matter to us.

Facing a tech roadblock? Get the help and guidance you need from experienced professionals who care. Ask your question anytime, anywhere, with no hassle.

Start your 7-day free trial
Davy ParidaensCommented:
Hi ospeng05,

You can download the Farbar tool from the following location:

https://www.bleepingcomputer.com/download/farbar-recovery-scan-tool/

Make sure Addition.txt is checked
execute scan

If there is any malware partition it wil be listed in Adition.txt log file under Drives and will be very small(arround 10MB):
==================== DRIVES ================================

Drive c: () (Fixed) (Total:475.47 GB) (Free:346.95 GB) NTFS
Drive j: () (Network) (Total:390 GB) (Free:84.42 GB)
Drive k: () (Network) (Total:390 GB) (Free:84.42 GB)
Drive q: (DATA) (Network) (Total:921.6 GB) (Free:564.28 GB) NTFS
Drive u: (DATA) (Network) (Total:921.6 GB) (Free:564.28 GB) NTFS
 
If you have questions let meknow

grz,

Davy
Davy ParidaensCommented:
2 basic solutions to troubleshoot malware infection
It's more than this solution.Get answers and train to solve all your tech problems - anytime, anywhere.Try it for free Edge Out The Competitionfor your dream job with proven skills and certifications.Get started today Stand Outas the employee with proven skills.Start learning today for free Move Your Career Forwardwith certification training in the latest technologies.Start your trial today
OS Security

From novice to tech pro — start learning today.