Can hardly believe how much damage this virus did

Collapse
X
 
  • Time
  • Show
Clear All
new posts
  • lti
    Badcaps Legend
    • May 2011
    • 2558
    • United States

    #21
    Re: Can hardly believe how much damage this virus did

    Originally posted by Uranium-235
    viruses don't have an exception for a FOLDER called autorun.inf, which has to be completly deleted before it can make the file
    Not yet...

    That could have gone in my list of stupid or retarded things malware writers have done. There was a program that created a folder called autorun.inf on every removable storage device that was currently connected to the computer. I thought that it would be easy to replace that folder with a malicious autorun.inf file.

    Comment

    • c_hegge
      Badcaps Legend
      • Sep 2009
      • 5219
      • Australia

      #22
      Re: Can hardly believe how much damage this virus did

      If a scan with malwarebytes antimalware doesn't fix it, then I just use a Live CD to back up the user's documents, pictures, music, desktop and email client data to an external HDD and then format the computer and copy it back. If I miss something and they don't have their own back up then it's their problem. They should keep their data in standard locations lioke my documents and they should have their own backup.
      I love putting bad caps and flat batteries in fire and watching them explode!!

      No wonder it doesn't work! You installed the jumper wires backwards

      Main PC: Core i7 3770K 3.5GHz, Gigabyte GA-Z77M-D3H-MVP, 8GB Kingston HyperX DDR3 1600, 240GB Intel 335 Series SSD, 750GB WD HDD, Sony Optiarc DVD RW, Palit nVidia GTX660 Ti, CoolerMaster N200 Case, Delta DPS-600MB 600W PSU, Hauppauge TV Tuner, Windows 7 Home Premium

      Office PC: HP ProLiant ML150 G3, 2x Xeon E5335 2GHz, 4GB DDR2 RAM, 120GB Intel 530 SSD, 2x 250GB HDD, 2x 450GB 15K SAS HDD in RAID 1, 1x 2TB HDD, nVidia 8400GS, Delta DPS-650BB 650W PSU, Windows 7 Pro

      Comment

      • yyonline
        Badcaps Veteran
        • Jul 2009
        • 692
        • USA

        #23
        Re: Can hardly believe how much damage this virus did

        Originally posted by c_hegge
        If a scan with malwarebytes antimalware doesn't fix it, then I just use a Live CD to back up the user's documents, pictures, music, desktop and email client data to an external HDD and then format the computer and copy it back. If I miss something and they don't have their own back up then it's their problem. They should keep their data in standard locations lioke my documents and they should have their own backup.
        I've found that combofix takes care of a lot of difficult to remove malware that malwarebytes can't remove. It sometimes requires multiple passes of combofix to get it all. With antivirus, malwarebytes and combofix I can usually fix about 85% of malware problems. The rest are either reformat or manual removal depending on how many difficult to reinstall programs (missing CDs, license keys, etc) there are and how much the owner wants to pay me for the time.

        Comment

        • kc8adu
          Super Moderator
          • Nov 2003
          • 8832
          • U.S.A!

          #24
          Re: Can hardly believe how much damage this virus did

          i also see a lot of stuff that a reinstall is not an option.specialised stuff where the disks are long gone and mfr bankrupt.so i have to keep in practice.

          Comment

          • Th3_uN1Qu3
            Believe in
            • Jul 2010
            • 6031
            • Romania

            #25
            Re: Can hardly believe how much damage this virus did

            Originally posted by ratdude747
            and what about the teacher's files? her gradebook may be there, among other things? once you have a lot of important (irreplaceable) files on your computer, you learn that reformatting is often a last resort.
            Exactly. Moving all the data back and forth would have been a pain in the behind, especially since i'm not doing very well in the free space department.
            Originally posted by PeteS in CA
            Remember that by the time consequences of a short-sighted decision are experienced, the idiot who made the bad decision may have already been promoted or moved on to a better job at another company.
            A working TV? How boring!

            Comment

            • severach
              Badcaps Legend
              • Aug 2007
              • 1055
              • USA

              #26
              Re: Can hardly believe how much damage this virus did

              ATTRIB does not unhide folders. Explorer can do it but it's a big hassle. Total Commander can do the whole drive at once including folders. Then I go back through and hide files that should be hidden.
              sig files are for morons

              Comment

              • momaka
                master hoarder
                • May 2008
                • 12175
                • Bulgaria

                #27
                Re: Can hardly believe how much damage this virus did

                WTF! 2 weeks ago, I cleaned a virus from my school laptop that would spread itself on flash drives. Haven't had any problem at all in the 2 weeks that followed. Yesterday I opened my school laptop and plugged in my flash drive to get some files and that motherf***er was back again on my flash drive! I'm starting to suspect my family's computer is the culprit since I didn't have a problem for 2 weeks, but I did use my flash drive yesterday on my family's computer before I used it on my school laptop. Haven't used the flash drive anywhere else either.
                Time to disable autorun, I guess. I already did that on my laptop yesterday after cleaning it up. Lets see if it comes up again.
                I can see when it's back because it copies a malicious autorun.inf file on my flash drive, along with a hidden folder called "recycler" with a weird-named file in it.
                I have hidden files and folders view enabled by default, so I can spot it right away.

                Comment

                • TBoneit
                  Senior Member
                  • Jun 2010
                  • 70

                  #28
                  Re: Can hardly believe how much damage this virus did

                  Originally posted by Th3_uN1Qu3
                  You can still do that in Windows from the cmd prompt.

                  I had a hunch so i also ran TDSSKiller and indeed i found a rootkit. After removing the rootkit a couple more nasties that ran on startup showed up... This time Avira removed those just fine. And yes i also scanned with Malwarebytes and removed another 10 items including a trojan downloader. The virus (or one of them at least) had also deleted the Windows Update service!

                  Now it's clean, except that the contents of some folders in the start menu are truly gone (not hidden, deleted). Same goes for the Administrative Tools folder, i wanted to check the Event Viewer because there's still an error sound played on startup, and i want to know what makes it. I'll open it from the command line. I'll prolly have to reinstall a bunch of programs.

                  Btw, i totally dig the keyboard on this thing. It's nice and clacky. It's a Toshiba Satellite A200 btw.
                  If no one has run a temp file cleaner on the computer then go to http://www.bleepingcomputer.com and get a copy of unhide.exe, It typically will unhide all the hidden files that the virus hides and copy back all of the start menu shortcuts that the virus moves to a temp folder to scare the owner that the hard drive is going bad and to pay for the program to save it.

                  Comment

                  • Th3_uN1Qu3
                    Believe in
                    • Jul 2010
                    • 6031
                    • Romania

                    #29
                    Re: Can hardly believe how much damage this virus did

                    Noted... However i gave the laptop back 2 weeks ago. And it wasn't one of those scare programs - it didn't flash any ads or anything.
                    Originally posted by PeteS in CA
                    Remember that by the time consequences of a short-sighted decision are experienced, the idiot who made the bad decision may have already been promoted or moved on to a better job at another company.
                    A working TV? How boring!

                    Comment

                    • lti
                      Badcaps Legend
                      • May 2011
                      • 2558
                      • United States

                      #30
                      Re: Can hardly believe how much damage this virus did

                      Was the virus still active? When I first read the post, it sounded like the executable had been removed already.

                      Comment

                      • TCKTMB
                        Senior Member
                        • Jun 2011
                        • 56

                        #31
                        Re: Can hardly believe how much damage this virus did

                        I've seen this 2X now, the first time on vista and I coppied the important files and format/installed 7. The second time I used combofix and it seemed to do the trick. http://www.bleepingcomputer.com/comb...o-use-combofix

                        Comment

                        • smason
                          Badcaps Legend
                          • Feb 2010
                          • 1652
                          • Canada

                          #32
                          Re: Can hardly believe how much damage this virus did

                          I wonder sometimes what the virus authors are smoking.
                          If viruses were better written, a lot of people would be in real trouble.
                          Often times users wouldn't know they were infected if the system didn't slow down/crash etc.
                          36 Monitors, 3 TVs, 4 Laptops, 1 motherboard, 1 Printer, 1 iMac, 2 hard drive docks and one IP Phone repaired so far....

                          Comment

                          Related Topics

                          Collapse

                          • mon2
                            Hunting down a virus in an office
                            by mon2
                            Hi. We have an office client who has been contacted by the local internet provider that one of the office Windows PCs is infected with a virus. The report has been confirmed. Apparently through a remote outside trigger, this virus is performing brute force attacks around the world from this local IP address at varying times. Aside from low level formatting each PC, what is the recommended approach for this case? Running F-prot (suggested by the internet supplier) has come up empty. We are planning to run hijack this. At this time, we do not know which PC is creating this issue. Internet provider...
                            01-09-2025, 09:42 PM
                          • Mr.Ultimate
                            Dell Precision 5540 - Absolute / Computrace permanently enabled. Need bios fix to disable
                            by Mr.Ultimate
                            Hi, I have Dell precision 5540 laptop from old workplace,decommissioned old stock. its a good spec laptop i9-9880H etc, so I decided to keep it and use it for personal purposes.
                            I was checking bios settings and I found that Absolute (Computrace) is permanently enabled/activated, and field is grayed out, unable to change it to disabled/deactivated state. The laptop status is clean, absolute has no any warnings or messages booting pre-bios pre-OS or post booting, while using laptop, im just not feeling safe having absolute permanently enabled having backdoor on a bios level enabled to my...
                            08-06-2024, 05:24 AM
                          • av4x
                            Fujitsu U7511 liquid damage, wont turn on anymore, does not respond to charger in any way.
                            by av4x
                            Good morning, everyone!
                            I've gotten my hands on a few laptops with various defects because I want to get more involved in repairing electronics.

                            First up is a Fujitsu Lifebook U7511.
                            It won't turn on anymore and doesn't respond in any way when you plug in a power adapter.

                            Model: Fujitsu Lifebook U7511
                            CPU: Intel Core i5-1135G7
                            GPU: Intel Iris Xe Graphics
                            RAM: 16GB DDR4 - 3,200 MHz
                            PCB manufacturer: ASKPCB?
                            PCB serial numbers: CP801602, CP7984241-Z4, E239218, CP809978-01
                            Damage: Liquid damage

                            The liquid probably...
                            11-01-2025, 03:09 AM
                          • rounin
                            MacBook Pro A2442 (Board No. 820-02443-05) – Liquid Damage Repair Assistance
                            by rounin
                            Device Information
                            • Model: MacBook Pro 14” M1 Pro (A2442)
                            • Logic board number: 820-02443-05

                            Original Issue
                            The device suffered liquid damage, causing a short circuit on the logic board.
                            Near the audio jack area, the CR852 capacitor pad was severely burned, creating a clear short-circuit path. The board could not power on properly.

                            Work Performed
                            Removed the short circuit by drilling through the board (bypassing the short path) in the CR852 area.

                            Current Status
                            • When powered on, the screen shows support.apple.com/mac/restore....
                            10-20-2025, 11:15 PM
                          • Joel Ohana
                            Lenovo IdeaPad 3 15IAU7 that suffered water damage
                            by Joel Ohana
                            Hi,

                            I have a Lenovo IdeaPad 3 15IAU7 that suffered water damage. It doesn't turn on (white power light flashes when on button pressed), and the amber light flashes when plugged in.

                            Symptoms:
                            • Short detected – sparks appear when touching the charging port connection with board with a metal (even a multimeter probe).
                            • Visible damage – after cleaning corrosion, I found 4 possibly burnt memory chips near PC3165, labeled UD5, UD6, UD7, and UD8.

                            What are my next steps to diagnose and possibly repair it without replacing the entire board? Any guidance would be greatly...
                            03-06-2025, 11:25 AM
                          • Loading...
                          • No more items.
                          Working...