Can hardly believe how much damage this virus did

Collapse
X
 
  • Time
  • Show
Clear All
new posts
  • lti
    Badcaps Legend
    • May 2011
    • 2547
    • United States

    #21
    Re: Can hardly believe how much damage this virus did

    Originally posted by Uranium-235
    viruses don't have an exception for a FOLDER called autorun.inf, which has to be completly deleted before it can make the file
    Not yet...

    That could have gone in my list of stupid or retarded things malware writers have done. There was a program that created a folder called autorun.inf on every removable storage device that was currently connected to the computer. I thought that it would be easy to replace that folder with a malicious autorun.inf file.

    Comment

    • c_hegge
      Badcaps Legend
      • Sep 2009
      • 5219
      • Australia

      #22
      Re: Can hardly believe how much damage this virus did

      If a scan with malwarebytes antimalware doesn't fix it, then I just use a Live CD to back up the user's documents, pictures, music, desktop and email client data to an external HDD and then format the computer and copy it back. If I miss something and they don't have their own back up then it's their problem. They should keep their data in standard locations lioke my documents and they should have their own backup.
      I love putting bad caps and flat batteries in fire and watching them explode!!

      No wonder it doesn't work! You installed the jumper wires backwards

      Main PC: Core i7 3770K 3.5GHz, Gigabyte GA-Z77M-D3H-MVP, 8GB Kingston HyperX DDR3 1600, 240GB Intel 335 Series SSD, 750GB WD HDD, Sony Optiarc DVD RW, Palit nVidia GTX660 Ti, CoolerMaster N200 Case, Delta DPS-600MB 600W PSU, Hauppauge TV Tuner, Windows 7 Home Premium

      Office PC: HP ProLiant ML150 G3, 2x Xeon E5335 2GHz, 4GB DDR2 RAM, 120GB Intel 530 SSD, 2x 250GB HDD, 2x 450GB 15K SAS HDD in RAID 1, 1x 2TB HDD, nVidia 8400GS, Delta DPS-650BB 650W PSU, Windows 7 Pro

      Comment

      • yyonline
        Badcaps Veteran
        • Jul 2009
        • 692
        • USA

        #23
        Re: Can hardly believe how much damage this virus did

        Originally posted by c_hegge
        If a scan with malwarebytes antimalware doesn't fix it, then I just use a Live CD to back up the user's documents, pictures, music, desktop and email client data to an external HDD and then format the computer and copy it back. If I miss something and they don't have their own back up then it's their problem. They should keep their data in standard locations lioke my documents and they should have their own backup.
        I've found that combofix takes care of a lot of difficult to remove malware that malwarebytes can't remove. It sometimes requires multiple passes of combofix to get it all. With antivirus, malwarebytes and combofix I can usually fix about 85% of malware problems. The rest are either reformat or manual removal depending on how many difficult to reinstall programs (missing CDs, license keys, etc) there are and how much the owner wants to pay me for the time.

        Comment

        • kc8adu
          Super Moderator
          • Nov 2003
          • 8832
          • U.S.A!

          #24
          Re: Can hardly believe how much damage this virus did

          i also see a lot of stuff that a reinstall is not an option.specialised stuff where the disks are long gone and mfr bankrupt.so i have to keep in practice.

          Comment

          • Th3_uN1Qu3
            Believe in
            • Jul 2010
            • 6031
            • Romania

            #25
            Re: Can hardly believe how much damage this virus did

            Originally posted by ratdude747
            and what about the teacher's files? her gradebook may be there, among other things? once you have a lot of important (irreplaceable) files on your computer, you learn that reformatting is often a last resort.
            Exactly. Moving all the data back and forth would have been a pain in the behind, especially since i'm not doing very well in the free space department.
            Originally posted by PeteS in CA
            Remember that by the time consequences of a short-sighted decision are experienced, the idiot who made the bad decision may have already been promoted or moved on to a better job at another company.
            A working TV? How boring!

            Comment

            • severach
              Badcaps Legend
              • Aug 2007
              • 1055
              • USA

              #26
              Re: Can hardly believe how much damage this virus did

              ATTRIB does not unhide folders. Explorer can do it but it's a big hassle. Total Commander can do the whole drive at once including folders. Then I go back through and hide files that should be hidden.
              sig files are for morons

              Comment

              • momaka
                master hoarder
                • May 2008
                • 12170
                • Bulgaria

                #27
                Re: Can hardly believe how much damage this virus did

                WTF! 2 weeks ago, I cleaned a virus from my school laptop that would spread itself on flash drives. Haven't had any problem at all in the 2 weeks that followed. Yesterday I opened my school laptop and plugged in my flash drive to get some files and that motherf***er was back again on my flash drive! I'm starting to suspect my family's computer is the culprit since I didn't have a problem for 2 weeks, but I did use my flash drive yesterday on my family's computer before I used it on my school laptop. Haven't used the flash drive anywhere else either.
                Time to disable autorun, I guess. I already did that on my laptop yesterday after cleaning it up. Lets see if it comes up again.
                I can see when it's back because it copies a malicious autorun.inf file on my flash drive, along with a hidden folder called "recycler" with a weird-named file in it.
                I have hidden files and folders view enabled by default, so I can spot it right away.

                Comment

                • TBoneit
                  Senior Member
                  • Jun 2010
                  • 70

                  #28
                  Re: Can hardly believe how much damage this virus did

                  Originally posted by Th3_uN1Qu3
                  You can still do that in Windows from the cmd prompt.

                  I had a hunch so i also ran TDSSKiller and indeed i found a rootkit. After removing the rootkit a couple more nasties that ran on startup showed up... This time Avira removed those just fine. And yes i also scanned with Malwarebytes and removed another 10 items including a trojan downloader. The virus (or one of them at least) had also deleted the Windows Update service!

                  Now it's clean, except that the contents of some folders in the start menu are truly gone (not hidden, deleted). Same goes for the Administrative Tools folder, i wanted to check the Event Viewer because there's still an error sound played on startup, and i want to know what makes it. I'll open it from the command line. I'll prolly have to reinstall a bunch of programs.

                  Btw, i totally dig the keyboard on this thing. It's nice and clacky. It's a Toshiba Satellite A200 btw.
                  If no one has run a temp file cleaner on the computer then go to http://www.bleepingcomputer.com and get a copy of unhide.exe, It typically will unhide all the hidden files that the virus hides and copy back all of the start menu shortcuts that the virus moves to a temp folder to scare the owner that the hard drive is going bad and to pay for the program to save it.

                  Comment

                  • Th3_uN1Qu3
                    Believe in
                    • Jul 2010
                    • 6031
                    • Romania

                    #29
                    Re: Can hardly believe how much damage this virus did

                    Noted... However i gave the laptop back 2 weeks ago. And it wasn't one of those scare programs - it didn't flash any ads or anything.
                    Originally posted by PeteS in CA
                    Remember that by the time consequences of a short-sighted decision are experienced, the idiot who made the bad decision may have already been promoted or moved on to a better job at another company.
                    A working TV? How boring!

                    Comment

                    • lti
                      Badcaps Legend
                      • May 2011
                      • 2547
                      • United States

                      #30
                      Re: Can hardly believe how much damage this virus did

                      Was the virus still active? When I first read the post, it sounded like the executable had been removed already.

                      Comment

                      • TCKTMB
                        Senior Member
                        • Jun 2011
                        • 56

                        #31
                        Re: Can hardly believe how much damage this virus did

                        I've seen this 2X now, the first time on vista and I coppied the important files and format/installed 7. The second time I used combofix and it seemed to do the trick. http://www.bleepingcomputer.com/comb...o-use-combofix

                        Comment

                        • smason
                          Badcaps Legend
                          • Feb 2010
                          • 1652
                          • Canada

                          #32
                          Re: Can hardly believe how much damage this virus did

                          I wonder sometimes what the virus authors are smoking.
                          If viruses were better written, a lot of people would be in real trouble.
                          Often times users wouldn't know they were infected if the system didn't slow down/crash etc.
                          36 Monitors, 3 TVs, 4 Laptops, 1 motherboard, 1 Printer, 1 iMac, 2 hard drive docks and one IP Phone repaired so far....

                          Comment

                          Related Topics

                          Collapse

                          • mon2
                            Hunting down a virus in an office
                            by mon2
                            Hi. We have an office client who has been contacted by the local internet provider that one of the office Windows PCs is infected with a virus. The report has been confirmed. Apparently through a remote outside trigger, this virus is performing brute force attacks around the world from this local IP address at varying times. Aside from low level formatting each PC, what is the recommended approach for this case? Running F-prot (suggested by the internet supplier) has come up empty. We are planning to run hijack this. At this time, we do not know which PC is creating this issue. Internet provider...
                            01-09-2025, 09:42 PM
                          • Mr.Ultimate
                            Dell Precision 5540 - Absolute / Computrace permanently enabled. Need bios fix to disable
                            by Mr.Ultimate
                            Hi, I have Dell precision 5540 laptop from old workplace,decommissioned old stock. its a good spec laptop i9-9880H etc, so I decided to keep it and use it for personal purposes.
                            I was checking bios settings and I found that Absolute (Computrace) is permanently enabled/activated, and field is grayed out, unable to change it to disabled/deactivated state. The laptop status is clean, absolute has no any warnings or messages booting pre-bios pre-OS or post booting, while using laptop, im just not feeling safe having absolute permanently enabled having backdoor on a bios level enabled to my...
                            08-06-2024, 05:24 AM
                          • Joel Ohana
                            Lenovo IdeaPad 3 15IAU7 that suffered water damage
                            by Joel Ohana
                            Hi,

                            I have a Lenovo IdeaPad 3 15IAU7 that suffered water damage. It doesn't turn on (white power light flashes when on button pressed), and the amber light flashes when plugged in.

                            Symptoms:
                            • Short detected – sparks appear when touching the charging port connection with board with a metal (even a multimeter probe).
                            • Visible damage – after cleaning corrosion, I found 4 possibly burnt memory chips near PC3165, labeled UD5, UD6, UD7, and UD8.

                            What are my next steps to diagnose and possibly repair it without replacing the entire board? Any guidance would be greatly...
                            03-06-2025, 11:25 AM
                          • kitor
                            HP Pro Mini 400 G9 - Led code 3/6 Processor does not support an enabled feature / disable AMT in dump?
                            by kitor
                            Hey,
                            I got HP Pro Mini 400 G9 waiting for a long time for a CPU. Bought I3-12100T which is on supported list just to receive code 3,6 which says "Processor does not support an enabled feature".
                            After research I found this is most likely due to all the management stuff being enabled in BIOS (it has vPRO essentials I5 sticker so that is very likely) where 12100T definitely does not support it.

                            Unfortunately I wasn't able to find any friend who would have and lend me their CPU to fix that... so the question is, can this be changed at bios dump level?
                            I attached...
                            02-03-2025, 11:09 AM
                          • azozexd
                            Need help hp 725 g3 liquid damage
                            by azozexd
                            Hello freind i have hp elitebook 725 g3 White liquide damage
                            after cleaning the board i find à damage resistor white no value i test it not reading in multimeter
                            could some one tell me the value of this resistor
                            Thank you...
                            12-15-2024, 06:01 PM
                          • Loading...
                          • No more items.
                          Working...