Go Back   PCMech Forums > Help & Discussion > Networking & Online Security

Need Some Help? Type Your Keywords Here:

Reply
 
LinkBack Thread Tools Search this Thread Rate Thread Display Modes
Old 01-29-2012, 12:16 PM   #1
Member (11 bit)
 
babylon5guy's Avatar
 
Join Date: Jun 2000
Location: Rochester, NY
Posts: 1,250
Question trogan win32/anomaly.gen!A

Hi,
I'm cleaning off a laptop with win 7 64 bit, the main culprit seems to be above virus although it had many more. When I first started cleaning this MSSE had not a fix for it, and said use their System Sweeper, which I could never get to update on CD or flash drive, and I checked to see if connect automatically was checked as posted in sticky. I ran malwarebytes several times and it found many things but never that. I also ran Superantispyware, TDSSKiller and ESET. Yesterday MSSE finally had a fix for it and it found it and attempted to clean it, it said on the files it wanted to quaranteen it couldn't because they were too big, so I don't know if it deleted them or not, that's when I ran the other scanners. The last one ESET scanned found things I deleted and when I restarted I got the BSOD. Couldn't boot into safe mode either. I went into command prompt and C: drive was empty, and I said oh no. However I took the hard drive out and opened it on my PC and all the data was on an I: Drive? Did the virus do that or what? How would I get it renamed C: drive and would that work on the laptop? I don't think I can do it on my PC as I already have a C: drive. Any help would be appreciated.
TIA
__________________
Greg

1- Gigabyte GA-P55A; i5-760 CPU; HSF XIGMATEK Gaia SD1283; 8 Gig Corsair XMS DDR 3 1600 Mem; HIS H577FK 1 GB Radeon 5770 VC; Linksys WRT54GL Router; SSD Intel X25-M 80 GIG; WD VelociRaptor 150 GIG; WD 6402AAEX HD; 2 LG SATA DVD Burners; PSU CORSAIR CMPSU-750TX 750W; Win 7 64 Bit; Acer 22" LCD Monitor
babylon5guy is offline   Reply With Quote
Old 01-29-2012, 12:34 PM   #2
Staff
Premium Member
 
rjfvillarosa's Avatar
 
Join Date: Sep 2004
Location: Cardiff, Wales. UK
Posts: 6,105
Quote:
Originally Posted by babylon5guy View Post
I took the hard drive out and opened it on my PC and all the data was on an I: Drive? Did the virus do that or what?
No, that was just the next drive letter available on your computer, try running all the scans on the infected harddrive via your computer. When you put the harddrive back in the laptop it will be seen as C:
__________________
Niwa no niwa ni wa, niwa no niwatori wa niwaka ni wani o tabeta.
rjfvillarosa is offline   Reply With Quote
Old 01-29-2012, 12:52 PM   #3
Member (11 bit)
 
babylon5guy's Avatar
 
Join Date: Jun 2000
Location: Rochester, NY
Posts: 1,250
Thanks rjfvillarosa, but it wouldn't boot on the laptop and command prompt showed C: drive empty? It has some strange drive ahead of it, H: which has file boot mgr and folders $recycle.bin, system information and Boot?

Last edited by babylon5guy; 01-29-2012 at 12:56 PM.
babylon5guy is offline   Reply With Quote
Old 01-29-2012, 01:09 PM   #4
Staff
Premium Member
 
rjfvillarosa's Avatar
 
Join Date: Sep 2004
Location: Cardiff, Wales. UK
Posts: 6,105
If you can see the documents via your computer, I would save them to your computer and then reinstall W7 after formatting the harddrive. It sounds like a bit of a nasty infection so I would even consider doing a zero fill of the harddrive.
rjfvillarosa is offline   Reply With Quote
Old 01-29-2012, 01:26 PM   #5
Member (11 bit)
 
babylon5guy's Avatar
 
Join Date: Jun 2000
Location: Rochester, NY
Posts: 1,250
Thanks rjfvillarosa, I was afraid I was going to have to do that. With all the files in Win 7 being protected what is the best way to move them over? From the Libraries or the the users directory? I'll reinstall the actual programs, she doens't have that many. I have run many scans with many different scanners and I do think the drive is clean now. What if I deleted that H: drive, I notice the same file and folders are on the I: drive and I think when it was in the laptop it was seeing the H: drive first.
babylon5guy is offline   Reply With Quote
Old 01-29-2012, 01:39 PM   #6
Staff
Premium Member
 
rjfvillarosa's Avatar
 
Join Date: Sep 2004
Location: Cardiff, Wales. UK
Posts: 6,105
Seeing the H: drive first doesn't make a lot of sense, but if it has card readers and USB ports I suppose it could happen.
I have found that simple copy and paste works ok for copying W7 documents to other computers. It will tell you that you don't have access but give it a moment for the green bar to travel across the entire header bar and it usually gives you access.
rjfvillarosa is offline   Reply With Quote
Old 01-29-2012, 01:58 PM   #7
Member (11 bit)
 
babylon5guy's Avatar
 
Join Date: Jun 2000
Location: Rochester, NY
Posts: 1,250
Thanks for all your help rjfvillarosa, I will do a Restore to the laptop, and copy the files over..
babylon5guy is offline   Reply With Quote
Reply

Bookmarks

Still Need Help? Type Your Keywords Here:


Thread Tools Search this Thread
Search this Thread:

Advanced Search
Display Modes Rate This Thread
Rate This Thread:

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is On
HTML code is On
Trackbacks are On
Pingbacks are On
Refbacks are On



All times are GMT -5. The time now is 07:16 PM.
Powered by vBulletin® Version 3.8.7
Copyright ©2000 - 2012, vBulletin Solutions, Inc.
SEO by vBSEO 3.6.0 PL2