Go Back   PCMech Forums > Windows Support > Windows Legacy Support (XP and earlier)

Need Some Help? Type Your Keywords Here:

Reply
 
LinkBack Thread Tools Search this Thread Rate Thread Display Modes
Old 11-07-2011, 10:14 AM   #1
Member (3 bit)
 
Join Date: Nov 2011
Posts: 5
Computer virus that will not DIE!

Having major major issues here and at my rope's end.

Long story short: Virus attacked (pc peformance and stability anti-virus) and began to systematically attack seemingly everything. Tried using malwarebytes but virus shut it down mid-stream. Re-booted and things got worse from there, files and programs began to disappear, particulary anti-malware programs and so forth... and then it would not let me load windows in safe mode; it then wouldn't let me load OEM system restore disk (just kept looping me back around). I eventually had to disconnect hard drive and reconnect to another machine (via usb external drive) just to reclaim data. I just gave up on reclaiming hard drive. (Eventually the drive wasn't even recognizable even from the new machine as virus made things worse with each passing attempt).

So now I have data from infected hard drive loaded on new hard drive (after scanning with multiple anti-virus and anti-malware programs) and I can SEE the files and click on the files, but they will not open in their respective software (nor will the .jpg files show up as thumbnails). The .pdf and word files say incompatible format or invalid file type when I try to open. (interestingly .bmp files DO open for whatever reason).

The only visible thing I can determine is that the file creation dates have all been changed (to the date and time I copied them from the old hard drive). I simply cannot open these files - even though they look perfectly normal in windows explorer. Is there some sort of 'permission' or access that I can unlock to open these files?

Any help would be MUCH appreciated
gdeck is offline   Reply With Quote
Old 11-07-2011, 10:22 AM   #2
Techphile.
 
David M's Avatar
 
Join Date: Nov 2003
Location: San Francisco Bay
Posts: 6,568
Welcome to PCMech. Sorry to hear this.

Any indication of the name of the malware? What are your system specs?

It's possible that things are so badly messed up that the safest thing to do is to zero out the drive with something like Darik's Boot and Nuke and reload the OS. This is the only certain way of getting rid of the malware. Others may have an idea before you have to resort to this.

Is your data backed up?
__________________
Asus P8P67 WS Revolution | Intel 2600K @ 4.7 GHz | Win 7 Pro 64 |8 gigs Corsair 1600 | Two Diamond 6990's in Crossfire| Corsair AX1200 | Thermalright Silver Arrow | Western Digital Black 2TB 64 meg cache | Lian-Li PC-A71B | Logitec Z-5500 | Three Asus 26" VW266H monitors running under Eyefinity |

Last edited by David M; 11-07-2011 at 10:27 AM.
David M is online now   Reply With Quote
Old 11-07-2011, 10:29 AM   #3
Ride 'em Cowboy
Staff
Premium Member
 
EzyStvy's Avatar
 
Join Date: Dec 1999
Location: Dallas, Tx
Posts: 9,472
Which operating systems are involved? (old sick pc and the new one)

Have to ask--> Do you have the same version of MS Office installed on the new machine?
__________________
Imagine a world where dogs took bad owners to the pound...
EzyStvy is offline   Reply With Quote
Old 11-07-2011, 10:31 AM   #4
Member (3 bit)
 
Join Date: Nov 2011
Posts: 5
I'm running windows xp (home) on a Gateway GT5228. I had most of the data backed up on an external hard drive; but since the data on my hard drive was the most up to date, I simply moved the data from the infected hard drive to the brand new hard drive via usb external drive enclosure device. (I know probably sounds stupid, but I thought the system and registry portions of the drive held the virus and not the data files).

I still think the data files are 'clean' to some degree - but their attributes have clearly been altered to forbid me from opening.

I literally reinstalled the exact same operating system (from OEM disk) and Office and all other data programs -- exactly as before. The only thing different is a new hard drive
gdeck is offline   Reply With Quote
Old 11-07-2011, 10:36 AM   #5
Techphile.
 
David M's Avatar
 
Join Date: Nov 2003
Location: San Francisco Bay
Posts: 6,568
Again, what do you have for the name of the malware? If your anti-malware software found it then it will know the name. Having the name allows others to research it to find possible solutions for eradicating it.

Last edited by David M; 11-07-2011 at 10:38 AM.
David M is online now   Reply With Quote
Old 11-07-2011, 10:49 AM   #6
Member (3 bit)
 
Join Date: Nov 2011
Posts: 5
I'm sorry.. I was never able to scan the actual infected drive as it wouldn't let me... I only scanned the external hard drive that I transferred the files to... I think the malware found only misc. small stuff there, unrelated to what I was dealing with. (I will look up the logs though if you think important)

When the virus attacked, the closest thing I could find online to this virus was the 'pc performance and stability analysis report' virus that creates a 'random.exe' file in several areas of the system and registry.
gdeck is offline   Reply With Quote
Old 11-07-2011, 10:52 AM   #7
Techphile.
 
David M's Avatar
 
Join Date: Nov 2003
Location: San Francisco Bay
Posts: 6,568
This thing is really nasty. Were it me I would wipe the drive and start from scratch. But as I said, others may still have some ideas.
David M is online now   Reply With Quote
Old 11-07-2011, 10:55 AM   #8
Ride 'em Cowboy
Staff
Premium Member
 
EzyStvy's Avatar
 
Join Date: Dec 1999
Location: Dallas, Tx
Posts: 9,472
Quote:
Thank you for contacting Microsoft Support. You have been directed here to download and install the beta version of Microsoft Standalone System Sweeper Beta, a recovery tool that can help you start an infected PC and perform an offline scan to help identify and remove rootkits and other advanced malware. In addition, Microsoft Standalone System Sweeper Beta can be used if you cannot install or start an antivirus solution on your PC, or if the installed solution can’t detect or remove malware on your PC.

Microsoft Standalone System Sweeper Beta | Microsoft Connect
Note that this app can take TONS of Time to run. My 320 gig drive took 6 or 7 hours....
EzyStvy is offline   Reply With Quote
Old 11-07-2011, 11:13 AM   #9
Member (3 bit)
 
Join Date: Nov 2011
Posts: 5
I just ran Malwarebytes on my new drive and it came up clean. I'll try the Microsoft system sweeper and see if that works, but I am doubtful as I feel like this is nothing in the conventional sense of a virus. what kind of virus alters every single data file on a hard drive to be recognizable but unreadable?

Some of the other recommendations I've seen involved trying to find and delete the autorun.inf file, which the virus conveniently hides... but I could never find it from safe mode via command prompt screen.

The virus just seemed to have this methodical way of morphing to something more and more invasive - just devastated everything and was always a step ahead.
gdeck is offline   Reply With Quote
Old 11-07-2011, 11:39 AM   #10
Moderator
Staff
Premium Member
 
jdeb's Avatar
 
Join Date: Nov 2008
Location: Detroit, MI
Posts: 5,223
Run MS system sweeper. It will find it and clean it but as far as fixing it, that remains to be seen. Burn that disc from a known clean PC.
jdeb is offline   Reply With Quote
Old 11-07-2011, 12:28 PM   #11
glc
Forum Administrator
Staff
Premium Member
 
glc's Avatar
 
Join Date: May 2000
Location: Joplin MO
Posts: 41,189
Are you sure you aren't just having a permissions issue? This will deny access to files. If this is what's happening, you need to take ownership of the files in question.

How to take ownership of a file or a folder in Windows XP
glc is offline   Reply With Quote
Old 11-07-2011, 02:08 PM   #12
Member (3 bit)
 
Join Date: Nov 2011
Posts: 5
glc -- thanks for your suggestion,

I just know it is a permission-related problem at this point -- I tried Microsoft's instructions but it didn't work... although I have a strong sense that I'm close - that this is the best way to get access to the files.

For some reason I just can't find the right key on the key chain.
gdeck is offline   Reply With Quote
Reply

Bookmarks

Still Need Help? Type Your Keywords Here:


Thread Tools Search this Thread
Search this Thread:

Advanced Search
Display Modes Rate This Thread
Rate This Thread:

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is On
HTML code is On
Trackbacks are Off
Pingbacks are Off
Refbacks are On



All times are GMT -5. The time now is 06:54 PM.
Powered by vBulletin® Version 3.8.7
Copyright ©2000 - 2013, vBulletin Solutions, Inc.
SEO by vBSEO 3.6.1