Anti-spyware virus on both laptop and ext drive

Discussion in 'Malware Help - MG (A Specialist Will Reply)' started by ColorStruck, Jun 26, 2011.

  1. ColorStruck

    ColorStruck Private E-2

    Please help. On June 18, my Dell Laptop Windows 7 Home Premium got attacked by a fake Windows 7 repair virus. The tech guy came on June 20 to "get rid" of it (I put it in quotes, but now I know he really didn't get rid of it). on Friday, it came back, and this time, in addition to my laptop, it's attacked my external hard drive, because when I click on it, it says "folder is empty". I see a blue bar and it says there's stuff on it, but when I click on it - nothing.

    The local tech guy is going to make me wait forever for help, and I'm very upset. Can someone please tell me what to do? I can't lose my files, especially on my ext hard drive, which I thought was safe.
     
  2. thisisu

    thisisu Malware Consultant

    Hi!

    Before we do anything, can you check your Recycle Bin for any files that you may have wanted to keep?
    Also, DO NOT run any type of disk cleaning programs! These type of programs can remove the potential ability to restore files.
     
  3. thisisu

    thisisu Malware Consultant

    After you've double checked your recycle bin.
    Plug in your External Hard Drive, make sure it is ON.

    Then download and save the below tool from Grinler @ bleepingcomputer to your Desktop or anywhere else you can find it ( if the Desktop is not showing )

    http://download.bleepingcomputer.com/grinler/unhide.exe

    Now run it. Now see if you can find your Programs / See your files on the external hard drive?
     
  4. ColorStruck

    ColorStruck Private E-2

    Quick question: do I do all of this in safe mode?
     
  5. thisisu

    thisisu Malware Consultant

  6. ColorStruck

    ColorStruck Private E-2

    Ok, I have an UPDATE:

    The tech guy came yesterday and used Ubuntu to view the files that the virus had hidden in both my laptop's hard drive and my external hard drive. Using Ubuntu, he backed up my files to my external hard drive, and then told me he was going to take my laptop and wipe the hard drive. So I asked him "well what about my external hard drive, it still has the virus on it". He said when I got my laptop back, to plug the (infected) external hard drive into, and then run malwarebytes to do a full scan of my ext drive. Which confused me because he warned me previously not to plug in my ext drive into my Ma's computer, for fear it would infect her system. So my question is, if I shouldn't plug it into Ma's computer, why would I want to plug into my laptop once I get it back from you? Isn't there the same chance it would infect that one?

    Need some answers. I'm really nervous for the files on my external drive.
     
  7. thisisu

    thisisu Malware Consultant

    Use the below method to make sure the files on the external drive don't go onto the laptop hard drive. Keep in mind this works for both flash drives and external hard drives

    For the external Hard Drive and a USB stick.

    Insert your flash drive before we begin. Hold down the Shift key when inserting the flash drive until Windows detects it to bypass the autorun feature. This will keep the autorun.inf from executing automatically.

    Please have all your removable storage devices ready for disinfection.

    Download Flash Disinfector by sUBs and save it to your desktop.

    • Double-click Flash_Disinfector.exe to run it.
    • Your desktop and icons may disappear. This is normal.
    • It will do a cleanup of removable storage devices, and write a protected Autorun.inf file to help prevent re-infection.
    • Follow any prompts that may appear.
    • The utility may ask you to insert your flash drive and/or other removable drives including your mobile phone. Please do so and allow the utility to clean up those drives as well.
    • Wait until it has finished scanning and then exit the program.
    • There will be no GUI interface or log file produced.
    • Reboot your computer when done.

    Note: Flash_Disinfector will create a hidden folder named autorun.inf in each partition and every USB drive plugged in when you ran it. Don't delete this folder. It will help protect your drives from future infection.
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds