Malware 17Pholmes, want to format to clean

Discussion in 'Malware Help (A Specialist Will Reply)' started by Rex Everything, Apr 10, 2008.

  1. Rex Everything

    Rex Everything Private E-2

    The infecting malware is "17pholmes1001186.exe" and "mrofinu1001186".
    I got a call from my intenet provider sayign that unsolicited e-mail was being sent from my IP address too. I think I got it in the last 4-5 days possibly through a torrent or watching embeded video if thats possible.

    I have used the "read and run me first" thread before to remove malware and it worked a treat. However this time I just want to back up all my music, videos and uni work onto a new extrenal hard drive; then completley format both internal hard drives and start a fresh (install all programs new, including anti-virus and firewalls). My main concern is re-infecting my computer and infecting the other computer in our home network.


    Here is my plan:

    1. Back up all my music (about 40GB), movies (about 40GB), documents and the intsall files of some downloaded programs.

    2. Format both internal drives from XP home disc and update with the sp2 disc from Microsoft

    3. Intstall AVG and some other protection before I start accessing the music and movies off the extrenal hard drive

    4. Hopefully live malware free from now on

    So here are my questions,

    1. What are some quick ways to back up large folders onto an external drive?
    2. How can I format both drives on my computer at once? (2 physically seperate drives, no partitions)
    3. How do I prevent the Malware from getting onto the external hard drive and re-infecting after the format? Should I clean the best I can before I start backing up?


    Thanks in advance for any help given, and many more thanks for the help already recieved!
     
  2. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    These are topics for the Malware Removal Forum. Try the Software Forum.

    In all honesty, the only guaranteed way is to not back up anything especially anything that is considered an executable type file. Even MP3 and video files can get infected. Second best thing would be to clean your current system first before doing any backups. And then do your reinstall if still desired. The two files you mentioned are not major issues to remove.
     
    Last edited: Apr 11, 2008
  3. Rex Everything

    Rex Everything Private E-2

    Thanks for the help, Ive ran the "read and run me first" thread and all went to plan except for that super anti-spyware which would not intstall (nor will avg).

    The files are still turning up in the processes list!

    I'm currently running kaspersky at home and will post all the required logs when I get back home.

    I'm pretty keen to get rid of this before I back-up and format.
     
  4. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    AVG is not in the READ ME.

    What processes?
     
  5. Rex Everything

    Rex Everything Private E-2

    I was trying to say that SAS wouldn't install or run and that AVG won't install either.

    I ended up running kaspersky virus remover and It got rid of "17pholmes1001186.exe" and "mrofinu1001186" but also stopped explorer from loading and killed nero.

    It found win32/virut though and from what I've read this can infect executable files easlily. So I scanned the external hard-drive that I backed up all my documents with (with AVG on another computer) and it found that the win32/virut had infected about20 .exe files that I used ages back to install some programs, including nero. I then used AVG to remove these infected .exe files.

    Will it be okay start using the external hard drive on my now reformatted system without win32/virut comming back? I have installed and updated AVG and PC tools firewall plus.

    By processes list I meant when you view running processes thru ctrl+alt+delete

    Sorry if this is a bit vague.

    Cheers
     
  6. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Yes it can infect every executable file on your PC so if only 20 were truly infected, you are lucky.

    I cannot honestly answer this since I do not know what types of files you had backed up or when you did the backups. It is still possible that you have infections. You really should complete the READ ME.

    And I would also recommend running the below on all drives

    Using BitDefender Online Scan


    Yes but there are always processes running. You did not say which processes you were talking about.
     
  7. Rex Everything

    Rex Everything Private E-2

    I scanned the external hard drive using BitDefender and attached the log. I hope it worked, I could only save it as a .html I then went and changed the file extension to .txt

    When I scan the external hard drive with AVG it keeps finding the win32/virut in the restore points of system volume information folder of the drive. Is there anyway I can turn this restore off? Or will deleting them do the trick?

    I meant the "17pholmes1001186.exe" and "mrofinu1001186", but these seem to be dealt with now.
     

    Attached Files:

  8. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    That's what you were supposed to do. ;) You need to delete all the files in the H:\My Documents\My Downloads\ folder. I expect that many of them if not all were infected based on the log.

    You cannot delete things in system restore. You have to disable System Restore while the external drive is connected.



    Okay but frequently many other problems come along with these. You really should comeplete the READ & RUN ME and attach the logs. If you don't do this, you are still at high risk.
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds