Malware Removal - Initial Scans completed

Discussion in 'Malware Help (A Specialist Will Reply)' started by BilawalJ, Oct 19, 2012.

  1. BilawalJ

    BilawalJ Private E-2

    Hello
    I read the Read and Run Me First and followed the correct link to the Windows XP Malware Removal page and I think I have all the logs required which I will attach here. Firstly, thank you for such a well written and elaborate set of instructions.

    Now, to the problem. I had this problem 2-3 days back and basically a virus seem to have struck my external HDD. Its capacity is 1 TB and now the name is all scrambled and is made up of strange characters. Also the contents of the HDD have been converted to these strange files and folders with scrambled character names. I am posting screenshots of all these pages to show you exactly what I mean.

    I would really appreciate if you could help me with not only removing the malware/virus that has struck the HDD but also preferably recovering most if not all the data.

    Thank you,
    Sohum-Bilawal
     

    Attached Files:

  2. BilawalJ

    BilawalJ Private E-2

    And here are the screenshots I told you about in the last post.

    "H virus1.jpg" is a screenshot of the name of the corrupt drive and "H vius2.jpg" is a screenshot of the now damaged contents of the said external HDD - which is a Seagate GoFlex 1TB External HDD, the kind which needs an external power supply : http://www.seagate.com/external-hard-drives/desktop-hard-drives/goflex-desk/

    Hope this helps.

    Thank you,
    Sohum-Bilawal
     

    Attached Files:

  3. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Welcome to Major Geeks!

    Are you saying that only the files on the external drive were affected?
    Has this external drive been plugged into any other PC?

    You have have several infections based on your logs. One is the Worm.Autorun infection pointed out by Malwarebytes and this can also be the same as a Sality infection which can infect all executable files. However, I'm not thinking this is what has impacted your external drive. That looks more like file encryption of some sort. Perhaps one of the below could help:

    Kaspersky XoristDecryptor 2.2.101.0

    Kaspersky RectorDecryptor


    Also what happens if you alllowed you Norton program to run full scans on your builtin hard disk as well as on your external hard disk?
     
  4. BilawalJ

    BilawalJ Private E-2

    I tried the scanning using Norton. The internal Hard Disk is clean as a whistle. As for the external hard disk, it scans these new big files created by the virus which are ~400 and says there are no infections. Which is kind of crazy as there are obviously a few if not many virus and malware occurrences in the external HDD.

    No, the external hard disk has never been plugged into any other PC and I regularly run scans for both my internal and external hard disk(s).

    I will try to run the Kaspersky products you recommended in your reply, @Chaslang, thank you. I will post results ASAP.

    As of now, I have disconnected the affected hard disk from my computer, will plug it in again for the scans.

    Thank you,
    Sohum-Bilawal

    EDIT : And yes, only the files on the external drive were affected.
     
    Last edited: Nov 3, 2012
  5. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    You're welcome.
    Let me know the results.
     
  6. BilawalJ

    BilawalJ Private E-2

    I ran both the Kaspersky scans. The RectorDecryptor scanned files after I chose the 'Changed' option at the pop-up window which asked me whether file extensions have been changed. It would not run any scan if I chose 'Not Changed' and selected one of the files.
    I have attached the Report.

    The xoristdecryptor report that I have attached shows the issue I have been having with it. I select 'Start Scan' choose one of the files from the external HDD and any file I select, I get such a report(attached).

    Hope this helps,
    Sohum-Bilawal
     

    Attached Files:

  7. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Well this is not looking good. It is possible that this is not even malware. Especially since nothing on the main hard disk has been impacted. It could just be that your external drive information somehow got corrupted. Have you tried running a disk error check on it?

    Also if you try writing one new file to this drive, does it show up properly?
    Are there other files on this drive that look okay and can you access them?
     
  8. BilawalJ

    BilawalJ Private E-2

    How do I run a disk error check?

    All files on the hard disk have been affected it seems. Nothing remaining. And I'll try to add a file or two to the external HDD and tell you what happens.
     
  9. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    From Windows Explorer ( aka My Computer ), right click on the drive and select Properties. Click the Tools tab and select the Error-Checking feature by click the Check Now button
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds