My back up hd and files are infected, and are infecting my computer too

Discussion in 'Malware Help (A Specialist Will Reply)' started by morethandork, Oct 3, 2013.

  1. morethandork

    morethandork Private E-2

    My old computer died of water damage. I had everything almost everything backed up but I also recovered the hard drive without any problem. I bought a new computer today, attached my usb key with the backed up files and my new computer immediately got infected with a virus.

    I followed the DO THIS FIRST guidelines and log files are attached.

    Some history: I've been traveling the past six months. My old computer died a month ago. While staying at a hostel, I connected my back-up usb to my hostel's computer three times. The first time, everything worked fine. The second time, things seemed off but it still functioned. The third time it didn't function at all and the computer's anti-virus program kept popping up with virus-blocked warnings. I ran a scan on my usb but stopped it half-way through. It claimed to find and automatically fix over 2000 infected files.

    I tried connecting my (now external) hard drive to the same hostel computer with similar results. I did not scan my hard drive with the anti-virus program.

    On my new computer, I created a restore point before inserting my usb for the first time.

    When I inserted my usb into my new computer for the first time, my new computer immediately blocked its virus, so it claimed. I was also running USB disk security, which caught malicious files in the usb but soon that program shut down and would not turn back on.

    I tried reverting to the restore point, but the program wouldn't open properly. That's when I came to MajorGeek. I have not yet attempted to connect my external hard drive or my second usb (which I never inserted into any hostel's computer).

    Looking at the files in my usb, they make no sense. There are two to four copies of every file and folder. Many files and folders are missing. The sizes of files and folders make no sense. Nothing will open.

    Thank you so much for your help. Every time in the past 10 years I've had serious virus problems, I've turned to MajorGeek and it's been fixed every time.

    PS. I may be remembering wrong. It may have been my external hard drive that I ran the virus scan on and not the usb key. I'm not sure.
     

    Attached Files:

  2. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    You're going to need to plug in your ext. drive and run the scans on it. Then attach the new logs.
     
  3. morethandork

    morethandork Private E-2

    I plugged in my ext hd and ran the tests but they seem to just be scanning my comp and not the ext hd. How do I scan the ext. hd instead?
     
  4. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Both SuperAntispyware and MBAM will allow you to scan your external HD.
     
  5. morethandork

    morethandork Private E-2

    I can't seem to figure out how. I tried installing MBAM onto my external hard drive and this is the log I got.

    It just scans the C drive.

    EDIT: Oh! I had to to a full scan instead of a quick scan. I've attached the log and removed the log of the scan of my C drive.
     

    Attached Files:

    Last edited: Oct 5, 2013
  6. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    I can only assume you had MBAM fix what it found. You can install SAS on your main drive and do a custom scan. Then choose the option to select specific folders and choose your ext. drive.
     
  7. morethandork

    morethandork Private E-2

    I didn't, no. The read me first instructions don't say to have MBAM fix what it finds. Should I run it and SAS and have them both fix what they find?

    The problem is like this:

    I've got my new computer, my usb key and my external hard drive. All three seem to be infected. If I clean the computer, it seems to get infected again by the external drive or the usb whenever I plug those in. Is there a certain order I have to do the cleaning in to get rid of this virus once and for all?

    Additionally, I'm not able to access files on my usb or my external drive. I'm assuming this is the result of the virus, but I don't know. My computer, I can use and access anything I want just fine.
     
  8. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Yes, you need to have MBAM and SAS fix what it finds. You can also try using this on the USB:

    For the external Hard Drive and a USB stick.

    Insert your flash drive before you begin. Hold down the Shift key when inserting the flash drive until Windows detects it to bypass the autorun feature. This will keep the autorun.inf from executing automatically.

    Please have all your removable storage devices ready for disinfection.

    Download Flash Disinfector by sUBs and save it to your desktop.

    * Double-click Flash_Disinfector.exe to run it.
    * Your desktop and icons may disappear. This is normal.
    * It will do a cleanup of removable storage devices, and write a protected Autorun.inf file to help prevent re-infection.
    * Follow any prompts that may appear.
    * The utility may ask you to insert your flash drive and/or other removable drives including your mobile phone. Please do so and allow the utility to clean up those drives as well.
    * Wait until it has finished scanning and then exit the program.
    * There will be no GUI interface or log file produced.
    * Reboot your computer when done.

    Note: Flash_Disinfector will create a hidden folder named autorun.inf in each partition and every USB drive plugged in when you ran it. Don't delete this folder. It will help protect your drives from future infection.
     
  9. morethandork

    morethandork Private E-2

    I ran MBAM and removed what it found. I inserted both my ext. drive and my flash drive while holding down the shift key.

    I downloaded Flash Disinfector. Put it on my desktop. When I double clicked a Windows window popped up and said, "this program may not have installed correctly." And gave me two options: "reinstall using recommended settings" and "this program installed correctly".

    I selected "reinstall using recommended settings." Nothing happened. I tried double-clicking Flash Disinfector again. Nothing happens.

    I ran MBAM again just to see if my computer'd been reinfected and it is still clean.

    Also, my computer's hard drive has been split into two drives suddenly. Now there's both C and D. I don't know how or why this has happened.
     
  10. morethandork

    morethandork Private E-2

    Oh, and I scanned the external drive with MBAM and Superanti-spyware and deleted what they found. I've attached the logs.

    It had no effect on my ability to access my files on the ext. drive.
     

    Attached Files:

  11. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Run both RogueKiller and Hitman and let's see what it finds. You may just have to reformat your external and reload your backup files.
     
  12. morethandork

    morethandork Private E-2

    I ran Rogue and Hitman on my computer. I've attached the logs. I made sure to ignore everything malicious they found.

    Reload my back files from where? My flash drive was my back up and I can't access any of those files either. I have a second back-up but it hasn't been updated in a long time and it may be infected too for all I know. I haven't dared plug it into my new computer yet before I know I won't accidentally infect it.

    I'll do whatever I have to, or pay whatever I have to, to make sure I don't lose all my life's work. That would be devastating. I would just take all this in to a computer expert and pay them to fix it, but I'm in Southeast Asia right now and won't be back in the US until March.

    My computer clearly says that there are 300gb of used space on my ext. drive. And when I scan my external hard drive, I can see it scanning all my files. So, I know they're in there somewhere. But when I plug the external drive into my computer it shows two files only: "CTS BURN PASS" and a text file called "freefallprotection".

    When I plug my flash drive into my computer and open it, it looks like chaos. There are duplicates and triplicates of my folders. Nothing will open. And there are folders files that have never been there before.

    Oh, and when I scanned my external drive with MBAM and Superantispyware yesterday, my computer's anti-virus program (ESET NOD32 ANTIVIRUS 4 business edition) continually told me that it was cleaning and deleting threats.

    EDIT: I should add that I greatly appreciate the help you're giving me!
     

    Attached Files:

    Last edited: Oct 8, 2013
  13. morethandork

    morethandork Private E-2

    I hadn't scanned my flash drive yet, so I did that and deleted what I found. The MBAM log is attached.

    Then I re-scanned my computer with MBAM and Rogue and Hitman. Those logs are attached. I deleted what MBAM found.
     

    Attached Files:

  14. morethandork

    morethandork Private E-2

    I don't know if this is related but now my computer has frozen up completely three times in the past hour, including twice in the past ten minutes. Running only a couple programs at once. Nothing that should overload it.
     
  15. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Your computer logs are clean. MBAM found quite a few files that were infected on the flash drive. I don/t know if they were false positives or not.

    Plug in your ext. and flash drive and so a complete scan at:

    eSet Online Scan.
     
  16. morethandork

    morethandork Private E-2

    I did the scan. It found two infected files, though I think one was MBAM.

    Log is attached.

    EDIT: Still can't read my flash or external drives properly.
     

    Attached Files:

  17. morethandork

    morethandork Private E-2

    I should add that I still can't access any of my files. But when the scanner runs, I can see it scanning every file that I had in there before the virus hit.

    There are computer repair stores in the neighborhood where I'm staying here in Cambodia. Do you think you can help me restore the drive to normal or would you recommend I take it to a shop here and town and see what they can do? The language barrier makes me hesitant to take it in to a shop. I don't want to make things worse and permanently lose anything that could be retrieved by a more skilled technician.
     
  18. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    I am afraid you may have to take it to a shop. :(
     
  19. morethandork

    morethandork Private E-2

    Okay, I will. Thank you for all your help. Truly.
     
  20. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Have you checked to make sure that the file attributes are not just set to hidden and perhaps that is why you do not see them but the scanners do?
     
  21. morethandork

    morethandork Private E-2

    They may be it. I have my computer set to show hidden files and wasn't able to see anything. So, I guess I don't know how to do what you're describing.

    But I took the flash drive into a shop this morning and they were able to unhide the files likity split. Only charged me five dollars. So, I'm pretty thrilled. They were still working on the external hard drive when I left them this morning. I'll go back tomorrow to find out if it worked just as well with the ext. drive.

    Thanks again for all your help.
     
  22. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    You are very welcome. Hope they can restore your files.
     
  23. morethandork

    morethandork Private E-2

    Okay, so, I got the flash drive and external drive back from the shop today. The flash drive is restored 100% and working perfectly. The external drive is not. I plugged it in and still can't see most of the files. I was there in the shop while I watched them make everything appear. They appeared in the faded way that hidden files appear and they said they'd get them all back for me. But it seems some are still hidden and I can't see them on my computer like they showed up at the shop. How do I unhide them?

    Also, I went through the folders on my external drive and tried opening everything. I couldn't open them all and I had to go out so I closed all my windows and clicked on the "safely remove" little button thing in my windows taskbar and it said it couldn't be removed because that drive was still being used. So, I shut down my computer. When I turned my computer back on, I plugged in the external drive and my anti-virus program (ESET NOD32 Antivirus 4.2.71.2) told me that it was sending certain suspicious files from my external drive to be analyzed. So I clicked "safely remove" and it was successfully removed and I unplugged it.

    Now I'm here, posting, asking for help yet again.
     
  24. morethandork

    morethandork Private E-2

    Oh and I scanned my computer with MBAM after unplugging the ext drive and it came back clean. I've attached the logs. I did a quick scan then a full scan.
     

    Attached Files:

  25. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Those are clean. I suggest you post in the software forum to try to get your hidden files to open on your ext. drive.
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds