What is this problem


  1. Posts : 5,941
    Linux CENTOS 7 / various Windows OS'es and servers
       #1

    What is this problem


    Hi all
    A co-worker at the next desk bought his laptop to me in a panic -- he'd let his 12 year old use it -- BAD BAD idea -- if you've got young kids you should NEVER let them use a computer you NEED (for work or any other purpose).

    However he seems to have some nasty problem

    Every directory and sub directory has a 68 byte file in it called "directoryname.exe or subdirectoryname.exe

    So for example if he had an .EXE file in application_z called application_z.exe this file has been replaced with the 68 byte file one.

    He's lost a bit of data as well.

    Apparently he was running AVAST so this obviously didn't do him any good.

    I've told him -- Wipe the disk totally and re-install -- I can't think of anything else.

    Seems like a really nasty piece of malware here -- very tiny and innocuous until you want to execute a program and nothing happens.

    I don't know if this is a new threat or the resurrection of an old one - maybe so old that it's been dropped from AVAST's database.

    I tried MSE on his machine - it wouldn't install due to the .EXE problem -- think he'd better re-install everything again.

    Just to re-iterate - NO AV software is 100% effective, ensure you have good backups of your DATA and don't let your kids use your personal machines.

    Cheers
    jimbo
      My Computer


  2. Posts : 22
    Microsoft Windows 7 Home Premium (32-Bit)
       #2

    Hi, jimbo45.

    What a mess! It goes to show how powerful malware is getting these days. Personally, I agree that he should get rid of everything and completely reformat his hard drive. I was, however, wondering if it'd be possible for you to ask your friend what his son was doing on the computer? Maybe it'd be a start if we knew what sites/downloads/content he's dealt with. I think that'd help a lot.

    I wish you all the best, good luck.
      My Computer


  3. Posts : 8,608
    Windows 7 Ultimate 32bit SP1
       #3

    I'm not sure which one he got, but in any case it's an 'auto-run' piece of malware:
    WinCE/Pmcryptic.A.intd
    W32/Autorun.worm.ac

    ***Change all passwords using a known clean machine, then wipe and re-install Windows.
      My Computer


  4. Posts : 587
    Windows 7 x64
       #4

    jimbo45 said:
    Hi all
    A co-worker at the next desk bought his laptop to me in a panic -- he'd let his 12 year old use it -- BAD BAD idea -- if you've got young kids you should NEVER let them use a computer you NEED (for work or any other purpose).

    Cheers
    jimbo
    .
    Did his 12 year old put Limewire on the PC and surf the infested P2P networks? - whatever....I would agree that wiping the drive and reinstalling is the way to go. He's lucky if he can save most of his data, preferably to Flashdrive or external hard disk (not a CD/DVD) so it can be disinfected if necessary before copying it back to the system.
      My Computer


 

  Related Discussions
Our Sites
Site Links
About Us
Windows 7 Forums is an independent web site and has not been authorized, sponsored, or otherwise approved by Microsoft Corporation. "Windows 7" and related materials are trademarks of Microsoft Corp.

© Designer Media Ltd
All times are GMT -5. The time now is 09:46.
Find Us