ENTIRE HDD Erased!

You ran Malwarebites in safe mode?

I would download Avast free home and accept its boot scan. See what else is picked up.

Next I would enter Safe Mode with networking and download Spybot S&D, only its scan function, update and run. If it finds little or nothing, then run Malwarebites again in Safe Mode and you can probably retrieve your files.

If you dont' see any end to it this way, then download Darik's Boot and Nuke and zero the HD before installing Win7. Only when zeroed will you know nothing can rise from the grave.


Yap, after I backup my data to optical storage I will low level format everything and then I will thoroughly scan my DVD's.

And the passwords changed ...... I use foxmarks for bookmarks and password sync (but not the sensitive login into whm or so). it'll be a mouthfull...

I edited Darik's out of my OP (use DISKPART) because optical drive media can be compromised in these situations: use a Win7 DVD copy made on another machine, scan or discard after reinstall.

Boot scan upon reinstall with Avast free home, Spybot in Safe Mode, Win7 DVD first.

The retrieved data DVD's will be a corruption path into any OS.
 
I'm in safe mode now, scanning with malware bytes, I already found that Display. HiJacker that is displayed in the 3rd image attachment.
 

My Computer My Computer

Computer Manufacturer/Model Number
Intel
OS
W7 X64 Ultimate, OSX, Linux
CPU
Intel Core i3 540M
Motherboard
Intel DH55TC
Memory
2GB Kingston DDR3 @ 1333MHz
Graphics Card(s)
nVidia gForce 250GTs, 512MB
Sound Card
OnBoard
Monitor(s) Displays
2xBenq E2200HDA
Screen Resolution
1920x1080
Hard Drives
Linux - 160GB WD 8MB Cache 7200rpm
OSX - 320GB Seagate Barracuda 16MB Cache 7200rpm
W7 - 80GB Seagate Barracude 8MB Cache 7200rpm
PSU
Antec 700W
Case
Cooler Master MidTower
Cooling
Standard
Keyboard
DeLux
Mouse
Logitech Wireless
Internet Speed
LAN/T1
I'm a computer power user since '99(everythign that I used since '99 to 2007 so far was cracks and keygens)

Thus your problem now. As long as you continue to use cracks and keygens you'll run into the problems you have now.

I won't play holier than thou, we all used these things but those days have passed and the world is too dangerous to play with computer security.

Do yourself a favor and stay away from cracked software. Sometimes the guys providing those cracks are a lot smarter then we think. ;)

Just my two cents.

Good luck with your repairs.
 

My Computer My Computer

Computer type
PC/Desktop
Computer Manufacturer/Model Number
Custom built by me.
OS
Windows 10 Pro
CPU
Intel Core i7-4770K (3.5Ghz)
Motherboard
Gigabyte G1 Sniper 5 (F10 Bios)
Memory
32 gig Corsair Dominator Platinum (4x8Gig)
Graphics Card(s)
Sapphire Tri-X R9 Fury
Sound Card
Soundblaster ZXR
Monitor(s) Displays
NEC PA242W 24" LCD Monitor
Screen Resolution
1920 x 1200
Hard Drives
Primary - Samsung 850 Pro (512gig), Samsung 840 Pro (256gig), 2TB WD Caviar Black.
PSU
EVGA Supernova 1000 G2
Case
Cooler Master HAF X
Cooling
Corsair H100i with Corsair Air Series SP120 Quiet Fans
Keyboard
Logitech Wireless Wave
Mouse
Logitech Performance MX
Internet Speed
High Speed Cable
Antivirus
Norton Security
Browser
IE11
Other Info
Memory Timings - 1866MHz @ 9-9-9-27-1T @ 1.5 volts
Thanks,

I scanned in safe mode with SpyBot S&D and Malware Bytes and it is all clean, I'm gonna start the recovery and after that I'll scan again.


EDIT: After spybot s&d and malware bytes scanned and cleaned everything after restart, Lavasoft Ad-Aware found two XXX.Hack.XXC Bot something, deleted as well. I have a little farm here :))
 

My Computer My Computer

Computer Manufacturer/Model Number
Intel
OS
W7 X64 Ultimate, OSX, Linux
CPU
Intel Core i3 540M
Motherboard
Intel DH55TC
Memory
2GB Kingston DDR3 @ 1333MHz
Graphics Card(s)
nVidia gForce 250GTs, 512MB
Sound Card
OnBoard
Monitor(s) Displays
2xBenq E2200HDA
Screen Resolution
1920x1080
Hard Drives
Linux - 160GB WD 8MB Cache 7200rpm
OSX - 320GB Seagate Barracuda 16MB Cache 7200rpm
W7 - 80GB Seagate Barracude 8MB Cache 7200rpm
PSU
Antec 700W
Case
Cooler Master MidTower
Cooling
Standard
Keyboard
DeLux
Mouse
Logitech Wireless
Internet Speed
LAN/T1
Run another AV, need second opinion.

In the future, anything you download from a torrent needs to be extracted and rightclick scanned with AV and Spybot before running.
 
It's ok, now lavasoft Ad-Aware reports everything to be clean. Imma start digging.... let's see what surprises do I stumble upon :))

It's freaky, with the system freshly installed, I had by default those 3 malwares. I didn't installed anything besides those anti malware and firefox and sync'ed my bookmarks. Need a low level format.
 

My Computer My Computer

Computer Manufacturer/Model Number
Intel
OS
W7 X64 Ultimate, OSX, Linux
CPU
Intel Core i3 540M
Motherboard
Intel DH55TC
Memory
2GB Kingston DDR3 @ 1333MHz
Graphics Card(s)
nVidia gForce 250GTs, 512MB
Sound Card
OnBoard
Monitor(s) Displays
2xBenq E2200HDA
Screen Resolution
1920x1080
Hard Drives
Linux - 160GB WD 8MB Cache 7200rpm
OSX - 320GB Seagate Barracuda 16MB Cache 7200rpm
W7 - 80GB Seagate Barracude 8MB Cache 7200rpm
PSU
Antec 700W
Case
Cooler Master MidTower
Cooling
Standard
Keyboard
DeLux
Mouse
Logitech Wireless
Internet Speed
LAN/T1
Yeah,, well I always say there are ,.,....

Those who have lost data, and those who will lose data.

If your data is important,, then you should have already had a backup / disaster recovery plan.

Please research Disater Recovery, or Basic Back up planning and create one.
 
Last edited:

My Computer My Computer

Computer Manufacturer/Model Number
Self Built
OS
Win 7 Ultimate 32bit
CPU
C2D E6600 2.4Ghz
Motherboard
Intel D965WH
Memory
4G Kingston KHX5400D2
Graphics Card(s)
EVGA GTX 570 HD SC (012-P3-1573-KR)
Sound Card
On-Board
Monitor(s) Displays
Samsung 226BW
Screen Resolution
1680 x 1050
Hard Drives
2 x 250 Seagate Barracuda
2 x 500 Seagate Barracuda (Raid1)
PSU
Corsair TX750W
Case
In-Win C589
Cooling
Stock Intel Cooling
Run SUPERAntiSpyware as well (the free version). Combined with Malwarebytes, this will identify pretty much every virus/trojan/bug out there.

Good luck!
 

My Computer My Computer

Computer Manufacturer/Model Number
me / #1
OS
windows 7 x64 Home Premium
CPU
intel q6600
Motherboard
gigbyte ga ep45 ud3l
Memory
g.skill 8gb ddr2 1066 (pc2 8500)
Graphics Card(s)
evga geforce 9800 gtx 512 mb
Screen Resolution
1680 x 1050
Hard Drives
wd caviar black 500 gb
wd caviar black 1tb
wd elements 1tb external hd x2
PSU
raidmax 500w
Case
smilodon (yes, t'was the pretty blue lites that got me!)
So, everything nice and dandy until 10 minutes ago, out of nowhere virtualgirlhd.exe appeared in my downloads folder and it was already installed when I checked.

I have antivirus, realtime protection from LavaSoft Ad-Aware, checked with Malware Bytes and nothing found. Now I am checking with spyBot S&D in safe mode,

in conclusion, the program installed itself automatically with UAC turned to paranoid and all those softwares protecting my PC, how the hell is that possible, and I wasn't afk at all, I am recovering data and scanning as I recover it, this is to freaky!

vghd.exe appears already in control panel, in the registries, deleted it from everywhere, waiting for another hit.

Ideas? THANKS!!!
 

My Computer My Computer

Computer Manufacturer/Model Number
Intel
OS
W7 X64 Ultimate, OSX, Linux
CPU
Intel Core i3 540M
Motherboard
Intel DH55TC
Memory
2GB Kingston DDR3 @ 1333MHz
Graphics Card(s)
nVidia gForce 250GTs, 512MB
Sound Card
OnBoard
Monitor(s) Displays
2xBenq E2200HDA
Screen Resolution
1920x1080
Hard Drives
Linux - 160GB WD 8MB Cache 7200rpm
OSX - 320GB Seagate Barracuda 16MB Cache 7200rpm
W7 - 80GB Seagate Barracude 8MB Cache 7200rpm
PSU
Antec 700W
Case
Cooler Master MidTower
Cooling
Standard
Keyboard
DeLux
Mouse
Logitech Wireless
Internet Speed
LAN/T1
A few excellent lessons are to be learned by this situation and should be noted by other users.

a.) UAC in Windows 7 is GOOD and should always stay enabled.
b.) Using cracked software is not only a security risk but it's piracy. You get what you pay for.
c.) Always, always, ALWAYS have a Backup Plan in place. Whether you burn your data to DVD, have a backup HDD, online storage, etc. This is probably the single most important best practice that many PC users still neglect until it's too late.
 
Last edited:

My Computer My Computer

Computer type
PC/Desktop
Computer Manufacturer/Model Number
Custom Desktop PC
OS
Windows 7 / Windows 8.1
CPU
Devils Canyon i7-4790K @ 4.8 GHz ~ 1.33v
Motherboard
Asus Z97 Deluxe
Memory
Corsair Vengeance Pro PC3-19200 DDR3 2400MHz
Graphics Card(s)
EVGA GeForce GTX 980 SuperClocked ACX 2.0
Sound Card
Realtek ALC1150 8 channels
Monitor(s) Displays
BenQ XL2720Z 27"
Screen Resolution
1920 x 1080 @ 144Hz
Hard Drives
SSD1: 512GB Samsung 850 Pro
SSD2: 1TB Samsung 850 EVO
SSD3: 1TB Samsung 850 EVO
HDD: 4TB Western Digital Black
Backup: Western Digital My Book Duo 8TB
PSU
Corsair HX1000i / CyberPower CP1500PFCLCD PFC Sinewave UPS 1
Case
Corsair Graphite 780T
Cooling
Custom single loop liquid; CPU delidded; Aerocool DS Fans
Keyboard
Logitech G710 Cherry MX Blue
Mouse
LogitechG502 Proteus Core
Internet Speed
Download: 119MBs /Upload 39.12MBs via Optimum 101 Ultra
Antivirus
MYOB
Browser
Firefox
Other Info
Cooling: EK-Supremecy MX Waterblock, XSPC AX360 Radiator, Swiftech MCP655 Series 12VDC D5 Pump, EK-RES x3 250 Reservoir, Primochill Ice Intensified Coolant, 11x AerocoolDS fans, Primochill Primoflex Avanced LRT Tubing
I guarantee that this piece of malware did not download and install on your computer all by its lonesome... read more about it -=> here
 

My Computer My Computer

Computer type
PC/Desktop
Computer Manufacturer/Model Number
LENOVO K450 @3.0GHZ
OS
64-bit Windows 8.1 Pro
CPU
Core(TM) i5 CPU 4330 Haswell @ 3.20GHz
Motherboard
LENOVO
Memory
12.00 GB
Graphics Card(s)
Intel(R) HD Graphics
Sound Card
Intel HD integtrated
Monitor(s) Displays
HP 25' ISP Monitor
Screen Resolution
1900/1020
Hard Drives
(1) ST1000DM003-1CH162 (2) Generic STORAGE DEVICE USB Device (3) Generic STORAGE DEVICE USB Device
Internet Speed
100mb down/10mb up
You have a program or file saved that re-infected you. Get rid of all torrrents and cracks!
Adware-VirtualGirl
 

My Computer My Computer

Computer type
PC/Desktop
Computer Manufacturer/Model Number
Bruce ... somewhere in his 40's
OS
Windows 7 Ultimate 32bit SP1
CPU
Intel(R) Core(TM)2 Quad CPU @ 2.40GHz, 2400 MHz
Motherboard
INTEL/D975XBX2
Memory
4 GB
Graphics Card(s)
ATI Radeon HD 2600 Pro
Monitor(s) Displays
Samsung SyncMaster 914v
Screen Resolution
1280 x 1024
Hard Drives
2/500GB each ... ST3500630AS ATA Device.
One is not connected
PSU
Rocketfish 700 W
Case
G.Skill Gigabyte Chassis
Keyboard
Standard PS/2 Keyboard
Mouse
Microsoft PS/2 Mouse
Internet Speed
DSL
Antivirus
Avira Internet Security
Browser
IE 11
Other Info
ATI HDMI Audio
Some people never learn... :p
 

My Computer My Computer

Computer type
PC/Desktop
Computer Manufacturer/Model Number
LENOVO K450 @3.0GHZ
OS
64-bit Windows 8.1 Pro
CPU
Core(TM) i5 CPU 4330 Haswell @ 3.20GHz
Motherboard
LENOVO
Memory
12.00 GB
Graphics Card(s)
Intel(R) HD Graphics
Sound Card
Intel HD integtrated
Monitor(s) Displays
HP 25' ISP Monitor
Screen Resolution
1900/1020
Hard Drives
(1) ST1000DM003-1CH162 (2) Generic STORAGE DEVICE USB Device (3) Generic STORAGE DEVICE USB Device
Internet Speed
100mb down/10mb up
I guarantee that this piece of malware did not download and install on your computer all by its lonesome... read more about it -=> here

How retarded could I be to download the file that appeared before every system failure that I had in the last day.

This a printscreen of all the programs installed since the reinstall, everything recovery related, and besides that Yahoo messenger and Winamp. NOTHING CRACKED.

And I recovered only PSD, eps and mp3 files.
 

Attachments

  • Capture.JPG
    Capture.JPG
    91.5 KB · Views: 68

My Computer My Computer

Computer Manufacturer/Model Number
Intel
OS
W7 X64 Ultimate, OSX, Linux
CPU
Intel Core i3 540M
Motherboard
Intel DH55TC
Memory
2GB Kingston DDR3 @ 1333MHz
Graphics Card(s)
nVidia gForce 250GTs, 512MB
Sound Card
OnBoard
Monitor(s) Displays
2xBenq E2200HDA
Screen Resolution
1920x1080
Hard Drives
Linux - 160GB WD 8MB Cache 7200rpm
OSX - 320GB Seagate Barracuda 16MB Cache 7200rpm
W7 - 80GB Seagate Barracude 8MB Cache 7200rpm
PSU
Antec 700W
Case
Cooler Master MidTower
Cooling
Standard
Keyboard
DeLux
Mouse
Logitech Wireless
Internet Speed
LAN/T1
Run an online scan using Kaspersky .... it won't disinfect you, but it will show what and where the infection is:

Go to http://www.kaspersky.com/kos/english/kavwebscan.html
a.. 1. In the new window that opens, click the "Accept" button to
accept the user agreement, install the ActiveX control, and download the
program.
b.. 2. When you get the Windows dialog asking if you want to install this
software, click the "Install" button.
c.. 3. When the "Update progress" line changes to "Ready" and the
"NEXT ->" button lights up with a
green arrow, click it.
d.. 4. Click on the "Scan Settings" button, and in the next window
select the "extended" database, and click Ok.
e.. 5. Under "Please select a target to scan:", click My Computer
to start the scan.
6. When the scan is finished, click the "Save as Text" button, and
save the file as kavscan.txt to your Desktop, close the Kaspersky On-line
Scanner window, and view the text in kavscan.txt.
 

My Computer My Computer

Computer type
PC/Desktop
Computer Manufacturer/Model Number
Bruce ... somewhere in his 40's
OS
Windows 7 Ultimate 32bit SP1
CPU
Intel(R) Core(TM)2 Quad CPU @ 2.40GHz, 2400 MHz
Motherboard
INTEL/D975XBX2
Memory
4 GB
Graphics Card(s)
ATI Radeon HD 2600 Pro
Monitor(s) Displays
Samsung SyncMaster 914v
Screen Resolution
1280 x 1024
Hard Drives
2/500GB each ... ST3500630AS ATA Device.
One is not connected
PSU
Rocketfish 700 W
Case
G.Skill Gigabyte Chassis
Keyboard
Standard PS/2 Keyboard
Mouse
Microsoft PS/2 Mouse
Internet Speed
DSL
Antivirus
Avira Internet Security
Browser
IE 11
Other Info
ATI HDMI Audio
I thought that this was a clean install.... You have directories going back to July ... and the infection could be hiding any where... the only way you are going to clean your system is to do a COMPLETE format and reinstall.... or you can continue to hit your head against a wall trying to find it ...
 

My Computer My Computer

Computer type
PC/Desktop
Computer Manufacturer/Model Number
LENOVO K450 @3.0GHZ
OS
64-bit Windows 8.1 Pro
CPU
Core(TM) i5 CPU 4330 Haswell @ 3.20GHz
Motherboard
LENOVO
Memory
12.00 GB
Graphics Card(s)
Intel(R) HD Graphics
Sound Card
Intel HD integtrated
Monitor(s) Displays
HP 25' ISP Monitor
Screen Resolution
1900/1020
Hard Drives
(1) ST1000DM003-1CH162 (2) Generic STORAGE DEVICE USB Device (3) Generic STORAGE DEVICE USB Device
Internet Speed
100mb down/10mb up
You need to back up your projects as soon as you can, from this running Windows installation - only data files of your projects, no programs or scripts at all.

After that, put your Windows DVD into your DVD ROM, and, FROM THAT disc, delete all partitions on your hard disk, format it (no need for a low level format) and reinstall Windows from scratch.

I hope you're not lying to us and it isn't really your Windows 7 installation that is corrupted.

Do not consider your PC clean just because antivirus scanners didn't find anything. Start anew, from a clean, clean disk.
 

My Computer My Computer

Computer Manufacturer/Model Number
Asus N73SV
OS
Windows 7 x64 Ultimate SP1
CPU
Core i7-2630QM
Motherboard
Intel HM 65
Memory
6 GB DDR3
Graphics Card(s)
Nvidia GT 540M / Intel HD 3000 - Optimus switching
Sound Card
HD Audio (Intel Azalia/Realtek) ALC269
Monitor(s) Displays
LED flat panel
Screen Resolution
1920 x 1080
Hard Drives
2x Seagate Momentus 640 GB - 1,28 TB in total
Internet Speed
4 MB/256 kbps
Other Info
External HDs

WD Elements 1,5 TB
WD MyBook 500 GB
Dban that HD

bezczyyea9yzi4cck.jpg
 

My Computer My Computer

Computer Manufacturer/Model Number
Colonel Travis 5000
OS
Black Label 7 x64
CPU
AMD Phenom II X6 1055t
Motherboard
GA-890FXA-UD5
Memory
8GB Corsair XMS3
Graphics Card(s)
Radeon HD 6790
Sound Card
X-FI Titanium Fatal1ty Pro
Monitor(s) Displays
Acer AJ15
Screen Resolution
1600x900
Hard Drives
OCZ Agility 3 SSD 120GB |
Corsair Force GT SSD 120 GB |
Barracuda 7200 SATA 300GB |
WD Caviar Green SATA 500GB
PSU
OCZ ModXStream 700W
Cooling
50 billion case fans
Internet Speed
35Mbps/35Mbps
I thought that this was a clean install.... You have directories going back to July ... and the infection could be hiding any where... the only way you are going to clean your system is to do a COMPLETE format and reinstall.... or you can continue to hit your head against a wall trying to find it ...


Those are the directory Windows created upon installation, I've been through two FULL formats of C: already. Either a low level format of everything will clear everything up, and if not it seems that someone with skills for whichever reason really wants to f**k me up.
 

My Computer My Computer

Computer Manufacturer/Model Number
Intel
OS
W7 X64 Ultimate, OSX, Linux
CPU
Intel Core i3 540M
Motherboard
Intel DH55TC
Memory
2GB Kingston DDR3 @ 1333MHz
Graphics Card(s)
nVidia gForce 250GTs, 512MB
Sound Card
OnBoard
Monitor(s) Displays
2xBenq E2200HDA
Screen Resolution
1920x1080
Hard Drives
Linux - 160GB WD 8MB Cache 7200rpm
OSX - 320GB Seagate Barracuda 16MB Cache 7200rpm
W7 - 80GB Seagate Barracude 8MB Cache 7200rpm
PSU
Antec 700W
Case
Cooler Master MidTower
Cooling
Standard
Keyboard
DeLux
Mouse
Logitech Wireless
Internet Speed
LAN/T1
c.) Always, always, ALWAYS have a Backup Plan in place. Whether you burn your data to DVD, have a backup HDD, RAID configuration, online storage, etc. This is probably the single most important best practice that many PC users still neglect until it's too late.

Not trying to nitpick...but;

RAID should never be confused with a backup. Even with a mirrored config, if you accidentally delete a file or get a virus which wipes out files..it gets both hard drives instantly. RAID is strictly for performance or for using multiple drives to make a large single drive...even with the various levels or redundancy.

If you have a spare hard drive at home, disconnect your normal drive. Use the secondary as a test hard drive...just load the OS from your OS disc and see what you get. If you have something right from step 1..your OS is obviously been compromised.
 

My Computer My Computer

Computer Manufacturer/Model Number
Self-Built in July 2009
OS
Windows 7 Ultimate x64
CPU
Intel Q9550 2.83Ghz OC'd to 3.40Ghz
Motherboard
Gigabyte GA-EP45-UD3R rev. 1.1, F12 BIOS
Memory
8GB G.Skill PI DDR2-800, 4-4-4-12 timings
Graphics Card(s)
EVGA 1280MB Nvidia GeForce GTX570
Sound Card
Realtek ALC899A 8 channel onboard audio
Monitor(s) Displays
23" Acer x233H
Screen Resolution
1920x1080
Hard Drives
Intel X25-M 80GB Gen 2 SSD
Western Digital 1TB Caviar Black, 32MB cache. WD1001FALS
PSU
Corsair 620HX modular
Case
Antec P182
Cooling
stock
Keyboard
ABS M1 Mechanical
Mouse
Logitech G9 Laser Mouse
Internet Speed
15/2 cable modem
Other Info
Windows and Linux enthusiast. Logitech G35 Headset.
Back
Top