VIRUS has formatted hard drive

There has been a lot of that going around lately. I cleaned one off a friends computer two weeks ago, then from my housemates rig just a few days back. For the housemate, I got tired of fighting it and just used a day-old Macrium Reflect image.

This might be a good time to put in a plug for having some type of regular backup system. With the friend, it took an entire evening of sorting things out. For the housemate with the drive image, boom - 30 minutes and I was done. :)

(29 minutes of which I spent wandering off to do something else while it restored automatically.) ;)
 

My Computer My Computer

At a glance

Main - Windows 7 Pro SP1 64-Bit; 2nd - Window...Main - Core i7 2600K; 2nd - Core i7 920Main - 16GB Corsair Vengeance; 2nd - 12GB Cor...Main - XFX Radeon 6870 1GB; 2nd - XFX Radeon ...
Computer Manufacturer/Model Number
Self
OS
Main - Windows 7 Pro SP1 64-Bit; 2nd - Windows Server 2008 R2
CPU
Main - Core i7 2600K; 2nd - Core i7 920
Motherboard
Main - Asus P8Z68-V Pro/Gen3; 2nd - Gigabyte GA-EX58-UDR3
Memory
Main - 16GB Corsair Vengeance; 2nd - 12GB Corsair Vengeance
Graphics Card(s)
Main - XFX Radeon 6870 1GB; 2nd - XFX Radeon 4870 1GB
Sound Card
Both: Onboard Realtek Azalia
Monitor(s) Displays
Main - Hann 25" + I-INC 25" + Acer 23"; 2nd - Upgrading Soon
Screen Resolution
Main - 1920x1080 (All Three Monitors); 2nd - Upgrading Soon
Hard Drives
Main - (1) Crucial M4 128GB (Boot)
Main - (1) Seagate 2TB 64MB Cache (Data)
Main - (1) Seagate 2TB 64MB Cache (Data Backup)
2nd - (1) Intel X25-M SSD 80GB (Boot)
2nd - (3) Seagate 1TB 32MB Cache (Data Backup)
2nd - (1) Seagate 320GB (Because)
PSU
Main - OCZ 600W Modular; 2nd - OCZ 600W
Case
Main - Thermaltake Element G; 2nd - NZXT something or other
Cooling
Main - Corsair H80; 2nd - Prolimatech Megahalems
Keyboard
Main - Razer Reclusa; 2nd - Old MS Keyboard
Mouse
Main - Logitech MX Revolution; 2nd - Old MS Mouse
Internet Speed
20Mbps Time-Warner Cable
ive just used roolback rx to rollback to the 20/11/2011 the day after the vrius attacked my pc what would you recommend the best steps would be to recover please and oohh yeah what was you doing ;) haha
 

My Computer My Computer

At a glance

Windows 7 Home Premium 64bit
OS
Windows 7 Home Premium 64bit
just done a hitmanpro 3.6.0 scan and it found this file Master Boot Record (Sector 0) C:$MBR red and white X Bootkit Win64/Bootkit this did not come up on the first scan i did when i got hitman pro 3.6.0 do i replace this or just ignore it
 

My Computer My Computer

At a glance

Windows 7 Home Premium 64bit
OS
Windows 7 Home Premium 64bit
just done a hitmanpro 3.6.0 scan and it found this file Master Boot Record (Sector 0) C:$MBR red and white X Bootkit Win64/Bootkit this did not come up on the first scan i did when i got hitman pro 3.6.0 do i replace this or just ignore it

Replace it ! but be carefull :p the MBR is needed to boot into Windows
 

My Computer My Computer

At a glance

Windows 7 Home Premium x64Core i7 2600K4GB DDR3 Kingston HyperXGigabyte GTX 670
Computer Manufacturer/Model Number
Homebuilt
OS
Windows 7 Home Premium x64
CPU
Core i7 2600K
Motherboard
Asus P8Z77-V LX
Memory
4GB DDR3 Kingston HyperX
Graphics Card(s)
Gigabyte GTX 670
Sound Card
Realtek HD Audio
Monitor(s) Displays
Delium Monitor
Screen Resolution
1360 x 768
Hard Drives
C: (500GB)
PSU
Corsair 620W
Case
Antec
Cooling
Cooling Master
Keyboard
Logitech
Mouse
Logitech wireless mouse M 505
Internet Speed
60MBPS
it is saying Contains Characteristics of an identified secruity risk do i rep;lace it or ignore it
 

My Computer My Computer

At a glance

Windows 7 Home Premium 64bit
OS
Windows 7 Home Premium 64bit
it is saying Contains Characteristics of an identified secruity risk do i rep;lace it or ignore it

Replace it with Hitman Pro (should work)
 

My Computer My Computer

At a glance

Windows 7 Home Premium x64Core i7 2600K4GB DDR3 Kingston HyperXGigabyte GTX 670
Computer Manufacturer/Model Number
Homebuilt
OS
Windows 7 Home Premium x64
CPU
Core i7 2600K
Motherboard
Asus P8Z77-V LX
Memory
4GB DDR3 Kingston HyperX
Graphics Card(s)
Gigabyte GTX 670
Sound Card
Realtek HD Audio
Monitor(s) Displays
Delium Monitor
Screen Resolution
1360 x 768
Hard Drives
C: (500GB)
PSU
Corsair 620W
Case
Antec
Cooling
Cooling Master
Keyboard
Logitech
Mouse
Logitech wireless mouse M 505
Internet Speed
60MBPS
hitman pro came up with the file and deleted it so its telling me to reboot now and just run that kapersky and found 4 threats so gna reboot now
 

My Computer My Computer

At a glance

Windows 7 Home Premium 64bit
OS
Windows 7 Home Premium 64bit
just loaded system restore and found 1 from 19/11/11 13:07 restore operation type Undo would i be able to use that to restore pc as this is the only 1 that i have that i think was there before the virus attack
 
Last edited:

My Computer My Computer

At a glance

Windows 7 Home Premium 64bit
OS
Windows 7 Home Premium 64bit
just tried to do a system restore and it came up saying system restore failed while mounting the registry from system restore point 0x800703f1 how can i fix it
 

My Computer My Computer

At a glance

Windows 7 Home Premium 64bit
OS
Windows 7 Home Premium 64bit
just opened a word document and it changed it all to ADVAPI32.dll KERNEL32.dllUSER32.dll msvcrt.dll ole32.dll ntdll.dll COMCTL32.dll also my folder lock files ive found some called flkw type and they wont open with folder lock and most of the files on the recovery have a red D on the file how do i fix this please
 

My Computer My Computer

At a glance

Windows 7 Home Premium 64bit
OS
Windows 7 Home Premium 64bit
just opened a word document and it changed it all to ADVAPI32.dll KERNEL32.dllUSER32.dll msvcrt.dll ole32.dll ntdll.dll COMCTL32.dll also my folder lock files ive found some called flkw type and they wont open with folder lock and most of the files on the recovery have a red D on the file how do i fix this please

It isn't smart to do System Restores at the moment as the virus has taken over al the restore points ...
 

My Computer My Computer

At a glance

Windows 7 Home Premium x64Core i7 2600K4GB DDR3 Kingston HyperXGigabyte GTX 670
Computer Manufacturer/Model Number
Homebuilt
OS
Windows 7 Home Premium x64
CPU
Core i7 2600K
Motherboard
Asus P8Z77-V LX
Memory
4GB DDR3 Kingston HyperX
Graphics Card(s)
Gigabyte GTX 670
Sound Card
Realtek HD Audio
Monitor(s) Displays
Delium Monitor
Screen Resolution
1360 x 768
Hard Drives
C: (500GB)
PSU
Corsair 620W
Case
Antec
Cooling
Cooling Master
Keyboard
Logitech
Mouse
Logitech wireless mouse M 505
Internet Speed
60MBPS
so what is best bet to do then as ive not restored it or restored any files off of that EASUS data recovery wizard and it has everything up including the windows folders etc...
 

My Computer My Computer

At a glance

Windows 7 Home Premium 64bit
OS
Windows 7 Home Premium 64bit
download and run a linux live cd. Access your important files with the file browser. Copy and paste to a usb an re install.
 

My Computer My Computer

At a glance

Windows Seven, UbuntuIntelIntel
Computer Manufacturer/Model Number
Samsung rv520
OS
Windows Seven, Ubuntu
CPU
Intel
Graphics Card(s)
Intel
why would i use a linux live cd if im on windows 7 though??
 

My Computer My Computer

At a glance

Windows 7 Home Premium 64bit
OS
Windows 7 Home Premium 64bit
why would i use a linux live cd if im on windows 7 though??

To copy over your data i'm sorry to say this but I think all your data you can't recover by now is just lost a Clean Windows 7 reinstall is strongly recommend :(
 

My Computer My Computer

At a glance

Windows 7 Home Premium x64Core i7 2600K4GB DDR3 Kingston HyperXGigabyte GTX 670
Computer Manufacturer/Model Number
Homebuilt
OS
Windows 7 Home Premium x64
CPU
Core i7 2600K
Motherboard
Asus P8Z77-V LX
Memory
4GB DDR3 Kingston HyperX
Graphics Card(s)
Gigabyte GTX 670
Sound Card
Realtek HD Audio
Monitor(s) Displays
Delium Monitor
Screen Resolution
1360 x 768
Hard Drives
C: (500GB)
PSU
Corsair 620W
Case
Antec
Cooling
Cooling Master
Keyboard
Logitech
Mouse
Logitech wireless mouse M 505
Internet Speed
60MBPS
download and run a linux live cd. Access your important files with the file browser. Copy and paste to a usb an re install.

The only problem is that all of the files are corrupt. I think it's time to cut your losses and do a clean install after formatting the drive.

A few suggestions for once your back up and running: keep a periodic external backup of your files andhave windows create backup system images, once you get it set up you won't need to touch it ever again. Also, stop using avast, I highly recommend Microsoft security essentials plus it's free. Finally, be more careful when browsing the web, there's a lot of nasty stuff out there and you wouldn't want to go through this ordeal again.

Best of luck and happy new year
 

My Computer My Computer

At a glance

Windows 7 Ultimate x64Intel Core i7 740QMG. Skill 8GB (2x4GB) DDR3 @ 1333MHznVidia GeForce GTX 460M
Computer Manufacturer/Model Number
Alienware m15x (my main PC)
OS
Windows 7 Ultimate x64
CPU
Intel Core i7 740QM
Memory
G. Skill 8GB (2x4GB) DDR3 @ 1333MHz
Graphics Card(s)
nVidia GeForce GTX 460M
Sound Card
IDT Integrated HD Audio
Monitor(s) Displays
15.6HDF+ WLED
Screen Resolution
1600 x 900
Hard Drives
240GB OCZ Agility 3 SSD
Mouse
Razer Orochi
Internet Speed
50Mb/s
Other Info
Intel Ultimate N Wi-Fi Link 5300, Bluetooth 2.0
ive found alot of my files but the image files are saying invalid image please cna you tell me a way to fix it please as ive had these pictures for over 10 years onw please thank you
 

My Computer My Computer

At a glance

Windows 7 Home Premium 64bit
OS
Windows 7 Home Premium 64bit
These files are likely lost because you kept using the computer after the incident which probably caused most of your data to be overwritten or corrupt, not to mention the damage done by the infection itself
 

My Computer My Computer

At a glance

Windows 7 Ultimate x64Intel Core i7 740QMG. Skill 8GB (2x4GB) DDR3 @ 1333MHznVidia GeForce GTX 460M
Computer Manufacturer/Model Number
Alienware m15x (my main PC)
OS
Windows 7 Ultimate x64
CPU
Intel Core i7 740QM
Memory
G. Skill 8GB (2x4GB) DDR3 @ 1333MHz
Graphics Card(s)
nVidia GeForce GTX 460M
Sound Card
IDT Integrated HD Audio
Monitor(s) Displays
15.6HDF+ WLED
Screen Resolution
1600 x 900
Hard Drives
240GB OCZ Agility 3 SSD
Mouse
Razer Orochi
Internet Speed
50Mb/s
Other Info
Intel Ultimate N Wi-Fi Link 5300, Bluetooth 2.0
today ive not used the pc and only thing i have done is a rollback rx to the 20/11/11 and that is it some of them are viewable more since ive done this
 

My Computer My Computer

At a glance

Windows 7 Home Premium 64bit
OS
Windows 7 Home Premium 64bit
just found a good program review would you be able to try it for me its called FileRestore profressinal 4.2.1 please as the reviews are really good off some people please
 

My Computer My Computer

At a glance

Windows 7 Home Premium 64bit
OS
Windows 7 Home Premium 64bit
Back
Top