What is this problem

jimbo45

New member
Guru
Gold Member
VIP
Local time
6:26 PM
Messages
5,941
Location
Hafnarfjörður IS
Hi all
A co-worker at the next desk bought his laptop to me in a panic -- he'd let his 12 year old use it -- BAD BAD idea -- if you've got young kids you should NEVER let them use a computer you NEED (for work or any other purpose).

However he seems to have some nasty problem

Every directory and sub directory has a 68 byte file in it called "directoryname.exe or subdirectoryname.exe

So for example if he had an .EXE file in application_z called application_z.exe this file has been replaced with the 68 byte file one.

He's lost a bit of data as well.

Apparently he was running AVAST so this obviously didn't do him any good.

I've told him -- Wipe the disk totally and re-install -- I can't think of anything else.

Seems like a really nasty piece of malware here -- very tiny and innocuous until you want to execute a program and nothing happens.

I don't know if this is a new threat or the resurrection of an old one - maybe so old that it's been dropped from AVAST's database.

I tried MSE on his machine - it wouldn't install due to the .EXE problem -- think he'd better re-install everything again.

Just to re-iterate - NO AV software is 100% effective, ensure you have good backups of your DATA and don't let your kids use your personal machines.

Cheers
jimbo
 

My Computer

Computer type
PC/Desktop
Computer Manufacturer/Model Number
Custom built, several laptops HP/ASUS
OS
Linux CENTOS 7 / various Windows OS'es and servers
CPU
Intel i7 Intel i5
Memory
8GB, 16GB
Graphics Card(s)
On Motherboard
Sound Card
Realtek HD audio
Monitor(s) Displays
Apple Cinema display, Samsung LCD
Screen Resolution
1920 X 1080
Hard Drives
4 X 1TB SATA
Mouse
Toshiba wireless laser
Internet Speed
> 20MB up
Hi, jimbo45.

What a mess! It goes to show how powerful malware is getting these days. Personally, I agree that he should get rid of everything and completely reformat his hard drive. I was, however, wondering if it'd be possible for you to ask your friend what his son was doing on the computer? Maybe it'd be a start if we knew what sites/downloads/content he's dealt with. I think that'd help a lot.

I wish you all the best, good luck.
 

My Computer

Computer Manufacturer/Model Number
Dell Inc./Inspiron 1545
OS
Microsoft Windows 7 Home Premium (32-Bit)
CPU
Genuine Intel(R) CPU 585 @ 2.16GHz
Motherboard
Dell Inc. 0G848F
Memory
4.00 GB
Graphics Card(s)
Mobile Intel(R) 45 Express Chipset Family
Sound Card
IDT High Definition Audio CODEC
Monitor(s) Displays
Generic PnP Monitor (15.3"vis, January 2008)
Hard Drives
250.02 Gigabytes Usable Hard Drive Capacity
PSU
Unknown
Case
Unknown
Cooling
Unknown
I'm not sure which one he got, but in any case it's an 'auto-run' piece of malware:
WinCE/Pmcryptic.A.intd
W32/Autorun.worm.ac

***Change all passwords using a known clean machine, then wipe and re-install Windows.
 

My Computer

Computer type
PC/Desktop
Computer Manufacturer/Model Number
Bruce ... somewhere in his 40's
OS
Windows 7 Ultimate 32bit SP1
CPU
Intel(R) Core(TM)2 Quad CPU @ 2.40GHz, 2400 MHz
Motherboard
INTEL/D975XBX2
Memory
4 GB
Graphics Card(s)
ATI Radeon HD 2600 Pro
Monitor(s) Displays
Samsung SyncMaster 914v
Screen Resolution
1280 x 1024
Hard Drives
2/500GB each ... ST3500630AS ATA Device.
One is not connected
PSU
Rocketfish 700 W
Case
G.Skill Gigabyte Chassis
Keyboard
Standard PS/2 Keyboard
Mouse
Microsoft PS/2 Mouse
Internet Speed
DSL
Antivirus
Avira Internet Security
Browser
IE 11
Other Info
ATI HDMI Audio
Hi all
A co-worker at the next desk bought his laptop to me in a panic -- he'd let his 12 year old use it -- BAD BAD idea -- if you've got young kids you should NEVER let them use a computer you NEED (for work or any other purpose).

Cheers
jimbo
.
Did his 12 year old put Limewire on the PC and surf the infested P2P networks? - whatever....I would agree that wiping the drive and reinstalling is the way to go. He's lucky if he can save most of his data, preferably to Flashdrive or external hard disk (not a CD/DVD) so it can be disinfected if necessary before copying it back to the system.
 

My Computer

Computer type
PC/Desktop
OS
Windows 7 x64
CPU
Intel Core2 Extreme Q6850 3.00GHz
Motherboard
EVGA 132-CK-NF79
Memory
8 GB
Graphics Card(s)
Radeon R7 260X
Sound Card
Xonar DS
Hard Drives
Hitachi Deskstar 1 tb
Back
Top