Jump to content
CCleaner Community Forums
Sign in to follow this  
rridgely

Just fixed a nasty virus

Recommended Posts

A family member brought over a laptop with a nasty virus. They told me the virus started out by telling them that their hard drive was failing and then all of their files, shortcuts, desktop background, and even start menu links disappeared. The virus hid every file on the computer. I had never seen anything quite like this one.

 

The remedy was to run Malware Bytes in safe mode to remove the virus and this tool to unhide the files:

http://www.bleepingcomputer.com/download/unhide/

 

The machine had Microsoft Security Essentials installed but it didn't catch the viruses. It did flag a few files, but MBAM was the only thing that cleaned it up.

Share this post


Link to post
Share on other sites

Are we talking MSE 2.x or 4.x? Yes I know MSE doesn't have the best detection rate. Glad to hear you cleaned it out. I also use MBAM and Superantispyware too.

Share this post


Link to post
Share on other sites

If I were you I'd also definately run Hitman Pro (trial but you can manually deal with stuff found), and also perhaps Comodo Cloud Scanner (freeware).

Share this post


Link to post
Share on other sites

The machine did have the latest MSE installed. It would flag a file at boot up but couldn't remove it permanently.

I had never seen a virus that will hide all the files on a computer before, the desktop looked crazy when I booted it up! I cant try any other scans thought because I backed up and formatted the machine. The laptop had a recovery partition, so this seemed like the easiest way to get a clean and safe windows install.

 

I have bookmarked hitman pro, seems interesting. I think I remember that program a while ago needing to have a bunch of different programs installed, now its getting all of their definitions from the cloud?(just from their description it what it seems like).

Share this post


Link to post
Share on other sites

Use Hirens to do an Eset Online Scan if you cannot use safe mode with networking.

 

Also rridgely when using HMPro if you hold down the Ctrl key and double click the installer it kills all running processes so it can do its job without interfence (like rkill)

 

Don't know if you are aware that MBAM, free and paid, has rkill built in sort of now (start-all progs-mbam-tools-chameleon)

Share this post


Link to post
Share on other sites

I have seen viruses that hide all the files quite a few times.

 

Yes, it does look weird. The start menu folders, desktop folders, & other places are affected because their folders are marked hidden.

 

Glad you got it sorted out!

Share this post


Link to post
Share on other sites

Join the conversation

You can post now and register later. If you have an account, sign in now to post with your account.

Guest
Reply to this topic...

×   Pasted as rich text.   Paste as plain text instead

  Only 75 emoji are allowed.

×   Your link has been automatically embedded.   Display as a link instead

×   Your previous content has been restored.   Clear editor

×   You cannot paste images directly. Upload or insert images from URL.

Loading...
Sign in to follow this  

×
×
  • Create New...