Jump to content
  • 0

Potential virus/worm on my computer, can't get it off with anti-virus software, urgently need help


Clearwater

Question

I am in a very dire situation here, guys. Last Friday, after getting home from my week at lycée, I found out that there was a worm on my computer which was slowly ravaging my system. I tried all sorts of anti-virus software (BitDefender, MalwareBytes Anti-Malware, etc.), but I think it's still on my computer, and I am at an utter loss on what to do. I need your help guys. I'll try my best to describe how the worm got on my computer and what it seems to be doing:

When I got home from lycée last Friday, I turned on my computer, inserted my pen drive (Flash drive for the Americans) and started to browse the stuff I had downloaded over the week.

About 10 to 15 minutes after I had inserted my pen drive, I noticed that the green light on the floppy drive (Yes, my computer has one of those things) at the front started to flash and make whirring sounds every few seconds, even though there was nothing inserted into it. Thinking that it was glitching, I disabled my floppy drive through the Device Manager.

When I reopened my pen drive, I had noticed that a new folder called 'RECYCLER' and 4 blank shortcuts seemingly leading to the Control Panel were created. Seeing as how the latter didn't do anything when I double-clicked on them, I deleted them straight off. However, when I refreshed a few seconds later, both the RECYCLER folder and the blank shortcuts reappeared. I ran a Chkdsk on my pen drive to make sure nothing was corrupted, and it said that it was perfectly fine.

When I glanced inside the RECYCLER folder, I noticed that there were randomly named .exes and .cpl files (The latter seems to be Control Panel extensions), which were being created 1 or 2 every five or ten seconds. Even if I deleted all of them, they would still come back. What I think is happening is an .exe that isn't appearing in the Task Manager is being ran, creating mentioned random .exe, then it runs the new .exe, which in turn creates another .exe, rinse and repeat, which was slowly taking up space on my pen drive. Even if I completely formatted the pen drive, the RECYCLER folder and blank shortcuts would still come up. So I asked my older brother to install MalwareBytes Anti-Malware onto my computer and do a full scan of everything, which revealed around 350 infected files across my computer hard and pen drives, which were promptly deleted and rebooted my computer.

However, when it restarted, it appeared the damage was already done. Not only was my pen drive was seemingly infected, it had now infected my internal hard drive (Luckily, I didn't have my external hard drive connected, which had +200GB worth of files on it). I don't know what the virus was doing to my hard drive, but every time I glanced at the exact free space left on it, it was going down 35 to 70 KB per 5 seconds. It didn't seem to do what it did to my pen drives though (It didn't create the RECYCLER folder, random .exes in it and blank shortcuts). So I cracked out my BitDefender Rescue CD, inserted it and restarted my computer, booting into the CD. From there, I did a full scan, which revealed around 350 infected files on my internal hard drive, most of which seemed to be VERY old .html files that I got years ago and I knew were clean. Because the CD was unable to disinfect them, I had to delete them. I ran another scan to make sure, and this time, it came up as clean. Seeing this, I now checked my pen drive and it reported that the random .exes and .cpl files that were being created were being reported as 'Virus.XGen'. I didn't like the sound of this, so I deleted the infected files straight off and formatted it twice through the CD's format tool into FAT32. Seeing how everything was now coming up clean, I rebooted my computer back into Windows and performed another MalwareBytes scan...

Only to find that the infected files were still there. I deleted them and ran another scan, this time on my pen drive. Despite me purging my system multiple times, it was still generating the randomly named .exes, .cpls and blank shortcuts.

Now at a loss on what to do, I followed this guide (http://malwaretips.com/blogs/malware-removal-guide-for-windows/ ), downloaded all the tools linked in it and followed the guide step-by-step: Rebooting into Safe Mode, using RKill to check for any malware processes it could terminate, etc.

And yet it still didn't fix the problem.

And here I find myself turning to the people I know to help me out. Me and my brother have agreed that if we just couldn't figure out how to remove the virus by this Thursday, he would completely format my internal hard drive and my pen drives and install Windows XP from scratch.

 

I need your help guys. Please. In case this information helps, I am using Windows XP Service Pack 3.

Link to comment
Share on other sites

14 answers to this question

Recommended Posts

  • 0

Hmm... That seems like something I had the other day. Although it probably was not the same virus, it did create the recycler folders and such on my flashdrive. What I did to solve the problem (or maybe solve the problem) was I used Avast antivirus, and it detected the virus and restarted my computer and went into the whole white text on a black background thing before windows starts. (Forgot what it was called.) It went and took off a lot of stuff that was infected, and it took like 3 hours to do so because it had so much crap on there. It deleted like, 5,000 HTML documents from Macromedia Flash, and a couple of files from my Steam games. (A.K.A, pretty much every single exe out there.) Try using Avast to scan stuff and if all fails, plug in your pendrive, add your important files, and clean it up with everything possible and then get out of there and do a clean install of Windows. (I heard that XP was the most vulnerable Windows OS out there, so I'd recommend something newer.) If it is the same virus that I had, it may be possible that when I sent you the link to the SwiftShader DLL file, it could have been infected. Although Avast didn't detect anything of the sorts with that file, that may be a reason you have the virus on the computer. I didn't even know I had the virus until a few days ago, when I upgraded to Windows 10 and Windows defender was like, "HOLY CRAP YOU HAVE MALWARE GO FIX IT OR SOMETHING *intense computer spasms* "

To sum it up, try the following.

Get Avast Antivirus (That's what I used)

Do a full system scan

Hope that it deletes stuff and solves the problem

 

If all else fails:

Plug in your pendrive and add all your personal and important stuff.

Scan it with everything possible to make sure your pendrive isn't infected.

Reinstall Windows. (Preferably something newer, since XP is the most vulnerable to viruses, and is no longer being supported by Microsoft.)

Before plugging your pendrive back in, make sure you have antivirus installed on your PC, so that way if something is still on it, it should take off the virus before it spreads to your computer.

 

Anyways, I hope that helps.

Link to comment
Share on other sites

  • 0

Hmm... That seems like something I had the other day. Although it probably was not the same virus, it did create the recycler folders and such on my flashdrive. What I did to solve the problem (or maybe solve the problem) was I used Avast antivirus, and it detected the virus and restarted my computer and went into the whole white text on a black background thing before windows starts. (Forgot what it was called.) It went and took off a lot of stuff that was infected, and it took like 3 hours to do so because it had so much crap on there. It deleted like, 5,000 HTML documents from Macromedia Flash, and a couple of files from my Steam games. (A.K.A, pretty much every single exe out there.) Try using Avast to scan stuff and if all fails, plug in your pendrive, add your important files, and clean it up with everything possible and then get out of there and do a clean install of Windows. (I heard that XP was the most vulnerable Windows OS out there, so I'd recommend something newer.) If it is the same virus that I had, it may be possible that when I sent you the link to the SwiftShader DLL file, it could have been infected. Although Avast didn't detect anything of the sorts with that file, that may be a reason you have the virus on the computer. I didn't even know I had the virus until a few days ago, when I upgraded to Windows 10 and Windows defender was like, "HOLY CRAP YOU HAVE MALWARE GO FIX IT OR SOMETHING *intense computer spasms* "

To sum it up, try the following.

Get Avast Antivirus (That's what I used)

Do a full system scan

Hope that it deletes stuff and solves the problem

 

If all else fails:

Plug in your pendrive and add all your personal and important stuff.

Scan it with everything possible to make sure your pendrive isn't infected.

Reinstall Windows. (Preferably something newer, since XP is the most vulnerable to viruses, and is no longer being supported by Microsoft.)

Before plugging your pendrive back in, make sure you have antivirus installed on your PC, so that way if something is still on it, it should take off the virus before it spreads to your computer.

 

Anyways, I hope that helps.

Thanks. I'll e-mail all this stuff to my brother and see if he can do anything. Keep the suggestions coming in guys, and I'll keep you posted on how it's going.

  • Like 1
Link to comment
Share on other sites

  • 0

1.) Get a new Flash Drive. Not the one you used before, completely new. Move everything of importance to that and scan it quick and remove.

2.) Second priority items move to like a online backup. Use only if sure the files were not infected and use the pendrive for the most important and vital files/pics/etc. I cannot stress that enough.

3.) System restore, system restore, system restore. If Sec. Programs and manual hunting have failed, revert to a time before you got the worm.

4.) Do not use the old pen drive. It sounds like what you downloaded onto that might have the virus. If anything bring to a computer specialist and get hem to safely disinfect that. 

  • Like 3
Link to comment
Share on other sites

  • 0

O.O that's quite the virus. My laptop had a pretty nasty one for a while. Then I slammed my laptop with every anti-virus/malware program I can get my hands on XD Ccleaner, avast, bitdefender, malwarebytes, etc etc etc (And MANY more I can't name, eventually it was bitdefender and avast that removed whatever I had, although when I uninstalled avast, my laptop started acting up again -.- So now I see avast more of a virus that gets petty when you remove it)

 

So if all else fails, just keep getting anti viruses until one just happens to work XP 

Link to comment
Share on other sites

  • 0

 

4.) Do not use the old pen drive. It sounds like what you downloaded onto that might have the virus.

Well, what I did while I was using the BitDefender Rescue CD was scan my old pen drive, disinfect/delete what it was saying was infected, then move everything to a temp file on the desktop of my hard drive. I haven't launched Windows on it since I moved everything across, so PROVIDING the moved files are still clean, my older brother'll bring down his spare external hard drive he uses for backups and stuff, relaunch the Rescue CD, scan the moved files and if they are clean, he'll then move them to his hard drive.

Link to comment
Share on other sites

  • 0

This is the kind of infection I wouldn't even bother trying to clean. You will probably never truly get rid of it.

I would do the following:

1 - Boot the machine from something other than the HDD, perhaps a Linux live CD.

2 - Back-up important NON-EXECUTABLE files to an external storage device (While running from the Live CD, of course). Use gparted on your linux live CD to nuke the existing partition on that flash drive if you wish to use it (or better yet, get a new one. Flash drives are cheap).

3 - Nuke it from orbit. Boot from your Windows CD and re-install. Make sure you destroy and recreate all partitions. This will force a new boot sector to be written. If you're really paranoid, you can boot a DBAN disk first and do DOD wipe.

4 - Scan your backup before restoring.

Edited by DZComposer
  • Like 4
Link to comment
Share on other sites

  • 0

This is the kind of infection I wouldn't even bother trying to clean. You will probably never truly get rid of it.

I would do the following:

1 - Boot the machine from something other than the HDD, perhaps a Linux live CD.

2 - Back-up important NON-EXECUTABLE files to an external storage device (While running from the Live CD, of course). Use gparted on your linux live CD to nuke the existing partition on that flash drive if you wish to use it (or better yet, get a new one. Flash drives are cheap).

3 - Nuke it from orbit. Boot from your Windows CD and re-install. Make sure you destroy and recreate all partitions. This will force a new boot sector to be written. If you're really paranoid, you can boot a DBAN disk first and do DOD wipe.

4 - Scan your backup before restoring.

Seems a little drastic, doesn't it? ...Well, if I really have no other option... I've forwarded your post to my older brother via e-mail; he'll take a look at it when he can. Also, would you need to burn DBAN to disk first, like with most .isos?

Link to comment
Share on other sites

  • 0

It's an hours of work to get results equation. You can spend two hours reformatting and be sure it's gone or you can spend four hours cleaning it up and not be sure it's gone. It's pretty much standard practice these days to just nuke machines infected with anything worse than adware for this very reason.

It looks like DBAN was actually bought-out and turned into adware by it's new owner. What a shame, that was a good tool. Nwipe on the Parted Magic live CD is pretty much the same thing. Note that you don't really have to do a wipe. Destroying the partition should be sufficient.

Edited by DZComposer
Link to comment
Share on other sites

  • 0

HOLD THE PHONE GUYS! I'VE MADE A BREAKTHROUGH!

 

I did some Googling around for my case and it turns out that I've been infected by the rather common 'Recycler Virus'. I've met some people online who've had EXACTLY the same problems as me (Blank shortcuts, random files in RECYCLER folder, etc.). I learned that the Recycler Virus is hard to be detected by standard anti-virus software such as MalwareBytes Anti-Malware, Avast, etc. I was told to use a bit of software called 'Recycler Death' and 'USBFix' to fix the problem. I'll download them on my old crappy 128MB pen drive (It's so small, I don't use it anymore), run them and see if it fixes the problem.

https://blog.udemy.com/how-to-remove-recycler-virus-2/

Link to comment
Share on other sites

  • 0

 

HOLD THE PHONE GUYS! I'VE MADE A BREAKTHROUGH!

 

I did some Googling around for my case and it turns out that I've been infected by the rather common 'Recycler Virus'. I've met some people online who've had EXACTLY the same problems as me (Blank shortcuts, random files in RECYCLER folder, etc.). I learned that the Recycler Virus is hard to be detected by standard anti-virus software such as MalwareBytes Anti-Malware, Avast, etc. I was told to use a bit of software called 'Recycler Death' and 'USBFix' to fix the problem. I'll download them on my old crappy 128MB pen drive (It's so small, I don't use it anymore), run them and see if it fixes the problem.

https://blog.udemy.com/how-to-remove-recycler-virus-2/

 

Did it work?

Edited by HOOBANANA
For some reason I had to do a quote.
Link to comment
Share on other sites

  • 0

I got an e-mail from my older brother yesterday saying he's wiped my computer clean: Completely reformatted my internal hard drive and installed a fresh batch of Windows 7 on it. We'll need to reinstall everything when I get back tonight, so for now, yes, the problem is fixed. I'll keep you updated on how everything's going and when I'm ready to use it again.

 

GAH, IT DELETED MY LUMINO CITY SAVES? NOW I HAVE TO REDO EVERYTHING AND GET BACK UP TO WHERE I WAS BEFORE I CAN RECORD AGAIN D:

Link to comment
Share on other sites

  • 0

Holy shit, man. I'm so sorry. I had to reinstall windows, but now I regret sending you those SwiftShader files so much.

Link to comment
Share on other sites

  • 0

Holy shit, man. I'm so sorry. I had to reinstall windows, but now I regret sending you those SwiftShader files so much.

Hey, it's not your fault; you didn't know it was infected as well as I. Either way, I'm good to go again.

Link to comment
Share on other sites

  • 0

Virus infection ain't what it used to be. Nowadays, it pretty much requires nuking it. I usually don't even bother trying to fix a machine unless restoring it would require abnormal effort.

Thankfully, actual viruses aren't as common these days. Nowadays, it's all spyware and adware.

Link to comment
Share on other sites

Create an account or sign in to comment

You need to be a member in order to leave a comment

Create an account

Sign up for a new account in our community. It's easy!

Register a new account

Sign in

Already have an account? Sign in here.

Sign In Now
×
×
  • Create New...