Closed Thread
Results 1 to 7 of 7

Hybrid View

  1. #1
    Join Date
    Feb 2012
    Location
    Ontario, Canada
    Posts
    3

    Exclamation [Inactive] Virus setting all files to 0kb!

    I have a huge virus problem on my hands guys. Some virus is setting ALL of my files to 0 kb to make it look like my hard disk is empty. I've tried to roll back to a system restore which does work, but the virus seems to start when windows starts up so it started to do the same thing after the system restore.

    I have restores left and I'm now in safe mode running scans with avast . I'm not sure if I will find anything because the virus isn't loaded when running safe mode. I need some help badly, is there someway I can try to catch it before windows starts? I've already tried a scheduled boot-time scan with avast and no luck.

  2. #2
    Join Date
    Apr 2000
    Location
    Elma,Wa.
    Posts
    48,399
    Follow the instructions at
    http://discussions.virtualdr.com/sho...d.php?t=167915

    Malwarebytes will install and update using Safe Mode with Networking.
    SMILE
    and post back. Let us know if it worked.
    [ Book mark this post to find it again]

  3. #3
    Join Date
    Feb 2012
    Location
    Ontario, Canada
    Posts
    3
    Is Malware-bytes a good antivirus remover? I thought it was for spyware only.

  4. #4
    Join Date
    Apr 2000
    Location
    Elma,Wa.
    Posts
    48,399
    Yes, it is for spyware and spyware can be worse the a virus.

    Fact is both can be horrible.
    SMILE
    and post back. Let us know if it worked.
    [ Book mark this post to find it again]

  5. #5
    Join Date
    Feb 2012
    Location
    Ontario, Canada
    Posts
    3
    Ok, I ran a scan and this is what it found. I'm now restoring again and ill post back to see if my files have been restored and virus or spyware hopefully removed.
    Attached Files

  6. #6
    Join Date
    Apr 2000
    Location
    Elma,Wa.
    Posts
    48,399
    Please post the logs as we have folks who will not open attachments. Plus they are easier to read.

    Malwarebytes Anti-Malware (Trial) 1.60.1.1000
    www.malwarebytes.org

    Database version: v2012.02.19.04

    Windows 7 Service Pack 1 x64 NTFS (Safe Mode/Networking)
    Internet Explorer 9.0.8112.16421
    Nick :: NICK-PC [administrator]

    Protection: Disabled

    19/02/2012 3:31:39 PM
    mbam-log-2012-02-19 (15-34-52).txt

    Scan type: Quick scan
    Scan options enabled: Memory | Startup | Registry | File System | Heuristics/Extra | Heuristics/Shuriken | PUP | PUM
    Scan options disabled: P2P
    Objects scanned: 229613
    Time elapsed: 2 minute(s), 17 second(s)

    Memory Processes Detected: 0
    (No malicious items detected)

    Memory Modules Detected: 0
    (No malicious items detected)

    Registry Keys Detected: 0
    (No malicious items detected)

    Registry Values Detected: 2
    HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\Explorer\Run|Nvidia (Trojan.Agent) -> Data: C:\Program Files (x86)\Defender\csrss.exe -> No action taken.
    HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Run|Realtek (Trojan.Agent) -> Data: C:\Program Files (x86)\Defender\csrss.exe -> No action taken.

    Registry Data Items Detected: 0
    (No malicious items detected)

    Folders Detected: 0
    (No malicious items detected)

    Files Detected: 4
    C:\Users\Nick\Downloads\ChromePass.exe (PUP.ChromePasswordTool) -> No action taken.
    C:\Users\Nick\Downloads\Codec-C.exe (Affiliate.Downloader) -> No action taken.
    C:\Users\Nick\Downloads\dvp_install.exe (Trojan.Spambot) -> No action taken.
    C:\Users\Nick\AppData\Local\Temp\xxxyyyzzz.dat (Malware.Trace) -> No action taken.

    (end)
    SMILE
    and post back. Let us know if it worked.
    [ Book mark this post to find it again]

  7. #7
    Join Date
    Apr 2000
    Location
    Elma,Wa.
    Posts
    48,399
    > No action taken.


    The instructions said to fix what was found. Plus, by using the restore, you just re-infected your computer.

    Rerun mbam [malwarebytes, fix what it found and POST the log.
    SMILE
    and post back. Let us know if it worked.
    [ Book mark this post to find it again]

Thread Information

Users Browsing this Thread

There are currently 1 users browsing this thread. (0 members and 1 guests)

     

Bookmarks

Posting Permissions

  • You may not post new threads
  • You may not post replies
  • You may not post attachments
  • You may not edit your posts