New and Used Car Talk Reviews Hot Cars Comparison Automotive Community

The Largest Car Forum in the Philippines

Page 1 of 2 12 LastLast
Results 1 to 20 of 23

Hybrid View

Previous Post Previous Post   Next Post Next Post
  1. Join Date
    May 2010
    Posts
    1,443
    #1
    recently nainfect laptop ko ng shortcut virus.
    pag sinaksak ko flashdrive at open, yung shortcut ng flashdrive lalabas. pag inopen ko yung shortcut, mag oopen ng new window, pero andun parin files ko. eto screenshot. pag inoepn ko yung file folder at shortcut ng flashdrive same lang laman.

    natry ko na iformat flashdrive ko pero ganun pa din e, may shortcut ulit lalabas pag inopen ko flashdrive ko. nasubukan ko narin yung attrib method: attrib -h -r -s /s /d f:\*.*

    may nakaranas nba ganito? pashare naman ano ginawa niyo para maalis yung shortcut virus. dalawang flashdrive na kasi nainfect e. ty!

    *im using Avira as my AV at malwarebytes & superantispyware pero wala sila madetect kahit full scan.
    full scan in Safe mode diko pa na try

  2. Join Date
    Nov 2009
    Posts
    3,522
    #2
    Your laptop is infected and now the host, i'd perform full hdd rebuild if i were you.

  3. Join Date
    May 2010
    Posts
    1,443
    #3
    thanks sir. yun din hinala ko e, nasa laptop ko na. dati kasi pag open ng flashdrive files agad lalabas, ngayon shortcut ng flashdrive. sana maayos ko pa ng di na kelangan i reformat laptop ko.

  4. Join Date
    Jun 2012
    Posts
    137
    #4
    try mo i run ng combofix and check natin ung log.

  5. Join Date
    Oct 2012
    Posts
    27,624
    #5
    We had the same issue company wide lol. you can't clean the usb since your OS is infected.

    Rootkit virus ata yan. Either contact avira or for quick repair...reinstall. ssd reinstalls are zippy fast.

  6. Join Date
    Nov 2009
    Posts
    3,522
    #6
    imageuploadedbytsikot-forums1432560195.180415.jpg
    Im now replacing my crappy norton with much better but still crap msse [emoji1] no issues yet using msse w/my other 2 lappies which were formerly using the company kaspersky.

  7. Join Date
    May 2010
    Posts
    1,443
    #7
    *mika: dl'ing combofix.
    *12vdc: sir natry ko narin mic essent, ok siya. nod32 ok din.

    - - - - - - - - - - - - - - - - - - - - - -

    *mika: dl'ing combofix.
    *12vdc: sir natry ko narin mic essent, ok siya. nod32 ok din.

  8. Join Date
    Dec 2005
    Posts
    624
    #8
    Try smadav, small footprint, effective and most of all, free.

  9. Join Date
    Oct 2002
    Posts
    15,528
    #9
    had encountered that one month ago sa PC namin sa house.
    what i did is to boot the computer in safe mode, run MSE and Malwarebytes.
    boot on normal mode.
    wala na.

    yung USB mo, i format mo na din habang naka safe mode ka.

    - - - - - - - - - - - - - - - - - - - - - -

    had encountered that one month ago sa PC namin sa house.
    what i did is to boot the computer in safe mode, run MSE and Malwarebytes.
    boot on normal mode.
    wala na.

    yung USB mo, i format mo na din habang naka safe mode ka.

  10. Join Date
    Oct 2002
    Posts
    40,599
    #10
    How about yun laging na redirect yun browser sa mga "powered by xxxx" or meron lumalabas na mga for sale ads sa girlie ng browser. How to remove those?

  11. Join Date
    Oct 2002
    Posts
    15,528
    #11
    Quote Originally Posted by shadow View Post
    How about yun laging na redirect yun browser sa mga "powered by xxxx" or meron lumalabas na mga for sale ads sa girlie ng browser. How to remove those?
    install a browser based adblocker bro.

  12. Join Date
    May 2006
    Posts
    8,357
    #12
    Quote Originally Posted by shadow View Post
    How about yun laging na redirect yun browser sa mga "powered by xxxx" or meron lumalabas na mga for sale ads sa girlie ng browser. How to remove those?
    anong browser mo? install ka ng adblock plus or ublock

  13. Join Date
    Oct 2002
    Posts
    40,599
    #13
    Quote Originally Posted by 1D4LV View Post
    install a browser based adblocker bro.
    Thanks...

    Quote Originally Posted by Syuryuken View Post
    anong browser mo? install ka ng adblock plus or ublock
    Firefox...

    Meron na ako Adblock plus eh, ganun pa rin

    Nag simul ayan nun inalis ko Symantec eh

  14. Join Date
    Oct 2002
    Posts
    15,528
    #14
    Quote Originally Posted by shadow View Post
    Thanks...



    Firefox...

    Meron na ako Adblock plus eh, ganun pa rin

    Nag simul ayan nun inalis ko Symantec eh
    baka mali ang configuration ng Adblock Plus mo bro...... It works for me.

    - - - - - - - - - - - - - - - - - - - - - -

    Quote Originally Posted by shadow View Post
    Thanks...



    Firefox...

    Meron na ako Adblock plus eh, ganun pa rin

    Nag simul ayan nun inalis ko Symantec eh
    baka mali ang configuration ng Adblock Plus mo bro...... It works for me.

  15. Join Date
    Oct 2002
    Posts
    40,599
    #15
    Quote Originally Posted by 1D4LV View Post
    baka mali ang configuration ng Adblock Plus mo bro...... It works for me.

    - - - - - - - - - - - - - - - - - - - - - -



    baka mali ang configuration ng Adblock Plus mo bro...... It works for me.
    Paano ba dapat configuration? Hinde ko run ma add yun ads Sa Adblock dati iadd ko Lang po na eh

  16. Join Date
    Aug 2003
    Posts
    9,720
    #16
    the symptoms are quite similar to what we had last year sa office. Nakita ko rin to on a cousin's flash drive. Eto ba yung gumagawa ng fake thumbs.db and desktop.ini, and me hidden file na *init* ?

    You can see the files by opening a command prompt and running "dir/a/p" on the flash drive.

    If you need to copy files from that flash drive, stick it into a linux box. The file managers typically list out all files, You may see a folder with no name, that's where your files are. In our case i just made sure i didn't copy any autorun.inf, desktop.ini, thumbs.db, *.init files. You can quickly do this by creating a bootable live USB of Ubuntu or Fedora. You will get the graphical UI so no Linux skills are necessary really(but do be careful what you delete).i try to keep one handy in case Windows goes awry.



    i think the way it works is that the malware hides all the files on the flash drive under a folder with an unprintable name; you will be tricked into clicking the shortcut, which loads the malware code, hidden in the .init, desktop.ini, and thumbs.db files. afaik the two files get read by Windows Explorer, inadvertently running the code.

    Better to check with your IT guys, but just to be safe, i deleted all desktop.ini and thumbs.db files on the flash drive.

    If possible, back up and go for complete reformat. Even the better AVs today can't totally clean our malware. And don't forget to install AV.

    afaik there should be some registry settings in Windows that prevents autorun,inf, desktop.ini and thumbs.db from being read automatically.
    Last edited by badkuk; May 26th, 2015 at 02:17 PM.

  17. Join Date
    Oct 2002
    Posts
    15,528
    #17
    Quote Originally Posted by badkuk View Post
    the symptoms are quite similar to what we had last year sa office. Nakita ko rin to on a cousin's flash drive. Eto ba yung gumagawa ng fake thumbs.db and desktop.ini, and me hidden file na *init* ?

    You can see the files by opening a command prompt and running "dir/a/p" on the flash drive.

    If you need to copy files from that flash drive, stick it into a linux box. The file managers typically list out all files, You may see a folder with no name, that's where your files are. In our case i just made sure i didn't copy any autorun.inf, desktop.ini, thumbs.db, *.init files. You can quickly do this by creating a bootable live USB of Ubuntu or Fedora. You will get the graphical UI so no Linux skills are necessary really(but do be careful what you delete).i try to keep one handy in case Windows goes awry.



    i think the way it works is that the malware hides all the files on the flash drive under a folder with an unprintable name; you will be tricked into clicking the shortcut, which loads the malware code, hidden in the .init, desktop.ini, and thumbs.db files. afaik the two files get read by Windows Explorer, inadvertently running the code.

    Better to check with your IT guys, but just to be safe, i deleted all desktop.ini and thumbs.db files on the flash drive.

    If possible, back up and go for complete reformat. Even the better AVs today can't totally clean our malware. And don't forget to install AV.

    afaik there should be some registry settings in Windows that prevents autorun,inf, desktop.ini and thumbs.db from being read automatically.

    errrr. may not work bro.... the malware attaches itself to the windows registry so there is a need to have the registry not load in full (via safe mode) and clean...

  18. Join Date
    Aug 2003
    Posts
    9,720
    #18
    Quote Originally Posted by 1D4LV View Post
    errrr. may not work bro.... the malware attaches itself to the windows registry so there is a need to have the registry not load in full (via safe mode) and clean...
    Sorry, i meant setting the disable autorun thing *before* you get infected. You can apply this on the new installation you will be doing.
    Last edited by badkuk; May 26th, 2015 at 05:56 PM.

  19. Join Date
    May 2010
    Posts
    1,443
    #19
    UPDATE: after performing full system scan in safe mode, "parang" ok na ulit laptop ko.
    pag sinaksak ko na flashdrive ko then open, files na agad lalabas, dina yung shortcut ng flashdrive.
    sana nga ok na ulit.
    eto pala isa sa naresearch ko, Help me Remove rundll32.exe Virus - Microsoft Community
    try ko din sana MRT ( malicious removal tool) after windows update and install May 2015 mrt pero mukhang ok naman na laptop ko. ty sa lhat ng suggestion, di na ako nag reformat :D

  20. Join Date
    May 2010
    Posts
    1,443
    #20
    *shadow: Lagi siguro sa adult site kaya ganyan, dineretso na agad sa favorite site. Haha. Jk!
    Performing full scan in safe mode (avira,malwarebytes, superantispyware) pag dipa naayos to reformat ko na.

Page 1 of 2 12 LastLast

Tags for this Thread

Usapang Virus