Windows XP Recovery Virus - Making its rounds.

21 replies
  • OFF TOPIC
  • |
I saw a few friends mention it wand while looking for a wordpress plugin...whammo. Got me.

It got right by Malwarebytes, PAID/LIVE version and as i do a full scan now...can see MB found it. Found it....well, that meaans it's a knoiwn virus so HOW COME IT DIDN'T CATCH IT.

Anyhow, make sure your MB defs are up to date.

Virus throws all these awful error messages, mainly YOUR HARD DRIVE FAILED
  • Profile picture of the author HankTheCowDog
    that is one nasty piece of malware. Blacks out your screen and hides all your programs, does not let you start any programs and you can boot into safe mode, but also no worky on the programs.

    Tried for a few to fix it....MB deleted it, but it was still there. A friends said he runs Norton ghost and it whacked his backup disc images too.

    this morning i admitted defeat and pulled out the Acronis rescue disc and loaded a clean disc image. 20 minutes later, back to normal. I wanted to roll back to an earlier image anyways

    The moral to the story here.....you better have a DISC based recovery program...any software only, where you cannot boot off a CD...and you might be DONE.
    {{ DiscussionBoard.errors[3933414].message }}
  • Profile picture of the author yukon
    Banned
    It %$#@*! got me today!

    I'm running an AVG/Linux CD [link] for the last couple of hours, I have so much crap on this PC (lol), it's taking forever.

    The virus keeps shutting down my old XP PC, lucky I have a backup of everything on an external hard drive that I only connect during backups, it wasn't connected when I got hit.

    I'll clean it with the linux disk, reboot, & run MBAM.

    I'm on a new Win7/PC that I only use to play Chess.
    {{ DiscussionBoard.errors[3933476].message }}
    • Profile picture of the author HankTheCowDog
      It's prettyu nasty...the info I saw over at bleeping computer said remnants could not be fixed, my friend said that too.

      MB deleted about 6 programs associated with it...but it came back.

      I run a dual boot XP/Ubuntu machine, acronis true Image, an external hard drive (which houses the Acronis disc images), and SOS Cloud backup for my data.

      at this point I'm wondering why pay for the "live" version of MB if the threat is known, but gets by anyways.

      When the virus first hit i saw the java window and said ....fugggg...and a few minutes later I got a hard drive failure message that didn'l llok right. Sure enough, I booted into Ubuntu and the hard disk was fine. But since I was in ubuntu i went ahead and made redudant copies of everything, lol.

      Good luck with it.
      {{ DiscussionBoard.errors[3933538].message }}
  • Profile picture of the author yukon
    Banned
    Yep, I got the same fake hard drive failure popups, then it started rebooting the PC.

    Even If you can't remove the virus, you should be able to burn a linux CD on another PC then boot from the linux/CD to retrieve any files. I've had to do that a couple of years ago, I still saved all my files that I needed, then formatted the C drive. It sucks & takes a long time to get cleaned up.

    I'm still running a linux cleanup CD as I post this comment.

    This virus kept blocking Ctrl+Alt+Delete, I've never seen that done before on a virus.

    It's one nasty mofo!
    {{ DiscussionBoard.errors[3933567].message }}
    • Profile picture of the author HankTheCowDog
      I'm up and running. Well, actually, I'm still trying out different drive images. Typing on the netbook now. Edit: I found a date I like and my Ubuntu install came out unscathed.

      With acronis it only took 20 minutes to return to normal. Last night I was playing around trying to fix the virus with my mad computer skills....NOT!

      Acronis true Image is worth its weight in gold. Except for Iolo system mechanic, I have never ran across a more productive and life saving program. Its saved my tail at least 3 times in the past year alone.

      Check back, let me know how the clean up went.
      {{ DiscussionBoard.errors[3933715].message }}
  • Profile picture of the author yukon
    Banned
    Update, the link I posted above didn't phase the virus.

    I rebooted into win/xp & ran RKILL from a USB drive.

    Now running MBAM, so far so good...
    {{ DiscussionBoard.errors[3933717].message }}
  • Man, this one has really been making the rounds lately. If either of you guys remember the url where you got infected, could you PM it to me, please? I'd like to take a look at this thing.

    And you are absolutely right about Acronis, Hank. It friggin' rocks!
    {{ DiscussionBoard.errors[3933883].message }}
    • Profile picture of the author yukon
      Banned
      Originally Posted by Bradley J Anderson View Post

      Man, this one has really been making the rounds lately. If either of you guys remember the url where you got infected, could you PM it to me, please? I'd like to take a look at this thing.

      And you are absolutely right about Acronis, Hank. It friggin' rocks!
      I was on this forum when the virus popped up.

      I had a few other windows that had been open a few hours, but I'm not sure all the pages I had loaded.

      This virus is hardcore!

      I've dealt with plenty of viruses on Windows, this is killer.

      I used RKILL to shut down the virus long enough to get MBAM to scan my drives. After the MBAM scan + reboot I can't find anything on my PC. I had tons of stuff on this PC (4+ years old).

      My last C\ drive backup to my external usb hard drive is two weeks old, I'm restoring now.

      I really don't think this virus formatted my C\ drive, but nothing (zilch) shows on even the C\ drive, it's just empty. It would have took a long time to format this drive (1TB) so it has me scratching my head on this one.

      It will take me all night to finish the restore from the usb drive, it's still running...

      I would pay $$ to kick the mofo in the sack, that wrote this virus.
      {{ DiscussionBoard.errors[3934077].message }}
    • Profile picture of the author HankTheCowDog
      Originally Posted by Bradley J Anderson View Post

      Man, this one has really been making the rounds lately. If either of you guys remember the url where you got infected, could you PM it to me, please? I'd like to take a look at this thing.

      And you are absolutely right about Acronis, Hank. It friggin' rocks!
      Mine got me while I was looking for a wordpress plugin. You might try a google search under wordpress sidebar subscribe plugin. It hit from a ranked blog, like i said, the website stalles, i saw the Java window pop up and then the hard drive errors and MB blocking outgoing traffic.

      --------------

      another nugget of wisdom - do not run a dual boot Windows / Ubuntu machine, and then use Windows Powertoys to change your default file locations. confuses the hell outta Acronis, or me. Heck, probably both.

      The good news, just to be safe i grabbed another 2TB at Staples, USB 3, $120 on sale, that saves $50 off regular price.

      What a festive weekend I had. Friday i found out somebody hacked my cell account and used both my pending smartphone upgrades. Then I got the virus. Frustrated, I went to play with my horses and got chased by an Africanized bee.. ******* chased me about a quarter mile, I did the tuck and roll, threw my back out and finally I said screw it, go ahead and sting me...then it disappeared. Coulda been rich with the viral video if somebody had a camera on me, i imagine it was funny as hell.

      Yukon how did you make out?
      {{ DiscussionBoard.errors[3937195].message }}
      • Profile picture of the author yukon
        Banned
        Originally Posted by HankTheCowDog View Post

        Mine got me while I was looking for a wordpress plugin. You might try a google search under wordpress sidebar subscribe plugin. It hit from a ranked blog, like i said, the website stalles, i saw the Java window pop up and then the hard drive errors and MB blocking outgoing traffic.

        --------------

        another nugget of wisdom - do not run a dual boot Windows / Ubuntu machine, and then use Windows Powertoys to change your default file locations. confuses the hell outta Acronis, or me. Heck, probably both.

        The good news, just to be safe i grabbed another 2TB at Staples, USB 3, $120 on sale, that saves $50 off regular price.

        What a festive weekend I had. Friday i found out somebody hacked my cell account and used both my pending smartphone upgrades. Then I got the virus. Frustrated, I went to play with my horses and got chased by an Africanized bee.. ******* chased me about a quarter mile, I did the tuck and roll, threw my back out and finally I said screw it, go ahead and sting me...then it disappeared. Coulda been rich with the viral video if somebody had a camera on me, i imagine it was funny as hell.

        Yukon how did you make out?
        Was it the Yoast WP plugin [website]? I think I had that window open when I got hit.
        {{ DiscussionBoard.errors[3937294].message }}
        • Profile picture of the author HankTheCowDog
          Originally Posted by yukon View Post

          Was it the Yoast WP plugin [website]? I think I had that window open when I got hit.
          you go check it out

          I'll put it into Virtual mode via Acronis and check it out.
          {{ DiscussionBoard.errors[3937803].message }}
      • Profile picture of the author sbucciarel
        Banned
        Originally Posted by HankTheCowDog View Post

        Frustrated, I went to play with my horses and got chased by an Africanized bee.. ******* chased me about a quarter mile, I did the tuck and roll, threw my back out and finally I said screw it, go ahead and sting me...then it disappeared.
        lol ... I'm sorry, but this is really funny.
        {{ DiscussionBoard.errors[3964262].message }}
  • Profile picture of the author yukon
    Banned
    [win/xp]

    Ok, everything is back to normal on my PC that got hit by this virus.

    Steps I took to cleanup the virus:

    1) Stop the virus from creating popups, I used a free DOS program called RKILL.

    2) Once the virus was stopped I used a free program called MBAM (Malwarebytes), this found 10 problems on the PC. One of the virus locks the "Windows Task Manager" with PUM.Hijack.TaskManager to prevent you from doing a Ctrl+Alt+Delete & trying to kill the virus (doubt it would killed it anyways, never hurts to try).

    3) Rebooted & ran MBAM a 2nd time, all good.

    4) The virus turns off most of the icons on the PC (desktop, etc..) to fix this go to here for instructions.

    [TIP]
    After you fix the hidden icons on your PC, the virus has set most of the icons to Read-Only + Hidden, the Hidden greys out the icon (annoying to look at).

    Select all icons on desktop > right click on any folder icon > uncheck the Hidden + Read-Only checkbox > Apply changes to this folder & all sub-folders > Apply > Done.
    {{ DiscussionBoard.errors[3937281].message }}
    • Profile picture of the author HankTheCowDog
      Originally Posted by yukon View Post

      [win/xp]

      Ok, everything is back to normal on my PC that got hit by this virus.

      Steps I took to cleanup the virus:

      1) Stop the virus from creating popups, I used a free DOS program called RKILL.

      2) Once the virus was stopped I used a free program called MBAM (Malwarebytes), this found 10 problems on the PC. One of the virus locks the "Windows Task Manager" with PUM.Hijack.TaskManager to prevent you from doing a Ctrl+Alt+Delete & trying to kill the virus (doubt it would killed it anyways, never hurts to try).

      3) Rebooted & ran MBAM a 2nd time, all good.

      4) The virus turns off most of the icons on the PC (desktop, etc..) to fix this go to here for instructions.

      [TIP]
      After you fix the hidden icons on your PC, the virus has set most of the icons to Read-Only + Hidden, the Hidden greys out the icon (annoying to look at).

      Select all icons on desktop > right click on any folder icon > uncheck the Hidden + Read-Only checkbox > Apply changes to this folder & all sub-folders > Apply > Done.
      I'm still missing entire drive contents that show up hidden. I have a few minutes left after making a another complete backup of all my data and pics.

      I've changed out 6 different drive images and am not sure if it's the virus, or the way i have my drives partitioned (two hard drives, each partitioned differently).

      Soon, we'll find out. I'll probably do a reformat, I am trying to save my current drive structure with Ubuntu in tact, but might not be able to. Getting dual monitors to take on Ubuntu always proves to be a royal painnin the arse, I'm trying to avoid that.
      {{ DiscussionBoard.errors[3937795].message }}
  • Profile picture of the author Sunfyre7896
    Is it just from Wordpress plugins or are there sites that have been known to carry it and infect people? I really don't want to have to deal with this because I don't have a recovery disk as there was an issue I found when I tried to make them. As for security, I have Malwarebytes, Panda Cloud antivirus, and Microsoft Security Essentials. Maybe not enough but hopefully they can clean it off if I do get it.
    {{ DiscussionBoard.errors[3937351].message }}
    • Profile picture of the author yukon
      Banned
      Originally Posted by Sunfyre7896 View Post

      Is it just from Wordpress plugins or are there sites that have been known to carry it and infect people? I really don't want to have to deal with this because I don't have a recovery disk as there was an issue I found when I tried to make them. As for security, I have Malwarebytes, Panda Cloud antivirus, and Microsoft Security Essentials. Maybe not enough but hopefully they can clean it off if I do get it.
      I updated my last comment about the Yoast WP plugin.

      I don't run Yoast, I only had the web page open in my browser (no plugin installed).

      I'm thinking that Yoast website might have been how I got hit with the virus.

      My advice is to backup everything you want to keep on an external USB hard drive.
      {{ DiscussionBoard.errors[3937400].message }}
  • Profile picture of the author HankTheCowDog
    BTW guys, nothing you run will stop it.

    I'm running behind a Netscreen 5GT firewall APPLIANCE, run Iolo System Mechanic (which uses Kaspersky anti-virus) and paid Malwarebytes, live protection, current on all updates.

    Except running in Linux or Mac, it can get you.

    Which means you better have a good backup plan in place.
    {{ DiscussionBoard.errors[3937836].message }}
    • Profile picture of the author HankTheCowDog
      Holy smokes Yukon - it was the hidden files issue. that means the virus is resident on the system files * somewhere * and re-attaches to a disk image from an earlier date.

      Ill add when I did the follow-up with your tip, to get rid of the annoying gray on the FILES and FILE FOLDERS, you do the same as you outlined, except start with:

      right click, PROPERTIES, uncheck the Hidden + Read-Only checkbox > Apply changes to this folder & all sub-folders > Apply > Done.

      Also, if there are system files in there, explorer will hang. apparently it will not let you change the properties from "hidden" so when you select a series of files to uncover, it will hang. Simply un-select the folder which contains the system files.

      i've noticed I cannot do an entire "'select all"; instead I'm selection lesser amounts of files and then changing their properties. If I select too many, Explorer hangs. Kind of sucks, but seems to be working.

      I also noticed too that after you have un-grayed everything using the above-method, you can go back in under Tools/folder options, and again choose not to display hidden folders, and it will again hide the system files which should be hidden.

      THANKS FOR THE TIP YUKON

      sent ya a thanks

      Oh, and it's not the Yost site, I tried it out.
      {{ DiscussionBoard.errors[3938132].message }}
  • Profile picture of the author yukon
    Banned
    [DELETED]
    {{ DiscussionBoard.errors[3941022].message }}
    • Profile picture of the author HankTheCowDog
      Originally Posted by yukon View Post

      I did finally go back & hide the system files when I finished cleaning up everything.

      I did a regedit of the registry & searched for anything that included the word recovery, I didn't get any hits related to the virus.

      Everything is running good now. I have a new (year old) win7 PC that I hardly ever use sitting here on my desk beside the old xp machine, this old xp has been a real work horse over the past few years, hard telling how many hours I have on this thing.

      The C drive is the factory drive, I'm surprised it hasn't already failed on it's own with so many hours on it (runs 24/7). I keep a backup of everything on a usb hard drive (offline), helps keep my sanity, lol.
      Same here, Yukon, running a couple of old XP computers....a 3 year old Asus netbook and 6 year old Dell.

      My desktop Dell - the original hard drive also works but it was only 80g so I formatted it, loaded it up and then set it in storage in case of a catastrophic failure of my newer hard drive I installed.

      The virus is gone, it was only the settings it left behind. It took a lot of cleanup but in the process I re-organized things and found out half the memory I was using was redundant backup files. So now I have 920G of free hard space on drive 1, 470gb on hard drive 2, 500gb on external drive 1 and now, 2TB on the new external drive. Wow, lol.

      I will sync local backup onto the new 2TB and the last item of business is to contact SOS cloud storage and figure out how to fix my online cloud data backup with them since I restructured everything.

      Learning more about the files structure was good (hidden files) and Powertoys for Windows made things pretty easy too.

      I lost a few days of time, but now the computer is B-A-N-G-I-N-G!

      Thanks for your help.
      {{ DiscussionBoard.errors[3948722].message }}
  • Profile picture of the author Floyd Fisher
    If anyone is getting this problem, here's real instructions on how to remove it:

    Windows XP Recovery - Virus Solution and Removal
    {{ DiscussionBoard.errors[3952846].message }}
    • Profile picture of the author HankTheCowDog
      Which part? lol

      Seems the accurate info is contained down in the discussion section, but you have to pick thru the responses to find a solution whcih will work on your computer.

      The best bet to resolve the issue is to visit bleeping computer and search it out.
      {{ DiscussionBoard.errors[3953590].message }}

Trending Topics