Welcome Guest ( Log In | Register )

Bump Topic Topic Closed RSS Feed

Outline · [ Standard ] · Linear+

 what is this?, print screen provided. help needed.

views
     
TSblackflam
post Mar 5 2007, 01:10 AM, updated 19y ago

Getting Started
**
Junior Member
183 posts

Joined: May 2005


Quick help needed, I do not know where to search for help... so I try my luck here. hopefully lowyat forum members can lend me a hand.

My system is infected with virus/trojan. I am not able to double click on my local drives, instead, I have to right click and choose "open". Everytime I double click on any of my local drives, my antivirus will show *print screen provided*. Is this trojan or virus? Sometimes it uses up all my system resources.. makes my system very unresponsive.

I used AVG, BitDefender 10, Lavasoft Ad-Adware, RegistryFix, even System Mechanic pro to check my system... but all of them showing no sign of problem at all. Yet, I am still have problem accessing those drives.

Reformat? Only reformatted 1 partition, which is the OS drive. I hope to keep my animes and mp3.. it's up to 500gb worth of data. I am not able to backup all of them. The problem still persist. Reformatting everything is the last resort. cry.gif

extra info:
I have 3 hard drives in my cpu. total 8 partitions drives. I've copied some anime from friend, and problem started to show up.

anything else I can do beside reformat all my 3 drives? icon_question.gif

9876789
post Mar 5 2007, 01:21 AM

lost soul
*****
Senior Member
866 posts

Joined: Jan 2003
From: KL


delete "autorun.inf" on every diskdrive of yours... check your pendrives as well


Added on March 5, 2007, 1:23 amoh, before you delete, please check what's written inside "autorun.inf"... it may contains info on the trojan you suffer from... biggrin.gif

This post has been edited by 9876789: Mar 5 2007, 01:23 AM
id86
post Mar 5 2007, 05:31 AM

GG
******
Senior Member
1,052 posts

Joined: Oct 2006
From: Malaysia


QUOTE(blackflam @ Mar 5 2007, 01:10 AM)

extra info:
I have 3 hard drives in my cpu. total 8 partitions drives. I've copied some anime from friend, and problem started to show up.

anything else I can do beside reformat all my 3 drives?  icon_question.gif
*
you copy the anime suing what device?

i think maybe your comp kena jangkit from your friends comp..

since you have more than one AV, do you update them?
maybe the AVs have conflict sweat.gif sweat.gif
TSblackflam
post Mar 5 2007, 09:11 AM

Getting Started
**
Junior Member
183 posts

Joined: May 2005


UPDATE:

Guys, I found that virus/trojan!! I was backing up my data and I found "autorun.inf" and "pet.exe" in each of the drives *picture provided*. I delete it by pressing "del".. it restored back immediately. I did this from the Nero Burning window mode. What I mean is, when you burn data, you have to choose location and select particular file to burn, right? I found the trojan from that window. But when I access it through My Computer, nothing found. I have enabled hidden files.

Is there any other way I can access the "autorun.inf" ? What should I do next?



This post has been edited by blackflam: Mar 5 2007, 10:13 AM
LovesReborn
post Mar 5 2007, 02:45 PM

Regular
******
Senior Member
1,739 posts

Joined: Sep 2005
From: somewhere
download and run flash disinfector here.
all the best...
eXPeri3nc3
post Mar 5 2007, 02:54 PM

It's coming! 3ɔu3ıɹǝdxǝ ♥
*******
Senior Member
9,257 posts

Joined: Aug 2005
From: Not so sure myself Status: 1+3+3=7



Try saving this and run it on your desktop.


http://www.kellys-korner-xp.com/regs_edits...whiddenexts.vbs

Try to find that pet32.exe now.

TSblackflam
post Mar 5 2007, 07:42 PM

Getting Started
**
Junior Member
183 posts

Joined: May 2005


QUOTE(LovesReborn @ Mar 5 2007, 04:45 PM)
download and run flash disinfector here.
all the best...
*
That only works with flashdrives right? All my flash drives have been disinfected.


Added on March 5, 2007, 7:47 pm
QUOTE(eXPeri3nc3 @ Mar 5 2007, 04:54 PM)
Try saving this and run it on your desktop.
http://www.kellys-korner-xp.com/regs_edits...whiddenexts.vbs

Try to find that pet32.exe now.
*
Double clicked and Logoff/Logon... followed exact instruction. Nothing worked. Pet32.exe still exist, it restored back automatically everytime I delete it sad.gif I am able to get rid of autorun.inf by creating another "autorun.inf" folder in the each of the root drives though.. but I still cannot access all the local drives.

This post has been edited by blackflam: Mar 5 2007, 07:47 PM
LovesReborn
post Mar 5 2007, 08:25 PM

Regular
******
Senior Member
1,739 posts

Joined: Sep 2005
From: somewhere
QUOTE(blackflam @ Mar 5 2007, 07:42 PM)
That only works with flashdrives right? All my flash drives have been disinfected.
not really... i faced the same problem as you are a few months ago. cannot open hard disc drives by double-clicking,but can open by right-click open. i use the flash disinfector and it manage to solve the problem.
TSblackflam
post Mar 5 2007, 09:32 PM

Getting Started
**
Junior Member
183 posts

Joined: May 2005


that's weird. I double checked my flash drives (which has been disinfected). The PET32.EXE and autorun.inf still exist... sad.gif

another victim added into list.. my girlfriend. she plug her flash drive into my system...I've forgotten to tell her :S Now her laptop also got infected.
eXPeri3nc3
post Mar 5 2007, 09:53 PM

It's coming! 3ɔu3ıɹǝdxǝ ♥
*******
Senior Member
9,257 posts

Joined: Aug 2005
From: Not so sure myself Status: 1+3+3=7



There should be a rootkit or backdoor in your computer I shall assume. Now,

Download ComboScan to your Desktop.
  1. Close all applications and windows.
  2. Double-click on comboscan.exe to run it, and follow the prompts.
  3. When the scan is complete, a text file will open - ComboScan.txt
  4. Copy (Ctrl+A then Ctrl+C) and paste (Ctrl+V) the contents of ComboScan.txt in your thread in the HijackThis Log Help Forum.
  5. A folder, C:\ComboScan, will also open. In it will be another text file, Supplementary.txt.
  6. Please attach Supplementary.txt to your post.

zulfajuniadi
post Mar 6 2007, 02:11 AM

Getting Started
**
Junior Member
71 posts

Joined: Mar 2007
From: Kajang, Selangor



QUOTE(blackflam @ Mar 5 2007, 09:32 PM)
that's weird. I double checked my flash drives (which has been disinfected). The PET32.EXE and autorun.inf still exist... sad.gif

another victim added into list.. my girlfriend. she plug her flash drive into my system...I've forgotten to tell her :S Now her laptop also got infected.
*
Please send me a copy of pet.exe and the autorun.inf. zulfajunadi@gmail.com. I'll try to help what i can.

thanks in advance
beelzebob13
post Mar 9 2007, 02:15 PM

**Newbie DeIllusionist**
****
Senior Member
591 posts

Joined: Jan 2007
From: the interWebs...
http://forum.kaspersky.com/index.php?showtopic=32916
seem to have a solve to pet32.exe problem.
kmkd
post Mar 9 2007, 03:10 PM

New Member
*
Junior Member
11 posts

Joined: Mar 2007


check ur sceulded task.. i didn't know how to rite it... any task given except from your av or your self add it, deleted... it re generated it self until task been deleted..
TSblackflam
post Mar 9 2007, 07:06 PM

Getting Started
**
Junior Member
183 posts

Joined: May 2005


hi guys... I've successfully remove this trojan.

1) I run "kill autorun".
2) restart computer and I see all hidden files. all "PET32.exe" file were found.
3) reboot system into safe mode
4) delete it. make sure all root drive were clean
5) restart into normal booting mood... ta daaa!

rclxm9.gif ouh yeah

Topic ClosedOptions
 

Change to:
| Lo-Fi Version
0.0177sec    0.40    5 queries    GZIP Disabled
Time is now: 22nd December 2025 - 01:57 AM