MultiDrive – free backup, clone & wipe disk utility from Atola Technology

All times are UTC - 5 hours [ DST ]




Post new topic Reply to topic  [ 11 posts ] 
Author Message
 Post subject: Strange problem poss a virus
PostPosted: May 14th, 2011, 6:37 
Offline

Joined: January 23rd, 2010, 16:20
Posts: 248
Location: Data Recovery in Glasgow, Scotland
WD 2500BMVU NTFS

everything shows up as shortcuts, you can extract individual files (just used r-studio to grab some DWG's) but when you extract enything in a folder structure it just shows up as shortcuts on the destination drive, its the USB version otherwise I would DDI it and hope for the best.

Drive shows to be correct volume size , when you right click on any object the path references \xesisthine.exe\ (for example) im guessing thats the virus thats throwing it out.

I can see everything in r-studio but when you try to lay it back on a drive it just reverts back to shortcuts.

tried chkdsk, formating the destination Fat32, creating a root folder, attributes etc etc

any ideas before i go nuts?

thanks

andy

_________________
Databusters Data Recovery Glasgow
http://www.datarecovery.co.uk/latest-data-recovery-jobs/


Top
 Profile  
 
 Post subject: Re: Strange problem poss a virus
PostPosted: May 14th, 2011, 6:44 
Offline

Joined: January 23rd, 2010, 16:20
Posts: 248
Location: Data Recovery in Glasgow, Scotland
just extracted 10 random folders, when you right click the folder you get the 1.8GB etc etc but nothing in it

_________________
Databusters Data Recovery Glasgow
http://www.datarecovery.co.uk/latest-data-recovery-jobs/


Top
 Profile  
 
 Post subject: Re: Strange problem poss a virus
PostPosted: May 14th, 2011, 8:43 
Offline

Joined: August 11th, 2010, 19:00
Posts: 145
Location: Portugal
format the other drive using ubuntu to eliminate the virus using linux ( kubuntu or ubuntu whatever)

use linux to copy the files that you want ( virus will not be executed because its only a windows virus)

format the pc after and reinstall windows

try to not get caught again :P


Top
 Profile  
 
 Post subject: Re: Strange problem poss a virus
PostPosted: May 14th, 2011, 9:00 
Offline

Joined: January 23rd, 2010, 16:20
Posts: 248
Location: Data Recovery in Glasgow, Scotland
customer drive mate, i was just about to fire up knopix

ta for that

andy

_________________
Databusters Data Recovery Glasgow
http://www.datarecovery.co.uk/latest-data-recovery-jobs/


Top
 Profile  
 
 Post subject: Re: Strange problem poss a virus
PostPosted: May 14th, 2011, 9:58 
Offline

Joined: January 8th, 2008, 5:21
Posts: 927
Location: uk
If it's a boot sector virus I would have at least tried re-writing the mbr using the old ms dos command:
fdisk /mbr
That way you don't lose the data on the drive.


Top
 Profile  
 
 Post subject: Re: Strange problem poss a virus
PostPosted: May 14th, 2011, 16:51 
Offline

Joined: April 5th, 2010, 23:02
Posts: 89
Location: Winder, GA
fdisk /mbr doesn't fix these new MBR viruses.
Download: http://www.sysint.no/nedlasting/mbrfix.htm
Boot from ERD commander or put the drive in an external enclosure and run mbrfix from there.
A few new viruses in circulation are putting system/hidden attributes on every file so it appears no files are on the drive until you choose "show all files"

When it shows up as shortcuts, are you booting from this drive or is it also showing up as shortcuts from another PC?
When you choose the properties of these shortcuts where does it point to?


Top
 Profile  
 
 Post subject: Re: Strange problem poss a virus
PostPosted: May 16th, 2011, 4:47 
Offline

Joined: January 23rd, 2010, 16:20
Posts: 248
Location: Data Recovery in Glasgow, Scotland
Thanks for that matt

UFS Explorer doing the trick, thanks sean :)

_________________
Databusters Data Recovery Glasgow
http://www.datarecovery.co.uk/latest-data-recovery-jobs/


Top
 Profile  
 
 Post subject: Re: Strange problem poss a virus
PostPosted: May 16th, 2011, 17:37 
Offline

Joined: November 29th, 2006, 10:08
Posts: 7864
Location: UK
Welcome :-)

_________________
PC Image Data Recovery
http://www.pcimage.co.uk

New!! HDD-PCB.COM for all your PCB and donor HDD requirements!


Top
 Profile  
 
 Post subject: Re: Strange problem poss a virus
PostPosted: May 16th, 2011, 20:04 
Offline

Joined: April 26th, 2011, 15:03
Posts: 45
Location: United States
On XP booting to recovery console and running FIXMBR also resolves this issue in most cases.


Top
 Profile  
 
 Post subject: Re: Strange problem poss a virus
PostPosted: May 19th, 2011, 20:33 
Offline

Joined: March 30th, 2011, 14:49
Posts: 22
Location: Copenhagen
A couple of non-MBR related workarounds.

This is TOUEW.EXE or 435534**.SCR Should be a process in Windows Explorer. Kill it if you see it. Run ComboFix.

More tediously, you can set WE to show hidden files, and then enable show extensions for known file types, then you should see your files in each folder. Copy them out.


Top
 Profile  
 
 Post subject: Re: Strange problem poss a virus
PostPosted: May 20th, 2011, 4:22 
Offline

Joined: January 23rd, 2010, 16:20
Posts: 248
Location: Data Recovery in Glasgow, Scotland
nice to know mate, thanks :)

_________________
Databusters Data Recovery Glasgow
http://www.datarecovery.co.uk/latest-data-recovery-jobs/


Top
 Profile  
 
Display posts from previous:  Sort by  
Post new topic Reply to topic  [ 11 posts ] 

All times are UTC - 5 hours [ DST ]


Who is online

Users browsing this forum: No registered users and 73 guests


You cannot post new topics in this forum
You cannot reply to topics in this forum
You cannot edit your posts in this forum
You cannot delete your posts in this forum
You cannot post attachments in this forum

Search for:
Jump to:  
Powered by phpBB © 2000, 2002, 2005, 2007 phpBB Group