Jump to content

Virus changed my .exe file to g*.exe

RadiKamiki
Go to solution Solved by tlink,

use a different system and download some nuking anti virus and anti malware scans. here are some recomendations that i use to destroy buggers like these. no clue to the actual name though.

 

http://www.surfright.nl/nl/hitmanpro

https://support.kaspersky.com/viruses/rescuedisk

https://help.comodo.com/topic-170-1-493-5214-.html

http://usa.kaspersky.com/downloads/TDSSKiller

 

i advice starting it in this order:

 

1: kaspersky rescue disk

2: Comodo rescue disk

3: hitman pro

4: TDSSkiller

I think the virus come to my laptop when i connect my external harddrive which borrowed before from my friend. After i connect that, first thing is my excel 2010 cant open.. and it spreading to all windows apps like freecell, windows media player, windows media center, and another installed apps like strawberry prolog, adobe photoshop, and many more in program files folder.

Im looking to app location in program files folder, and i've found that real Photoshop.exe is changed with gPhotoshop.exe and hidden, and the virus making a fake .exe with same name.

 

What should i do to remove this virus from my laptop and my external harddrive? And what is name of this virus? Avast said this virus name is "?"... but what is the real name of this virus? 

Thanks before and sorry if you can't understand my language ^^

1476864971856.jpg

Link to comment
Share on other sites

Link to post
Share on other sites

First is stop using the infected drives to keep it from spreading. Next, do you have a separate system? I keep a separate laptop that has antivirus, and also have a backup of the entire system on an external that I can restore from in case the laptop becomes compromised, but have used it to clean various drives from infected systems I've worked on. I do this by plugging the infected drive as an external through usb and then have the antivirus do a full scan on the drive before opening it. It is a real possibility that plugging in an infected bootable drive to a different system for cleaning can result in a clean but unbootable windows installation after cleaning that will need either repaired or reinstalled. Sometimes, the virus won't block you from installing an antivirus program on the infected drive/system and let it run from there, but I've usually just skipped trying that because of the high chances of it failing anyway.

 

This is only worth the trouble if there's data on the infected drive that would be missed, otherwise just do a clean install as it's much easier, faster, and a sure way of getting rid of the issue.

CPU: AMD Sempron 2400+ / MOBO: Abit NF7-S2G / GPU: WinFast A180BT 64MB / RAM: Mushkin DDR333 256MBx2 / HDD: Seagate Barracuda 7200RPM 120GB

Link to comment
Share on other sites

Link to post
Share on other sites

use a different system and download some nuking anti virus and anti malware scans. here are some recomendations that i use to destroy buggers like these. no clue to the actual name though.

 

http://www.surfright.nl/nl/hitmanpro

https://support.kaspersky.com/viruses/rescuedisk

https://help.comodo.com/topic-170-1-493-5214-.html

http://usa.kaspersky.com/downloads/TDSSKiller

 

i advice starting it in this order:

 

1: kaspersky rescue disk

2: Comodo rescue disk

3: hitman pro

4: TDSSkiller

Link to comment
Share on other sites

Link to post
Share on other sites

21 minutes ago, meenmeen1103 said:

First is stop using the infected drives to keep it from spreading. Next, do you have a separate system? I keep a separate laptop that has antivirus, and also have a backup of the entire system on an external that I can restore from in case the laptop becomes compromised, but have used it to clean various drives from infected systems I've worked on. I do this by plugging the infected drive as an external through usb and then have the antivirus do a full scan on the drive before opening it. It is a real possibility that plugging in an infected bootable drive to a different system for cleaning can result in a clean but unbootable windows installation after cleaning that will need either repaired or reinstalled. Sometimes, the virus won't block you from installing an antivirus program on the infected drive/system and let it run from there, but I've usually just skipped trying that because of the high chances of it failing anyway.

 

This is only worth the trouble if there's data on the infected drive that would be missed, otherwise just do a clean install as it's much easier, faster, and a sure way of getting rid of the issue.

Yes i have a separate system, but its linux deepin.. i have another laptop which installed windows 10 but not have an antivirus..

 

11 minutes ago, tlink said:

use a different system and download some nuking anti virus and anti malware scans. here are some recomendations that i use to destroy buggers like these. no clue to the actual name though.

 

http://www.surfright.nl/nl/hitmanpro

https://support.kaspersky.com/viruses/rescuedisk

https://help.comodo.com/topic-170-1-493-5214-.html

http://usa.kaspersky.com/downloads/TDSSKiller

 

i advice starting it in this order:

 

1: kaspersky rescue disk

2: Comodo rescue disk

3: hitman pro

4: TDSSkiller

 About rescue disk, is it run on windows or i have to make a usb bootable?

Link to comment
Share on other sites

Link to post
Share on other sites

1 minute ago, RadiKamiki said:

Yes i have a separate system, but its linux deepin.. i have another laptop which installed windows 10 but not have an antivirus..

 

 About rescue disk, is it run on windows or i have to make a usb bootable?

every tool i linked (probably) runs its own flavor of linux. they are all bootable.

Link to comment
Share on other sites

Link to post
Share on other sites

3 minutes ago, The Belgian Waffle said:

You're welcome

58572963.jpg

I cant use chrome now because all my browser is infected ^^

Link to comment
Share on other sites

Link to post
Share on other sites

3 minutes ago, RadiKamiki said:

I cant use chrome now because all my browser is infected ^^

Don't worry, I'm just trolling you. 

Do you have an external backup? I would simply consider wiping your disks, but this might be a second solution if you have sensitive datas that aren't backed up

Link to comment
Share on other sites

Link to post
Share on other sites

4 minutes ago, tlink said:

every tool i linked (probatqbly) runs its own flavor of linux. they are all bootable.

Ahh okay, im downloading the rescue disk... but with what i make bootable usb? Is it okay if im using linuxlive usb creator?

 

4 minutes ago, The Belgian Waffle said:

Don't worry, I'm just trolling you. 

Do you have an external backup? I would simply consider wiping your disks, but this might be a second solution if you have sensitive datas that aren't backed up

Haha...

I dont have any external backup. So i cant do that second solution ^^ but can i rename all app name which changed by the virus to original name and unhide them?

Link to comment
Share on other sites

Link to post
Share on other sites

1 hour ago, RadiKamiki said:

Ahh okay, im downloading the rescue disk... but with what i make bootable usb? Is it okay if im using linuxlive usb creator?

 

Haha...

I dont have any external backup. So i cant do that second solution ^^ but can i rename all app name which changed by the virus to original name and unhide them?

Maybe try to copy the "healthy files" somewhere else and wipe your HDD when you're done

Link to comment
Share on other sites

Link to post
Share on other sites

2 hours ago, RadiKamiki said:

Ahh okay, im downloading the rescue disk... but with what i make bootable usb? Is it okay if im using linuxlive usb creator?

 

Haha...

I dont have any external backup. So i cant do that second solution ^^ but can i rename all app name which changed by the virus to original name and unhide them?

i would advice making a backup now actually before you do any of the removals. they can fuck up your system if the virus is rooted really deep. just NEVER access it using a windows computer, use linux for that. but even linux is not safe so you might just infect everything all over again if you try to copy healthy files. even knowing what files are healthy and what files are infected is a huge hassle.

Link to comment
Share on other sites

Link to post
Share on other sites

2 hours ago, RadiKamiki said:

Ahh okay, im downloading the rescue disk... but with what i make bootable usb? Is it okay if im using linuxlive usb creator?

i guess it is, im not really sure. i just burned them to disk because its easier and cheaper without the risk of also infecting the USB.

Link to comment
Share on other sites

Link to post
Share on other sites

Create an account or sign in to comment

You need to be a member in order to leave a comment

Create an account

Sign up for a new account in our community. It's easy!

Register a new account

Sign in

Already have an account? Sign in here.

Sign In Now

×