Sunday, July 26, 2009

Much More Computer Woes

I've gotten OS working on another partition, but its still infected, though haven't gotten the fatal explorer.exe error, which will be so sooner or later. This virus starts from , its found in the Windows>system32 folder. From what I've read, this virus variant modifies .exe programs, saved webpages and screensavers. Even goes through zipped/compressed files. So far I've managed to nominally block net access for it and 1.exe through a firewall, but I can't get netstat to stay open long enough to check my connections.

Here what happens, reader_s connects to net, downloads more malware. Your temp folder in Windows will be filled with illegible files(each prolly meant to send out spam), and multiple copies of InternetExplorer and svchost.exe show up in the task manager processes. But that's not all yet, since it modifies any ***.exe, its just a matter of time before it gets to crucial OS executables, then you'll have a corrupted OS. In other words, (as someone put it) a glorified lit-up brick.

Hopefully the computers stays in working condition until my hols, infected or not. Will try cleaning the registry in Safe mode without networking, if not then there's only zero-fill(HDD) left. Till then I just hope it doens't gain the ability to infect media files. Will also get Ubuntu asap.

ARE YOU INFECTED?

More Computer Woes

So I just wasted 10 hours of formatting and installing OS/drivers. After the mandatory restart from Service Pack 2 installation, OS was screwed. First it wouldn't boot normally, so I went into Safe mode to do a system restore. Next thing I knew, no OS detected.

Have installed OS(again...) on a second partition. My deduction is that some malware interfered the SP2, possibly carried over from the data copied from the infected HDD. But virus scan came back with nothing. It could be possible the OSes with the same serial clashed, I had a slave HDD with the same serial OS. But then again it was OK until SP2 was installed.

Another estimated 2 hours before SP2 finishes downloading. Got a fresh SP2 installation from microsoft site. Funny I couldn't access MS official site all this while until this OS install, malware again?

Friday, July 24, 2009

Computer Woes

The last month or so has brought an onslaught of tech woes, mainly computer-related. I'm typing this post as I'm in the midst of backing up a whopping 40GB of my mum's stuff on DVD.

So, what happened? A lot.
1) Serious virus infection.
2) Dying HDD.
3) Formatted the wrong HDD.
4) Ultimate, unremovable virus(es)

Solved (1) with simple scan through Spybot to remove system.exe

(2) was the source random freezes, finally escalating to a reboot loop. Bought new HDD, but it doesn't end there.

After making sure that all data were safely on the slave, I went through the motions of formatting the new drive. Scroll down, choose partition, press 'D', ENTER. I can't remember the exact sequence of events, but what I do remember is when I loaded a fresh OS, the first thing I did was check the secondary drive, only to be greeted by a pop-up asking me to 'Format drive to use'. Which meant that I had deleted the partition, which meant the HDD was blank, which meant every single bit of data accumulated over the past few years are gone, zilch.

So on to the web to look for ways to recover data. HandyRecovery4 worked well except for some files with name too long. Happiness.

Now onto (4), this batch of viruses, infected through USB drives, disguises itself as New Folder. Disables task manager, connects to the net on its own, and finally, screwed explorer. Impossible to do anything since its always running, including in Safe Mode. Only option left is a full format.