Jump to content


 


Register a free account to unlock additional features at BleepingComputer.com
Welcome to BleepingComputer, a free community where people like yourself come together to discuss and learn how to use their computers. Using the site is easy and fun. As a guest, you can browse and view the various discussions in the forums, but can not create a new topic or reply to an existing one unless you are logged in. Other benefits of registering an account are subscribing to topics and forums, creating a blog, and having no ads shown anywhere on the site.


Click here to Register a free account now! or read our Welcome Guide to learn how to use this site.

Photo

Virus appears to have wiped Excel documents from my laptop


  • Please log in to reply
1 reply to this topic

#1 mooretwin

mooretwin

  • Members
  • 1 posts
  • OFFLINE
  •  
  • Local time:01:33 AM

Posted 20 July 2014 - 04:55 AM

My laptop appears to have been attacked by a virus that (from what I can detect):

- duplicated all my documents and photographs from "Documents" and "Pictures" into new folders located in different places (including folders on the Desktop);
- seems to have reverted Word documents to a point in July 2012 (so all documents created since then and all changes to documents made since then have been lost);
- wiped all my Excel documents completely.

When I first discovered that documents had been duplicated and moved, I thought I had done something inadvertently and moved the documents back to their original location in "Documents" and deleted the duplicates. I also emptied the recycle bin.

Only after I'd done this did I discover that the Excel documents were gone and that the Word documents were two years old. I assumed I had deleted them by mistake and so I downloaded a recovery programme (Recuva) to try to recover the deleted documents.

Recuva succeeded in finding scores of Word documents, but I believe these were documents that I had deleted on previous occasions (i.e. not the missing documents). However, at least it means I have recovered more recent versions of some documents. Recuva did not find any of the Excel documents, except for 2 or 3 that were unrecoverable.

By this time a new problem had developed: my cursor was flying all over the screen and impossible to control with the touchpad.

I ran AdAware and it found a number of viruses, including this: Trojan.Win32.Generic!BT.

I downloaded Comodo and ran it. It found this: ApplicUnwnt@#2vwywi00n7rg1

At this point the cursor returned to normal.

Later, Comodo found this:
Malware@#rxx70bs6hjda



Is there any way I can recover the lost documents. I particularly want to recover a number of Excel documents that contain all my family's financial information. I've searched the computer for documents by name, and also changed folder options to allow hidden documents to be viewed, but to no avail.



BC AdBot (Login to Remove)

 


#2 dc3

dc3

    Bleeping Treehugger


  • Members
  • 30,752 posts
  • OFFLINE
  •  
  • Gender:Male
  • Location:Sierra Foothills of Northern Ca.
  • Local time:04:33 PM

Posted 20 July 2014 - 11:55 AM

Please run the following scans.


Please run the ESET OnlineScan

  • Hold down Control and click on this link to open ESET OnlineScan in a new window.
  • Click the esetonlinebtn.png button.
  • For alternate browsers only: (Microsoft Internet Explorer users can skip these steps)
    • Click on esetsmartinstaller_enu.exe to download the ESET Smart Installer. Save it to your desktop.
    • Double click on the esetsmartinstaller_enu.png icon on your desktop.
  • Check "YES, I accept the Terms of Use."
  • Click the Start button.
  • Accept any security warnings from your browser.
  • Under scan settings, check "Scan Archives" and "Remove found threats"
  • Click Advanced settings and select the following:
    • Scan potentially unwanted applications
    • Scan for potentially unsafe applications
    • Enable Anti-Stealth technology
  • ESET will then download updates for itself, install itself, and begin scanning your computer. Please be patient as this can take some time.
  • When the scan completes, click List Threats
  • Click Export, and save the file to your desktop using a unique name, such as ESETScan. Include the contents of this report in your next reply.
  • Click the Back button.
  • Click the Finish button.

 

Please download Malwarebytes Anti-Malware.  After clicking on the link the download will start automatically.
 
1)  Double-click on mbam-setup.exe, then click on Run to install the application, follow the prompts through the installation.
 
2)  Malwarebytes will automatically open.  If this is the first time you have run this version of Malwarbytes you will see an image like the one below.
 
mbam1_zps95cc812c.png
 
Click on Update Now, after Malwarebytes is updated click on Scan.
 
If this isn't the first time you have run this version, then you will see an image like the one below.  Click on Scan
 
mbam1_zps98e7fba9.png
 
You will be prompted to update Malwarebytes, to do so click on Update Now.
 
 mbam2_zps85f38f0c.png
 
3)  The scan will automatically run now.
 
mbamreplace_zps3ead4824.png
 
 
4)  When the scan is complete the results will be displayed.  Click on Quarantine All, then click on Apply Actions
 
mbam4_zps23e52ad4.png
 
 
5)  To complete any actions taken you will be asked if you want to restart your computer, click on Yes
 
 mbam4_zps490948cc.png
 
6)  Please post the Malwarebytes log.
 
To find your Malwarebytes log,download mbam-check.exe from here and save it to your desktop.
 
To open the log double click on mbam-check.exe on your desktop.  When the log opens, scroll down toward the bottom of the log to Quarantined Items.  Copy and paste this in your next post.
 
 
Please download AdwCleaner and run it.
 
An image like the one below will open, click on Scan.
 
adwcleaner11_zps48314883.png
 
Once the search is complete a list of the pending items will be displayed.  If you see any which you do not want removed, remove the check mark next to it.  
 
Click on Clean to remove the selected items.  If you have any questions about any items in the list please copy and paste the list in your topic so we can review it.  
 
You will receive a message telling you that all programs will be close so that the infections can be removed.  Click on Ok.
 
When the cleaning process is complete a log of what was removed will be presented.  Please copy and the paste this log in your next post.

Family and loved ones will always be a priority in my daily life.  You never know when one will leave you.

 

 

 

 





0 user(s) are reading this topic

0 members, 0 guests, 0 anonymous users