PDA

View Full Version : Help! I need emergency computer help!



Pocketa
2008-08-11, 02:09 AM
So, basically, I was searching for my ISO burner on my computer, using the search tool with the search term 'iso', I saw a bunch of files I never downloaded but would've remembered downloading, like software, etc., and I opened the file location, and there were 33,692 files.

Pirate, copyrighted material.

None of which I downloaded.

Needless to say, I deleted all the materials, but it keeps coming back! I'm really worried that it could be in other places too.

If it helps, the directory is C:\Users\Usernamegoeshere\'. However, the " ' " folder (the folder is literally named the apostrophe symbol) is hidden from the outside.

I was wondering if aynone could tell me how somebody would be able to get that onto my computer, how I could avoid that happening in the future, and how I can fix it now.

I really, really need help. Is there a way of finding out where the material is coming from, because it says that it's from 1/10/07, but there's no way it is, because I got the computer new in March or May of last year, and some of the stuff was new (i.e. a Wall-E iso). Also, I was wondering if there's a way of finding out if other stuff is being streamed to other folders in my computer?

tyckspoon
2008-08-11, 03:14 AM
First up: acquire and run a good set of spyware-control and antivirus programs if you don't already have them. Also get a firewall- you want one that does both inbound and outbound control and reports unauthorized contacts, which is.. well, pretty much any of them with decent reviews. I've had fairly good experiences with ZoneAlarm and Comodo.

Second step: If those steps don't fix your problem, boot the computer in Safe Mode. (http://support.microsoft.com/kb/315222) Run the spyware and antivirus scans again and attempt to delete the offending material- Safe Mode uses a very limited set of functions, which can prevent malware from accessing the tricks it normally uses to hide or recreate itself.

Step three: If the crap is still around after doing a Safe Mode cleanup, Try HijackThis. (http://www.whatthetech.com/hijackthis/) It's a tool that can provide a detailed look at what things are doing on your computer; you'll probably need to post the results to a more technically-inclined forum for more guidance once you have that information, but it should have the information and the tools to fix most things once you've found a place with somebody who knows how to work with it.

Ashtar
2008-08-11, 06:13 AM
Or if it's really bad, get your data off onto a CD-rom, scan that in another computer and reformat / reinstall your own PC.

Because if it's really compromised, it's very very hard to disinfect and clean your computer.

All the above advice is very good though.

valadil
2008-08-11, 09:15 AM
Does anyone else use your computer regularly? If so you might want to have a little talk with them.

Are all those files what they claim to be? Check how much disk space they're using. Even if your computer is being used to store someone's warez, I find it hard to believe that 30,000 videos would fit on your machine or get downloaded as soon as you delete them.

expirement10K14
2008-08-11, 09:31 AM
This could be where it is storing .torrents, as I believe certain programs back them up. If you are using Vuze/azureus it may be pre-loading them based on things you already downloaded.

bluewind95
2008-08-11, 11:21 PM
This could be where it is storing .torrents, as I believe certain programs back them up. If you are using Vuze/azureus it may be pre-loading them based on things you already downloaded.

... But hiding it from the user..? :smallconfused:

.... I'd recommend HijackThis, definitely. Do you have access to hidden files?

Edit: Oh, yeah. To remove a virus, first you have to disable Windows Recovery, if you're using that. Otherwise, it'll come back.

Zeb The Troll
2008-08-12, 12:33 AM
It really sounds to me like it's file sharing bits, like experiment suggested. If you're using something like bit torrents, disable it, delete the files, and watch. Yes, it's entirely plausible that they would hide that folder from the user so that you can't as easily mess with their mojo.