Infected .doc files

Closed
RacerKid - Sep 29, 2010 at 05:16 AM
 Anonymous User - Oct 7, 2010 at 07:09 PM
Hello,

I'm having problem with my document files. First, i scanned my external harddisk with Avira, after scanning, it detected 10k of infected files which is the TR/QuickBatch.Gen.It send the viruses into the quarantine then i deleted the viruses.

After that, I've noticed that all my document files have the similar sized of 1kb and then I opened the document and it only written venom venom venom venom venom venom venom venom venom venom venom 666 Lucifer.

All documents such as powerpoint, and excel has this kind of message written in it..

Can U help me...pls...

Related:

27 responses

Anonymous User
Sep 30, 2010 at 09:50 AM
ok I think we're gonna use DrWeb

? Download [Dr Web CureIt ftp://ftp.drweb.com/pub/drweb/cureit/drweb-cureit.exe] on your desktop:

? restarts in Safe mode


? - Double click (right click "as admin" in Vista / 7) and then clicking <drweb-cureit.exe> <Analyse>;

? - Click <Ok> to prompt rapid analysis. If it finds the process infected then click the button <Yes>.

Note: A window will open with options to "Order" or "50% discount": Exit by clicking the "X".

? - When the fast scan is complete, click on the menu then <Options> <Changing <config; <scanner> Choose the tab, and uncheck <Analyse heuristique>. Then click on <Ok>.
? - Back in the main window: click to activate <Analyse complète>

selects all drives


? - Click the button with green arrow on the right and the scan will begin.
? - Click <Yes> for all at the prompt "Disinfect?" when a file is detected, and then click "Disinfect".
? - When the scan is complete, see if you can click on the icon adjacent to the files found (several leaves on top of one another). If yes, then click and then click on the icon <Next>, below, and choose Quarantine <Déplacer l'objet indésirable>.
? - From the main menu of the tool at the top left, click on the menu and choose <File> <Save the report>. Save the report to your desktop. The latter will be called DrWeb.csv


?-for the report you registered on your desktop, you right click / send to / compressed folders

Then:

you send me the archive like this:

click on this link: http://www.cijoint.fr/

? Click on Browse and look for the above file.

? Click Open.

? Click on "Click here to submit the file".

Link to this:

http://www.cijoint.fr/cjlink.php?file=cjge368/cijSKAP5fU.txt

is added to the page.

? Copy this link to your response.

? - Close Dr.Web CureIt
? - Restart your computer (important because some files can be moved / repaired on reboot).
0
Anonymous User
Sep 30, 2010 at 12:52 PM
My doc file in external harddisk still written venom venom venom 666 lucifer

say me more about that

is this the name of your doc file or what is written inside ?
0
Ok sir,

Its my document of office words, excel, and powerpoint.....I saved many of my files in my external harddisk. But then i just found out that after I plugin into my lab's computer, and i scanned it with my Avira with my pc.....it detects sooo many viruses up to 10000 viruses detected...

Therefore i've deleted all the viruses in the quarantine...And then i checked in my external to see if there is any file or folder missing....

I become shocked for what i saw that all the document including words,excel and powerpoint were sized of 1kb only.......then i open the file all it says venom venom venom venom venom venom venom venom venom 666 Lucifer

All my document were written like that.....my resume, assignment, journal was all written with that sentenced.


Other than that, I checked the properties of the document file.......stated that the size of the file is 80bytes and size on disk stated 4.00kb........

How can i retrieve back my document sir.....

plz help me......the doc is important to me.....the external is the only backup i have.......
0
Anonymous User
Sep 30, 2010 at 03:02 PM
ok

? Download [Dr Web CureIt ftp://ftp.drweb.com/pub/drweb/cureit/drweb-cureit.exe] on your desktop:

? restarts in Safe mode


? - Double click (right click "as admin" in Vista / 7 ) and then clicking <drweb-cureit.exe> <Analyse>;

? - Click <Ok> to prompt rapid analysis. If it finds the process infected then click the button <Yes>.

Note: A window will open with options to "Order" or "50% discount": Exit by clicking the "X".

? - When the fast scan is complete, click on the menu then <Options> <Changing <config; <scanner> Choose the tab, and uncheck <Analyse heuristique>. Then click on <Ok>.
? - Back in the main window: click to activate <Analyse complète>

selects all drives

? - Click the button with green arrow on the right and the scan will begin.
? - Click <Yes> for all at the prompt "Disinfect?" when a file is detected, and then click "Disinfect".
? - When the scan is complete, see if you can click on the icon adjacent to the files found (several leaves on top of one another). If yes, then click and then click on the icon <Next>, below, and choose Quarantine <Déplacer l'objet indésirable>.
? - From the main menu of the tool at the top left, click on the menu and choose <File> <Save the report>. Save the report to your desktop. The latter will be called DrWeb.csv


?-for the report you registered on your desktop, you right click / send to / compressed folders

Then:

you send me the archive like this:

click on this link: http://www.cijoint.fr/

? Click on Browse and look for the above file.

? Click Open.

? Click on "Click here to submit the file".

Link to this:

http://www.cijoint.fr/cjlink.php?file=cjge368/cijSKAP5fU.txt

is added to the page.

? Copy this link to your response.

? - Close Dr.Web CureIt
? - Restart your computer (important because some files can be moved / repaired on reboot).
0

Didn't find the answer you are looking for?

Ask a question
Anonymous User
Oct 2, 2010 at 07:30 AM
hello are you lost ? ^^
0
Ambucias Posts 47356 Registration date Monday February 1, 2010 Status Moderator Last seen February 15, 2023 11,169
Oct 2, 2010 at 07:38 AM
One of your messages got filtered again. Sorry, i just retored it!
0
Anonymous User
Oct 2, 2010 at 05:05 PM
yes I understood but where is our friend ?
0
Ambucias Posts 47356 Registration date Monday February 1, 2010 Status Moderator Last seen February 15, 2023 11,169
Oct 2, 2010 at 05:07 PM
Fouille-moi! Search me!
Bizarre! I hate it when they do that!
0
Hello sir....sorie for the late reply........since i was studying

The DOctor web is very difficult for me..........


Its ok sir......i'll stop this matter for now.......i'm giving up......its getting harder n harder........

Thank You for both of u for helping me.....i really appreciate it....
0
Anonymous User
Oct 7, 2010 at 07:09 PM
ok sorry for the late reply too

it's not really so difficult....^^
0