Jump to content

Recommended Posts

Some of you might already heard of this virus, so I'am just gonna tell what it did, what did i did, and what happened in order.

Yesterday my PC boot was *****ed, basically it told me that it couldn't boot, Windows just let me open CMD and couple of other things, when I tried CMD because I thought simply my SSD worn out, I opened DISKPART and noticed the root of CMD was X (it should be C:/) I disconnected my HDD and I thought it was weird and told a friend to come over with a fresh flash USB because I wanted to recover my files from the disks (I have a 128gb SSD and 1TB HDD), he came over and we ran a flash version of Windows, we could access my drives, we were transfering some of my files into a different USB and suddenly Windows told me that the remaining files I was transfering to my USB weren't there anymore, we went an checked the drive in the "This PC" tab and C:/ was completly gone, the only thing that was there was: the USB with the flash, my own USB, and the Boot (X) disk (which was a partition of the C:/ drive), so my SSD was suddenly gone, we had some utilities in one of those USBs (dont remember which) and we tried executing Recuva and CrystalDiskInfo, instead of them apps opening we just received the "this file isn't located here anymore do you wanna erase it" I can't remember the exact message but it happens whenever you try to open a direct link of an app and the app isn't there anymore.

So after this we thought that the PC was absolutely bricked, my SSD was gone, and both USB (including the one that was running Windows) were both infected and probably if we reeboted the PC it wouldn't boot anymore, we disconnected the GPU and the Internet PCIe wi-fi card in my PC (I don't have Ethernet and also my Motherboard doesn't have wi-fi by default) so we rebooted to see if we could flash the BIOS or something, we rebooted and not even the BIOS screen showed, just the "Insert appropiate BOOT device" message, so we took the CMOS battery of the motherboard off and both RAMS (16GB dual-channel) so the PC could not boot, then inserted one stick of RAM, then we took a different and clean USB, connected it to a different and clean laptop and downloaded the lastest firmware for my motherboard (Gigabyte A520M-H) right after that we remembered that we had a HDD disk with WinterOS just laying around, we disconnected the SSD and connected the hard drive with the OS, and it booted up but we saw lots of process that weren't native from Windows and the ones that were Windows native were consuming lots of resources, so then we knew that this virus survived the new firmware, so we tried out best running antiviruses and Windows Defender but nothing got detected, we rebooted again and opened Task Manager once again, we didn't saw any weird processes so we thought maybe the PC was clean, we inserted the PCIe Wi-fi card, GPU and the remaining RAM stick, he left and I continued using my PC normally (without any of the 2 drives I had, just the one that was clean and just laying around disconnected) after like 3 hours of just watching Youtube I went to the PC and turned it off, noticed it was taking a long time to turn off but I waited and decided to boot up again to see what was up, well, THE EXACT SAME THING AT THE START, like Windows couldn't boot and just let me like open CMD and couple of other stuff.

Right now my whole PC is disconnected, you can do your research on this virus (even though it doesnt have a lot of info on the Internet) but its like you can get rid of it, it goes into your devices firmware, into the memory of your USB devices (mouse, keyboard) and I've read some cases of guys that found the virus on the router or something like that.

What should I do?, I suppose lots of stuff in my house are infected and I'am going to install new firmware on my router and do a factory reset, but it seems useless, I just can't use my PC anymore, it scares me, anything will be of great help, I just want to game again.

PC Specs:
Ryzen 5 3400G
RX 580 8GB Nitro +
16GB RAM Dual-Channel
Gigabyte A520M-H
600W Cougar 80 Plus Bronze
128GB SSD and 1TB HDD

Redragon Dragonborn 60% Keyboard
G203 Lightsync Mouse
HyperX Stinger Headphones

GLG 27" 75hz Monitor
DELL 24" 60hz Monitor

Link to post
Share on other sites

  • Root Admin

Try a new NVMe hard drive and see if you can install Windows with that and if there are any issues doing so.

 

Example drive for testing only since it's so cheap.

https://www.newegg.com/kingspec-128gb/p/0D9-000D-00150?Item=9SIB1V8HP68400

image.png

 

Clean Install Windows 10 & 11 (2023)
https://answers.microsoft.com/en-us/windows/forum/all/clean-install-windows-10-11-2023/1c426bdf-79b1-4d42-be93-17378d93e587

Also, please review the following topic

Bypass Microsoft Online Account Creation during installation of Windows 11
https://forums.malwarebytes.com/topic/296613-bypass-microsoft-online-account-creation-during-installation-of-windows-11/

 

 

Link to post
Share on other sites

2 hours ago, AdvancedSetup said:

Try a new NVMe hard drive and see if you can install Windows with that and if there are any issues doing so.

 

Example drive for testing only since it's so cheap.

https://www.newegg.com/kingspec-128gb/p/0D9-000D-00150?Item=9SIB1V8HP68400

image.png

 

Clean Install Windows 10 & 11 (2023)
https://answers.microsoft.com/en-us/windows/forum/all/clean-install-windows-10-11-2023/1c426bdf-79b1-4d42-be93-17378d93e587

Also, please review the following topic

Bypass Microsoft Online Account Creation during installation of Windows 11
https://forums.malwarebytes.com/topic/296613-bypass-microsoft-online-account-creation-during-installation-of-windows-11/

 

 

I already test it in a new hard drive (HDD), in some hours of use the disk got useless again by BOOT X:, i think that is a virus really

Link to post
Share on other sites

Guest
This topic is now closed to further replies.
  • Recently Browsing   0 members

    • No registered users viewing this page.
Back to top
×
×
  • Create New...

Important Information

This site uses cookies - We have placed cookies on your device to help make this website better. You can adjust your cookie settings, otherwise we'll assume you're okay to continue.