Everything in Programfiles(x86) gone

King_Geedorah

Commendable
Mar 15, 2016
2
0
1,510
Hi there,

I'm hoping somebody on this forum can give me a sanity check. A couple of days ago I had what I'm 99% sure was Java pop up from my task bar asking for an update while I was making some music. I was distracted at the time but the update was definitely legit (or at least it was coming from an already installed app on my Laptop rather than from an online popup) and I allowed it to update while I carried on with what I was doing. A little while later I went to open a program only to find that it was gone. Long story short, I then went on to discover that my D: drive was 700gb lighter and that everything that had been in the program files(x86) folder on that drive was now gone.

After a bit of research on google and in forums like this one I decided that it sounded like I'd contracted the java.blacole virus and that it had wiped my program files (x86) folder. First thing I did was delete Java. Over the past few days I've backed up as much as I can from the laptop and run a ridiculous number of security programs in an attempt to find and kill the virus (Avast, Malware Bytes ESET Online, MSE, Spybot, aswMBR, TDDSKiller, Roguekiller, MSE Offline and probably more). I simply cannot find the virus, and I'm hoping that's because I managed to kill it by deleting Java immediately. I know the simple answer to this is that I should re-format the laptop to be 100% sure the virus is gone but I really don't want to do that, it's set up just how I like it and fortunately a lot of the apps I use to work on were in the program files folder and are thus ok, I've mainly lost games which are easily reinstalled.

I'm hoping somebody here can tell me if I've missed something crucial to making sure the virus is gone, or if I was even on the right lines in the first place by thinking it was this particular virus. I've heard that the exploit can be used for a number of things including key logging and stealing financial data so I really want to be as sure as I can be that it is gone, though I'm hoping that this particular strain was just a malicious one made to delete the infected's programs rather than one to steal data.

Thanks in advance!
 
Solution
Not seeing anything astray in what you have done and there may not be much more that you can immediately do.

However, I would keep the laptop isolated from any other computers or devices while using the laptop. I.e., do not coy files to other locations.

Just keep using the laptop and add back the games, etc., one by one. Watch for any unexplainable behavior such as disk activity when nothing should be happening.

Researche and check out the app that started the whole situation - maybe there is some vulnerability being exploited.

Use Task Manager to monitor the processes and services that are running. Research any that you cannot account for or account for why they might be running at a particular time.

Run regular AV scans plus...
Not seeing anything astray in what you have done and there may not be much more that you can immediately do.

However, I would keep the laptop isolated from any other computers or devices while using the laptop. I.e., do not coy files to other locations.

Just keep using the laptop and add back the games, etc., one by one. Watch for any unexplainable behavior such as disk activity when nothing should be happening.

Researche and check out the app that started the whole situation - maybe there is some vulnerability being exploited.

Use Task Manager to monitor the processes and services that are running. Research any that you cannot account for or account for why they might be running at a particular time.

Run regular AV scans plus a few others at random. Hopefully you got the virus but wise to presume not and keep your guard up.
 
Solution

King_Geedorah

Commendable
Mar 15, 2016
2
0
1,510
Thanks Ralston, really appreciate the feedback and the great advice. Glad to hear that you think it sounds like what I've done thus far is right, I'll keep an eye on everything you've suggested and hope it's not still lurking somewhere.

If anybody has any specific experience with java.blacole I'd love to hear their thoughts too, I'm pretty perturbed that after 20+ years of using PCs and managing to never contract anything serious that something has managed to wipe 700gb of my data in a blink of an eye.