Jump to content

Welcome to Geeks to Go - Register now for FREE

Need help with your computer or device? Want to learn new tech skills? You're in the right place!
Geeks to Go is a friendly community of tech experts who can solve any problem you have. Just create a free account and post your question. Our volunteers will reply quickly and guide you through the steps. Don't let tech troubles stop you. Join Geeks to Go now and get the support you need!

How it Works Create Account
Photo

Malicious virus - thwarts AV software; overruns CPU [Solved]


  • This topic is locked This topic is locked

#16
Transience

Transience

    Unofficial Music Guru

  • Retired Staff
  • 2,448 posts
Yes go ahead and stop Kaspersky if it hasn't finished yet... no need to let it finish. It won't delete critical system files even if you tell it to, but no need to try either. Just don't let it delete anything when it prompts you, and then go on with the backing up/formatting.
  • 0

Advertisements


#17
jsmitchell

jsmitchell

    Member

  • Topic Starter
  • Member
  • PipPip
  • 18 posts
Since PC #1 was dead, I used (old) PC #2 to download files to my flash drive and then run them on PC #1. The scary thing is that Kaspersky flagged some of the files on the flash drive I had left in as being infected! This virus apparently will infect every file on your PC if you let it. I reformatted the flash drive. I'm assuming there are no hidden files that can be re-infected I can't see (e.g. recycler, autorun.inf) that need to be worried about?

I purchased a WD MyBook 1T external hard drive in order to run Acronis disk imaging software on it. Since that itself came with software, I've backed that up to the flash drive and removed the drive. I'm now backing up PC #1's data files to it, all in safe mode. It's painfully slow. I'm also backing up the iTunes to CDs via the automated backup. I copied Outlook's PST file to preserve the email. I'm trying to be sure no application files are copied over. After reformatting PC #1 and reinstalling the software, when all is said and done, I will need to one more time do a Kaspersky check on the external hard drive to be sure I don't reinfect. After restoring the PC I'll download Acronis and take a disk image, and then keep doing that.

Important question: Each time anyone connects a USB device to a PC ii invokes an autorun.inf procedure. A sneaky virus would easily modify this file to immediately infect the USB device such that when you attach it to any other PC it infects that one as well. How do you prevent this? Is there anything else I should be aware of?
  • 0

#18
Transience

Transience

    Unofficial Music Guru

  • Retired Staff
  • 2,448 posts

I'm assuming there are no hidden files that can be re-infected I can't see (e.g. recycler, autorun.inf) that need to be worried about?

If you formatted the flash drive then no there's nothing to worry about.

After reformatting PC #1 and reinstalling the software, when all is said and done, I will need to one more time do a Kaspersky check on the external hard drive to be sure I don't reinfect

That's exactly the way to go about it, you should just take over my job here :). Once you've reformatted I'll give you a couple tools you can use to scan the drive to make sure that you won't reinfect your fresh install.

A sneaky virus would easily modify this file to immediately infect the USB device such that when you attach it to any other PC it infects that one as well. How do you prevent this?

Problems like these are becoming more and more common unfortunately, there are a couple registry keys that you can use to turn off most autorun functions, if you like I can write up a registry script for you that will make these changes once you've reinstalled. The other tool we use is called Flash Disinfector, which will help to protect your drives from future infection using a specially configured autorun.inf file. Just run it with your removable storage plugged in and it'll be immunized against any autorun attacks.

Cheers,
Dave
  • 0

#19
Transience

Transience

    Unofficial Music Guru

  • Retired Staff
  • 2,448 posts
Since this issue appears to be resolved ... this Topic has been closed. Glad we could help. :)

If you're the topic starter, and need this topic reopened, please contact a staff member with the address of the thread.

Everyone else please begin a New Topic.
  • 0






Similar Topics

0 user(s) are reading this topic

0 members, 0 guests, 0 anonymous users

As Featured On:

Microsoft Yahoo BBC MSN PC Magazine Washington Post HP