A few hints and tips from the Ookmeister

The_Unbeliever

Honorary Master
Joined
Apr 19, 2005
Messages
103,196
Way back in 2002-2003 I was fortunate enough to meet the Opaserv worm.

The PC's in question was Windows98 and 98SE with Norton 2003.

Norton would pick up the worm and clean it out, but could not stop the worm from infecting the PC.

So what we did was the following :

We would check for the name of the executable which Norton deleted/quarantined, and then we would create a folder of exactly the same name in the c:\windows and c:\windows\system folders.

So, for example, one variant of the Opaserv worm created an executable called BRASIL.EXE or BRASIL.PIF. Then one would just create a folder with the exact same name, and this stopped the worm cold. No more infection, until some bright spark at the other side tweaked the worm's code and it created other executables. Same method applied - check with Norton, create a folder.

Which brings us to 2010 - and beyond.

Recently I had to go to site to test an iBurst setup. The target PC had a nasty floozy trojan which would infect my memory stick, and I had to clean it every time I want to use it.

Brainwave.

I checked the memory stick with a Linux PC, and found that :

1. More often than not, the poxy trojan/worm/virus would create an autorun.inf file which would point to some random executable hidden within the Recycler folder.

So, I deleted the autorun.inf file, and created a folder with the name of autorun.inf

And I also created a file called Recycler

From that point onwards my memory stick remained clean and no further infections was possible even though the PC I introduced my memory stick to, was infected.

Please note that this might be of help to you in a tight spot, but I cannot guarantee that it will work 100%.

Regards

Libs
 

ubercal

Expert Member
Joined
Dec 5, 2005
Messages
3,986
Use a program called flash disinfector.Its creates a hidden autorun.inf folder / file and cleans out memory sticks and the root of all your partitions.Prevnets your memory stick from being inflected when you plug it into a virus infested pc.
 

Dixie

NSFW
Joined
Jan 23, 2009
Messages
19,389
Use a program called flash disinfector.Its creates a hidden autorun.inf folder / file and cleans out memory sticks and the root of all your partitions.Prevnets your memory stick from being inflected when you plug it into a virus infested pc.

Please note that this might be of help to you in a tight spot

Sometimes it's enough to hold the comments, listen/read, learn and admire the pearls of wisdom :)

Brilliant!

Thank you Libs.
 

Budza

Executive Member
Joined
Oct 14, 2008
Messages
8,620
Neat trick! Doing that on my flash right now :)

Assume the same is true for a (much more valuable) external HDD??
 

copacetic

King of the Hippies
Joined
Nov 22, 2009
Messages
57,908
That is excellent. That particular infection has been driving me around the bend.
 

Asha'man X

Expert Member
Joined
Aug 31, 2006
Messages
1,401
When I check the NOD32 server log at work, all I see are autorun and other random exe's on flashdrives. Obviously the kids' computers at home are infected, but they don't know it. Hell, one stick I disinfected today had 11 nasties on it. Man, I can't wait to get Win 7 on those machines so that you can control USB features through Group Policy so much easier...
 
Top