kengr: (Default)
[personal profile] kengr
My main machine seems to have picked up something nasty.

Thursday night I noticed that BitTorrent wasn't running any longer. And attempts to run it failed.

A reinstall got some really weird outgoing connection attempts, and a few other things were acting odd.

So I rebooted. To discover that a "software restriction policy" had disabled the firewall I use, Windows Firewall (which was turned off anyway) and my AV program.

Safe mode didn't work either. Got the login screen, but the keyboard and mouse were both disabled.

Trying for safe mode with command line got that too (which it shouldn't have).

Obviously something had majorly compromised things.

I wasted a few hours trying to get Windows installed on a spare drive (install went ok, except I couldn't boot off the drive).

I've spent time since then sticking the drives from the main box into a removable "rack" in another system (one at a time) and doing AV scans on them.

Didn't find anything significant.

Currently backing up the drives, and then I'll stick the boot drive back into the main system and try various repair tricks.

Worst case, I'll reformat it and reinstall Windows (and entirely too much other stuff).

Any suggestions on how to fix that software policy BS?

Date: 2014-11-23 05:21 am (UTC)
From: [identity profile] fayanora.livejournal.com
By the way, that reminds me: is there a way to scan a thumb drive for viruses without risking my computer, too?

Date: 2014-11-25 01:29 am (UTC)
From: [identity profile] dornbeast.livejournal.com
Can you rename your AV program's main file without causing problems?

At one time, I had a piece of malware that blocked my running web browsers and Task Manager, but it blocked them by file name, so by renaming taskmgr.exe to maskmgr.exe, I got around it.

June 2025

S M T W T F S
1234567
891011121314
15161718192021
2223242526 2728
2930     

Most Popular Tags

Style Credit

Expand Cut Tags

No cut tags
Page generated Jul. 5th, 2025 11:47 pm
Powered by Dreamwidth Studios