kengr: (Default)
kengr ([personal profile] kengr) wrote2014-11-22 06:50 pm
Entry tags:

Virus/Malware

My main machine seems to have picked up something nasty.

Thursday night I noticed that BitTorrent wasn't running any longer. And attempts to run it failed.

A reinstall got some really weird outgoing connection attempts, and a few other things were acting odd.

So I rebooted. To discover that a "software restriction policy" had disabled the firewall I use, Windows Firewall (which was turned off anyway) and my AV program.

Safe mode didn't work either. Got the login screen, but the keyboard and mouse were both disabled.

Trying for safe mode with command line got that too (which it shouldn't have).

Obviously something had majorly compromised things.

I wasted a few hours trying to get Windows installed on a spare drive (install went ok, except I couldn't boot off the drive).

I've spent time since then sticking the drives from the main box into a removable "rack" in another system (one at a time) and doing AV scans on them.

Didn't find anything significant.

Currently backing up the drives, and then I'll stick the boot drive back into the main system and try various repair tricks.

Worst case, I'll reformat it and reinstall Windows (and entirely too much other stuff).

Any suggestions on how to fix that software policy BS?

[identity profile] fayanora.livejournal.com 2014-11-23 05:21 am (UTC)(link)
By the way, that reminds me: is there a way to scan a thumb drive for viruses without risking my computer, too?

[identity profile] dornbeast.livejournal.com 2014-11-25 01:29 am (UTC)(link)
Can you rename your AV program's main file without causing problems?

At one time, I had a piece of malware that blocked my running web browsers and Task Manager, but it blocked them by file name, so by renaming taskmgr.exe to maskmgr.exe, I got around it.