|
Posted by Dustin Cook on March 15, 2008, 9:17 pm
Please log in for more thread options $CO3.141@trnddc04:
>
>| well to make the short story long -tried from a supposedly clean 98/
>| XP PC with attached infected win98 disk : comd.line mcafee, nod32,
>| avg, addaware,avast with no sucess 'cause either they get stuck in the
>| infinitely deep recursive subfolders virus makes in windows folder and
>| elsewhere or the AVs could not open/check bunch of files.
>| Comm.line Sophos did find, but only on usb flash, MAL/AUTOINF-A but
>| did not clean it in full mode.
>| Personally I saw (also on USB) an autorun and MSOCACHE/90000.../
>| kb915865.exe however its killer?VirusCleaner from e-nil site (nor
>| avg,avast) did not find anything on hdd from which usb was infected.
>| Anyway aside from recursive folders on infected win98 HDD, problem is
>| there are 2 types of infected files and virus refuses to get zipped or
>| submited to an antivirus site(havent tried ftp though)
>| -if you try in win/dos to zip or copy the first kind
>| of infected files-the falsely too big ones(example pkunzip.pif
>| 129MB), the virus is not included-i.e. you get a clean
>| file-with normal size(changing attributes does not help)
>| - the other type of files are the ones whose names are
>| malformed with including \ or | so you cant even rename
>| In addition virus (or viruses) hide in boot sector cause the mentioned
>| win98 infected hdd will not boot any more and also when reformated
>| another infected disk, to prepare a clean win98 PC it would get stuck
>| in installation until the disk was zeroed first!
>| Also when you stick flash in infected PC(while the disk still worked-
>| now it cannot be accesed at all-&probably needs fixboot) the usb diode
>| just kept flashing and PC bluescreened reporting usspdrr.vxd error
>| Anone came across this evil or can suggest antivirus that has
>| definitions for rootkits or registry checker that can load registry
>| hives from an attached disk as EasyPCFix can?
>
> Huh ??
>
Lost you too huh? :)
--
Regards,
Dustin Cook - http://bughunter.it-mate.co.uk BugHunter v2.2e AntiMalware Removal Utility
|