1. SPS Accounts:
    Do you find yourself coming back time after time? Do you appreciate the ongoing hard work to keep this community focused and successful in its mission? Please consider supporting us by upgrading to an SPS Account. Besides the warm and fuzzy feeling that comes from supporting a good cause, you'll also get a significant number of ever-expanding perks and benefits on the site and the forums. Click here to find out more.
    Dismiss Notice
Dismiss Notice
You are currently viewing Boards o' Magick as a guest, but you can register an account here. Registration is fast, easy and free. Once registered you will have access to search the forums, create and respond to threads, PM other members, upload screenshots and access many other features unavailable to guests.

BoM cultivates a friendly and welcoming atmosphere. We have been aiming for quality over quantity with our forums from their inception, and believe that this distinction is truly tangible and valued by our members. We'd love to have you join us today!

(If you have any problems with the registration process or your account login, please contact us. If you've forgotten your username or password, click here.)

Cleaning up virus-infected files

Discussion in 'Techno-Magic' started by Ziad, Apr 16, 2009.

  1. Ziad

    Ziad I speak in rebuses Veteran

    Joined:
    Aug 3, 2004
    Messages:
    4,088
    Media:
    57
    Likes Received:
    47
    [​IMG] As I mentioned yesterday I got a nasty case of virus contamination from W32/Sality.L. As far as I can tell the system is now clean and the virus hasn't made a return. However I have over a hundred exe files in Quarantine and I would like to have some of them back. From what I can tell Avira (my current anti-virus) cannot clean them, all it can do is stick them in Quarantine and make sure the infection doesn't spread. I've found a couple of Sality removal tools on the net (one from AVG's website) but they refuse to run under 64-bit Windows (Vista Home Premium in my case). Anyone knows a tool I can use under 64-bit Vista to clean the infected files and get them back, or is the only solution to just delete these files and forget about them?
     
  2. Munchkin Blender Gems: 22/31
    Latest gem: Sphene


    Joined:
    Apr 18, 2007
    Messages:
    1,413
    Likes Received:
    14
    Gender:
    Male
    I like using Iobit advance system care on Vista 32; I'm not sure about Vista 64 though.
     
  3. Morgoth

    Morgoth La lune ne garde aucune rancune Veteran

    Joined:
    Jul 21, 2002
    Messages:
    3,652
    Media:
    8
    Likes Received:
    86
    Gender:
    Male
    A cleanup won't really help with a virus infection. You'll never be really sure whether the removal tool really found all of the infected files, and you'll never really know if the virus left a backdoor open for its next version. You shouldn't use your system for anything that is sensitive, like paying with your credit card. By the by: Sality is also a keylogger, meaning that it is designed to steal sensitive info so I would also make sure that your creditcard hasn't been hacked.

    I'd suggest you backup all nonexecutable files (exe's and dll's that were used after the infection and before detection are a lost cause,) reinstall your system and try to prevent any behaviour that led to a virus infection in the first place.
     
  4. Ziad

    Ziad I speak in rebuses Veteran

    Joined:
    Aug 3, 2004
    Messages:
    4,088
    Media:
    57
    Likes Received:
    47
    OK thanks for the info. I think I'll just format and reinstall the OS, seems to be the only way to be sure.
     
  5. Ragusa

    Ragusa Eternal Halfling Paladin Veteran

    Joined:
    Nov 26, 2000
    Messages:
    10,140
    Media:
    63
    Likes Received:
    250
    Gender:
    Male
    A re-install would also be my recommendation.

    I have now gotten myself an 8GB Sandisk U3 US stick, that I use for saving all my (web) e-mails to so I won't have to bother whether my comp is Vista 32, 64 or XP or Win7. Currently I use Vista 64 bit, Win7 64 bit and XP 32bit. It is a pain to either solely rely on web-mail or to synchronise multiple installations of Thunderbird. What I want to say with that is this: 'Outsourcing' some of my private data to a device I can simply plug out and keep physically safe somewhere (admittedly, at the expense of speed) has made re installations far less trouble prone for me. Of course, the other thing that solution lends itself to is centralising storage of bookmarks.

    Of course, the task of keeping the stick virus free remains, but that means, whatever I process to the stick passes web mail provider's virus check, my virus check and ultimately my stick's virus check. It's not that much of an issue.
     
  6. Ziad

    Ziad I speak in rebuses Veteran

    Joined:
    Aug 3, 2004
    Messages:
    4,088
    Media:
    57
    Likes Received:
    47
    The restoration is done. I've reconfigured everything (a bit of a pain, but oh well), downloaded all the updates and everything's up and running again. I think I've figured out where the virus came from - I had DosBox on a USB drive and the main exe there was infected, so it must have contaminated everything when I ran it on this system. I don't know why the antivirus didn't pick it up on runtime, and I don't know how the USB drive got contaminated in the first place (probably when I plugged it into a friend's PC). I'll just have to be more careful from now on.

    Thanks everyone for the suggestions and advice!
     
Sorcerer's Place is a project run entirely by fans and for fans. Maintaining Sorcerer's Place and a stable environment for all our hosted sites requires a substantial amount of our time and funds on a regular basis, so please consider supporting us to keep the site up & running smoothly. Thank you!

Sorcerers.net is a participant in the Amazon Services LLC Associates Program, an affiliate advertising program designed to provide a means for sites to earn advertising fees by advertising and linking to products on amazon.com, amazon.ca and amazon.co.uk. Amazon and the Amazon logo are trademarks of Amazon.com, Inc. or its affiliates.