Post mortem of a virus :)


 
Thread Tools Search this Thread
Top Forums UNIX for Dummies Questions & Answers Post mortem of a virus :)
# 1  
Old 11-07-2008
Post mortem of a virus :)

Hi,

My pen-drive got infected with a virus when I used it on a windows system.

When working on a fedora system, I could view the files that the virus created, and the virus exe file itself.
I navigated into the pen drive using the bash prompt, and opened the virus exe file with the vi editor. I deleted all the lines in the file and saved the file. Now the file contains nothing Smilie (details of the files and folders provided below)

The trouble is that I'm not able to delete the file.
The folder that contains the two virus files shows this for an ls -l

-rwxr-xr-x 1 p913001 root 19 2008-11-03 00:32 Desktop.ini
-rwxr-xr-x 1 p913001 root 29 2008-11-03 00:33 ise32.exe

Question 1:
I've tried modifying the file permissions with chmod, but still couldn't delete the file. How to delete it?
Question 2:
If I simply delete these file from the pen drive, can I consider my pen drive virus free? (additionally, since the ise32.exe file now contains nothing, does it mean that the virus is dead?)

Details:
The root folder of the pen-drive contained an autorun.inf file which the virus created. I deleted that file.
There's a folder called 'restore' which I can't delete. This 'restore' folder contains a folder called 'S-1-5-21-1482476501-1644491937-682003330-1013'. It is this S-1-5-21-1482476501-1644491937-682003330-1013 folder which contains the Desktop.ini file and the ise32.exe file.
# 2  
Old 11-07-2008
Why not format ie. mkfs it?
# 3  
Old 11-07-2008
Well, Fedora doesn't provide the option to format a pen-drive.
As for mkfs, I'm worried if it'll format the pen drive in some format that I won't be able to use it on a windows system again....
What parameters could I use for the mkfs command to format the pen drive without any problem?

More importantly, I'd like to know how to delete those virus files and whether just deleting them gets rid of the virus?
# 4  
Old 11-08-2008
Do I need to change the permissions from 'root' to something else? If so, how?
# 5  
Old 11-09-2008
Well it is next to impossible to destroy your Pen drive with only software ( you might have to rewrite the partition table if anything failed, but it would still be ok) ... just try formatting it with fat32.... mkfs.fat32 (your commands might be different, never used fedora) And the data will be gone(EVERYTHING stored on the stick; if there is anything important back-up scan with ClamAV and then put it back on afterwards).

The permissions should be ok....
# 6  
Old 11-11-2008
Hey, thanks a lot for the reply....could I get a confirmation about the Fedora part? One more thing....should I navigate into the root directory of the pen drive and then type mkfs.fat32 or can I do it from the root directory of the hard disk itself (I've got a feeling this is a stupid question, but I'm a unix newbie)

P.S: During this period of time, I took my pen-drive to a clean windows system, scanned it with Avast (and no virus was detected, probably coz I removed all the code from the exe file Smilie and I formatted it in windows)
But a friend borrowed it and got it infected again....this time, there's a wcluf.pif file and an autorun.inf file in the pen drive. It doesn't look like a virus to me, but I'm gonna try removing the contents of these two files too Smilie (Bless this VI editor)

Meanwhile, I'm repeating the question for the third time...if anyone knows the answer, please reply: the virus files weren't getting deleted, probably coz it had root permissions or something. The ls -l command output which I posted above shows it. How can I delete those files?
# 7  
Old 11-11-2008
ok step-by-step ( do this on a root shell)

a) Find the device your USB stick is on
type "mount"
this will list all drives you have. Note where your USB stick is
(something like /dev/sdb1 ,etc... , starts with /dev/ ).
b) Then you should type "umount (path to your USB stick device, starts with /dev/,m the one you got in step 1 )"
c) then you type "mkfs.fat32 (path to USB stick device from a)


Note: you should not have any programs accessing your USB stick during the procedure or umount might fail...
 
Login or Register to Ask a Question

Previous Thread | Next Thread

9 More Discussions You Might Find Interesting

1. Windows & DOS: Issues & Discussions

Windows XP keeps getting virus

Hi All, My old laptop has Windows XP. I reinstalled only last month and installed AVG free anti-virus. It's like every month, I get some kind of spyware or virus issue. which anti-virus software you guys using? Thanks. (8 Replies)
Discussion started by: samnyc
8 Replies

2. AIX

Post mortem for critical Production AIX System Reboot/Crash

Hello All, Critical AIX production box crashed/rebooted while our team is working on it and we need to generate a detailed report for that, below are few questions that need to be included in the report. (We are System Administration team and everyone in our team has root access via sudo as well... (3 Replies)
Discussion started by: lovesaikrishna
3 Replies

3. UNIX Desktop Questions & Answers

Virus and Malware

How do i manage virus and melware in Unix ? (2 Replies)
Discussion started by: Suriano10
2 Replies

4. Windows & DOS: Issues & Discussions

virus help:

:confused: folder option is dissapiaring in tool menu iam formatting c drive after removal of this virus & also regedit is also not opening the messerge say's administrater disabled with out formattiung how ican solve this problem i.e iwant to get folder options& regedit (2 Replies)
Discussion started by: seshumohan
2 Replies

5. UNIX for Dummies Questions & Answers

unix and virus

why one normally hears tht virus has stuck windows and one does not hear that unix has been stuck by virus...wht make unix so powerfull tht virus does not stuck it. (9 Replies)
Discussion started by: taurian1234
9 Replies

6. UNIX for Dummies Questions & Answers

Worm Virus

I am running Unix SCO and have discovered the worm virus. It is enabled through a BIOS connections, I am able to get around it using telnet, believe it or not. - Can anyone recommend a virus scan software? - Has anyone successfully used a virus scan software on unix without a problem? ... (2 Replies)
Discussion started by: ana_cr32
2 Replies

7. UNIX for Dummies Questions & Answers

Virus !!!!!!!!!!!!!!!!!!!

can linux get a virus on the boot sec from windows? becuse my buddys computer micro trend cmos virus keeps telling him that there is a boot sec virus on my hdd is that possable or is the box being dumb and looking at the linux boot as a virus? it was set up as a windows box not a linux... (4 Replies)
Discussion started by: amicrawler2000
4 Replies

8. UNIX for Dummies Questions & Answers

virus????????

i tought you can;t get virus in unix ? i have some admins buddys that work in bsd all he time and they sayed you can;t get viurs in unix is that true? download.com is putting virux updates out for mac OS X ................ (7 Replies)
Discussion started by: amicrawler
7 Replies

9. Cybersecurity

do i have a virus???

nice board, makes interesting reading! glad to know im not the only one to have problems!! :D :D last week, our database started to crash (run on unix / solaris) for no apparant reason. the problem seems to be intermiant which lead us to believe it may be a hardware problem causing the... (2 Replies)
Discussion started by: mdma
2 Replies
Login or Register to Ask a Question