Help - Search - Members - Calendar
Full Version: Scanning Infected Laptop Drive
BleepingComputer.com > Security > AntiVirus, Firewall and Privacy Products and Protection Methods
   
garmanma
My daughter's friend has a laptop that needs a new mother board. She can't afford it at the moment but wants me to try and retrieve her pictures. My daughter informs me that the computer is "infected beyond belief". After I put the drive in an external enclosure and scan it with my anti-virus, are there any other recommended tools I can use so I can transfer/burn the files safely? I'm not that familiar with external drives yet
Thanks
Mark
tos226
Mark,

I'd backup your own system first, who knows what it'll do to you as you connect smile.gif

I think a good antivirus will catch things on that drive, and then again as you copy so long as you set it to monitor read and write.

The problem is if that drive has some rootkit on it or some other hijacker ...

I'd run more that one AV on that drive and I'd definitely run a-square and on-line Kaspersky and I think NOD32 has an on-line scanner as well. Spyware is minor but superantispyware run might bot be a bad idea.

I really don't know just hinting at possible ways.

This is a very interesting topic. I'll be watching the expert replys!
Teenage.Zombiee
tos226 gave you some great advice smile.gif

The main thing is your going to scan it with your anti virus as soon as its hooked up to your computer just so you don't get infected ;)
Online scans are your best bet. Id try Kaspersky, Housecall (Trend Micro) and anothe of your choice. See what they find.

You could maybe run AVG Anti rootkit. Im not exactly sure how that program works but Im pretty sure you could select to scan that drive.

Super Anti Spyware is a good idea to run. Just to be sure.

See what they find.

Also as for transfering the files. I would virus and spyware scan them first. Then either burn to a data CD or put on a flash drive.

Im quiet interested in how this goes garmanma and I hope it all turns out well thumbup.gif
garmanma
QUOTE(tos226 @ Jan 21 2008, 09:05 PM) *
Mark,

I'd backup your own system first, who knows what it'll do to you as you connect smile.gif

I think a good antivirus will catch things on that drive, and then again as you copy so long as you set it to monitor read and write.

The problem is if that drive has some rootkit on it or some other hijacker ...

I'd run more that one AV on that drive and I'd definitely run a-square and on-line Kaspersky and I think NOD32 has an on-line scanner as well. Spyware is minor but superantispyware run might bot be a bad idea.

I really don't know just hinting at possible ways.

This is a very interesting topic. I'll be watching the expert replys!

I'll probably start this weekend. I figured I'd try all the online virus scanners. It's the other nasties I'm a little worried about
Mark
boopme
Mark after running Online Panda active scan and say eset online scanner and running your A/V, run SuperAntispyware. Alll are on the freeware page, except this one yet
ESET's Online Scanner

Then use steps 1 & 2 here SmitFraudFix

Run Super and`Smit from Safe mode
garmanma
Thanks. I'm making up my-to do list now. I'm in for a busy week and week-end. I'll post back with results when I find out
Mark
garmanma
Results of what has been done so far:
---------------
AVG anti-virus clean
---------------
AVG anti-spy normal cookies
-----------
TrendMicro normal cookies
-----------------------
Onecare live normal cookies
one high risk win32/NewDotNet also mentioned Kazzaa
------------------
Eset clean
------------------
Bit defender 15 viruses identified
I'll copy/paste the log if anyone cares
--------------
Kapersky
No viruses found

Still have to try SmitfraudFix
Mark
ruby1
I would suggest you DO post the results and logs from the scans for the Team to check out;how well does the comp run?
garmanma
QUOTE(ruby1 @ Feb 10 2008, 12:34 PM) *
I would suggest you DO post the results and logs from the scans for the Team to check out;how well does the comp run?

It doesn't. It's a drive from a computer that I'm fixing for a friend, in a USB enclosure. She didn't have the money to fix it right away so I was going to pull the pictures off it. She just dropped off the money last night so I'll probably fix it then do a Hijack log. I'll still probably run Smitfraud as long as it's hooked up to my computer
Mark
This is a "lo-fi" version of our main content. To view the full version with more information, formatting and images, please click here.
Invision Power Board © 2001-2008 Invision Power Services, Inc.