You are here

ClamWin: Dealing w/ worm on desktop

10 posts / 0 new
Last post
prr
Offline
Last seen: 11 months 3 weeks ago
Joined: 2010-01-21 12:08
ClamWin: Dealing w/ worm on desktop

There is a worm (conficker)that keeps infecting a desktop I plug my USB drive into. I see portable apps has ClamWin and Spybot. What would be the best solution for me to keep my usb drive clean? I'm not trying to clean up the desktop--that has been done in the past and someone keeps re-infecting it. I just wanna shield my own usb drive. I'm tired of plugging it back into my laptop and getting that message again.

ZachHudock
ZachHudock's picture
Offline
Last seen: 1 year 10 months ago
Developer
Joined: 2006-12-06 18:07
No way to guarantee your

No way to guarantee your drive stays clean if the desktop is infected.

I would recommend trying to remove the worm. Check out the below sites

http://www.confickerworkinggroup.org/infection_test/cfeyechart.html
http://www.ghacks.net/2009/03/31/conficker-worm-detection-and-removal/
https://isc.sans.edu/diary.html?storyid=5860

The developer formerly known as ZGitRDun8705

solanus
solanus's picture
Offline
Last seen: 10 years 1 month ago
Joined: 2006-01-21 19:12
Did you talk to the person responsible for the desktop?

Whoever it is, I'm sure they don't want to have that worm. Lots of people tend to neglect their virus definition updates until they have a problem; telling them may get them to take action to protect themselves, which would be good for you as well.

I made this half-pony, half-monkey monster to please you.

prr
Offline
Last seen: 11 months 3 weeks ago
Joined: 2010-01-21 12:08
Yeah I guess not

I went onto the desktop this morning but couldn't even get online--I was gonna download something to clean it up. I see that there are several malware scanners for USB drives, but nothing that will act as a resident 24/7 scanner (just the manual one-time scanners). Oh well it was worth asking.

Yeah the long term solution is to clean the desktop, but as I said, someone is obviuosly reinfecting it, so I'll need to protect my own drive from it till it gets an updated AV.

vf2nsr
vf2nsr's picture
Offline
Last seen: 8 years 1 month ago
Developer
Joined: 2010-02-13 17:10
With all due respect

I would not be playing with fire, if it is infected I would be putting nothing into the machine, unless it w as a cd version of an AV program to rid it of the issues!

“Be who you are and say what you feel because those who mind don't matter and those who matter don't mind.” Dr. Seuss

solanus
solanus's picture
Offline
Last seen: 10 years 1 month ago
Joined: 2006-01-21 19:12
Is this a school desktop,

Is this a school desktop, work computer, library, or friend? If you can't talk to the owner, maybe put a paper post-it on the screen that says, "This computer is infected with the conficker worm."
The squeaky hinge gets the oil, yadayada.

I made this half-pony, half-monkey monster to please you.

prr
Offline
Last seen: 11 months 3 weeks ago
Joined: 2010-01-21 12:08
Sent an email and a phone call to tech support

Yes its a computer at school. The guy said he cleaned it up last week, but av isn't being updated.... Hopefully he decided to do something about it that will be a permanent solution.

Ken Herbert
Ken Herbert's picture
Offline
Last seen: 20 hours 23 min ago
DeveloperModerator
Joined: 2010-05-25 18:19
AV not updating is another

AV not updating is another side-effect of Conficker - so the computer is more than likely still infected.

As I said below, using your standard AV will only remove the surface effects of malware like this. He needs to use some Google magic to find a dedicated Conficker removal tool and/or removal guide to really have a proper go at destroying it.

Ken Herbert
Ken Herbert's picture
Offline
Last seen: 20 hours 23 min ago
DeveloperModerator
Joined: 2010-05-25 18:19
Just because the computer

Just because the computer keeps being reinfected does not mean "someone" is doing it on purpose.

Many worms, trojans etc. use a back-end that is nearly undetectable to your usual spyware and antivirus programs - all they detect and remove is the primary effects of the malware - but usually files remain that don't flag as malware that cause the infection to reoccur.

Conficker is one of these.

rgilley7
Offline
Last seen: 12 years 12 months ago
Joined: 2011-11-28 06:43
Can't Get On Line

Check to see if the worm has set up a proxy in the web browser. After removing the proxy you may be able to get on line. I've been using Microsoft Security Essentials recently and it does a decent job of protecting my users. MSE also has a setting to scann USB devices when they are connected to a computer.

Bob Gilley

Log in or register to post comments