Saturday, December 24, 2011

Virus & Trojan

Just hours before a final, I got a virus that slipped by the scanner....

What a nightmare.  It destroyed my start menu, shortcuts,....  It hid all the files on the hard drives.  At first I thought it had wiped the drives.  It wouldn't even let  task manager or system explorer start. 

After a little digging, it came to me.  I copied system explorer to a.exe.  Then the virus allowed it to start.  It wasn't smart enough to look at program signatures, only the running name.  Once system explorer started, I was able to find the running program that was blocking everything and kill it.  Then I removed that program.  Updated the virus signatures and scanned the disk.

Now to unhide the files...... Quickest way I knew of was to start a command prompt and use the attrib command with recursion.  Voila, files back.

I was able to use the laptop for taking the final.

After the final, I finished resetting file attributes and rebuilt my start menu.

At that point I was so glad to have multiple backups.  I was very afraid that I was going to be rebuilding a system from scratch.  But my important data was backed up.

No comments:

Post a Comment