Showing posts with label false positives; Windows XP. Show all posts
Showing posts with label false positives; Windows XP. Show all posts

October 30, 2010

New computer!

My trusty old Acer TravelMate 2490 is getting - well old. It is running Windows XP ok, but could do with a reinstall. Ubuntu has been performing well and I recently upgraded from 10.04 to 10.10. But memory is sparse (1.5 GB - well enough for Ubuntu - a little on the low side for Windows XP) and the battery is tired - very tired. Ubuntu reports that it is down to 6.6 % and it can barely hold power for the boot sequence.

So it was time for a new computer. The tm2490 has not been retired yet - I will run a recovery for Windows XP and readjust the split for Windows/Ubuntu filespace. It will then serve as a computer for our soon to be 4-year-old. I am keeping the Windows XP just in case some of the educational games we have won't run under Wine.

I have been on the hunt for a new computer for a couple of months now and had a few favourites. I wanted a smaller computer than the tm2490 (a 15.4") preferably a 13.3" with a long battery life. Small and light with plenty of battery life so that I can use it for programming and web development. I would also like a reasonable 3D Graphics card as I spend time playing 3D games (WoW, Planet Calypso, etc, and hopefully Civ V soon - mostly in Windows, sorry!). But as our budget did not allow any new purchases during that time span I kept looking.

As an opening in our budget opened it would not support a small, speedy 13" 3D racer. So I decided upon the Acer Aspire 5738ZG. Specifications: Intel Pentium T4500 (dual core, 2.3 GHz), ATI Radeon HD4650 (1GB), 4 GB DDR3, 320 GB HDD, 15.6" (1366 x 768) LCD.

This laptop came with Windows 7 Home Premium 64-bit preinstalled, which I intend to keep. Partly for gaming, partly as I need to know Windows 7 better for my everyday work needs (I sell computers).

Acer used to devide their hard drives into 3 partitions, of which 2 were visible to the user. One "Windows" partion (usually named "ACER"), one Recovery partition (hidden from Windows), and one data partition (usually named "ACERDATA"). The plan was that you use the "ACERDATA" to store your documents and other user files and leave the "ACER" partition for Windows and installed programs. If You needed to recover or re-install Windows you then would not loose your documents, music, pictures, etc. I am not awar if this has changed with Windows 7, but at least on this computer, there was only the recovery partition and one large Windows partition.

This lap top is a bit bigger and heavier than I wanted but so far it has been a good machine to work on. In my next post I will be covering my Ubuntu experiences on this computer.

April 15, 2009

Windows Vira fixed with Ubuntu & ClamAV?

Earlier today to my fear and disgust I found out that I had been the "lucky" landlord of a Virus. Apparently the B****** crept in either because the Anti Virus software I am using was not fully updated. So what does a clever man do?

Luckily (hopefully) I found out while windows was booting which I aborted, so I am hoping not too much damage has been done.

On Ubuntu ClamAV is offered as both an Anti Virus Software in the personal sense as well as deamons that can be integrated into both email and HTTP (web) proxy servers in the defense of a network. This blog will concentrate on looking for and removing a virus/worm/trojan horse on a hard drive (and in this case a Windows partition)

Well as we speak I am currently screening the hard drive with ClamAV from Ubuntu as my laptop is a dual (actually triple) boot system with Windows XP and Ubuntu 9.04 Jaunty Jackalope Alpha6/Beta. (It was installed as Alpha6 but should have a Beta status, as it is updated almost daily).

So far the intruder (Trojan.Swizzor.Gen) has been found twice on the boot partition now I have to remove it, without too much damage. It might also have hid itself somewhere in the windows disguising itself from the AV-software, but I am hoping that ClamAV will get it. I hope to return to this matter with a positive report, probably tomorrow.

Update (April 16th, 7.05 am GMT+3):
The result of the scan was:
/media/ACER/i386/FONTEXT.DL_: Trojan.Swizzor.Gen FOUND
/media/ACER/WINDOWS/system32/fontext.dll: Trojan.Swizzor.Gen FOUND
/media/ACER/WINDOWS/Installer/$PatchCache$/Managed/00002119F20000000000000000F01FEC/12.0.4518/XL12CNV.EXE: W32.Virut.Gen.D-163 FOUND
/media/ACER/WINDOWS/Installer/$PatchCache$/Managed/00002119F20000000000000000F01FEC/12.0.4518/EXCEL.EXE: W32.Virut.Gen.D-163 FOUND
/media/ACER/WINDOWS/Installer/$PatchCache$/Managed/00002119F20000000000000000F01FEC/12.0.4518/VBE6.DLL: W32.Virut.Gen.D-159 FOUND
/media/ACER/WINDOWS/Installer/$PatchCache$/Managed/00002119F20000000000000000F01FEC/12.0.6215/EXCEL.EXE: W32.Virut.Gen.D-163 FOUND
/media/ACER/WINDOWS/Installer/$PatchCache$/Managed/00002119F20000000000000000F01FEC/12.0.6215/XL12CNV.EXE: W32.Virut.Gen.D-163 FOUND
/media/ACER/WINDOWS/Installer/15826ea.msp: W32.Virut.Gen.D-163 FOUND
/media/ACER/WINDOWS/Installer/15826fc.msp: W32.Virut.Gen.D-163 FOUND
/media/ACER/WINDOWS/Installer/1f3ab5.msp: W32.Virut.Gen.D-163 FOUND
/media/ACER/WINDOWS/Installer/1f3ac7.msp: W32.Virut.Gen.D-163 FOUND
/media/ACER/WINDOWS/Installer/2d377c4.msp: W32.Virut.Gen.D-163 FOUND
/media/ACER/WINDOWS/Installer/2d377d6.msp: W32.Virut.Gen.D-163 FOUND
/media/ACER/WINDOWS/Installer/a0f264.msp: W32.Virut.Gen.D-163 FOUND
/media/ACER/WINDOWS/Installer/a0f276.msp: W32.Virut.Gen.D-163 FOUND
/media/ACER/WINDOWS/$NtServicePackUninstall$/fontext.dll: Trojan.Swizzor.Gen FOUND
/media/ACER/WINDOWS/ServicePackFiles/i386/fontext.dll: Trojan.Swizzor.Gen FOUND
/media/ACER/Programmer/Microsoft Office/Office12/EXCEL.EXE: W32.Virut.Gen.D-163 FOUND
/media/ACER/Programmer/Microsoft Office/Office12/excelcnv.exe: W32.Virut.Gen.D-163 FOUND
/media/ACER/.Trash-1000/files/RESTORE/k-1-3542-4232123213-7676767-8888886/BLUE.exe: Trojan.Agent-81496 FOUND

Known viruses: 539153
Engine version: 0.95.1
Scanned directories: 12009
Scanned files: 121566
Infected files: 20

Apparently ClamAV does false positives on the Trojan.Swizzor.Gen virus. I do not know what to think but I am uploading the files to an online virus scan as we speak.

However the scan also found W32.Virut.Gen.D-163 and Trojan.Agent-81496 in my files. These are viruses. I am uploading all the files reported by ClamAV to virusscan.jotti.org to verify ClamAVs claims and to confirm if they are (a) false positive(s). An update on this will follow later.