Help - Reinstall Windows and avoid getting virus from slave drive

Associate
Joined
3 Jun 2003
Posts
1,775
Location
Gibraltar
This is the background

One of my PCs is current running a very sick Windows XP SP3, with at least one virus that uses any FTP accounts to upload rubbish to my websites (see iframe hacks).

With the FTP port blocked I am able to contain the effect but no antivirus has been able to clear the PC up, and Windows Updates are broken. The main problem is my original Antivirus, AVG, didnt stop the infection, and everything I installed after can't do the job properly because the virus is already in there and seems to stop any well known AV software from working properly. I suspect it must be some kind of rootkit, so its been a while since I've used that PC for anything important like online banking.

There are 3 internal hard disks on the PC and one external for backups.

The solution ?

Since the internal hard disks are relatively old small ones that have been inherited after several upgrades of just mobo/cpu/memory/graphics, I have bought two 1TB hard disks.

The plan is to install Windows 7 on one of them and start afresh. The problem is that then I need to somehow securely get my data back from the old drives.

My guess is I need to keep them disconnected, get Win7 installed and secured with an up to date antivirus (which one do you guys recommend?) and only then connect each old drive in turn, do a full scan on it and copy the data I need.

Is there a better way of doing this? My fear is that after all that somehow the virus/rootkit rears its ugly head again on the new installation.

AVG didnt manage to stop it originally and it was up-to-date at the time. The source was most likely a USB pen that had been used on an infected PC.

Any advice would be appreciated. Thanks.
 
Don
Joined
21 Oct 2002
Posts
46,750
Location
Parts Unknown
try this

disable system restore
remove your 'av'
run ccleaner slim http://www.ccleaner.com/download/builds/downloading-slim
run nod32 trial http://www.eset.com/download/free_trial_download_int.php
run mbam http://www.malwarebytes.org/mbam-download.php
run spybot http://fileforum.betanews.com/download/Spybot-Search-Destroy/1043809773/1


still screwed?
run combofix http://www.bleepingcomputer.com/combofix/how-to-use-combofix


following this, stop going to bad sites etc

use firefox http://www.mozilla-europe.org/en/firefox/
install this addon for firefox https://addons.mozilla.org/en-US/firefox/addon/1865

when firefox opens following the restart, tick the 'Easylist' subscription


AVG is pretty poor
 
Associate
OP
Joined
3 Jun 2003
Posts
1,775
Location
Gibraltar
Thanks for the quick replies. Am I wrong in thinking those are ways to recover the current installation? At this point my main aim to prevent the virus from jumping from the old hard drives (connected as slave) into a new clean installation on the new hard drives I just bought.
 
Soldato
Joined
19 Dec 2006
Posts
9,996
Location
UK
Thanks for the quick replies. Am I wrong in thinking those are ways to recover the current installation? At this point my main aim to prevent the virus from jumping from the old hard drives (connected as slave) into a new clean installation on the new hard drives I just bought.

As long as you have a decent (not AVG) anti-virus installed before you reconnect the old drive it should be fine, MS Security Essentials, Avira or Avast will do the job and they'll detect any viruses on the old drive either when you try to copy one or when you preferably do a full scan on it before doing anything else.
 
Associate
OP
Joined
3 Jun 2003
Posts
1,775
Location
Gibraltar
As long as you have a decent (not AVG) anti-virus installed before you reconnect the old drive it should be fine, MS Security Essentials, Avira or Avast will do the job and they'll detect any viruses on the old drive either when you try to copy one or when you preferably do a full scan on it before doing anything else.

Thanks. I'll go with Avira and cross my fingers. I think I'll also flash my BIOS just in case there's something in the CMOS ready to come back after I reinstall.
 
Back
Top Bottom