Starting Fresh

Post Reply
BobSeager
Ally of Robinhood
Ally of Robinhood
Posts: 465
Joined: Thu Nov 29, 2007 9:42 am

Starting Fresh

Post by BobSeager »

My network was long overdue for a complete wipeout/overhaul but I want to be sure nothing malicious is going to transfer over when I reload 5 computers with data from backed up drives and usb keys, etc. (external storage). I'm almost sure their was a trojan on the network that by the end, had all the computers effed up.

That said, how do you guys handle this? I took them all off the network and one at a time reloaded windows and reinstalled programs. I have not yet connected my external devices which essentially were clones of the drives that were wiped out or at the least contained many of the same files. The do not have system files tho, they are simply documents/pictures/video, etc. backed up from all the computers.

My intention is to wipe the systems and reload those documents/etc. back over to them.

It worries me to connect any of them up to my new network because I do not want the damn thing to spread again.

What I have done in the meantime before I conenct the rest of the systems is setup one computer, isolated from the network, with xp, sp3 and avg with updated definitions and am one at a time connected my external devices to that pc and having it scan them. I don't know if I should hope it finds something or not. Any other utilities you guys use or processes to prevent corrupting the network again. My systems started booting very very slowly, and shutting down very very slowly, folders wouldn't load contents, etc. Kaspersky never found anything but did get popups reading "C:/Windows/Servicing/Trustedinstaller.exe" was trying to access sensitive files.

Thanks guys.
Image
User avatar
technoe
Ally of Robinhood
Ally of Robinhood
Posts: 1767
Joined: Wed Jan 14, 2009 2:30 pm
Location: Clarksville, TN

Re: Starting Fresh

Post by technoe »

That's exactly what I would've done. I've got avast instead of avg but both are great programs. Also if you have any utilities for malware or spyware that'd be something to look into as well.
Image
Today Money, Tomorrow the WORLD!!
BobSeager
Ally of Robinhood
Ally of Robinhood
Posts: 465
Joined: Thu Nov 29, 2007 9:42 am

Re: Starting Fresh

Post by BobSeager »

Do you think theres a high risk in reattaching these storage drives to the fresh computers, ie. could something have replicated itself from the infected pcs to the usb drives, and now they will migrate back when attached?

Thanks again
Image
User avatar
technoe
Ally of Robinhood
Ally of Robinhood
Posts: 1767
Joined: Wed Jan 14, 2009 2:30 pm
Location: Clarksville, TN

Re: Starting Fresh

Post by technoe »

Not if you're doing a good scan of them first. And most AV software will scan external devices as soon as there attached and any info transferring between the device and your pc.
Image
Today Money, Tomorrow the WORLD!!
User avatar
Riax
Bandit
Bandit
Posts: 55
Joined: Thu Mar 12, 2009 6:11 pm
Location: Nottingham, UK :)

Re: Starting Fresh

Post by Riax »

Make sure you format your computers correctly first sometimes programs pickup on old infected files

As for the devices scan each one on a non networked fresh computer or use a bootdisk its the best way to detect infections and avoid rootkits

Use
dban
ultimatebootcd
User avatar
technoe
Ally of Robinhood
Ally of Robinhood
Posts: 1767
Joined: Wed Jan 14, 2009 2:30 pm
Location: Clarksville, TN

Re: Starting Fresh

Post by technoe »

There's a free program called Eraser that will format the drive rewrite it with all 1's and format again. It does this three times.
Image
Today Money, Tomorrow the WORLD!!
Post Reply

Return to “General information”