maemo.org - Talk

maemo.org - Talk (https://talk.maemo.org/index.php)
-   Nokia N900 (https://talk.maemo.org/forumdisplay.php?f=44)
-   -   N900 virus_USBS(■╒ê. fle (https://talk.maemo.org/showthread.php?t=81226)

lornier 2011-12-31 10:50

Re: N900 virus_USBS(■╒ê. fle
 
Quote:

Originally Posted by Mike Fila (Post 1143811)
then type "mount -o remount,rw /home/user/MyDocs" enter
then "rm -rf /home/user/MyDocs/.sounds/FSCK0000.001" enter
then "rm -rf /home/user/MyDocs/DCIM/FSCK0000.002" enter
then start at umount

and dont use that antivirus program on your phone again

Thanks Mike Fila. I followed your instructions. Should I reboot my device again? Does this mean that my device is clean again and that file is removed?
Is it the antivirus program or the USB security app that caused it?

Mike Fila 2011-12-31 10:55

Re: N900 virus_USBS(■╒ê. fle
 
the usb security app and antivirus ...did fsck come up clean? yes then reboot

Estel 2011-12-31 10:59

Re: N900 virus_USBS(■╒ê. fle
 
It is not a matter of antivirus program. It is known w$ndoze virus, caused by security hole about autostart. It was fixed by microsoft in windows update few months ago (thus bug was known for many years, with 3rd party fixes available for ages - often for no charge, like Panda USB Vaccinate).

Anyway, it is *not* N900 "virus", nor Linux one (in any flavor). It just affect vfats, connected @ mass storage mode. You should take care about Your desktop PC (cause You don't want to spread virus on every pendrive / portable multimedia player / whatever mass storage vfat, do You?). Then, recreate whole /dev/mmcblk0p1 partition - Your files are gone already, so it doesn't matter - no sense in fsck'ing, You're damned to mkfs.

To prevent further infecting, I recommend using (legally, free of charge) vaccinate released by Panda on Your computer, and every pendrive etc. *except* - AFAIK it's most clever implementation of general idea .It disabled autostart on w$ndows @all - this is same for every vaccinate implementation - and it creates autostart file on mass storage device, corrupting it every possible way, starting by wrong file entry in partition database, ending on some voodoo. This ensure, that file is unremovable, thus impossible to being overwritten by virus - this autostart on mass storage is used only by bogus windows implementation, so it doesn't matter anyway.

You can also do the same for Your N900 vfat partition, although having my machines and pendrives protected (and not connecting my N900 in mass storage mode to unknown w$ndowses) I don't feel need to. Even still, having 'uber' corrupted file - even not important - on My Docs would made me feel uneasy.

/Estel

nicholes 2011-12-31 11:03

Re: N900 virus_USBS(■╒ê. fle
 
I don't know how to help but it is > just for info!

that happened to me too but not with my phone, it was my friend's micro sd card when i inserted it through a card reader to my pc my friend's sound files gone and my pc showed the same file you mentioned. I think this is something not good with your and my pc.

BTW I don't connect my N900 with usb , i use WinSCP (openssh)

lornier 2011-12-31 12:45

Re: N900 virus_USBS(■╒ê. fle
 
Quote:

Originally Posted by Mike Fila (Post 1143823)
the usb security app and antivirus ...did fsck come up clean? yes then reboot

Hi I tried again, fsck still showed the same error as before. :((

lornier 2011-12-31 12:57

Re: N900 virus_USBS(■╒ê. fle
 
Quote:

Originally Posted by Estel (Post 1143825)
It is not a matter of antivirus program. It is known w$ndoze virus, caused by security hole about autostart. It was fixed by microsoft in windows update few months ago (thus bug was known for many years, with 3rd party fixes available for ages - often for no charge, like Panda USB Vaccinate).

Anyway, it is *not* N900 "virus", nor Linux one (in any flavor). It just affect vfats, connected @ mass storage mode. You should take care about Your desktop PC (cause You don't want to spread virus on every pendrive / portable multimedia player / whatever mass storage vfat, do You?). Then, recreate whole /dev/mmcblk0p1 partition - Your files are gone already, so it doesn't matter - no sense in fsck'ing, You're damned to mkfs.

To prevent further infecting, I recommend using (legally, free of charge) vaccinate released by Panda on Your computer, and every pendrive etc. *except* - AFAIK it's most clever implementation of general idea .It disabled autostart on w$ndows @all - this is same for every vaccinate implementation - and it creates autostart file on mass storage device, corrupting it every possible way, starting by wrong file entry in partition database, ending on some voodoo. This ensure, that file is unremovable, thus impossible to being overwritten by virus - this autostart on mass storage is used only by bogus windows implementation, so it doesn't matter anyway.

You can also do the same for Your N900 vfat partition, although having my machines and pendrives protected (and not connecting my N900 in mass storage mode to unknown w$ndowses) I don't feel need to. Even still, having 'uber' corrupted file - even not important - on My Docs would made me feel uneasy.

/Estel


Hi! I've downloaded panda vaccine as advised. so you mean to say there is no more hope in removing the virus? What should I do? I can't really say the the files are gone because it can still be played in my device. It's just that it cannot be found when I tried mass storage mode with our PC. How to recreate whole /dev/mmcblk0p1 partition?

sicelo 2011-12-31 13:07

Re: N900 virus_USBS(■╒ê. fle
 
i had suggested getting a live linux system before. it is still the simplest way to recover. ubuntu was mentioned. u could also use knoppix. u don't need any special skills for this.

alternatively, u can (if u have wifi access to your n900 and ssh server on it) install winscp on pc, and grab your files from n900.

then u can format MyDocs on N900 (by opening file manager, and long-press the internal storage). after this u could transfer your files back via wifi.

until your computer is fixed it's a bad idea to use mass storage mode.

EDIT: u can also copy your files onto a memory card (if u have one big enough for your files). u can use Filebox to copy them, or XTerm. it's not difficult. mainly u need to use 'cp', 'ls', 'cd' and these are easy to use command explained on the wiki, http://wiki.maemo.org/Terminal#Using_the_terminal

dr_frost_dk 2011-12-31 13:35

Re: N900 virus_USBS(■╒ê. fle
 
I also say try a live cd.

GOTO http://www.ubuntu.com/download/ubuntu/download and get a 11.10, burn it to a CD or better use it with a usb pen drive (>=1GB), boot from CD or USB and try to access you N900 files in mass storage mode.

lornier 2011-12-31 13:50

Re: N900 virus_USBS(■╒ê. fle
 
Thanks! I am now downloading ubuntu-11.10-desktop-i386.iso though I still don't know how to work through it. I have no cd rom drive, but have an external drive, is that ok? what do I need to do to use with a usbpen drive, does it mean that I will install it in my external drive? won't this be a problem with my windows system?

dr_frost_dk 2011-12-31 13:58

Re: N900 virus_USBS(■╒ê. fle
 
Quote:

Originally Posted by lornier (Post 1143896)
Thanks! I am now downloading ubuntu-11.10-desktop-i386.iso though I still don't know how to work through it. I have no cd rom drive, but have an external drive, is that ok? what do I need to do to use with a usbpen drive, does it mean that I will install it in my external drive? won't this be a problem with my windows system?

there is a guide on the page that you downloaded it from, scroll down and select install from USB & windows and "Show me how", it is really simple, and as long as you don't begin an install process after booting from usb or USB HDD, then no changes to you system will be made.

This is also a good way to establish a VERY SAFE connection to home banking and so on.


All times are GMT. The time now is 00:26.

vBulletin® Version 3.8.8