Page 4 of 4 FirstFirst 1234
Results 31 to 35 of 35

Thread: win32.delf.uc keeps coming back

  1. #31
    Junior Member
    Join Date
    Dec 2011
    Posts
    18

    Default

    thank you for the list of items.

    If I install XP on a different hard drive and then attach the original as a secondary, run virus detection on both drives then copy data from secondary to primary and then repartition the secondary, is there any more risk than copying data to a different backup since I would no longer be booting from the original or using any of the exe's from there?

  2. #32
    Malware Team-Emeritus
    Join Date
    May 2010
    Posts
    212

    Default

    Quote Originally Posted by spybob View Post
    If I install XP on a different hard drive and then attach the original as a secondary, run virus detection on both drives then copy data from secondary to primary and then repartition the secondary, is there any more risk than copying data to a different backup since I would no longer be booting from the original or using any of the exe's from there?
    There's a bump in the road again.

    Do you have any experience in how to swap out internal components of a computer? Do you know how minimize the risk of static discharge while working with computers like that?

  3. #33
    Junior Member
    Join Date
    Dec 2011
    Posts
    18

    Default

    I'm not concerned with the physical tasks as an issue, just the OS and software implications.

  4. #34
    Malware Team-Emeritus
    Join Date
    May 2010
    Posts
    212

    Default

    It appears to me that you have experience with hard drive swapping and that you know how to minimize the risk of damaging static discharge while swapping internal components of a computer.

    Quote Originally Posted by spybob View Post
    (...) is there any more risk than copying data to a different backup since I would no longer be booting from the original or using any of the exe's from there?
    Using a different (empty) physical hard drive should work and you will definitely not lose any data until you repartition the original drive. The risk is low if you only copy the files described in my previous post back to the fresh install.

    Please note:
    • It might be a good idea to have the original drive disconnected while installing Windows on the different drive to avoid accidental format and loss of data on the original drive.
    • Please make sure that you do not accidentally boot from the original hard drive.
    • Run an online virus scan on the files before copying anything back. Note that copying back entire profile/user directories is really bad practice.
    • Use extra care not to accidentally copy back other files and directories than described since your backup now contain all files.
    • Keep the computer disconnected from any network until Service Pack 3 and anti-virus is installed (read below).



    When you have finished installing windows, determine which service pack is installed:
    • Click Start, and then click Run.
    • Copy and paste, or type the following command and then click OK:
      winver
      A dialog box displays the version of Windows and the service pack that is currently installed on your computer.


    As previously written, you should not connect the computer to any network until updated to Service Pack 3 (SP3) and anti-virus installed. Currently I'm only recommending Microsoft's anti-virus solution.

    Service Pack version must be SP1a or SP2 to upgrade to SP3. Install the appropriate service packs, SP1a if no service pack or SP2 if your Windows media had SP1 preinstalled, then install SP3. Make sure to reboot after each service pack install.

    The safest method is to download and burn the necessary tools to cd(s) on a known uninfected computer:

    Windows XP Service Pack 1a (SP1a)
    Windows XP Service Pack 2 (SP2)
    Windows XP Service Pack 3 (SP3)
    Microsoft Security Essentials Installer
    Microsoft Security Essentials Definitions
    Flash Disinfector

    When finished installing SP3, run the Microsoft Security Essentials Installer, followed by the definitions update, then run Flash_Disinfector.


    Flash Disinfector

    Running Flash Disinfector will disable autorun on your computer to avoid infection if plugging in an infected external usb/hard-drive.

    • Double click the file to run it.
    • You will be prompted to plug in your flash drive. Please do not plug in any external drives for this first run! Just click OK.
    • Flash_Disinfector will start disinfecting and secure your hard drive(s). This takes a few seconds, and your desktop will disappear during the process (this is normal).
    • When done, a message box will appear. Click OK.
    • Your desktop should now re-appear.
    • If it doesn't.
      • Press Ctrl + Alt + Del to open Task Manager.
      • Click on File > New Task (Run...).
      • Type in explorer.exe and press OK.
      • Your desktop should now appear.

    If you want to "disinfect" and secure external drives later, then re-run Flash Disinfector and plug in the device when prompted.



    Update Windows and Internet Explorer

    Connect the computer to the internet, but do not use it for anything until you have fully updated Windows and Internet Explorer:

    Update Windows and Internet Explorer to protect your computer from malware. Update Internet Explorer even if you do not plan to use it. Having an outdated version installed is a security risk.

    Please open the Windows Update site in Internet Explorer and install all critical updates. Repeat the process until no further updates are offered.


    Select your desired settings for updating.

    • Go to Start > Control Panel > Automatic Updates
      1. Select Automatic (recommended) radio button if you want the updates to be downloaded and installed without prompting you.
      2. Select Download updates for me, but let me choose when to install them radio button if you want the updates to be downloaded automatically but to be installed at another time.
      3. Select Notify me but don't automatically download or install them radio button if you want to be notified of the updates.



    I'll be back with another post with further recommendations, please do not download files/install any further programs until you have read my next post.

  5. #35
    Malware Team-Emeritus
    Join Date
    May 2010
    Posts
    212

    Default

    Install Various Common Programs

    Here follows instructions to install various common programs. Please do not install a program you don't need. Make sure you read the prompts during the installation of all programs and uncheck options to install any toolbars and alternate homepage.

    Mozilla Firefox: http://www.mozilla.org/en-US/firefox/new/

    Java: Download and install Java Runtime Environment (JRE) 6 Update 30 (~16Mb) (Windows Offline)

    Adobe Flash Player:
    Uncheck the option to install McAfee Security Scan Plus before downloading!
    http://get.adobe.com/flashplayer/otherversions/
    Note: There are separate versions for "other browsers" and Internet Explorer. Don't install the one for Internet Explorer if you do not plan to use Internet Explorer.

    Consider using the more lightweight Foxit Reader (14Mb) rather than Adobe Reader (66Mb) to read pdf files.
    • Please uncheck the options to Install Foxit PDF Creator Toolbar and make Ask my browser default search provider, also uncheck the option to Set Ask.com as my hompage while installing Foxit Reader.
    • Please uncheck the optional install of McAfee Security Scan Plus if/when downloading Adobe Reader



    Consider using the following security programs

    • WinPatrol
      This is a lightweight system monitor. Download it from here. You can find information about how WinPatrol works here.
    • Malwarebytes' Anti-Malware
      Download and install Malwarebytes Anti Malware Free.
      Update and perform a quick scan 1-2 times a week.
    • Spybot Search & Destroy
      Instructions are located here. Do not enable Teatimer during the install if using Winpatrol. Update, re-immunize & scan using Spybot Search & Destroy regularly.
    • Hosts File
      Every version of windows includes a hosts file as part of them. A hosts file is a bit like a phone book, it points to the actual numeric address (i.e. the IP address) from the human friendly name of a website. This feature can be used to block malicious websites.
      Download HostsXpert and unzip it to your computer, somewhere where you can find it.
      • Run HostsXpert
      • If Hosts file is Read Only, click on Make Writeable, otherwise move on to next stage.
      • Click Download button.
      • Click MVPs Hosts
      • Click Merge File
      • Press OK to download latest MVPs update and merge it with your Hosts file.
      • When finished click File Handling
      • Click Make Read Only to secure your Hosts file.
      • Close HostsXpert.


      Note: On some PCs, having a custom HOSTS file installed can cause a significant slowdown. Following these instructions should resolve the issue:

      • Click Start > Run
      • Type services.msc & click OK
      • In the list, find the service called DNS Client & double click on it.
      • On the dropdown box, change the setting from automatic to manual.
      • Click OK & then close the Services window.


      Update the hosts file regularly. For a more detailed explanation of the HOSTS file, click here.
    • Secunia Online Inspector
      Microsoft isn't the only company whose products can contain security vulnerabilities. To check for vulnerable programs running on your PC that are in need of an update, you can use the Secunia Online Software Inspector (OSI). I suggest that you run it and install the suggested updates at least once a week.



    It is ABSOLUTELY ESSENTIAL to keep Windows, Java, Adobe and all of your security programs up to date. If you forget, then your computer will likely get reinfected.


    Please read the topic below which will give you a few suggestions on how to minimize your chances of getting another infection.


    If following all this advise does not keep your computer clear of infections, then ask for help at the forum directly. Installing/uninstalling all sorts of anti virus and security programs to scan your computer is not recommended.


    Do you have any further questions related to this case?
    Last edited by tashi; 2012-02-01 at 19:29. Reason: Date of archive

Posting Permissions

  • You may not post new threads
  • You may not post replies
  • You may not post attachments
  • You may not edit your posts
  •