InterviewSolution
| 1. |
Solve : Trojan Win32.PEPatch.AO found in Non-bootable PC? |
|
Answer» A FRIEND brought his Dell 2100 (3 1/2 yrs old, XP Home (with SP3, I believe), 512 mb ram, single 80 gb Hd Drv, with Norton AntiVirus installed) to me. The owner assured me that he had noticed no aberrant behavior until YESTERDAY, when it refused to boot. After confirming that it would not boot in either normal or safe mode (it displays the splash screen, then a cursor appears in the center of the screen, and all activity STOPS - in Safe Mode, the screen displays the safe mode indications at the edges of the screen, and the cursor again shows up, but no further activity), I removed the hard drive, and set it up as an external drive to one of my PCs. The drive spun right up, and I had no problems reading it. AVG Free found two instances of a TROJAN - Win32.PEPatch.AO, attached to two familiar files in Windows\System32\, spoolsv.exe and svchost.exe, both dated August 10, 2004. AVG reported that forced removal of this malware would cause the host system to be unstable - which, for whatever it's worth, makes sense to me. |
|