PDA

View Full Version : Flash guardian



Petr Schreiber
28-02-2009, 22:23
Hi,

I just realized I have some odd files on my flash drive, and yes, it was some kind of malware.
When I remember DOS times, when viruses were silently inserting to files, trying to keep as hidden as possible...

... now in 2009 virus on flash drive is 100kB file launched by autorun.inf :roll:.

If you want to quick test your removable drives, you can use attached very elemental checker.
It seeks for inf and cmd files in root of your drives, and it allows to delete them, or copy their list to clipboard.

Use at own risk, but do not worry, this program does not delete anything unless asked for it :)

It uses WMI for drives enumeration, so I guess it is not usable for Win 9x systems.

Petr

GSAC3
01-03-2009, 01:49
Petr --

I downloaded FlashGuardian and used thinAir to bundle it.

However, when I ran the bundled copy in the directory in which thinBasic.exe and thinBasicc.exe are loacted, FlashGuardian deleted both thinBasic.exe and thinBasicc.exe when it finished execiting.

I think maybe there is a bug somewhere but I dont know where. If I run the un-bundled version in this same directory, everything seems to work OK with no deletions of either thinBasic.exe or thinBasicc.exe.

Don

ErosOlmi
01-03-2009, 08:02
It is not a problem of Petr script but a problem of thinBundle or (better to say) it works as designed.
When you run a bundled exe (without the isolation flag), thinBundle extract all files in current dir in order to run them. When script is finished all extracted files are deleted.

Solution: never execute a thinBasic bundled exe from thinBasic installation directory.
We have to improve thinBundle in this side.

Petr Schreiber
01-03-2009, 08:27
Hi Don,

I am sorry for your trouble, I use just pure script files in 99% of cases.
There is one workaround - using "Activate isolation flag" when bundling.

But as Eros recommends - it is better to not place any bundle in ThinBasic root directory.


Thanks,
Petr

GSAC3
01-03-2009, 19:04
Eros & Petr --

Thanks for the explanation. This was the first time I have ever tried to execute a bundled file in the thinBasic root directory.

Don