Register FAQ SearchLogin
Tuxera Home
View unanswered posts | View active topics It is currently Fri May 24, 2013 09:26



Post new topic Reply to topic  [ 6 posts ] 
malware file created (by ntfs-3g)? 
Author Message

Joined: Wed Oct 14, 2009 11:59
Posts: 3
Post malware file created (by ntfs-3g)?
hi to all.
the situation is this:

os: Ubuntu 9.04
2 ntfs partition (Windows Vista version).

Vista was infected by Autoit trojan.

The user delete (on Ubuntu) the files like autorun.inf, AcroR.exe etc created by malware.
But when he reboot (and remout ntfs partitions) with ubuntu these files are created again.

The user *do not* boot Vista, only Ubuntu.

How this is possible???


Wed Oct 14, 2009 12:07
Profile
NTFS-3G Lead Developer

Joined: Tue Sep 04, 2007 17:22
Posts: 1009
Post Re: malware file created (by ntfs-3g)?
Hi,

Quote:
The user *do not* boot Vista, only Ubuntu.

How this is possible???

Well, the usual way... some program copying the files, eg triggered by opening some mail.

Reminder : there is no sane reason why a Linux program should write into the Windows system partition, and there is an option "ro" to mount it read-only.

Regards

Jean-Pierre


Wed Oct 14, 2009 22:05
Profile
Tuxera CTO

Joined: Tue Nov 21, 2006 23:15
Posts: 1645
Post Re: malware file created (by ntfs-3g)?
Hi,

We distribute NTFS-3G only in source code. Download and check it. It has no malware included.

If Ubuntu, or anybody else, creates a malware on the Windows partition then it must be some other software. Obviously it must use the operating system to place the malware but we are not a antivirus company, we simply execute what other software want to read and writte from/to the disk.

Regards, Szaka


Wed Oct 14, 2009 22:11
Profile

Joined: Wed Oct 14, 2009 11:59
Posts: 3
Post Re: malware file created (by ntfs-3g)?
Well, I think there is a misunderstatement.

I know ntfs-3g is virus-free and I know open source.

The question is: because Ubuntu is virus-free too and that files are obviously windows virus, how it is possible they are restored in ntfs partition? The user do not start Vista anymore.

Can be because some recover feature in ntfs supported by ntfs-3g (something like journaling or shadow copies or other)?

Thank you.


Wed Oct 14, 2009 22:38
Profile
Tuxera CTO

Joined: Tue Nov 21, 2006 23:15
Posts: 1645
Post Re: malware file created (by ntfs-3g)?
guiodic wrote:
Can be because some recover feature in ntfs supported by ntfs-3g (something like journaling or shadow copies or other)?

No, it can't be. Something reinfects the partition.

Regards, Szaka


Thu Oct 15, 2009 00:20
Profile

Joined: Wed Oct 14, 2009 11:59
Posts: 3
Post Re: malware file created (by ntfs-3g)?
thank you.

Just another couple of questions:

1) In ntfs-3g manpages i read:

Quote:
recover, norecover
Recover and repair a corrupted or inconsistent NTFS volume if
it's possible. The default behaviour is recover.


What about this? Can this feature recover "damaged" files? And if yes, can it related to that files?

2) do you know if shadow copies in ntfs can recover automatically deleted files without a specific software?

Thank you very much.


Thu Oct 15, 2009 02:18
Profile
Display posts from previous:  Sort by  
Post new topic Reply to topic  [ 6 posts ] 


Who is online

Users browsing this forum: Ginopic, Google [Bot] and 4 guests


You cannot post new topics in this forum
You cannot reply to topics in this forum
You cannot edit your posts in this forum
You cannot delete your posts in this forum
You cannot post attachments in this forum

Search for:
Jump to:  
Powered by phpBB © 2000, 2002, 2005, 2007 phpBB Group.
Original forum style by Vjacheslav Trushkin.