Just as an FYI for people, check your thumbdrives. There's a "Gazma" folder, as well as a few other pretty fun files (svchost.exe, and an autorun.inf) on all of our drives.
Since neither Otto nor I run windows and haven't used the thumbdrives at all other than the lazor computer, we're assuming that's where they came from.
An email is being sent to Front Desk about it, but the rest of yous should probably take care.
-Aoife (who is SO glad she runs macs) :-P
svchost.exe and autorun.inf
svchost.exe and autorun.inf are necessary and harmless windows files unless corrupted.
The Gazma folder apparently is a internet sales site that probaly came in with all that spam on the forum.
I suggest running malwarebytes anti-malware directly from the internet (google it), it's a powerful antivirus program, is updated constantly and best of all it's free! It scans fairly quickly and will tell you what it found, the threat level and automatically fix it.
Yes I know autorun and
Yes
I know autorun and svchost are "harmless" normal files.
And there is no reason for them to be on my thumbdrive, they weren't there before, and had never been on there previously.
Hence, they are quite obviously corrupted, and so therefore people should be on the lookout for these otherwise "harmless" files.
:)
Laser computer is being rebuilt
Just for everyone's information, we're currently rebuilding the laser computer from scratch. It will be a very minimal install -- limited software and limited access. This should minimize both the flakiness of the install as well as the potential for malicious software.
Hopefully we'll have something up and running in the next couple of days. Feel free to contact me or hunt me down at TechShop if you have any concerns.
- Jeff
Contact Info
Is the software gonna be able
Is the software gonna be able to take care of infected thumb drives?
Als might want to throw up a sign to remind people to check their drives, I'm sure there's folks who haven't realized it yet.
More than just the laser
More than just the laser computer is infected. I picked up the "Gazma" folder on my thumb drive from the Shop Bot. Malwarebytes identifies it as containing backdoor.bot a serious threat. It is very difficult to remove and will spread itself to any computer the thumb drive is attached to. It is going to be especially difficult to eradicate from the Tech shop system since it has likely spread to every computer connected and is on every portable drive every attached since first appearance and everything will be reinfected any time an infected drive is used.
Virus issues
Dear all-
Anytime that you have computers that are used by many people who bring thumbdrives, you are going to have a problem with viruses/malware. Jeff and I are cleaning computers and applying effective antivirus software on each public use computer. We should have clean images of secure computers in the next week.
Never the less, you should ALWAYS practice safe computing. If you put your drive into a public computer, be sure to scan and clean it immediately after. An excellent, free antivirus software suite can be found at:
http://www.avira.com/en/pages/index.php
Be safe!
peter
The vinyl cutter computer
The vinyl cutter computer also has virii. I plugged in my thumb drive and was reinfected on Sunday night.
We'll clean it again
Thanks for the heads up Jon. We'll take care of it.
Scott