More info on the portable Maxtor infected hard discs

Nov 13, 2007 08:43 GMT  ·  By

Yesterday, Seagate confirmed the rumors talking about a potential virus included in the Maxtor Basics 500G portable devices, saying that all the hard discs were removed from the shelves and only a few of them managed to reach the consumers. Today, the Taipei Times informed that no less than 1,800 discs were sent to Taiwan, most of the 500 GB being meant to be used by the government. But what's more interesting is that the drives contained two viruses which could upload all the information copied by the users on two websites which were apparently shut down. Imagine that the government could place any of their secret documents on the hard drives which could be then accessed by anyone on the web.

Taipei Times wrote that "the bureau said that the method of attack was unusual, adding that it suspected Chinese authorities were involved. In recent years, the Chinese government has run an aggressive spying program relying on information technology and the Internet, the bureau said."

The two viruses which could be identified by looking for filenames such as autorun.inf and ghost.pif were published on the hard disc drives even before they were released on the market. That's why numerous consumers could get infected, the Taiwanese bureau suspecting that some of their secret documents were already accessed by the creators of the viruses through the websites which stored all the uploaded information.

Seagate reported that many of the antiviruses were already updated to provide protection against Virus.Win32.AutoRun.ah, the threat which was first discovered by security vendor Kaspersky. "If your Maxtor Basics Personal Storage 3200 unit is infected or to ensure that your unit is clear from this virus, install the latest virus definition list for your anti-virus software. As of October 2, 2007, 28 of the 32 anti-virus software titles have updated their virus definition list to include detect and clean this virus," Seagate wrote in a notification published on the company's official page.