Credit Cards | Budapest | Credit Report | Secured Loans | Mortgage Calculator
New Virus? [Archive] - PCMech Forums

PDA

View Full Version : New Virus?


kittyfire
12-28-2002, 02:21 PM
Before I start digging, wanted to run this past y'all and see if you've heard of anything like this.

Lady says she went to bed and everything was fine, woke up and has no icons on her desktop and all internet options and settings are gone. Looks like some of the microsoft functionality was compromised as well.

Can't identify a trigger and based on her habits, as she is telling them to me, it had to be a malicious script on a webpage...

Any thoughts?

Tuf
12-28-2002, 04:43 PM
I suppose my answer would depend upon which OS she is using. Win9X is famous for having problems with the desktop and icons.

It certainly could be a virus I guess but based on the symptoms it doesn't sound like one to me.

kittyfire
12-28-2002, 04:55 PM
It's XP. : /

Tuf
12-29-2002, 11:52 PM
I haven't had any trouble with Icons in XP but then I don't run any :D But I haven't heard of any in XP from anyone else either. You could very well be right but generally someones bad intentions wouldn't be to knock you off the internet but to gain control of your computer while on the internet. But i guess you can't second guess the idiot's that do stuff like that.

Does she have anything unusual in her history files?

reboot
12-30-2002, 11:05 AM
Is she using Outhouse Express?
Does she have "active scripting" enabled?
What anti-virus, and when was the last update?
Is this computer "always on", with cable or dsl, or is it a dial-up?

kittyfire
12-30-2002, 08:15 PM
Hey guys! Sorry for the delay, was out of town. She does have Outhouse. ::laughs:: DSL with an always on connection (ie... auto connects when it sense tcp/ip traffic). She was running no anti-virus software. (We had a long talk about that.) I got her connected and we went out to pcpitstop and ran their online virus scan but it didn't find anything. But she says all she did was go to bed and when she got up everything was gone. I was able to roll back her registry and everything came up like it used to be but I'm still very suspicious of how it all went away in the first place. Not only had her icons disappeared, but she couldn't get to her address book or any stored information in Outlook and the options to scan and defrag weren't there... not that those were important here but like most people that was the first thing she wanted to try before calling for help and those options weren't there... very strange...

reboot
12-31-2002, 10:43 AM
Check HAL's post in the "System Security" forum.
PCPitstop's scan won't catch the latest, unless they've updated. Housecall will. Part of the payload (of the Yaha trojan) disables anti-virus scanners.
Outhouse Express automatically will "run" any attachment that it can, based on "Active Scripting" settings in IE's security section. Probably the biggest flaw in it. If she's a novice, set her up with Eudora, Pegasus, or even Incredimail (though it's bloatware, all free), disable the "Use Microsoft's viewer", and then the stuff will show up as attachments, not automatically run them. Then teach her about NOT clicking on stuff, especially in email.
Another option is Zonealarm, with it's active email scanner...giving her both a nice firewall, and a little more protection from the nasties.