Computing.Net > Forums > Security and Virus > Suspect Virus-here are the symptoms

Suspect Virus-here are the symptoms

Reply to Message Icon

Original Message
Name: TypicalGirl
Date: August 15, 2003 at 02:43:18 Pacific
Subject: Suspect Virus-here are the symptoms
OS: W2K pro
CPU/Ram: Athlon TB1800/256mb ram
Comment:

This is either a really strange cooincidence or a virus...

A couple days ago one of my IIS servers went a little screwy and so I took it down and reformatted it. Its a crappy little machine with AMD K6-2 500 cpu and 512 mb ram.
I did a low level format, fdisk, system format then installed W98 se and then a new copy (as opposed to update) of W2k pro.
Same as I do on all systems I build.
But even after that it was acting buggy. Didn't want to install NAV, then wouldn't do the live update or Windows updates. Also, when I went to Add/Remove programs, all I got was the window with "Add/Remove Programs and some other text I don't remember, across the top of the window, in system font.Didn't want to do a virus scan and when I went to Symantec to use thier online virus scan, I could not get any of the links to work. I ended up having to save each link in my favorites and access it that way. The online scan didn't find any viruses. I also applied the Blaster patch and used the Blaster removal tool, just to be sure.

Not sure what I did to fix it, and its still wierd, but here's the thing...
A customer called me yesterday and they are having the same sort of issue. Same exact problem with Add/Remove programs, same inability to use NAV or live update, same issues with the links to the online scan, plus, they can use thier dialup, but cannot disconnect it. It says its disconnected, but its not. Also, Thier Outlook Express will recieve mail but won't send it. They get an error about insufficient memory.

I built the system myself and recently replaced the modem (internal PCI 56K v.90/92) and up until just a few days ago, it worked great.

So I'm suspecting a virus.
Anyone have any ideas?
Thanks!


Report Offensive Message For Removal


Response Number 1
Name: JackG
Date: August 15, 2003 at 03:01:15 Pacific
Reply: (edit)

That sounds a little like the problems I ran into on someones laptop running XP. They had picked up MSBLASTER on the system, but Nortons had removed it, and they were not even aware it had been on their machine. But all the other symptoms were there.

So is it possible that you connected to the Internet during the install of the OS and AV, picked up MSBLASTER and the AV removed it without you noticing, and then you installed the Windows Updates for it, after it had already corrupted parts of the system?


Report Offensive Follow Up For Removal







Use following form to reply to current message:

   Name: From My Computing.Net Settings
 E-Mail: From My Computing.Net Settings

Subject: Suspect Virus-here are the symptoms

Comments:

 


  Homepage URL (*): 
Homepage Title (*): 
         Image URL: 
 
Data Recovery Software




Have you ever used OpenOffice?

Yes, as my main suite.
Yes, occationally.
Yes, but only once.
No, never.


View Results

Poll Finishes Today.
Discuss in The Lounge