Possible New Virus, Need Help Identifying It
Results 1 to 9 of 9

Thread: Possible New Virus, Need Help Identifying It

  1. #1
    Registered User
    Join Date
    Sep 2001
    Location
    Minnesota
    Posts
    108

    Possible New Virus, Need Help Identifying It

    I've got two computers here that seem to have a virus, but when I virus scan it with the newest definitions, nothing turns up.

    Situation 1: Computer comes in with these symptoms, can't find the solution so I restore it with restore CD's. Works great. Customer brings it home, 2 days later comes back with the exact same problem.

    Situation 2: A different customer with a different computer comes in with the exact same problem, thus prompting me to post this. It's getting a bit much to be coincidence.

    Symptoms: Video is wrong, like the drivers aren't installed (low color, low res). And the mouse doesn't work. If you boot into safe mode, the mouse works, but obviously the video won't show normal in safe mode. When I run a virus scan in safe mode, it doesn't find any viruses, but gives read only errors on thousands of html/gif/xml files. Running a full wipe and reload will fix it, but I'm wondering if theres an easier way.

    There doesn't seem to be anything unusual in msconfig or system or win.ini files. The strange fact, and maybe this is doing it, maybe not, is both computers have kazaa on them. The first computer had kazaa on it the first time, and I restored it (thus removing it in the process), when it came back in it had kazaa on it again.

    I realize it's probably going to need to be wiped and reloaded, but I would like to have some information to give to the customers about -what- happened.

    Thanks Much,

    /|rokh
    "I can depend on my brain when I need it, but not necessarily when I want it to work."

  2. #2
    Registered User Archer's Avatar
    Join Date
    Mar 2000
    Location
    Blighty
    Posts
    4,224
    Hmmmm........Lots of bad files on Kazaa could be anything really,a bit hard to diagnose.
    Do the systems have anything in common apart from this that may be getting corrupted or ask them not to use Kazaa for two weeks to see if it reoccours?
    Perhaps with the owners permission you could install a piece of logging software and see if it gives you any clues.

  3. #3
    Registered User Wayward Clam's Avatar
    Join Date
    Dec 2000
    Location
    the depths of Lake Superior
    Posts
    3,778
    What antivirus program are you using? Sometimes people have better luck switching to a different brand; I have heard stories of viruses slipping past one scanner and being caught by another.

    Another obvious thing to check for is spyware using AdAware or Spybot. Be warned, the latest versions of Kazaa will not function if you remove their spyware... but if that's the problem, you will at least be able to blame the luser instead of the machine or yourself...
    Flash! Don't heckle the supervillain!

  4. #4
    Registered User
    Join Date
    Sep 2001
    Location
    Minnesota
    Posts
    108
    Ok, I did a virus scan on PC #2, and this one actually identifies a few interesting things. First of all it sees REGSEEKER or something, I'm not worried about it, I think I can fix it

    The second thing it found was 39 infected files with something called [097M_TRISTATE]. What is that? A google search turns up nothing.

    Thanks

    /|rokh

    EDIT - Nevermind, I found the info on this tristate virus. Goes back 3 or so years, I doubt thats the new virus on the horizon answer that I'm looking for. Must keep searching...
    Last edited by arokh; January 17th, 2003 at 05:30 PM.
    "I can depend on my brain when I need it, but not necessarily when I want it to work."

  5. #5
    Registered User Archer's Avatar
    Join Date
    Mar 2000
    Location
    Blighty
    Posts
    4,224
    Just a thought they`ve not both used MS auto update by any chance have they its terrible at getting the correct hardware drivers ?

  6. #6
    Registered User
    Join Date
    Sep 2001
    Location
    Minnesota
    Posts
    108
    Add PC #3 to this problem. This is getting crazy, I can picture the feds showing up in the PC equivalent of bio-epidemic suits. Something is going on here, and none of the virus companies seem to have picked up on it yet.

    This one is running WinXP, and for some reason it isn't affected by the mouse/video problems, but it comes up with the same errors when running a virus scan. This one does not have kazaa on it, so I don't think it's that now.

    /me scratches head

    /|rokh
    "I can depend on my brain when I need it, but not necessarily when I want it to work."

  7. #7
    Registered User MacGyver's Avatar
    Join Date
    Oct 2000
    Location
    Ottawa
    Posts
    4,232
    Send one of the infected files to Symantec for analysis.

  8. #8
    Registered User
    Join Date
    Oct 2000
    Posts
    1,569
    check THIS page for info on this.

  9. #9
    Registered User geoscomp's Avatar
    Join Date
    Apr 2002
    Location
    Minnesota
    Posts
    2,340
    There is a bit of freeware out there for download called regseeker..if thats what you are finding..it's a system tool that supposedly scans and finds registry entries..but it has some problems with autoclean functions, and can identify windows system fiiles as problem registry entries from time to time..if this is what you arfe finding, sounds like the users are maybe causing their own problems?

Bookmarks

Posting Permissions

  • You may not post new threads
  • You may not post replies
  • You may not post attachments
  • You may not edit your posts
  •