So, my boss gets this virus on her home computer and it goes out to everyone on her contact list(including me). She tells me about it and I inform her that the best thing to do is not open it and make sure she runs NAV and delete in from her inbox and then from the deleted items folder. Finally I tell her to empty her recycle bin to make sure there isn't a copy in there just waiting to be restored.
Good advice right???
What do I do?....Me being the inquisitive type, I go home, scan the email with NAV and it finds NOTHING! So I open the email and there are two attachements...one recipe.doc and one shell.pif(DOS batch file of some sort). I save them both to a folder and quarantine them. I scan the folder and NAV says its all good. I open the doc file and it is ACTUALLY a recipe for spinich quiche.
Right on!
I open the shell file in notepad but of course it is compiled and I don't get into that sort of thing so I have no idea what the hell it does.
Of course there is only one thing I can do....I run it.
What was I thinking?!? It gave me an error msg and then closed. I check everything and there aren't any probs. I figure I'll play it safe and reboot. As soon as XP comes back up and I log in, BOOM! 100% CPU usage and nothing will open! I shut off my cable modem and reboot into safe mode. CPU usage back to normal so I figure I'll just restore to a point before I did the dirty deed. Low and behold....system restore is no longer installed on my system! All that's left is a shortcut that has the "what program do you want to open this with" icon.
AAAAHHHHHH!!!!!
Boot from CD....resore console....boot into windows in safe mode...and finally restore to yesterdays check point.
Fixed(2HRS!)
Let this be a lesson for the masses!![]()


Reply With Quote

Bookmarks