RSS Forums RSS
Please support our Windows NT / 2000 / XP / 2003 advertiser: 64-bit Windows Community
Views: 3055 | Replies: 13
Reply
Join Date: Jan 2004
Posts: 35
Reputation: Pitufo is an unknown quantity at this point 
Rep Power: 5
Solved Threads: 0
Pitufo Pitufo is offline Offline
Light Poster

Do I have a virus?

  #1  
Jan 21st, 2004
Ok, I was on a page I probably shouldn't have been on and I clicked on a link to download. The download started and I realized it wasn't what I thought it was and cancelled the download almost immediately. Then things got weird: on the bottom right of my display the icon hiding function kept moving left and right and any button I pushed would just make another button activate(such as when I was scrambling to disable my net connection) and i particularly remember going to shut down the computer and pushing "turn off" but stand-by kept hilighting and then it just went into standby mode. Upon successfully restarting my computer a got about a zillion error-reporting things and the analyses ranged from a Mcaffee firewall error (which I uninstalled a long time ago) to a device driver error to I don't even know what else. It always said that the system had recovered from a serious error over and over again after each report was sent. Yikes that got me scared.
SO, I ran my virus scanner, deleted all my temp internet files, searched for new files created today, didn't find anything, ran system restore, the problem came back and when I undid the system restore things seem to be working fine now... but I'm worried. The download had barely begun?!?! It was like my desktop had been taken over or something, anyone heard of something like this before?
AddThis Social Bookmark Button
Reply With Quote  
Join Date: Jan 2004
Location: new yawk
Posts: 38
Reputation: Dominick is an unknown quantity at this point 
Rep Power: 5
Solved Threads: 0
Dominick's Avatar
Dominick Dominick is offline Offline
Light Poster

Re: Do I have a virus?

  #2  
Jan 21st, 2004
It was like my desktop had been taken over or something, anyone heard of something like this before?
the one thing you probably didnt think to do was run a netstat. That would have told you what connections were in or outbound on your pc at the time when your machine freaked. Do you run a router? Does it have a log file?
Dominick@tech-lounge.com
www.tech-lounge.com
www.v-dommi.net
Reply With Quote  
Join Date: Jan 2004
Location: Netherlands
Posts: 152
Reputation: floris has a spectacular aura about floris has a spectacular aura about 
Rep Power: 6
Solved Threads: 2
floris's Avatar
floris floris is offline Offline
vBulletin.com Staff

Re: Do I have a virus?

  #3  
Jan 21st, 2004
Before it downloads, it could trigger a script.

Like:

<?php

start function here
evil code here to force down user's throat

present download

end function here
?>



I'd run several anti virus softwares if I were you, and several spy bots detector and anti trojan stuff and just see what comes up. Goto windowsupdate.microsoft.com and get the latest patches for ie6.
Reply With Quote  
Join Date: Jan 2004
Location: new yawk
Posts: 38
Reputation: Dominick is an unknown quantity at this point 
Rep Power: 5
Solved Threads: 0
Dominick's Avatar
Dominick Dominick is offline Offline
Light Poster

Re: Do I have a virus?

  #4  
Jan 21st, 2004
Originally Posted by floris
Before it downloads, it could trigger a script.

Like:

<?php

start function here
evil code here to force down user's throat

present download

end function here
?>



I'd run several anti virus softwares if I were you, and several spy bots detector and anti trojan stuff and just see what comes up. Goto mozilla.org and get the latest stable release of mozilla.
fixed that for you
Dominick@tech-lounge.com
www.tech-lounge.com
www.v-dommi.net
Reply With Quote  
Join Date: Jan 2004
Posts: 35
Reputation: Pitufo is an unknown quantity at this point 
Rep Power: 5
Solved Threads: 0
Pitufo Pitufo is offline Offline
Light Poster

Re: Do I have a virus?

  #5  
Jan 21st, 2004
Originally Posted by Dominick
the one thing you probably didnt think to do was run a netstat. That would have told you what connections were in or outbound on your pc at the time when your machine freaked. Do you run a router? Does it have a log file?

How can I run a netstat? and no I don't have a router and if there was a logfile where can I find it?
Reply With Quote  
Join Date: Jan 2004
Posts: 35
Reputation: Pitufo is an unknown quantity at this point 
Rep Power: 5
Solved Threads: 0
Pitufo Pitufo is offline Offline
Light Poster

Re: Do I have a virus?

  #6  
Jan 21st, 2004
I only have the one virus scanner that I got through my ISP, not sure how good it is it's called "Freedom" anti-virus" I ran my spyware programs but I don't have any trojan programs to run. One other thing I've noticed a program called "dvpapi.exe" running and all the searches I've done say it's some kinda anti-virus thing but I don't remember installing it or ever seeing it there before.
o ya I've got my windows updates all updated.
Reply With Quote  
Join Date: Jan 2004
Location: new yawk
Posts: 38
Reputation: Dominick is an unknown quantity at this point 
Rep Power: 5
Solved Threads: 0
Dominick's Avatar
Dominick Dominick is offline Offline
Light Poster

Re: Do I have a virus?

  #7  
Jan 21st, 2004
from a command line type netstat
it will display all concurrent connections over tcpip to your pc. You can also run "Nbtstat -A" following the -A switch you would include your ip address. This will tell you what netbios connections you have on your pc.
Dominick@tech-lounge.com
www.tech-lounge.com
www.v-dommi.net
Reply With Quote  
Join Date: Jan 2004
Location: In my "home-y" home!
Posts: 6
Reputation: PMB76 is an unknown quantity at this point 
Rep Power: 0
Solved Threads: 1
PMB76 PMB76 is offline Offline
Newbie Poster

Re: Do I have a virus?

  #8  
Jan 21st, 2004
I still say do the MSCONFIG bit.... check for ULS (unidentified loaded software).
pmb76@technologist.com :idea:
support.dell.com
www.dell.com
Reply With Quote  
Join Date: Jan 2004
Posts: 35
Reputation: Pitufo is an unknown quantity at this point 
Rep Power: 5
Solved Threads: 0
Pitufo Pitufo is offline Offline
Light Poster

Re: Do I have a virus?

  #9  
Jan 21st, 2004
i just did that and yes there are unidentified stuff in there... I guess always turn those off?
Reply With Quote  
Join Date: Jan 2004
Location: In my "home-y" home!
Posts: 6
Reputation: PMB76 is an unknown quantity at this point 
Rep Power: 0
Solved Threads: 1
PMB76 PMB76 is offline Offline
Newbie Poster

Re: Do I have a virus?

  #10  
Jan 21st, 2004
Crosscheck the files via google to verify/identify the files. Leave the suspicious files unchecked.
pmb76@technologist.com :idea:
support.dell.com
www.dell.com
Reply With Quote  
Reply

Only community members can participate in forum threads. You must register or log in to contribute.

Currently Active Users Viewing This Thread: 1 (0 members and 1 guests)

 

Thread Tools Display Modes
Forums | Blogs | Tutorials | Code Snippets | Whitepapers | RSS Feeds | Advertising
All times are GMT -4. The time now is 11:23 pm.
Newsletter Archive - Sitemap - Privacy Statement - Acceptable Use Policy - Contact Us
Forum system based on vBulletin Copyright ©2000 - 2008, Jelsoft Enterprises Ltd.
©2003 - 2008 DaniWeb® LLC