Welcome to SecurityForumz.com!
FAQFAQ      ProfileProfile    Private MessagesPrivate Messages   Log inLog in

Is this a virus?

 
   Security Forums (Home) -> General Discussions RSS
Next:  New False Positive from Spyware Doctor?  
Author Message
jay

External


Since: Feb 01, 2007
Posts: 2



(Msg. 1) Posted: Thu Feb 01, 2007 7:34 pm
Post subject: Is this a virus?
Archived from groups: alt>comp>virus (more info?)

We have a PC running Windows 95 (because of some very old apps that
need to keep running). It is on a small network, behind a firewall.
There is supposedly no access to the outside from this computer and
the outside certainly cannot see it. We do not normally use IE or any
Windows-based software on that machine that talks to the outside
world. Any such connection is done via Xwindowing to a linux machine
which does the talking to the outside world from other hardware.

For no apparent reason (while nobody was using it) it suddenly went
from correctly working desktop to a Windows Network login screen. It
had seemingly rebooted itself. When I logged it in, it proceeded for
just a little while and then put up a white box with black text that
stated [don't recall all the text] ".... must reinstall Window."
NOTE: that is "Window", not "Windows". The misspelling got me
thinking that it was a virus.

Reboot attempts got worse and worse with serious file damage and
degradation; scandisk finding all sorts of problems each time
including FAT problems. Eventually scandisk itself could not even be
found.

On one attempt, to Safe Mode, it DID boot up and let me start a virus
scan. While it was scanning, I checked IE to see a) if there was any
IE history showing and b) if the history showed any inappropriate
activity. The IE history was present, but only showed LOCAL and
proper activity -- and even that was very, very old. In other words
no recent activity to www.VirusSite.com. In any case, a couple minutes
later, I got the blue screen of death. After that, all attempts to
restart Windows (Safe Mode) end halfway through the process by going
directly to "It is safe to turn off your computer" without any error
messages.

Does anything about this sound like a virus? Especially the "....
must reinstall Window."

Thanks.

Jay

 >> Stay informed about: Is this a virus? 
Back to top
Login to vote
jay

External


Since: Feb 01, 2007
Posts: 2



(Msg. 2) Posted: Thu Feb 01, 2007 8:47 pm
Post subject: Re: Is this a virus? [Login to view extended thread Info.]
Archived from groups: per prev. post (more info?)

Thanks Virus Guy. That actually makes me feel a little better. I am
more concerned about security than the mechanical. Yes, I can
replicate the contents of the drive, but it is a pain.

The thought of pulling the drive and putting it on as a nth drive on
another machine did cross my mind. However, Win95 is so prone to
crashes for any reason or no reaon that I figured it was just another
one of those annoying incidences.

The time when it did boot up in safe mode was after the machine had
been off for a couple hours; that fits perfectly with your theory.
Perhaps I can cool it down enough (is it safe to refrigerate a drive?)
to run it long enough to pull some stuff off it (that would take less
time than rebuidling from what I can replicate).

We do actually do exactly as you describe with the airflow except that
each drive carrier has its own fan in addition. However, I have never
had one run "cool". If I remember correctly, these are 8000 or 8500
RPM drives and they have always been hot. I have another machine
(linux) that has SIX 10,000 RPM drives and they are really hot.

Thanks.

Jay

 >> Stay informed about: Is this a virus? 
Back to top
Login to vote
Virus Guy

External


Since: Aug 05, 2005
Posts: 424



(Msg. 3) Posted: Thu Feb 01, 2007 11:23 pm
Post subject: Re: Is this a virus? [Login to view extended thread Info.]
Archived from groups: per prev. post (more info?)

jay RemoveThis @JaySmith.com wrote:

> We have a PC running Windows 95
>
> Reboot attempts got worse and worse with serious file damage

You should have removed the drive and slaved it to another computer
and scanned the drive for malware instead of putzing with it.

It looks more like the drive has failed mechanically. Hope you have a
backup.

The drives in our servers are mounted in an open 5.25" drive bay. All
other air access to the chasis is closed off, which means all air
entering the chasis must pass by and around the hard drive before
being sucked into the power supply and out the back. The drives run
cool to the touch this way and it extends their life.

> On one attempt, to Safe Mode, it DID boot up and let me start
> a virus scan.

Too bad you spent the last few minutes of it's life putzing with
anti-virus tools. You should have used that opportunity to do a drive
backup or clone the drive before total failure.
 >> Stay informed about: Is this a virus? 
Back to top
Login to vote
Display posts from previous:   
Related Topics:
Why the PC Virus cannot attack my XP? I am the administrat.. - The answer is: I know the Virus better than you smart asses who give bogus reasons blaming the users for your ignorance, I went to the core blocking the entries of the Virus's. Like I told you, Microsoft Windows is the one allowing the Virus to come in...

Mail Anti-Virus,alt.comp.virus - My AV application: Kaspersky Anti-Virus (6.0.2.6210) According to http://www.oehelp.com/OETips.aspx#3 e-mail scanning does not provide any additional protection. Would it be safe/advisable to disable the Mail Anti-Virus function?

List of the Virus makers's IP, there is one Virus maker in.. - IP's to block: 208.100.132.167 208.100.170.5 208.100.244.206 67.215.12.210 Or you can create your own block list from this registry, this is for IE 6.0, XP SP2 Windows Registry Editor Version 5.00..

about virus - Hello, Help me please. When I browse internet, I often get virus warning messages: Virus name: W32/Deloder.worm Infected file: C:\WINNT\system32\Dvldr32.exe and Virus name: BackDoor-ARG.dr Infected file: C:\WINNT\system32\inst.exe Neither files can be....

Have I a virus? - Avery now and then, randomly, no pattern a loud duck quack sounds from my computer. I have no WAV file ion my system for this and have searched evrywhere for something that would explain it. I have SPY BOT and AD-ware installed. n uptodate virus cvheck....
   Security Forums (Home) -> General Discussions All times are: Pacific Time (US & Canada) (change)
Page 1 of 1

 
You can post new topics in this forum
You can reply to topics in this forum
You cannot edit your posts in this forum
You cannot delete your posts in this forum
You cannot vote in polls in this forum



[ Contact us | Terms of Service/Privacy Policy ]