undetectable "virus".

Oldmrjim_at_aol.com
Date: 01/11/04


Date: Sun, 11 Jan 2004 13:26:34 -0800

A deadly new yet unknown "virus" is destroying Windows XP
PCs in my customer base.
This "virus" surfaced Monday 05, 2004 in the Prattville,
Alabama area. It prevents Windows XP from activating user
accounts, removing the START icon and bar.
The latest Norton (02072004), McAfee and Trend AV did not
detect this "virus." Also used Spybot.
It apparently has various XP symptoms infecting XP Pro and
Home:
Appears to use the DCOM vulnerability to infect the
computer before a user can download the Microsoft updates.
There are NO users in the USERS folder. A USER cannot be
added.
Windows Explorer cannot search for files and folders.
The task bar and start menu disappear.
The Program Files folder become read only.
The administrator cannot access the Services folder. The
result is a blue square in lieu of the expected data.
The network connectivity is halted. One cannot connect by
modem or LAN.
It disables the AV software and prevents it from reloading.
It disables COPY and PASTE and writing to a r/W CD drive
so it is almost impossible to scan the infected software.
As a test, I reloaded one WindowsXP Home machine. I then
ran every conceivable test I could and could not locate
any suspect code. Since I replaced the Windows folder, the
only way it could have reinfected that folder was via
memory or from the Program Files folder. I had also
powered off/on the machine to erase memory. I suspect it
is hiding somewhere in Program Files in a renamed file.
It appears to download and then sequentally perform its
chores.
Various other features do not operate correctly.
 
The only known cure is to prevent it. So far, I have
received NO worthy response re this code. We believe if
the Microsoft security updates in XP are installed, it
will prevent it. Go to START, and select WINDOWS UPDATE.
Install ALL the security updates.
 
With 4 PCs infected, we saved one to furthur troubleshoot.
The other three were fixed by formatting the hard drive
and completely reloading all software. The PC MUST be
powered off and then powered ON to remove any suspected
code from memory before reloading. You can save your data
files by various methods before formatting the drive.
I have about 37 years software experience (midframe, large
systems, and PCs) plus about 47 years hardware SO I am no
novice. I knew Bill Gates when he was a "developer" along
with his sidekick.



Relevant Pages

  • XP partition size
    ... i do this bc of all the program files and such that make ... windows and small things like direct x, ... dif partition) bc u still are taking up space in the c ... Files" folder - the "XP ...
    (microsoft.public.windowsxp.setup_deployment)
  • Re: Sharing Program Files folder
    ... I know what you are saying but I think Simple File Sharing only ... Windows folder. ... error when trying to access shared Program Files folder. ...
    (microsoft.public.windowsxp.network_web)
  • Re: Program Files - Read only
    ... If you look carefully you will see EVERY folder on the PC is marked as read ... Is Program Files supposed to be a read-only ... >>Try to kill all Money related Processes using Task ... Select Safe Mode on Windows Advanced ...
    (microsoft.public.windowsxp.general)
  • Re: Sharing Program Files folder
    ... >I would like to be able to access the Program Files ... >folder on my XP desktop from my WIN2000 laptop, however, ... NTFS disk partition using "Simple File Sharing". ... sharing the Documents and Settings, Program Files, or Windows folders. ...
    (microsoft.public.windowsxp.network_web)
  • Re: How share program files folder on LAN?
    ... program files folder for backup purposes? ... > from your Windows XP Pro machine using remote desktop or you ... > | On my Home LAN I cannot see contents of the Program Files ... > | admin on all PCs. ...
    (microsoft.public.windowsxp.general)