PCTechTalkhttp://www.pctechtalk.com/forums/

Go Back   PCTechTalk > PC Tech > Operating Systems and Software > Microsoft > NT/2000/XP

Reply
 
LinkBack Thread Tools Display Modes
Old 09-30-2005, 07:49 AM   #1 (permalink)
PCTT Articles
 
igalan's Avatar
 
Join Date: Apr 2002
Location: Barcelona, SPAIN
Posts: 1,018
igalan is on a distinguished road
Angry New install of Win2000 SP4 caught virus after less than 1 day!! fgxxgdsh

My aging laptop (Pentium III 600 MHz) needed an update quickly. It came with WinME and since I purchased it 4 years ago I didn't had to reinstall or anything. Of course I did clean the system carefully and tried to keep it in good shape. Lately I found that it was about time to do something more definitive; so I decided to install Windows 2000 SP4, because Windows XP is too much for this older computer.

I did a Norton Ghost image to an external disk just in case something goes wrong, and an additional manual copy of the whole drive to another external disk. I don't like surprises with my data . I had a Win2000 CD with SP4 slipstreamed. I installed the OS formatting the disk, then installed all the drivers that were necessary including the driver for my 802.11g PC-Card and set up the network. After that I installed all Windows Updates available (over 20 MB, hopefully my ADSL was much faster downloading the files than my computer installing them). And that was it.

Yesterday my wife was working with it and told me that Internet Explorer was launched at start up and a window popped up. I didn't think much about it, it may be one of the updates that needed to do something. But surprise, surprise! At night when I went to check it, the computer would not boot, it remained at the start up screen of Windows 2000. I tried a repair with the CD, but it didn't help (before I tried restoring last config, run a full checkdisk from a BartCD...) When I ran out of ideas, I booted again from the BartCD and saved the updated documents to an USB memory, just in case. Then rebooted once again and let the computer while I went to check the files I just rescued. When I came back 15m later Windows 2000 already had started, so I quickly looked the system event and the taskmanager. I found a very nasty surprise in the taskmanager when I saw several *.pif processes along with some highly suspicious processes. I killed all of them and from there started a long night removing viruses and restoring the computer to a safe and clean state.

Ok, I didn't install an antivirus (AVG for that matter). That was scheduled for a later stage, because the system was fully patched and no Internet browsing was going to be made until the AV was installed. My router does NAT, so I don't know how the hell those viruses managed to get in. Unfortunately the IP of the notebook was set up as DMZ because before reinstalling it had a FW. That was probably the reason. Still I don't know how it's possible that a fully patched OS gets infected with all this sh*t so quickly even when you don't surf the web at all!!!
__________________
AMD64 X2 3800+, Asus A8N-SLI Deluxe, 2 GB RAM, GeForce 6600GT, Windows XP Home SP2
igalan is offline   Reply With Quote
Old 09-30-2005, 09:17 AM   #2 (permalink)
Staff
 
Lion7718's Avatar
 
Join Date: Mar 2003
Location: Florida
Posts: 2,317
Lion7718 will become famous soon enough
If you didn't surf it might be your Windows Install CD.......
__________________
"Protect me from my friends, I can take care of my enemies"
You better not be touching my mannequin
Lion7718 is offline   Reply With Quote
Old 09-30-2005, 10:08 AM   #3 (permalink)
PCTT Articles
 
igalan's Avatar
 
Join Date: Apr 2002
Location: Barcelona, SPAIN
Posts: 1,018
igalan is on a distinguished road
Nope, it isn't. I have used that CD several other times.
__________________
AMD64 X2 3800+, Asus A8N-SLI Deluxe, 2 GB RAM, GeForce 6600GT, Windows XP Home SP2
igalan is offline   Reply With Quote
Old 09-30-2005, 11:41 AM   #4 (permalink)
AdMiN oF RoCk!
 
RipperRoo's Avatar
 
Join Date: Mar 2003
Location: uk
Posts: 2,080
RipperRoo is on a distinguished road
I've had similar problems in the past, because there are always more holes to patch than the latest service pack fixes.
my guess is you got hit with a worm in the time between going online with the machine and installing the last update/patching the last security hole, all too easyly done

the only way i found of doing an install without getting caught is to run the pc in series behind a fully patched/updated/anti virused/firewalled pc and do every single update, add a firewall and install and update anti virus software BEFORE connecting it directly to your router/modem
__________________
PcTechtalk.com Admin
A7V8X xp2600 Barton SLK 97U, GeForce FX 5700, 1GB 2700DDR Ram
Sony DVD -R/+R/RW, SB Live 5.1 Digital, 1 x 30gb 3 x 200GB 2x120GB 1 x 250GB HDD'S, 19" TFT Epson R265
HP NX6125 Laptop 1gb memory

http://www.minotaur-computers.co.uk/
RipperRoo is offline   Reply With Quote
Reply

Thread Tools
Display Modes

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is On
HTML code is Off
Trackbacks are On
Pingbacks are On
Refbacks are On


All times are GMT -5. The time now is 05:45 AM.


Powered by vBulletin® Version 3.7.3
Copyright ©2000 - 2008, Jelsoft Enterprises Ltd.
Search Engine Optimization by vBSEO 3.2.0
2001 PCTechTalk