»
 

Go Back   ResellerRatings Store Ratings > ResellerRatings Forums > Tech Support

Reply
 
LinkBack Thread Tools Display Modes
Old 09-30-2003, 04:53 AM   #1 (permalink)
Registered User
 
Join Date: Oct 2001
Location: The Neon Desert , AZ
Posts: 39
Raydeo is on a distinguished road
Gaming Visiting Porn Site KILLS my computer...

Well I went and did it this time : Clicking on a link to an unknown porn site provided a very unpleasant surprise:

I was immediately "mouse-trapped" (unable to close out of the page). Unable to do a ctrl-alt-del and kill tasks. Had to power down the system, and on the boot discovered a blank screen(not "blue screen") with a functioning mouse, and that's all. Ctrl-Alt-Del showed nothing running ! Tried the following :

1) Using Win98 boot disc, I ran Scanreg/Restore and set system back to a previous registry setup.

2) Ran AVG anti-virus from DOS and found no infections

3) Reloaded Win98 twice.

4) Ran "sys c:" from the boot disc

Fortunately, I had a backup "clone" of my drive and booted to it and went exploring the infected drive. Found the file "himem sys" in the Temp folder ??? Ran the AV again to no avail. Ran Spybot and found no malware. Deleted existing "himem sys" and copied over a known good copy.

After all that, I just bit-the-bullet and copied all my data over from my backup drive and formatted the infected drive. My curiosity just won't let go : Is there something else that I could have done to rescue my infected drive???

Have since discovered that disabling scripting in IE may have prevented this???

All opinions appreciated. I know, "Stop going to those Porn Sites"!!


Regards, Raydeo

It's a Jungle out there, and it's not far from the Jungle to the Zoo.


Last edited by Raydeo; 10-01-2003 at 10:35 AM.
Raydeo is offline   Reply With Quote
Old 09-30-2003, 02:02 PM   #2 (permalink)
Registered User
 
Eraserhead's Avatar
 
Join Date: Jun 2003
Location: Nowhere
Posts: 96
Eraserhead is on a distinguished road
It might have been possible to reboot into Safe Mode and look for any malicious programs in Startup using msconfig.

For future use, there's a good Spyware blocker that will add in to your Registry at

http://www.spywareguide.com/blockfile.php

which should stop nasty websites from automatically installing their malicious cr*p on your system.
Eraserhead is offline   Reply With Quote
Old 09-30-2003, 02:17 PM   #3 (permalink)
Registered User
 
meese's Avatar
 
Join Date: Jun 2003
Location: NJ
Posts: 1,096
meese is on a distinguished road
Rebooting is not good if you just got nailed with a virus. It will usually add it self to the start list or run key in the registry. Once you restart your done.
meese is offline   Reply With Quote
Old 09-30-2003, 06:26 PM   #4 (permalink)
Registered User
 
elmers's Avatar
 
Join Date: Sep 2003
Location: Euroland
Posts: 397
elmers is on a distinguished road
Ya and don't be copying files on your backup cause you might screw that one up too.
elmers is offline   Reply With Quote
Old 09-30-2003, 07:04 PM   #5 (permalink)
Registered User
 
Join Date: Oct 2001
Location: TOO close to Wash DC
Posts: 7,956
vass0922 is on a distinguished road
FYI - Run away from IE period

If you're gonna be off the mainstream sites avoid IE like the plague.

Use Opera or maybe even Mozilla

if you absolutely MUST use IE KILL activeX controls too
Be warned though this will also kill flash and shockwave... but using IE is a huge gamble on those sites.
__________________
<< Insert exceedingly large and overly verbose message of how 1337 you are here including full specs of every vehicle you've ever driven and PC you've owned >>

Last edited by vass0922; 09-30-2003 at 07:17 PM.
vass0922 is offline   Reply With Quote
Old 09-30-2003, 07:11 PM   #6 (permalink)
Registered User
 
crouse's Avatar
 
Join Date: Jun 2002
Location: Iowa
Posts: 2,527
crouse is on a distinguished road
Send a message via ICQ to crouse
Quote:
Originally posted by vass0922
FYI - Run away from IE period

If you're gonna be on off the mainstream sites avoid IE like the plague.

Use Opera or maybe even Mozilla

if you absolutely MUST use IE KILL activeX controls too
Be warned though this will also kill flash and shockwave... but using IE is a huge gamble on those sites.
I agree 100% ............. only thing better would be to ditch M$ and use FreeBsd or Linux or some other OS that isn't going to be vulnerable .

oh yeah........... and stay off the porn sites
__________________
The day Microsoft makes something that doesn't suck is probably the day they start making vacuum cleaners. --- Author Unknown.
crouse is offline   Reply With Quote
Old 10-01-2003, 08:15 AM   #7 (permalink)
Registered User
 
Join Date: Oct 2001
Location: The Neon Desert , AZ
Posts: 39
Raydeo is on a distinguished road
Here's the latest info on my infection. My gut tells me that this was the culprit. I neglected to mention that prior to being mousetrapped on a site, my AVG detected a trojan that I don't remember the name of. In my haste(haze?) I just denied access and surfed on (Not one of my more brilliant moves). I then went to a site that mousetrapped me and had to power down to get out of it. This activated the Trojan...
For the Registry Tweakers out there, note the changes it makes to the Registry. In particular, "DisableRegistryTools"... : Very Clever . Perhaps this explains why running Scanreg/restore did no good ??? Here's Symantec's take on it:

http://securityresponse.symantec.com...offensive.html

This damn thing put "NO" on everything in the box...Did everything but wipe the drive and wash the windows...At least they gave it the proper name..!

This thing makes viruses,spyware, and homepage hijacking quite tame by comparison. I had heard of sites that were setup to essentially "destroy" your computer by just going to them, but had never before had that misfortune. At least it didn't wipe the harddrive...

Thanx again for your input,
Raydeo is offline   Reply With Quote
Old 10-01-2003, 09:12 AM   #8 (permalink)
Registered User
 
Join Date: Sep 2003
Location: Germany
Posts: 39
Selphie is on a distinguished road
God hates pornoboys.

Love god. Hate porno.
__________________
Alles geht kaputt
Selphie is offline   Reply With Quote
Old 10-01-2003, 09:25 AM   #9 (permalink)
Registered User
 
meese's Avatar
 
Join Date: Jun 2003
Location: NJ
Posts: 1,096
meese is on a distinguished road
Lets save the preaching for church.
meese is offline   Reply With Quote
Old 10-01-2003, 09:32 AM   #10 (permalink)
Registered User
 
elmers's Avatar
 
Join Date: Sep 2003
Location: Euroland
Posts: 397
elmers is on a distinguished road
Opera rocks!
elmers is offline   Reply With Quote
Reply




Currently Active Users Viewing This Thread: 1 (0 members and 1 guests)
 
Thread Tools
Display Modes

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is On
HTML code is Off
Trackbacks are On
Pingbacks are On
Refbacks are On


Most Active Discussions

Recent Discussions

All times are GMT -6. The time now is 10:11 PM.