posted 22 years ago
I'm pretty sure that I have one or two virus programs running on my computer. I believe that one does initialize during startup as I have seen a mysterious program icon appear on the main taskbar and in the taskbar tray. I'm quite familiar with controlling what programs run at startup (through start menu, registry run entries, and ini files) but I cannot figure out how this program is able to run and what exactly it's doing. Norton AntiVirus 2002 cannot find a virus or malicious script.
The icon and title that appear (only briefly) on the taskbar claims to be the SETI Spy program, but I know that it is not this program as I do not have it installed. The icon that has appeared one time (and only for ten seconds) in the taskbar tray was an icon that looks like the old speaker control icon found on default installations of Windows 95 and 98. The program name associate with this icon claimed to be mIRC. I do not have mIRC or any IRC program installed. The graphics for both of these icons were not of the same quality as the actual program and system icons and I find them to be highly suspect.
Also, about five times during the past 3 days, internet explorer windows start appearing at an uncontrolled rate in what would seem to be uncontrolled numbers. The only way I've been able to stop the windows from popping is by pressing ctrl+alt+delete and terminating all internet explorer processes.
Looking at the processes list (when pressing ctrl+alt+delete) doesn't reveal any programs that seem suspect or out of the ordinary.
ZoneAlarm doesn't report any blocked or attempted internet access or service.
This would seem to have all started when I was browsing the web a few days ago looking for security information related to blocking port trojans and loser script bunnies. I happened upon a site that tried to run some quesionable scripts and install a plug-in. I refused the plug-in and scripts and when I closed my browser window I found a program installation file (and exe) sitting on my desktop and a shortcut to it in my start menu. I deleted both files and didn't think to remember their names. Shortly thereafter, this suspicious activity began.
Has anybody else experienced anything like this?
[ August 28, 2002: Message edited by: Dirk Schreckmann ]