Friday, April 07, 2006

Seattle, WA

First thing I need to do is apologize for my lengthy absence. I have been dealing with a virus the likes of which I've never seen before. This thing is not only destroying my system files and propogating itself like most viruses, it actually uninstalls programs or moves the entire contents of the folder so that the program no longer functions. It's almost intelligent and seems to go into hiding or become dormant when I aggressively seek it with different virus scanning and spyware removal software I've had to purchase due to it rendering my McAfee and Spybot programs useless.

I don't want to make the claim that this is a new virus until I substantiate my findings, but currently I have been working to eradicate this thing for 2 weeks now and for all my efforts it is still firmly embedded in my system and although I can keep it at bay by running a script that scans the system every 10 minutes for the latest viruses and spyware, it has still managed to evade detection and/or fool the scan into thinking it found something but in reality it just places random files throughout the system which my software identifies as various malware and such. Deleting these files solves nothing and is almost like this thing is toying with me.

This Virus seems intelligent because it seems to evolve and 'learn' as I fight to destroy it. Each time I fix something and get a handle on it, the Virus changes it's mode of attack on my system so that I have to start again.


To date this program has done the following damage:

Rendered Spybot Search & Destroy unable to connect to it's server to check for updates.

Corrupted McAfee Virus Scan so that it will not open.

Uninstalled McAfee Security Center completely.

Placed over 100 different files throughout my system that are for the most part adware or tracking cookies which I believe are only created to keep the Spyware programs busy.

Added shortcuts to various sites in my Favorites folder for Internet Explorer.

Hijacked the home page and locked me out of the internet options panel on Internet Explorer.

Crashed my Windows Explorer (Desktop) over a dozen times now.

You won't believe this last one... I wouldn't if I hadn't seen it with my own eyes.... It actually RE-WROTE the windows code for the GUI on my internet connection software so that the button that I click to CONNECT was just not there. Not only that, but it removed certain other graphical elements of the connection manager so that my NETWORK tab was missing as well as a few other tabs that had to do with monitoring network status.

That's just incredible. I have never seen anything like this and I'm stunned to put it mildly. I had to reinstall the entire program for my Sierra Wireless Aircard in order to get the GUI back to normal. I was essentially unable to go online until I did this. This Virus not only corrupts files, IT REWRITES THE GUI CODE!

And the latest tactict this thing has taken is to lock the task bar so that my icons are inaccessable. By that I mean my Connection Manager and McAfee programs by default load when Windows starts and they load into the task bar at the bottom right of the screen. I would normally just click on the icon to invoke the program, but since the taskbar is essentially 'Frozen' Windows can't or doesn't load those programs when it starts now. If I want to run those programs I have to manually open them from the actual folders as the shortcuts are also not functional anymore.... Why don't the shortcuts work you ask? Well it's really simple, the folders that the shortcuts point to are EMPTY. Yes, it takes the contents of the folders and just moves them to another folder. UNBELIEVABLE.

Windows is becoming increasingly more unstable and I don't think I can keep booting to Safe Mode to fix problems much longer. My files are backed up for the most part though in the event that I lose this battle.

If you are saying to yourself.. Why don't you just format the hard drive? Well I will be formating soon and will update both McAfee and a few others who have asked for me to document what I can on this and forward it.

I'm in Seattle, WA and not sure where I'm headed next. I will update as soon as I know anything. I'm sorry for not having a podcast up yet but it's been impossible due to the situation with my laptop.