Page 1 of 2

school disconnected my account (virus question)...

Posted: Wed Sep 13, 2006 8:54 pm
by werldhed
My school disconnected my wireless access because of what they think is a virus. Here's the email they sent me:
Because of behavior consistent with a virus infection,
the user account xxxxxx cannot use the modem/VPN/Wireless access.
This happened while using the address xxx.xx.xxx.xxx connected to xxxxx.
Your system needs to be taken off the network until it is cleaned up.

(You will also not be able to log into to the RACS system in the dorms.)

This reason was : spyware.

The computer in question appears to be infected with
a backdoor Trojan that steals private information.
(see http://en.wikipedia.org/wiki/Spyware for more
information on spyware).

This system should be cleaned with current Symantec antivirus
before bringing back online.
Now, I have scanned my computer with AVG, Symantec, and SpyBot, and it comes up clean. I also keep my definitions up to date, do daily/semi-daily scans, and keep the Windows Firewall on. I'm pretty confident there is no spyware on this machine.

So I called up the IT folks and asked them what's up. They said that their "expert" is of the opinion that the only safe way to ensure your computer is clean of spyware is to reinstall Windows; no amount of scanning or cleaning will fix it. Therefore, they won't let me use my wireless connection until I reinstall XP.

Frankly, fuck that.

My question is this: is there a way they might be mistaken about what they perceive to be "behavior consistent with a virus infection"?
And if not, is there truth to their claim that reinstallation is the only solution? Theoretically, I could tell them that I reinstalled, just to get them to reconnect me, but if there really is something wrong, they might disconnect me again for good.

Any insight is appreciated, thanks.

Posted: Wed Sep 13, 2006 11:09 pm
by dzjepp
Spybot isn't as good as it used to be a few years ago. There have been several products since then (most shareware) that have suprpassed it's accuracy and quality.

I'd say, give webroot spy sweeper a try, the free trial should work uncrippled. See if it comes up with anything.

http://www.webroot.com/consumer/product ... 5d10f234a2

Re: school disconnected my account (virus question)...

Posted: Thu Sep 14, 2006 12:12 am
by +JuggerNaut+
werldhed wrote:My school disconnected my wireless access because of what they think is a virus. Here's the email they sent me:
Because of behavior consistent with a virus infection,
the user account xxxxxx cannot use the modem/VPN/Wireless access.
This happened while using the address xxx.xx.xxx.xxx connected to xxxxx.
Your system needs to be taken off the network until it is cleaned up.

(You will also not be able to log into to the RACS system in the dorms.)

This reason was : spyware.

The computer in question appears to be infected with
a backdoor Trojan that steals private information.
(see http://en.wikipedia.org/wiki/Spyware for more
information on spyware).

This system should be cleaned with current Symantec antivirus
before bringing back online.
Now, I have scanned my computer with AVG, Symantec, and SpyBot, and it comes up clean. I also keep my definitions up to date, do daily/semi-daily scans, and keep the Windows Firewall on. I'm pretty confident there is no spyware on this machine.

So I called up the IT folks and asked them what's up. They said that their "expert" is of the opinion that the only safe way to ensure your computer is clean of spyware is to reinstall Windows; no amount of scanning or cleaning will fix it. Therefore, they won't let me use my wireless connection until I reinstall XP.

Frankly, fuck that.

My question is this: is there a way they might be mistaken about what they perceive to be "behavior consistent with a virus infection"?
And if not, is there truth to their claim that reinstallation is the only solution? Theoretically, I could tell them that I reinstalled, just to get them to reconnect me, but if there really is something wrong, they might disconnect me again for good.

Any insight is appreciated, thanks.
they're asking you to use Symantec, is that what you're using? either way, use it if you have to, and print the fucking log after scanning and cram it up their ass.

Re: school disconnected my account (virus question)...

Posted: Thu Sep 14, 2006 10:42 am
by ^misantropia^
werldhed wrote:So I called up the IT folks and asked them what's up. They said that their "expert" is of the opinion that the only safe way to ensure your computer is clean of spyware is to reinstall Windows; no amount of scanning or cleaning will fix it. Therefore, they won't let me use my wireless connection until I reinstall XP.
They say that because it is the only way for them to be sure your computer really is clean. Don't fight it, just reinstall.

Re: school disconnected my account (virus question)...

Posted: Thu Sep 14, 2006 10:58 am
by SOAPboy
^misantropia^ wrote:
werldhed wrote:So I called up the IT folks and asked them what's up. They said that their "expert" is of the opinion that the only safe way to ensure your computer is clean of spyware is to reinstall Windows; no amount of scanning or cleaning will fix it. Therefore, they won't let me use my wireless connection until I reinstall XP.
They say that because it is the only way for them to be sure your computer really is clean. Don't fight it, just reinstall.
I disagree. Fight it.

If every "tool" you have and they ahve find NOTHING, they can shove it up their ass. And id goto the board about it.. Frankly reinstalling is a pain in the ass if you have a shit ton of things running and installed.

Posted: Thu Sep 14, 2006 11:00 am
by ek
umm just say you formatted?

Posted: Thu Sep 14, 2006 11:00 am
by 4days
do what djzepp said, and what juggs said, then tell them you reinstalled xp too.

edit:
ek wrote:umm just say you formatted?
eggzackree :icon14:

Posted: Thu Sep 14, 2006 7:04 pm
by werldhed
Thanks all.
Is there a possibility that something else is making them think I have a virus? e.g. Azureus, or something like that?

The reason I don't want to just say I reinstalled is because if they detect a virus again, they'll probably disconnect me for good.

@dzjepp: Thanks for the suggestion. I'll give that a try when I get home (can't access the net with the laptop right now, afterall :icon33: )

Posted: Thu Sep 14, 2006 7:34 pm
by Captain
Do what Juggz said. Just print out a bunch of scan logs from different programs and shove em up their asses.

Posted: Thu Sep 14, 2006 8:16 pm
by werldhed
Aye... I'm gonna do that once I try a scan with Spy Sweeper. :icon14:

Posted: Thu Sep 14, 2006 8:58 pm
by dzjepp
Wait, are they claiming it's a virus or spyware? spy sweeper dosen't scan for viruses ya know, but as long as we're on the same issue I could recommend a better virii scanner as well :icon30:

nod32 and kaspersky av are both damn good

http://www.eset.com/download/index.php

http://fileforum.betanews.com/detail/Ka ... 08918303/2

Posted: Thu Sep 14, 2006 9:17 pm
by Captain
AVG Free ftw ey :drool:

Posted: Thu Sep 14, 2006 9:21 pm
by werldhed
dzjepp wrote:Wait, are they claiming it's a virus or spyware? spy sweeper dosen't scan for viruses ya know, but as long as we're on the same issue I could recommend a better virii scanner as well :icon30:

nod32 and kaspersky av are both damn good

http://www.eset.com/download/index.php

http://fileforum.betanews.com/detail/Ka ... 08918303/2
They claimed both. First they said it was behavior consistant with a virus, then they said it was spyware, then they said it was a trojan.

But they said it I should scan with Symantec, so I don't know what they really want. :icon8:

Posted: Thu Sep 14, 2006 9:22 pm
by werldhed
Captain Mazda wrote:AVG Free ftw ey :drool:
That's what I use. :icon14:

Posted: Fri Sep 15, 2006 1:18 am
by Tormentius
werldhed wrote:
That's what I use. :icon14:
Which Symantec product is it they want you to use? If its the corporate edition it trounces AVG in every way possible but if its Norton 200x its not too great.

Posted: Fri Sep 15, 2006 1:41 am
by werldhed
They didn't mention which they wanted me to use, but this computer has Corporate Ed. v.9.0.3.1000 on it.

Posted: Fri Sep 15, 2006 3:08 am
by Tormentius
Thats a far better app than AVG will ever be IMO.

Posted: Fri Sep 15, 2006 3:32 am
by +JuggerNaut+
JUST SEND IN THE FUCKING REPORT ALREADY.

Posted: Fri Sep 15, 2006 12:00 pm
by Captain
+JuggerNaut+ wrote:JUST SEND IN THE FUCKING REPORT ALREADY.
olo

Plus if they switched around between the culprit so much, I bet they know they fucked up and don't want to admit it. Shitstorm time.

Posted: Fri Sep 15, 2006 5:34 pm
by werldhed
+JuggerNaut+ wrote:JUST SEND IN THE FUCKING REPORT ALREADY.
lol... relax, tiger. :p
I've already sent the scan logs. I'm just waiting for a reply now.

I'll let you know what they say.

Posted: Fri Sep 15, 2006 7:19 pm
by +JuggerNaut+
lol i know man, giving you a hard time. i'm real interested in their response.

Posted: Fri Sep 15, 2006 9:11 pm
by dzjepp
Did spy sweeper find anything?

Posted: Fri Sep 15, 2006 9:23 pm
by werldhed
Nope. Just some old cookies I forgot to delete from IE back in the day.


Bah... no reply yet. I suspect I won't hear from them until after the weekend.

Posted: Sat Sep 16, 2006 1:50 pm
by werldhed
I already ran Blacklight, and it came up clean... Although, I forgot to mention that when I emailed them. Oh well..

Blacklight is the only one I'm familiar with. Any suggestions for other rootkit scanners?

Posted: Sun Sep 17, 2006 1:06 am
by shadd_
what you need is a good firewall set to block everything and see what tries to get out.