PDA

View Full Version : BIG problem



hammerjammer
07-12-2003, 10:24 PM
i have a GREAT new 2-part problem for you guys:

1] in removing the RiveraGoldCasino spyware/malware from one of my systems, i somehow made windows delete the account profile for that system. the administrator account is perfectly intact, but PORT4 does not even show up in users, has no folder in Documents and Settings, etc. wierd thing is, you can still log IN as PORT4. what happens when you do this is windows CREATES the PORT4 account (documents and settings folder and all). then when you log out, it disappears just as quickly. Just for now, i didn't consider this much of a problem because whatever monkey business the people who use this public, coffeehouse kiosk-style system do to this account doesn't save when i log it out and literally everything is wiped out. this includes all the spyware and malware and toolbars and all that BS they download, as well as all the wierd settings and backgrounds and homepages they seem to want to put on it. which brings me to the second part:

2] this guy came in last night and spent four hours downloading kiddieporn and also is apprently the head of a Yahoo Groups club that swaps kiddieporn as well as trolls various underage chatrooms searching for prey. the owner of the establishment and i looked over the URLs he visited, and the files he downloaded, etc... and she plans on calling the local police on monday. we've got the guy's name and drivers license info (which we collect when we rent the kiosk-computers to customers; problem is in the meantime, the account has now been logged out, thus removing all traces of the creep's activity. i doubt that there's been any deleting, just the account is gone so all paths to the files/folders are unaccessable.

Norton Ghost was unable to find the data, as was a few other programs i tried.

any ideas?
HJ

laurieA
07-13-2003, 01:25 AM
Can't help on 1st, but for 2nd there's a free data recovery utility http://www.pcinspector.de/file_recovery/UK/welcome.htm

Andy-S
07-13-2003, 09:17 AM
HJ,

I would take the PC offline and hand it over to the police. They will have a much better chance of retreiving the data than you will with any of the free utilitites available.

Even if the data is unretreivable at least you have brought the problem to the attention of the correct people.

Cheers
Andy

jlambt
07-14-2003, 04:31 AM
1) Try using policy's or desktop lock's to prevent any installation of plugin's/malware etc. Enforce user rights wich disable any such priviliges.

2) should there not be any .log file left ?

Or even some cookies etc. in the temp directory's for internet explorer. Another place to look would be the registry. Some amount of activity are available for one who knows to look hard enough.

No guarantees though if the guy installed some software himself to make sure everything was 'cleaned'.

jdharm
07-14-2003, 09:56 AM
I'm with Andy. Pull the plug on the system and hand over the hdd to the authorities. If you are in the US I wouldn't give the drive to the locals though, I would try the state police or nearest FBI field office. Chances are the locals won't know what to do with it and you don't want them loosing or overwriting the data. You might give them a copy of your proxy and/or router logs while you're at it.

Josh
<a target="_blank" href=http://www.jdharm.net>www.jdharm.net</a>