Notices
ScoobyNet General General Subaru Discussion

### VIRUS ###

Thread Tools
 
Search this Thread
 
Old Nov 26, 2001 | 10:24 AM
  #1  
Graham Beal's Avatar
Graham Beal
Thread Starter
Scooby Regular
 
Joined: Nov 2001
Posts: 239
Likes: 0
Unhappy

Looks like my comp has got a virus. Its one of those ones that sends itself from outlook express to everyone in my address book. If any of you get a dodgy mail from me then please delete it asap.

Thanks

Graham
Reply
Old Nov 26, 2001 | 11:50 AM
  #2  
47 NAT's Avatar
47 NAT
Scooby Regular
 
Joined: Dec 2000
Posts: 1,708
Likes: 0
From: In a village in Hants
Post

I've been sent a few via the RSOC BB. But in all fairness they probably did'nt know they done it....

Nath
Reply
Old Nov 26, 2001 | 11:56 AM
  #3  
nom's Avatar
nom
Scooby Senior
 
Joined: Oct 2001
Posts: 2,602
Likes: 0
Post

Got that one from you - thanks!
Well, I didn't get it, my AV stuff did instead.

If anyone's 'worried' they might have caught it, it has the catchy name W32/Badtrans@MM and there's some info on it here:
http://vil.nai.com/vil/virusSummary.asp?virus_k=99069
There's 'how to remove' info in there as well although it doesn't look much fun
Reply
Old Nov 26, 2001 | 11:57 AM
  #4  
mole's Avatar
mole
Scooby Regular
 
Joined: Jun 2001
Posts: 1,080
Likes: 0
Post

I got a mail earlier via webmail, contained an attachment something like new_napster_software.MP3.pif.

Deleted it.

Mole...
Reply
Old Nov 26, 2001 | 12:03 PM
  #5  
MorayMackenzie's Avatar
MorayMackenzie
Scooby Senior
 
Joined: Jun 1999
Posts: 3,410
Likes: 0
Post

Its an interesting way of finding whose address book you've made it into... Thanks for the attachments Mr Beal and several others. Sorry, I just binned them rather than replying.
Reply
Old Nov 26, 2001 | 12:05 PM
  #6  
nom's Avatar
nom
Scooby Senior
 
Joined: Oct 2001
Posts: 2,602
Likes: 0
Post

Yup, look out for something.something.something files - that's the way that they do stuff. Normally .pif at the end, I think! But two dots rather than the usual one means BAD
Reply
Old Nov 26, 2001 | 12:06 PM
  #7  
dingy's Avatar
dingy
Scooby Regular
 
Joined: Aug 2000
Posts: 1,842
Likes: 0
Post

W32/Badtrans-B is a worm which uses MAPI to spread. The worm
arrives in an email message with no message text. The attachment
filename is randomly generated from three parts. The first part
is taken from the list:

FUN
HUMOR
DOCS
S3MSONG
Sorry_about_yesterday
ME_NUDE
CARD
SETUP
SEARCHURL
YOU_ARE_FAT!
HAMSTER NEWS_DOC
New_Napster_Site
README
IMAGES
PICS

The second from the list:

.DOC.
.MP3.
.ZIP.

and the last from:

pif
scr

If the attached file is run, it copies itself into the Windows
system directory with the filename KERNEL32.EXE and changes the
registry key
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Run Once so that
the worm runs the next time Windows is started. The worm also
drops a file named kdll.dll, which is the password stealing
Trojan Troj/PWS-AV.


Enjoy
Reply
Old Nov 26, 2001 | 12:38 PM
  #8  
GavinP's Avatar
GavinP
Scooby Regular
 
Joined: Jun 1999
Posts: 1,430
Likes: 0
Lightbulb

If anyone's interested, I happened across this program yesterday - full-blown anti-virus suite (including e-mail scanner) as freeware:

http://www.grisoft.com/

I've only had a brief look at it so far but seems pretty good.

Thanks

Gavin
Reply
Old Nov 26, 2001 | 02:21 PM
  #9  
JackClark's Avatar
JackClark
Scooby Senior
25 Year Member
Liked
Loved
Community Favorite
 
Joined: Dec 2000
Posts: 20,896
Likes: 53
From: Overdosed on LCD
Post

Gavin, good detection rates, bit of a pain to look after, techie tool realy.
Reply
Old Nov 26, 2001 | 03:08 PM
  #10  
ChrisB's Avatar
ChrisB
Moderator
 
Joined: Dec 1998
Posts: 23,573
Likes: 0
From: Staffs
Post

Aye, somebody kindling sent me BadTrans this morning.

VirusScan killed it off for me.

Chris.

{Cheque to the usual place please Mr Clark )
Reply
Old Nov 26, 2001 | 06:17 PM
  #11  
Graham Beal's Avatar
Graham Beal
Thread Starter
Scooby Regular
 
Joined: Nov 2001
Posts: 239
Likes: 0
Talking

I have finally rid my system of that virus. Appologys to all those who got sent it, it wasnt intentional. If anyone is having difficulty removing i then look at

http://www.symantec.com/avcenter/venc/data/w32.badtrans.13312@mm.html

that shows you how to get rid of it.

Graham

Reply
Old Nov 26, 2001 | 06:22 PM
  #12  
JackClark's Avatar
JackClark
Scooby Senior
25 Year Member
Liked
Loved
Community Favorite
 
Joined: Dec 2000
Posts: 20,896
Likes: 53
From: Overdosed on LCD
Post

I can help over in Non Scooby Related if anyone's in real trouble.
Reply
Old Nov 26, 2001 | 06:32 PM
  #13  
EvilBevel's Avatar
EvilBevel
Scooby Regular
 
Joined: Oct 1999
Posts: 3,491
Likes: 0
Angry

Hmmmm... just got it in the mail (ta Harj ). Strange this is that upon opening the mail, OE 5.5 immediately asks if you want to run or save the file (without actually clicking on the attachment). First time I see it do that.

Could this be because the message title & body are empty ?

Anyway, it makes this virus a bit more dangerous than others.

Theo
Reply
Old Nov 26, 2001 | 06:59 PM
  #14  
Graham Beal's Avatar
Graham Beal
Thread Starter
Scooby Regular
 
Joined: Nov 2001
Posts: 239
Likes: 0
Thumbs down

when I got it this morning it automatically opened itself before I clicked on the attachment. Damn thing!!
Reply
Old Nov 26, 2001 | 07:48 PM
  #15  
lumby's Avatar
lumby
Scooby Regular
 
Joined: Jan 2001
Posts: 534
Likes: 0
Post

i got it last night i am now getting emials off allsorts of people i have never heard of .

will norton anti virus killl it off??
Reply
Old Nov 26, 2001 | 07:56 PM
  #16  
Spudgun GTR's Avatar
Spudgun GTR
Scooby Regular
 
Joined: Sep 2001
Posts: 547
Likes: 0
Thumbs up

lumby
i recieved 2 today, both from people ive never heard of. norton weeded 'em out straight away
Reply
Old Nov 26, 2001 | 08:06 PM
  #17  
Mr.Cookie's Avatar
Mr.Cookie
Scooby Regular
 
Joined: Apr 2000
Posts: 5,757
Likes: 0
From: www.mrcookie.co.uk
Post

LOL@Theo

I got it from H too and Skippy and Graham and a few more, looks like it spread a bit

Si
Reply
Old Nov 26, 2001 | 08:40 PM
  #18  
Shark's Avatar
Shark
Scooby Regular
 
Joined: Aug 1999
Posts: 3,539
Likes: 0
Angry

Got the basta*d tonight. Will post for help if I can't sort it.

Norton AntiVirus does not pick it up unless you have the very latest live update

David
Reply
Old Nov 26, 2001 | 08:43 PM
  #19  
DavidLewis's Avatar
DavidLewis
Scooby Regular
 
Joined: Apr 1998
Posts: 1,864
Likes: 0
Post

Got notification of mine yesterday. Came from Andy Ewings. Corporate virus checker got it first
Reply
Old Nov 26, 2001 | 08:45 PM
  #20  
Hel's Avatar
Hel
Scooby Regular
 
Joined: Sep 2001
Posts: 322
Likes: 0
Post

I had it too. Had to fork out £40 on Norton 2002, did the job though didnt know i had it till too late.
sorry if i passed it on to anyone.
Hel
Reply
Old Nov 26, 2001 | 10:13 PM
  #21  
Lee's Avatar
Lee
Scooby Regular
 
Joined: Mar 1999
Posts: 1,681
Likes: 0
From: Essex
Exclamation

This is spreading INCREDIBLY FAST !!!

I checked our mailservers to see how many they've stripped the virus from..JEEZ !!

Make sure you update those definitions !! or use a host who scans your email for viruses
Reply
Old Nov 26, 2001 | 11:09 PM
  #22  
adge's Avatar
adge
Scooby Regular
iTrader: (22)
 
Joined: Aug 1999
Posts: 1,937
Likes: 2
Red face

I got it as well, fortunately Norton 2001 got to it first. Just upgraded to Norton after getting the loveletter virus [img]images/smilies/mad.gif[/img]
Reply
Old Nov 27, 2001 | 12:47 AM
  #23  
muddy's Avatar
muddy
Scooby Regular
 
Joined: Dec 2000
Posts: 1,379
Likes: 0
From: E.Midlands/S.Yorkshire
Post

I got 2 today, one off my dad (he probably got it off the EVO list) and one from somebody I'd never heard of.

Haven't got any anti virus stuff, but was suspicous with them both because they didn't have any content so deleted both.

I take it that they will only corrupt your computer if you opened the attachments i.e save to disk.


Muddy
Reply
Old Nov 27, 2001 | 01:10 AM
  #24  
Shaun's Avatar
Shaun
Scooby Regular
25 Year Member
Liked
 
Joined: Mar 2000
Posts: 8,619
Likes: 24
From: 5 beats 4 - RS3 Rulez!!!
Exclamation

I have also been infected, but have since been to the doctors and been cleared.........

I must point out though......

THE VIRUS WILL AFFECT YOUR PC, EVEN IF YOU DONT VIEW/DETACH THE ATTACHMENT. ALL IT TAKES IS FOR YOU TO VIEW THE EMAIL CONTENT, EITHER IN THE PREVIEWER OR BY DOUBLE CLICKING ON THE EMAIL TITLE!!!!!!!

Make sure your email previewer is switched off!!!!

Regards,
Shaun.

[Edited by Shaun - 11/27/2001 1:11:28 AM]
Reply
Old Nov 27, 2001 | 01:51 AM
  #25  
jon44w's Avatar
jon44w
Scooby Regular
 
Joined: Sep 2001
Posts: 5,359
Likes: 0
Angry

i got the b45tard as well

emails were from darius and had no subject [img]images/smilies/mad.gif[/img]

hotmail picked it up no problem

john.
www.jon44w.com
Reply
Old Nov 27, 2001 | 08:52 AM
  #26  
Octane Man's Avatar
Octane Man
Scooby Regular
 
Joined: Apr 2001
Posts: 366
Likes: 0
Post

I'm glad I'm not the only one, I've received blank emails from a number of Scoobynetters and with an attachment called "Unknown".

I hope we can track the source of this as I've never emailed any of the people I've got Emails from so how can they have my details in their address book ??????
Reply
Old Nov 27, 2001 | 09:08 AM
  #27  
JGRIFF's Avatar
JGRIFF
Scooby Regular
 
Joined: Apr 2000
Posts: 945
Likes: 0
Thumbs down

Yes, I've had it too, it opened automatically yesterday morning. Apologies to all of you that it e-mailed automatically, Moray thanks for the warning!!, I got rid of the thing this morning, unfortunately it's corrupted the operating system which is going to take a little longer to sort out

[Edited by JGRIFF - 11/27/2001 9:09:56 AM]
Reply
Old Nov 27, 2001 | 01:24 PM
  #28  
scooby nutter's Avatar
scooby nutter
Scooby Regular
 
Joined: Dec 2000
Posts: 1,028
Likes: 0
Thumbs down

Ive just recieved three emails with no subject.
one had three attatchments! deleted all three emails.saved one to disk and checked with norton and no virus was detected in the scan!i should have subscribed for their updates!
One came from a guy off the lancer register.
Reply
Related Topics
Thread
Thread Starter
Forum
Replies
Last Post
Big RS Dave
ScoobyNet General
5
Apr 14, 2001 08:12 PM




All times are GMT +1. The time now is 12:44 AM.