Notices
Non Scooby Related Anything Non-Scooby related

BEWARE - COMPUTER VIRUS

Thread Tools
 
Search this Thread
 
Old 29 November 2000, 12:07 AM
  #1  
Dave T-S
Scooby Regular
Thread Starter
 
Dave T-S's Avatar
 
Join Date: Aug 2000
Location: Newmarket Suffolk
Posts: 8,897
Likes: 0
Received 4 Likes on 1 Post
Angry

I believe I have found out why my PC has been crashing out of Scoobynet the last few days......

I was sent an Email from Italy at the weekend from somebody I was expecting a reply from. I got two messages. The first one was legit, the second one had an attachment called "Jimi Hendrix". I thought he had sent it to me in error or something so did what we would all do (or me anyway), against all the advice, and clicked on the attachment.

Nothing happened, or so I thought.....then I started getting problems.

This is a known W95.MTX variant worm virus (or now I know this – hindsight eh??). It also manifests itself under a whole list of names including “hanson.scr” (which I accidentally sent to Webmaster after it had infected me - OOPS sorry Simon SIR).

It also has the capability to block access to certain web sites – sounds familiar?

What it does is that the worm component makes a copy of Wsock32.dll and names it Wsock32.mtx. It then allows the virus to mail a copy of the worm infected with this virus in parallel to the person any legitimate mail is sent to. You click on the Jimi Hendrix (or hanson.scr) attachment, and you can guess the rest.

According to Symantec’s website it can be a bit of a pig to remove.

Further information can be obtained from
Old 29 November 2000, 12:53 AM
  #2  
Lee
Scooby Regular
 
Lee's Avatar
 
Join Date: Mar 1999
Location: Essex
Posts: 1,681
Likes: 0
Received 0 Likes on 0 Posts
Exclamation

This virus is certainly doing the rounds - I've had loads of reports from my server where people have tried to send email with it attached.

Thank god for server based email virus scanning eh !
Old 29 November 2000, 12:57 AM
  #3  
Dave T-S
Scooby Regular
Thread Starter
 
Dave T-S's Avatar
 
Join Date: Aug 2000
Location: Newmarket Suffolk
Posts: 8,897
Likes: 0
Received 4 Likes on 1 Post
Angry

Lee
Thank God for having updated my Norton AV - oh bugger - about a year ago

Guess what i'm doing tonight??
Old 29 November 2000, 02:56 PM
  #4  
Puff The Magic Wagon!
Moderator
Support Scoobynet!
iTrader: (2)
 
Puff The Magic Wagon!'s Avatar
 
Join Date: May 2000
Location: From far, far away...
Posts: 16,978
Received 15 Likes on 9 Posts
Talking

Lee

Yup! + auto update enabled

Scored 5 virus's in the last few days on our network.

I even got my brother-in-law to send me an email 'cos he was told he had a virus but not what! (So I could tell him what it was )

Caught & killed

Every time we get a virus, my pager goes off - bit tedious...
Old 29 November 2000, 03:05 PM
  #5  
Dave T-S
Scooby Regular
Thread Starter
 
Dave T-S's Avatar
 
Join Date: Aug 2000
Location: Newmarket Suffolk
Posts: 8,897
Likes: 0
Received 4 Likes on 1 Post
Wink

James
So exactly which bit of that post is supposed to make me feel better then??
Old 29 November 2000, 03:17 PM
  #6  
Peter Ford
Scooby Regular
 
Peter Ford's Avatar
 
Join Date: Aug 2000
Posts: 45
Likes: 0
Received 0 Likes on 0 Posts
Angry

I fell foul to the 'kak' worm virus a while ago, from an email- and this one you dont even have to click on. It manifests itself in a signature in the email, in some sort of active x scripting, so as soon as you opened the email, your infected.
Old 29 November 2000, 04:40 PM
  #7  
David Lock
Scooby Regular
 
David Lock's Avatar
 
Join Date: Mar 2000
Location: Weston Super Mare, Somerset.
Posts: 14,102
Likes: 0
Received 0 Likes on 0 Posts
Post

Peter,
Being a computer muppet (well nearly) and working from home (not surrounded by IT gurus) I am very nervous about viruses. Do I take your post to mean that by just reading an e-mail I can catch something?? I know of course about opening dodgy attachments but I really didn't think reading e-mails carried a risk. Can somebody put me right? Thanks in advance. BTW I do use Norton and so far, touch whatever no problems. I haven't a clue what active x scripting is. David
Old 29 November 2000, 05:16 PM
  #8  
ChrisB
Moderator
 
ChrisB's Avatar
 
Join Date: Dec 1998
Location: Staffs
Posts: 23,573
Likes: 0
Received 0 Likes on 0 Posts
Post

David,

You are indeed at risk if you use Outlook Express with the Preview Pane.

For instance, one of the variants of KAK (http://vil.nai.com/vil/virusChar.asp?virus_k=10509) can be activated by viewing an infected message 'with' the Preview Pane.

Things to do...

1) Ensure your anti-virus software is updated (at a minimum get an update every month) and enabled.

2) Use
Old 29 November 2000, 10:03 PM
  #9  
Dave T-S
Scooby Regular
Thread Starter
 
Dave T-S's Avatar
 
Join Date: Aug 2000
Location: Newmarket Suffolk
Posts: 8,897
Likes: 0
Received 4 Likes on 1 Post
Wink

I've run the Symantec W95.MTX fix and reloaded Win 98 - looks like I am back in business guys - getting update version of Norton System Works tomorrow and gonna install a firewall - then go gunning for the ba5stard that infected me

1000 posts here I come.....
Old 30 November 2000, 12:51 AM
  #10  
Dave T-S
Scooby Regular
Thread Starter
 
Dave T-S's Avatar
 
Join Date: Aug 2000
Location: Newmarket Suffolk
Posts: 8,897
Likes: 0
Received 4 Likes on 1 Post
Smile

By strange coincidence I was looking at those three firewalls this morning after my little visitor earlier in the week....

Mrs T-S is at home today so she very kindly loaded me one this morning.....been to PC World (UGH - but convenient) in my lunch hour to get an update of my viruschecker with auto online update - that should tighten things up - live and learn eh guys??
Old 30 November 2000, 08:31 AM
  #11  
Puff The Magic Wagon!
Moderator
Support Scoobynet!
iTrader: (2)
 
Puff The Magic Wagon!'s Avatar
 
Join Date: May 2000
Location: From far, far away...
Posts: 16,978
Received 15 Likes on 9 Posts
Wink

OH NO!

Quick someone, send him some more viruses!

Glad to know your sorted
Old 30 November 2000, 09:34 AM
  #12  
David Lock
Scooby Regular
 
David Lock's Avatar
 
Join Date: Mar 2000
Location: Weston Super Mare, Somerset.
Posts: 14,102
Likes: 0
Received 0 Likes on 0 Posts
Post

Chris B,

Many thanks indeed for your helpful reply. I will spring into action. Cheers, David.
Old 30 November 2000, 09:50 AM
  #13  
Peter Ford
Scooby Regular
 
Peter Ford's Avatar
 
Join Date: Aug 2000
Posts: 45
Likes: 0
Received 0 Likes on 0 Posts
Post

As well as updating my virus checker I also got a software update patch thingy from micro$oft, which stops the loop hole in outlook that allows worms like kak into the system.
Good to know you got everything sorted out dave. The few I've had in the past have meant whole hd formats!
Old 30 November 2000, 10:00 AM
  #14  
Markus
Scooby Regular
 
Markus's Avatar
 
Join Date: Mar 1999
Location: The Great White North
Posts: 25,080
Likes: 0
Received 0 Likes on 0 Posts
Post

win85.mtx

Nastiest virus I've ever come across. We had a problem with a a few weeks back. one of the PC chaps got sent an email and this crashed our mailserver, on closer inspection it was something to do with some file called 'metalica.mp3.pif' that he was trying to send. Which he was not.

I grabbed the file on my mac and opened it up and had a scan through the info, and found out what it was.

You should have seen their faces when I looked it up on the symantec site.

Trully horrible little bast. Glad I've got a mac, which can't get infected by it.
Old 30 November 2000, 11:04 AM
  #15  
ChrisB
Moderator
 
ChrisB's Avatar
 
Join Date: Dec 1998
Location: Staffs
Posts: 23,573
Likes: 0
Received 0 Likes on 0 Posts
Post

David,

I'd also recommend running a personal firewall. I use ZoneAlarm on my Windows 2000 PC at home (
Related Topics
Thread
Thread Starter
Forum
Replies
Last Post
Wish
Computer & Technology Related
3
30 September 2015 10:39 PM



Quick Reply: BEWARE - COMPUTER VIRUS



All times are GMT +1. The time now is 10:52 AM.