Notices
ScoobyNet General General Subaru Discussion
Sponsored by:
Sponsored by:

### VIRUS ###

Thread Tools
 
Search this Thread
 
Old 26 November 2001, 10:24 AM
  #1  
Graham Beal
Scooby Regular
Thread Starter
 
Graham Beal's Avatar
 
Join Date: Nov 2001
Posts: 239
Likes: 0
Received 0 Likes on 0 Posts
Unhappy

Looks like my comp has got a virus. Its one of those ones that sends itself from outlook express to everyone in my address book. If any of you get a dodgy mail from me then please delete it asap.

Thanks

Graham
Old 26 November 2001, 11:50 AM
  #2  
47 NAT
Scooby Regular
 
47 NAT's Avatar
 
Join Date: Dec 2000
Location: In a village in Hants
Posts: 1,708
Likes: 0
Received 0 Likes on 0 Posts
Post

I've been sent a few via the RSOC BB. But in all fairness they probably did'nt know they done it....

Nath
Old 26 November 2001, 11:56 AM
  #3  
nom
Scooby Senior
 
nom's Avatar
 
Join Date: Oct 2001
Posts: 2,602
Likes: 0
Received 0 Likes on 0 Posts
Post

Got that one from you - thanks!
Well, I didn't get it, my AV stuff did instead.

If anyone's 'worried' they might have caught it, it has the catchy name W32/Badtrans@MM and there's some info on it here:
http://vil.nai.com/vil/virusSummary.asp?virus_k=99069
There's 'how to remove' info in there as well although it doesn't look much fun
Old 26 November 2001, 11:57 AM
  #4  
mole
Scooby Regular
 
mole's Avatar
 
Join Date: Jun 2001
Posts: 1,080
Likes: 0
Received 0 Likes on 0 Posts
Post

I got a mail earlier via webmail, contained an attachment something like new_napster_software.MP3.pif.

Deleted it.

Mole...
Old 26 November 2001, 12:03 PM
  #5  
MorayMackenzie
Scooby Senior
 
MorayMackenzie's Avatar
 
Join Date: Jun 1999
Posts: 3,410
Likes: 0
Received 0 Likes on 0 Posts
Post

Its an interesting way of finding whose address book you've made it into... Thanks for the attachments Mr Beal and several others. Sorry, I just binned them rather than replying.
Old 26 November 2001, 12:05 PM
  #6  
nom
Scooby Senior
 
nom's Avatar
 
Join Date: Oct 2001
Posts: 2,602
Likes: 0
Received 0 Likes on 0 Posts
Post

Yup, look out for something.something.something files - that's the way that they do stuff. Normally .pif at the end, I think! But two dots rather than the usual one means BAD
Old 26 November 2001, 12:06 PM
  #7  
dingy
Scooby Regular
 
dingy's Avatar
 
Join Date: Aug 2000
Posts: 1,842
Likes: 0
Received 0 Likes on 0 Posts
Post

W32/Badtrans-B is a worm which uses MAPI to spread. The worm
arrives in an email message with no message text. The attachment
filename is randomly generated from three parts. The first part
is taken from the list:

FUN
HUMOR
DOCS
S3MSONG
Sorry_about_yesterday
ME_NUDE
CARD
SETUP
SEARCHURL
YOU_ARE_FAT!
HAMSTER NEWS_DOC
New_Napster_Site
README
IMAGES
PICS

The second from the list:

.DOC.
.MP3.
.ZIP.

and the last from:

pif
scr

If the attached file is run, it copies itself into the Windows
system directory with the filename KERNEL32.EXE and changes the
registry key
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Run Once so that
the worm runs the next time Windows is started. The worm also
drops a file named kdll.dll, which is the password stealing
Trojan Troj/PWS-AV.


Enjoy
Old 26 November 2001, 12:38 PM
  #8  
GavinP
Scooby Regular
 
GavinP's Avatar
 
Join Date: Jun 1999
Posts: 1,430
Likes: 0
Received 0 Likes on 0 Posts
Lightbulb

If anyone's interested, I happened across this program yesterday - full-blown anti-virus suite (including e-mail scanner) as freeware:

http://www.grisoft.com/

I've only had a brief look at it so far but seems pretty good.

Thanks

Gavin
Old 26 November 2001, 02:21 PM
  #9  
JackClark
Scooby Senior
 
JackClark's Avatar
 
Join Date: Dec 2000
Location: Overdosed on LCD
Posts: 20,852
Received 51 Likes on 34 Posts
Post

Gavin, good detection rates, bit of a pain to look after, techie tool realy.
Old 26 November 2001, 03:08 PM
  #10  
ChrisB
Moderator
 
ChrisB's Avatar
 
Join Date: Dec 1998
Location: Staffs
Posts: 23,573
Likes: 0
Received 0 Likes on 0 Posts
Post

Aye, somebody kindling sent me BadTrans this morning.

VirusScan killed it off for me.

Chris.

{Cheque to the usual place please Mr Clark )
Old 26 November 2001, 06:17 PM
  #11  
Graham Beal
Scooby Regular
Thread Starter
 
Graham Beal's Avatar
 
Join Date: Nov 2001
Posts: 239
Likes: 0
Received 0 Likes on 0 Posts
Talking

I have finally rid my system of that virus. Appologys to all those who got sent it, it wasnt intentional. If anyone is having difficulty removing i then look at

http://www.symantec.com/avcenter/venc/data/w32.badtrans.13312@mm.html

that shows you how to get rid of it.

Graham

Old 26 November 2001, 06:22 PM
  #12  
JackClark
Scooby Senior
 
JackClark's Avatar
 
Join Date: Dec 2000
Location: Overdosed on LCD
Posts: 20,852
Received 51 Likes on 34 Posts
Post

I can help over in Non Scooby Related if anyone's in real trouble.
Old 26 November 2001, 06:32 PM
  #13  
EvilBevel
Scooby Regular
 
EvilBevel's Avatar
 
Join Date: Oct 1999
Posts: 3,491
Likes: 0
Received 0 Likes on 0 Posts
Angry

Hmmmm... just got it in the mail (ta Harj ). Strange this is that upon opening the mail, OE 5.5 immediately asks if you want to run or save the file (without actually clicking on the attachment). First time I see it do that.

Could this be because the message title & body are empty ?

Anyway, it makes this virus a bit more dangerous than others.

Theo
Old 26 November 2001, 06:59 PM
  #14  
Graham Beal
Scooby Regular
Thread Starter
 
Graham Beal's Avatar
 
Join Date: Nov 2001
Posts: 239
Likes: 0
Received 0 Likes on 0 Posts
Thumbs down

when I got it this morning it automatically opened itself before I clicked on the attachment. Damn thing!!
Old 26 November 2001, 07:48 PM
  #15  
lumby
Scooby Regular
 
lumby's Avatar
 
Join Date: Jan 2001
Posts: 534
Likes: 0
Received 0 Likes on 0 Posts
Post

i got it last night i am now getting emials off allsorts of people i have never heard of .

will norton anti virus killl it off??
Old 26 November 2001, 07:56 PM
  #16  
Spudgun GTR
Scooby Regular
 
Spudgun GTR's Avatar
 
Join Date: Sep 2001
Posts: 547
Likes: 0
Received 0 Likes on 0 Posts
Thumbs up

lumby
i recieved 2 today, both from people ive never heard of. norton weeded 'em out straight away
Old 26 November 2001, 08:06 PM
  #17  
Mr.Cookie
Scooby Regular
 
Mr.Cookie's Avatar
 
Join Date: Apr 2000
Location: www.mrcookie.co.uk
Posts: 5,757
Likes: 0
Received 0 Likes on 0 Posts
Post

LOL@Theo

I got it from H too and Skippy and Graham and a few more, looks like it spread a bit

Si
Old 26 November 2001, 08:40 PM
  #18  
Shark
Scooby Regular
 
Shark's Avatar
 
Join Date: Aug 1999
Posts: 3,539
Likes: 0
Received 0 Likes on 0 Posts
Angry

Got the basta*d tonight. Will post for help if I can't sort it.

Norton AntiVirus does not pick it up unless you have the very latest live update

David
Old 26 November 2001, 08:43 PM
  #19  
DavidLewis
Scooby Regular
 
DavidLewis's Avatar
 
Join Date: Apr 1998
Posts: 1,864
Likes: 0
Received 0 Likes on 0 Posts
Post

Got notification of mine yesterday. Came from Andy Ewings. Corporate virus checker got it first
Old 26 November 2001, 08:45 PM
  #20  
Hel
Scooby Regular
 
Hel's Avatar
 
Join Date: Sep 2001
Posts: 322
Likes: 0
Received 0 Likes on 0 Posts
Post

I had it too. Had to fork out £40 on Norton 2002, did the job though didnt know i had it till too late.
sorry if i passed it on to anyone.
Hel
Old 26 November 2001, 10:13 PM
  #21  
Lee
Scooby Regular
 
Lee's Avatar
 
Join Date: Mar 1999
Location: Essex
Posts: 1,681
Likes: 0
Received 0 Likes on 0 Posts
Exclamation

This is spreading INCREDIBLY FAST !!!

I checked our mailservers to see how many they've stripped the virus from..JEEZ !!

Make sure you update those definitions !! or use a host who scans your email for viruses
Old 26 November 2001, 11:09 PM
  #22  
adge
Scooby Regular
iTrader: (22)
 
adge's Avatar
 
Join Date: Aug 1999
Posts: 1,937
Received 2 Likes on 2 Posts
Red face

I got it as well, fortunately Norton 2001 got to it first. Just upgraded to Norton after getting the loveletter virus [img]images/smilies/mad.gif[/img]
Old 27 November 2001, 12:47 AM
  #23  
muddy
Scooby Regular
 
muddy's Avatar
 
Join Date: Dec 2000
Location: E.Midlands/S.Yorkshire
Posts: 1,379
Likes: 0
Received 0 Likes on 0 Posts
Post

I got 2 today, one off my dad (he probably got it off the EVO list) and one from somebody I'd never heard of.

Haven't got any anti virus stuff, but was suspicous with them both because they didn't have any content so deleted both.

I take it that they will only corrupt your computer if you opened the attachments i.e save to disk.


Muddy
Old 27 November 2001, 01:10 AM
  #24  
Shaun
Scooby Regular
Support Scoobynet!
 
Shaun's Avatar
 
Join Date: Mar 2000
Location: 5 beats 4 - RS3 Rulez!!!
Posts: 8,617
Received 22 Likes on 18 Posts
Exclamation

I have also been infected, but have since been to the doctors and been cleared.........

I must point out though......

THE VIRUS WILL AFFECT YOUR PC, EVEN IF YOU DONT VIEW/DETACH THE ATTACHMENT. ALL IT TAKES IS FOR YOU TO VIEW THE EMAIL CONTENT, EITHER IN THE PREVIEWER OR BY DOUBLE CLICKING ON THE EMAIL TITLE!!!!!!!

Make sure your email previewer is switched off!!!!

Regards,
Shaun.

[Edited by Shaun - 11/27/2001 1:11:28 AM]
Old 27 November 2001, 01:51 AM
  #25  
jon44w
Scooby Regular
 
jon44w's Avatar
 
Join Date: Sep 2001
Posts: 5,359
Likes: 0
Received 0 Likes on 0 Posts
Angry

i got the b45tard as well

emails were from darius and had no subject [img]images/smilies/mad.gif[/img]

hotmail picked it up no problem

john.
www.jon44w.com
Old 27 November 2001, 08:52 AM
  #26  
Octane Man
Scooby Regular
 
Octane Man's Avatar
 
Join Date: Apr 2001
Posts: 366
Likes: 0
Received 0 Likes on 0 Posts
Post

I'm glad I'm not the only one, I've received blank emails from a number of Scoobynetters and with an attachment called "Unknown".

I hope we can track the source of this as I've never emailed any of the people I've got Emails from so how can they have my details in their address book ??????
Old 27 November 2001, 09:08 AM
  #27  
JGRIFF
Scooby Regular
 
JGRIFF's Avatar
 
Join Date: Apr 2000
Posts: 945
Likes: 0
Received 0 Likes on 0 Posts
Thumbs down

Yes, I've had it too, it opened automatically yesterday morning. Apologies to all of you that it e-mailed automatically, Moray thanks for the warning!!, I got rid of the thing this morning, unfortunately it's corrupted the operating system which is going to take a little longer to sort out

[Edited by JGRIFF - 11/27/2001 9:09:56 AM]
Old 27 November 2001, 01:24 PM
  #28  
scooby nutter
Scooby Regular
 
scooby nutter's Avatar
 
Join Date: Dec 2000
Posts: 1,028
Likes: 0
Received 0 Likes on 0 Posts
Thumbs down

Ive just recieved three emails with no subject.
one had three attatchments! deleted all three emails.saved one to disk and checked with norton and no virus was detected in the scan!i should have subscribed for their updates!
One came from a guy off the lancer register.
Related Topics
Thread
Thread Starter
Forum
Replies
Last Post
Big RS Dave
ScoobyNet General
5
14 April 2001 08:12 PM



Quick Reply: ### VIRUS ###



All times are GMT +1. The time now is 11:54 AM.