Notices
ScoobyNet General General Subaru Discussion
Sponsored by:
Sponsored by:

******* VIRUS ALERT - W32/ProLin@MM ********

Thread Tools
 
Search this Thread
 
Old 02 December 2000, 01:22 PM
  #1  
DazV
Scooby Regular
Thread Starter
 
DazV's Avatar
 
Join Date: Jun 2000
Posts: 3,783
Likes: 0
Received 0 Likes on 0 Posts
Post

W32/ProLin@MM is an Internet worm that spreads via email. McAfee AVERT has given it a risk assessment of MEDIUM TO
HIGH-RISK. The email comes with an attachment named CREATIVE.EXE, which carries the icon of a Shockwave Media Player application. You may receive the email in this format:

Subject = A great Shockwave flash movie
Body = Check out this new flash movie that I downloaded just now ... It's Great Bye
Attachment = creative.exe

If you run CREATIVE.EXE, it finds and alters all .JPG and .ZIP files on your system and forwards a copy of itself to everyone in your email address book. Please do not run the attachment.

(for the person who got stung by a worm virus recently on here)

DV
Old 02 December 2000, 05:23 PM
  #2  
Dave T-S
Scooby Regular
 
Dave T-S's Avatar
 
Join Date: Aug 2000
Location: Newmarket Suffolk
Posts: 8,897
Likes: 0
Received 4 Likes on 1 Post
Unhappy

....i know what you mean about the worm virus - having got hit by one last week.

Got my virus checker back up to date - and new version upgrade - plus put a firewall in. Firewall has already picked up people trying to access my PC (and blocked them out).

There's some sad people out there...
Old 02 December 2000, 05:26 PM
  #3  
DavidG
Scooby Regular
 
DavidG's Avatar
 
Join Date: Apr 1999
Posts: 470
Likes: 0
Received 0 Likes on 0 Posts
Question

how do you put a firewall in?
Old 02 December 2000, 05:38 PM
  #4  
logiclee
Scooby Regular
 
logiclee's Avatar
 
Join Date: Sep 2000
Location: Notts, UK
Posts: 4,935
Likes: 0
Received 0 Likes on 0 Posts
Angry

Too Late

Just spent 36 hours trying to back up what files I could and writing down any info etc.
McAfee found it while scanning but it was too late.
Could open internet explorer but could not change frome homepage without a IE caused fault in bla bla bla. Also could not use windows explorer or my computer to get at my hard drives.
Just reinstalled after formating Harddrive, was getting ready for a clearout anyway.

Lee
Old 02 December 2000, 05:47 PM
  #5  
Blow Dog
Scooby Regular
 
Blow Dog's Avatar
 
Join Date: May 1999
Location: London
Posts: 3,855
Likes: 0
Received 0 Likes on 0 Posts
Post

I dont want to be the one to put salt in the wound, but why oh why do people insist on double clicking on any EXE file that some 'stranger' has sent to you.

If it is an executable or any self extracting archive, BIN IT.

Cem

Old 02 December 2000, 06:30 PM
  #6  
DazV
Scooby Regular
Thread Starter
 
DazV's Avatar
 
Join Date: Jun 2000
Posts: 3,783
Likes: 0
Received 0 Likes on 0 Posts
Post

Make sure you haven't got the layout option in outlook express that auto-opens any emails in a preview pane - its bad news.

DV
Old 02 December 2000, 06:34 PM
  #7  
Dave T-S
Scooby Regular
 
Dave T-S's Avatar
 
Join Date: Aug 2000
Location: Newmarket Suffolk
Posts: 8,897
Likes: 0
Received 4 Likes on 1 Post
Talking

DavidG
Old 02 December 2000, 06:44 PM
  #8  
Blow Dog
Scooby Regular
 
Blow Dog's Avatar
 
Join Date: May 1999
Location: London
Posts: 3,855
Likes: 0
Received 0 Likes on 0 Posts
Post

THE BAST4RD!

...
Old 02 December 2000, 06:46 PM
  #9  
Dave T-S
Scooby Regular
 
Dave T-S's Avatar
 
Join Date: Aug 2000
Location: Newmarket Suffolk
Posts: 8,897
Likes: 0
Received 4 Likes on 1 Post
Wink

.....oh no, they killed my PC.....

[This message has been edited by Dave T-S (edited 02 December 2000).]
Old 02 December 2000, 07:07 PM
  #10  
ChrisB
Moderator
 
ChrisB's Avatar
 
Join Date: Dec 1998
Location: Staffs
Posts: 23,573
Likes: 0
Received 0 Likes on 0 Posts
Post

<BLOCKQUOTE><font size="1" face="Verdana, Arial">quote:<HR>Originally posted by Blow Dog:
<B>I dont want to be the one to put salt in the wound, but why oh why do people insist on double clicking on any EXE file that some 'stranger' has sent to you.

If it is an executable or any self extracting archive, BIN IT.

Cem

[/quote]

Hell, if I get an attachment even from somebody I know that I haven't asked for, I delete it any way.

Chris.
Old 02 December 2000, 07:16 PM
  #11  
whizzer
Scooby Regular
 
whizzer's Avatar
 
Join Date: Oct 1999
Posts: 83
Likes: 0
Received 0 Likes on 0 Posts
Post

Just a warning to new users of firewalls , don't think you're 100% safe , I've been using a firewall for some time now and even use a special app to port scan my own computer to see any possible back doors . Anyway somehow a trojan found it's way on my hard drive and bypassed the firewall and I lost 2.4megs of hard drive to a hacker , even with a updated Norton antivirus list . So don't become too complacent .
Old 02 December 2000, 07:17 PM
  #12  
DazV
Scooby Regular
Thread Starter
 
DazV's Avatar
 
Join Date: Jun 2000
Posts: 3,783
Likes: 0
Received 0 Likes on 0 Posts
Post

Hell if I get an attachment, even from somebody I know, I bin it, go around to their house kick their tv set over and slap them - just to be on the safe side.
Old 02 December 2000, 07:19 PM
  #13  
Dave T-S
Scooby Regular
 
Dave T-S's Avatar
 
Join Date: Aug 2000
Location: Newmarket Suffolk
Posts: 8,897
Likes: 0
Received 4 Likes on 1 Post
Smile

ChrisB
So do I - now!! In any case the firewall intercepts them.

DavidG
BTW - the firewall has already intercepted one attempt to get access to our PC - and denied it.
Old 02 December 2000, 07:21 PM
  #14  
DazV
Scooby Regular
Thread Starter
 
DazV's Avatar
 
Join Date: Jun 2000
Posts: 3,783
Likes: 0
Received 0 Likes on 0 Posts
Post

Don't talk to me about firewalls.

They take a fortune in petrol to maintain, and I'm taking McAfee to court over the unmoveable scorch marks on my ceiling, not to mention the lingering smell that I can't shift.

DazV
Old 02 December 2000, 07:22 PM
  #15  
Dave T-S
Scooby Regular
 
Dave T-S's Avatar
 
Join Date: Aug 2000
Location: Newmarket Suffolk
Posts: 8,897
Likes: 0
Received 4 Likes on 1 Post
Post

DazV
You have mail.....

Whizzer
Agree - while the PC is plugged in the phone line you are never 100% safe.
Old 02 December 2000, 07:23 PM
  #16  
Blow Dog
Scooby Regular
 
Blow Dog's Avatar
 
Join Date: May 1999
Location: London
Posts: 3,855
Likes: 0
Received 0 Likes on 0 Posts
Smile

<BLOCKQUOTE><font size="1" face="Verdana, Arial">quote:<HR>Hell if I get an attachment, even from somebody I know, I bin it, go around to their house kick their tv set over and slap them - just to be on the safe side.<HR></BLOCKQUOTE>

LOLLOL
Old 02 December 2000, 07:24 PM
  #17  
Dave T-S
Scooby Regular
 
Dave T-S's Avatar
 
Join Date: Aug 2000
Location: Newmarket Suffolk
Posts: 8,897
Likes: 0
Received 4 Likes on 1 Post
Wink

DazV
That was the chicken phal you had last night M8.....
Old 02 December 2000, 07:31 PM
  #18  
DazV
Scooby Regular
Thread Starter
 
DazV's Avatar
 
Join Date: Jun 2000
Posts: 3,783
Likes: 0
Received 0 Likes on 0 Posts
Post

The TCP/IP stack from implementation was built for 2 way communication.

Anything built on top to vet incoming requestes (eg. firewall) can be pretty much disabled once you suss how it works.

Nothing is safe.

Hell, this message may even be typed by some deranged lunatic. (I can feel Dave's fingers twitching to answer this very paragraph)

DazV
Old 02 December 2000, 07:37 PM
  #19  
DazV
Scooby Regular
Thread Starter
 
DazV's Avatar
 
Join Date: Jun 2000
Posts: 3,783
Likes: 0
Received 0 Likes on 0 Posts
Post

Dave, don't talk to me about chicken phal's

Now thats what I CALL unauthorised access to my backdoor(!) I'm still trying to close it.
DazV
Old 02 December 2000, 07:52 PM
  #20  
Dave T-S
Scooby Regular
 
Dave T-S's Avatar
 
Join Date: Aug 2000
Location: Newmarket Suffolk
Posts: 8,897
Likes: 0
Received 4 Likes on 1 Post
Wink

DazV
.....putting the roll of toilet paper in the freezer beforehand usually helps.....
Old 02 December 2000, 08:46 PM
  #21  
logiclee
Scooby Regular
 
logiclee's Avatar
 
Join Date: Sep 2000
Location: Notts, UK
Posts: 4,935
Likes: 0
Received 0 Likes on 0 Posts
Cool

Cem,

Can't recall opening any exe files or attachements as I don't open such files. I haven't a clue where it came from.

Lee
Old 02 December 2000, 09:12 PM
  #22  
Blow Dog
Scooby Regular
 
Blow Dog's Avatar
 
Join Date: May 1999
Location: London
Posts: 3,855
Likes: 0
Received 0 Likes on 0 Posts
Post

This is class material...wasted in the General Questions forum.

Old 02 December 2000, 09:24 PM
  #23  
DazV
Scooby Regular
Thread Starter
 
DazV's Avatar
 
Join Date: Jun 2000
Posts: 3,783
Likes: 0
Received 0 Likes on 0 Posts
Post

Dave, toilet paper in the freezer is good idea.

Personally I use WAX WIZARD - everyone on here raves about it. You be amazed at just how flexible it is.

It offers me a level of protection not surpassed by even frozen toilet paper.

Old 02 December 2000, 09:42 PM
  #24  
logiclee
Scooby Regular
 
logiclee's Avatar
 
Join Date: Sep 2000
Location: Notts, UK
Posts: 4,935
Likes: 0
Received 0 Likes on 0 Posts
Cool

Cem

I'll guarantee you'll feel a right muppet if you get it

Lee
Old 03 December 2000, 07:16 PM
  #25  
Dave T-S
Scooby Regular
 
Dave T-S's Avatar
 
Join Date: Aug 2000
Location: Newmarket Suffolk
Posts: 8,897
Likes: 0
Received 4 Likes on 1 Post
Wink

Blowdog
Not sure this one is good enough quality for u yet....
Old 03 December 2000, 07:35 PM
  #26  
Mr.Cookie
Scooby Regular
 
Mr.Cookie's Avatar
 
Join Date: Apr 2000
Location: www.mrcookie.co.uk
Posts: 5,757
Likes: 0
Received 0 Likes on 0 Posts
Talking

Tis now Dave im here Christ how did i miss this some funny sh*t in here

Si
Old 03 December 2000, 08:00 PM
  #27  
Dave T-S
Scooby Regular
 
Dave T-S's Avatar
 
Join Date: Aug 2000
Location: Newmarket Suffolk
Posts: 8,897
Likes: 0
Received 4 Likes on 1 Post
Wink

Si
Cos you're too busy intefering in my other posts M8
Related Topics
Thread
Thread Starter
Forum
Replies
Last Post
smunns
ScoobyNet General
286
01 October 2015 11:51 AM
smunns
Dealer and Third Party Supplier Queries
5
14 September 2015 08:08 PM
a2jcy
ScoobyNet General
3
30 May 2001 12:38 PM
Big RS Dave
ScoobyNet General
5
14 April 2001 08:12 PM



Quick Reply: ******* VIRUS ALERT - W32/ProLin@MM ********



All times are GMT +1. The time now is 02:40 AM.