Notices
ScoobyNet General General Subaru Discussion

### VIRUS ###

Thread Tools
 
Search this Thread
 
Old 26 November 2001 | 11:24 AM
  #1  
Graham Beal's Avatar
Graham Beal
Thread Starter
Scooby Regular
 
Joined: Nov 2001
Posts: 239
Likes: 0
Unhappy

Looks like my comp has got a virus. Its one of those ones that sends itself from outlook express to everyone in my address book. If any of you get a dodgy mail from me then please delete it asap.

Thanks

Graham
Old 26 November 2001 | 12:50 PM
  #2  
47 NAT's Avatar
47 NAT
Scooby Regular
 
Joined: Dec 2000
Posts: 1,708
Likes: 0
From: In a village in Hants
Post

I've been sent a few via the RSOC BB. But in all fairness they probably did'nt know they done it....

Nath
Old 26 November 2001 | 12:56 PM
  #3  
nom's Avatar
nom
Scooby Senior
 
Joined: Oct 2001
Posts: 2,602
Likes: 0
Post

Got that one from you - thanks!
Well, I didn't get it, my AV stuff did instead.

If anyone's 'worried' they might have caught it, it has the catchy name W32/Badtrans@MM and there's some info on it here:
http://vil.nai.com/vil/virusSummary.asp?virus_k=99069
There's 'how to remove' info in there as well although it doesn't look much fun
Old 26 November 2001 | 12:57 PM
  #4  
mole's Avatar
mole
Scooby Regular
 
Joined: Jun 2001
Posts: 1,080
Likes: 0
Post

I got a mail earlier via webmail, contained an attachment something like new_napster_software.MP3.pif.

Deleted it.

Mole...
Old 26 November 2001 | 01:03 PM
  #5  
MorayMackenzie's Avatar
MorayMackenzie
Scooby Senior
 
Joined: Jun 1999
Posts: 3,410
Likes: 0
Post

Its an interesting way of finding whose address book you've made it into... Thanks for the attachments Mr Beal and several others. Sorry, I just binned them rather than replying.
Old 26 November 2001 | 01:05 PM
  #6  
nom's Avatar
nom
Scooby Senior
 
Joined: Oct 2001
Posts: 2,602
Likes: 0
Post

Yup, look out for something.something.something files - that's the way that they do stuff. Normally .pif at the end, I think! But two dots rather than the usual one means BAD
Old 26 November 2001 | 01:06 PM
  #7  
dingy's Avatar
dingy
Scooby Regular
 
Joined: Aug 2000
Posts: 1,842
Likes: 0
Post

W32/Badtrans-B is a worm which uses MAPI to spread. The worm
arrives in an email message with no message text. The attachment
filename is randomly generated from three parts. The first part
is taken from the list:

FUN
HUMOR
DOCS
S3MSONG
Sorry_about_yesterday
ME_NUDE
CARD
SETUP
SEARCHURL
YOU_ARE_FAT!
HAMSTER NEWS_DOC
New_Napster_Site
README
IMAGES
PICS

The second from the list:

.DOC.
.MP3.
.ZIP.

and the last from:

pif
scr

If the attached file is run, it copies itself into the Windows
system directory with the filename KERNEL32.EXE and changes the
registry key
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Run Once so that
the worm runs the next time Windows is started. The worm also
drops a file named kdll.dll, which is the password stealing
Trojan Troj/PWS-AV.


Enjoy
Old 26 November 2001 | 01:38 PM
  #8  
GavinP's Avatar
GavinP
Scooby Regular
 
Joined: Jun 1999
Posts: 1,430
Likes: 0
Lightbulb

If anyone's interested, I happened across this program yesterday - full-blown anti-virus suite (including e-mail scanner) as freeware:

http://www.grisoft.com/

I've only had a brief look at it so far but seems pretty good.

Thanks

Gavin
Old 26 November 2001 | 03:21 PM
  #9  
JackClark's Avatar
JackClark
Scooby Senior
 
Joined: Dec 2000
Posts: 20,878
Likes: 51
From: Overdosed on LCD
Post

Gavin, good detection rates, bit of a pain to look after, techie tool realy.
Old 26 November 2001 | 04:08 PM
  #10  
ChrisB's Avatar
ChrisB
Moderator
 
Joined: Dec 1998
Posts: 23,573
Likes: 0
From: Staffs
Post

Aye, somebody kindling sent me BadTrans this morning.

VirusScan killed it off for me.

Chris.

{Cheque to the usual place please Mr Clark )
Old 26 November 2001 | 07:17 PM
  #11  
Graham Beal's Avatar
Graham Beal
Thread Starter
Scooby Regular
 
Joined: Nov 2001
Posts: 239
Likes: 0
Talking

I have finally rid my system of that virus. Appologys to all those who got sent it, it wasnt intentional. If anyone is having difficulty removing i then look at

http://www.symantec.com/avcenter/venc/data/w32.badtrans.13312@mm.html

that shows you how to get rid of it.

Graham

Old 26 November 2001 | 07:22 PM
  #12  
JackClark's Avatar
JackClark
Scooby Senior
 
Joined: Dec 2000
Posts: 20,878
Likes: 51
From: Overdosed on LCD
Post

I can help over in Non Scooby Related if anyone's in real trouble.
Old 26 November 2001 | 07:32 PM
  #13  
EvilBevel's Avatar
EvilBevel
Scooby Regular
 
Joined: Oct 1999
Posts: 3,491
Likes: 0
Angry

Hmmmm... just got it in the mail (ta Harj ). Strange this is that upon opening the mail, OE 5.5 immediately asks if you want to run or save the file (without actually clicking on the attachment). First time I see it do that.

Could this be because the message title & body are empty ?

Anyway, it makes this virus a bit more dangerous than others.

Theo
Old 26 November 2001 | 07:59 PM
  #14  
Graham Beal's Avatar
Graham Beal
Thread Starter
Scooby Regular
 
Joined: Nov 2001
Posts: 239
Likes: 0
Thumbs down

when I got it this morning it automatically opened itself before I clicked on the attachment. Damn thing!!
Old 26 November 2001 | 08:48 PM
  #15  
lumby's Avatar
lumby
Scooby Regular
 
Joined: Jan 2001
Posts: 534
Likes: 0
Post

i got it last night i am now getting emials off allsorts of people i have never heard of .

will norton anti virus killl it off??
Old 26 November 2001 | 08:56 PM
  #16  
Spudgun GTR's Avatar
Spudgun GTR
Scooby Regular
 
Joined: Sep 2001
Posts: 547
Likes: 0
Thumbs up

lumby
i recieved 2 today, both from people ive never heard of. norton weeded 'em out straight away
Old 26 November 2001 | 09:06 PM
  #17  
Mr.Cookie's Avatar
Mr.Cookie
Scooby Regular
 
Joined: Apr 2000
Posts: 5,757
Likes: 0
From: www.mrcookie.co.uk
Post

LOL@Theo

I got it from H too and Skippy and Graham and a few more, looks like it spread a bit

Si
Old 26 November 2001 | 09:40 PM
  #18  
Shark's Avatar
Shark
Scooby Regular
 
Joined: Aug 1999
Posts: 3,539
Likes: 0
Angry

Got the basta*d tonight. Will post for help if I can't sort it.

Norton AntiVirus does not pick it up unless you have the very latest live update

David
Old 26 November 2001 | 09:43 PM
  #19  
DavidLewis's Avatar
DavidLewis
Scooby Regular
 
Joined: Apr 1998
Posts: 1,864
Likes: 0
Post

Got notification of mine yesterday. Came from Andy Ewings. Corporate virus checker got it first
Old 26 November 2001 | 09:45 PM
  #20  
Hel's Avatar
Hel
Scooby Regular
 
Joined: Sep 2001
Posts: 322
Likes: 0
Post

I had it too. Had to fork out £40 on Norton 2002, did the job though didnt know i had it till too late.
sorry if i passed it on to anyone.
Hel
Old 26 November 2001 | 11:13 PM
  #21  
Lee's Avatar
Lee
Scooby Regular
 
Joined: Mar 1999
Posts: 1,681
Likes: 0
From: Essex
Exclamation

This is spreading INCREDIBLY FAST !!!

I checked our mailservers to see how many they've stripped the virus from..JEEZ !!

Make sure you update those definitions !! or use a host who scans your email for viruses
Old 27 November 2001 | 12:09 AM
  #22  
adge's Avatar
adge
Scooby Regular
iTrader: (22)
 
Joined: Aug 1999
Posts: 1,937
Likes: 2
Red face

I got it as well, fortunately Norton 2001 got to it first. Just upgraded to Norton after getting the loveletter virus [img]images/smilies/mad.gif[/img]
Old 27 November 2001 | 01:47 AM
  #23  
muddy's Avatar
muddy
Scooby Regular
 
Joined: Dec 2000
Posts: 1,379
Likes: 0
From: E.Midlands/S.Yorkshire
Post

I got 2 today, one off my dad (he probably got it off the EVO list) and one from somebody I'd never heard of.

Haven't got any anti virus stuff, but was suspicous with them both because they didn't have any content so deleted both.

I take it that they will only corrupt your computer if you opened the attachments i.e save to disk.


Muddy
Old 27 November 2001 | 02:10 AM
  #24  
Shaun's Avatar
Shaun
Scooby Regular
 
Joined: Mar 2000
Posts: 8,617
Likes: 23
From: 5 beats 4 - RS3 Rulez!!!
Exclamation

I have also been infected, but have since been to the doctors and been cleared.........

I must point out though......

THE VIRUS WILL AFFECT YOUR PC, EVEN IF YOU DONT VIEW/DETACH THE ATTACHMENT. ALL IT TAKES IS FOR YOU TO VIEW THE EMAIL CONTENT, EITHER IN THE PREVIEWER OR BY DOUBLE CLICKING ON THE EMAIL TITLE!!!!!!!

Make sure your email previewer is switched off!!!!

Regards,
Shaun.

[Edited by Shaun - 11/27/2001 1:11:28 AM]
Old 27 November 2001 | 02:51 AM
  #25  
jon44w's Avatar
jon44w
Scooby Regular
 
Joined: Sep 2001
Posts: 5,359
Likes: 0
Angry

i got the b45tard as well

emails were from darius and had no subject [img]images/smilies/mad.gif[/img]

hotmail picked it up no problem

john.
www.jon44w.com
Old 27 November 2001 | 09:52 AM
  #26  
Octane Man's Avatar
Octane Man
Scooby Regular
 
Joined: Apr 2001
Posts: 366
Likes: 0
Post

I'm glad I'm not the only one, I've received blank emails from a number of Scoobynetters and with an attachment called "Unknown".

I hope we can track the source of this as I've never emailed any of the people I've got Emails from so how can they have my details in their address book ??????
Old 27 November 2001 | 10:08 AM
  #27  
JGRIFF's Avatar
JGRIFF
Scooby Regular
 
Joined: Apr 2000
Posts: 945
Likes: 0
Thumbs down

Yes, I've had it too, it opened automatically yesterday morning. Apologies to all of you that it e-mailed automatically, Moray thanks for the warning!!, I got rid of the thing this morning, unfortunately it's corrupted the operating system which is going to take a little longer to sort out

[Edited by JGRIFF - 11/27/2001 9:09:56 AM]
Old 27 November 2001 | 02:24 PM
  #28  
scooby nutter's Avatar
scooby nutter
Scooby Regular
 
Joined: Dec 2000
Posts: 1,028
Likes: 0
Thumbs down

Ive just recieved three emails with no subject.
one had three attatchments! deleted all three emails.saved one to disk and checked with norton and no virus was detected in the scan!i should have subscribed for their updates!
One came from a guy off the lancer register.
Related Topics
Thread
Thread Starter
Forum
Replies
Last Post
Big RS Dave
ScoobyNet General
5
14 April 2001 09:12 PM




All times are GMT +1. The time now is 07:25 AM.