Web Hosting Forum | Lunarpages
News: October 6, 2008 - Submit Your Site for the October 2008 Site of the Month!
 
*
Welcome, Guest. Please login or register.
Did you miss your activation email?
October 14, 2008, 02:09:01 AM


Login with username, password and session length


Pages: [1]   Go Down
  Print  
Author Topic: Help with virus  (Read 258 times)
Johnny
Support
Über Jedi
*****
Offline Offline

Posts: 1914



« on: May 31, 2002, 02:58:00 PM »

I received a virus in the e-mail about an hour ago. It came to outlook Express, which I have lunarpages account set up at. I'm using IE 5.0 and Windows 98 SE. When I clicked on the Mail subject, I was prompted to download the following file: L01pd2nm1. I clicked cancel. I loaded my virus scanner, and went back to Outlook, and clicked on the message again. This time the virus scanner gave me the following message:
The file: C:/Windows/Temp/R.WAV is infected with the W32/klez.h@MM virus. Please try to clean this file or delete the file and restore from backup.
I chose to delete the file. After I did that, I had the download window pop up, and it prompted me to run file from current location or save to disk. The message in the download window was: You have choosen to download a file from the following location: L01pd2nm1, which I clicked cancel.
I then scanned the system, and no viruses were found, and I have the latest dat files. Also, I peeked at the attachments, but I didn't open them. The following attachments were included with the e-mail:
ATT00003.txt- file size = 0 and aimtoday[1].htm - file size = 21KB.
I'm pretty certain that I wasn't infected. I would , however, like to get other's feedback that is more advanced in this field. Also, I did get the full e-mail header, and it turns out that this was sent from a person that was angry with me because I didn't use his banner on my site. I have e-mailed lunarpages for advice on what, if any, actions I should take against this person. I would also appreciate any advice that the members here offer.
Thanks!
Logged

tom_14_2001
Spacescooter Operator
*****
Offline Offline

Posts: 48


WWW
« Reply #1 on: June 07, 2002, 04:30:00 PM »

I was working when i realised i had new mail so i checked it out using hotmail in my browser. Even when the email is opened in the browser it can still be set lose!
I never knew any thing was wrong as i didnt download anything and the email from box was from a friend. The file seemed pretty big though for what it was. All it said was there was a virus called the kleez worm going around do you wish to download a file to make your system immune or something.

Anyway....  A few days later my sysem coundnt start up very well and was going so slow!! I had to restart it 15 times in one day it kept on freezing. Shocking!!!
I had a heath check dew with my 'Windows 98' second edition (just like yours! Is yours a Packard Bell Too?) I took it along to pc world for the check and they found some virus'

        * The Kleze Worm
          and
        * Sub seven (whats that?? email me)

They cleaned it from my system and told me its the latest one that will slow down your system and you will most likely get it again as most anti-virus programs can't detect it! (Shame, not that i ever use mine it just seems like a waste of time because i would never get a virus'!... would i?)

They gave me my computer back and they had left the disk in the drive that clears all the latest virus'!! (Such as Kleeze!)

So anyway the point of this is if you want send me an email and ill try to send you the patch. (I know you dont know me and can't be sure to trust me or not, but i guess you can try.)

My email is...   tom_14_2001@hotmail.com

Oh and in the same style as the kleeze email i have been send an explorer patch and my explorer has been getting errors!! (Eh Oh!!!!)
Have you heard of one like this?

Thanx for reading!
Logged
saytheb
Space Explorer
***
Offline Offline

Posts: 8


WWW
« Reply #2 on: June 07, 2002, 04:41:00 PM »

SubSeven is a Trojan horse virus that, when it's successfully loaded will allow anyone who can find the server active on your computer complete control. This could explain why you were running slow as they are able to do anything they wish with your comp as though they were actually on it.

 NEVER allow SubSeven or any trojans onto your computer as your giving them complete controll.

(When I say complete, they can do anything like opening programs, editing/deleting/uploading files, launching webbrowsers and surfin, they can even get keylogs to grab all text you type. Worst of all, they can send messages, do anything weird to your computer or even shut it down, ect. I highly suggest using a firewall as it stops trojans dead in their tracks once they ask to run as a server.)

Good firewalls are anything by norton, mcafee, zonealarm, or even blackice.

Hope this helps.

(I use to sniff out computers with Sub7 trojans on their computer and control their comp for a bit to warn them that they had it active. You'd be suprised how many people think a message from no-where is unconvincing. I actually had to surf around the net, open the cd-rom, and shut-down the comp before they believed me ;;. I was stopped though because I was reported to my isp that I was actually using them for harmful intentions, so I guess those I didn't reach are out of luck. DO NOT LET A TROJAN ON YOUR COMP!! Some people are NOT nice, and they will do anything they wish.)
Logged

-saytheb
Johnny
Support
Über Jedi
*****
Offline Offline

Posts: 1914



« Reply #3 on: June 07, 2002, 05:07:00 AM »

No, I ran my virus scan, with the latest dat files, and there are no viruses found. Everything is fine on my computer. If I were using IE 5.5 or 6.0 without the security patch, I would have been in trouble, but I'm using IE 5.0, so I was prompted to download a file, which I canceled.
Logged

the prof
Trekkie
**
Offline Offline

Posts: 18


WWW
« Reply #4 on: June 08, 2002, 08:03:00 AM »

The Klez virus is particularly nasty.

It attaches itself to your address book, and places a file called Wink*.exe in your Windows/System folder.

If you try to delete it manually, it simply rewrites itself as another Wink*.exe file - eg: Winkhky.exe, Winkfpq.exe, etc.

Its main goal is to corrupt all the .exe files in your C:/Program Files folder.

There's a free Klez remover at www.bitdefender.com

You might need to re-install some programs if it has made some progress on your PC.
Logged

The Prof from Cyberschool
Johnny
Support
Über Jedi
*****
Offline Offline

Posts: 1914



« Reply #5 on: June 08, 2002, 08:14:00 AM »

Yeah it is. I try to stay ahead of these things. I also made a dummy contact in my address book. I gave it a name only, no e-mail address, so if I get an error where an e-mail had attempted to go out to that contact, then I know somethings not right....lol. I'm still trying to figure why this virus was laced in a .wav file.
Logged

stephan
Guest
« Reply #6 on: June 09, 2002, 04:19:00 PM »

They could send a .bat file to rename it to .exe
Logged
SithLegend
Jedi
*****
Offline Offline

Posts: 772



WWW
« Reply #7 on: June 09, 2002, 05:57:00 PM »

hackers keep viruses inside zip files
beacose normaly when you view a folder and it has a zip file in it explorer dosent trie to open it

i used to collect ms-dos viruses like ping pong
but one day 1 virus i didint know about erased my pc

still i have a couple of them on 5 1/4 floppy disks

f you get viruses a lot maybe you should start a collection on floppy of course

who knows maybe 1 day you could have the only copy of a rare virus and sell it

thats probably not legal  but its just talk    

i dont support viruses and i think neither does lunarpages
Logged

"I swear on the soul of my father, Domingo Montoya, you will reach the top alive."
pakhos
Newbie
*
Offline Offline

Posts: 5


WWW
« Reply #8 on: June 16, 2002, 08:59:00 PM »

only way ...most of trajon server´s user  change port of the servers and it is a little bit good because  just they know you have a trajon horse.Ok then You need go to autoexec.bat because  some sub seven  servers write theirself under autoexec.bat and when you restart the computer they activate theirself again. Edit your autoexec.bat in a notpad and look if there is a comment like that . Second advise is that : If you can download TDS-3 from diamond company you can see everything on your computer .When someone request to connect your computer it will inform you and even you will see the IP of the client...that is all dont worry if happens again just shut down machine and wait a while ( until Bad boy  goes to sleep    )

[ June 17, 2002: Message edited by: Pakhos ]

Logged
pakhos
Newbie
*
Offline Offline

Posts: 5


WWW
« Reply #9 on: June 16, 2002, 09:03:00 PM »

dont worry about that . Norton antivirus can detect and erase.email me and i will give you secret of the norton
Logged
SithLegend
Jedi
*****
Offline Offline

Posts: 772



WWW
« Reply #10 on: July 01, 2002, 02:54:00 AM »

a firewall is a must this days
3 days afther i installed the norton firewall i had had like 17 attacks from trojans

the firewall blocks them but before i had the firewall the virus got tru and norton antivirus denied acces to write itself

this are he ip's of that had been sending me virus subseven

209.242.135.137
63.126.4.101
Logged

"I swear on the soul of my father, Domingo Montoya, you will reach the top alive."
Johnny
Support
Über Jedi
*****
Offline Offline

Posts: 1914



« Reply #11 on: July 01, 2002, 10:59:00 AM »

An alternative to Nortons, is ZoneAlarm. You have to give permission for any program to access the net. Some programs, like ICQ, act as a server, but with ZA, you can choose not to let it, and it doesn't affect the program.

ZA also notifies you of any computer that attempts to connect to any port on your PC. It tells you what port was used, the IP # of the computer that tried to connect, and the port it tried to connect to.

 It also runs in a stealth mode, meaning that you are invisable to all on the internet.

And best of all; It's free.
Logged

Pages: [1]   Go Up
  Print  
 
Jump to:  

Powered by MySQL Powered by PHP Powered by SMF 1.1.6 | SMF © 2006-2008, Simple Machines LLC

Valid XHTML 1.0! Valid CSS! Dilber MC Theme by HarzeM