Web Hosting Forum | Lunarpages
News: October 6, 2008 - Submit Your Site for the October 2008 Site of the Month!
 
*
Welcome, Guest. Please login or register.
Did you miss your activation email?
October 14, 2008, 02:02:14 AM


Login with username, password and session length


Pages: [1]   Go Down
  Print  
Author Topic: MCAFEE LATEST DAT MISSED BADLANDS  (Read 233 times)
TWebMan
Quantum Encyclopedia Writer
*****
Offline Offline

Posts: 3112



WWW
« on: November 28, 2001, 09:54:00 AM »

I get the suspect email.  It tries to autoexecute (run automatically) an attachment (DEFCON 1).  My Outlook Express settings pop-up the warning window and ask me what to do.  I choose not to run it, but to save it (normal procedure).  Upon saving it, Zone Alarm kicked in, and renamed it, on save, to a .zlo file (DEFCON 2).  Okay, right-click, "Scan For Viruses".  Nothing.  Hmmm. File name...a giveaway, "New_Napster_Site.Mp3.pif"-definitely a worm (DEFCON 3).  I open it in notepad (after asking Zone Alarm to allow me to save it normally) and lo and behold, there's the server stuff, registry entries to add, etc.  I go to mcafee.com.  They say I'm protected from Badlands.  I re-scan.  NOTHING.  I double-check.  Yes, I have the latest upgrade and dat. I scan with The Cleaner, it catches it (DEFCON 4 -DEPLOY), and cleaned it (deleted the file). Don't know what went wrong with Mcafee.  Also, this worm is using the new, more passive (less-detectable) infection method, like NIMDA.  I suspect we'll be seeing a lot more of these.
Logged

"Computers cause people to make more mistakes than any other invention in history, with the possible exception of handguns and tequila."  - Unknown
"Liberty of any kind is seldom lost all at once." - D. Hume
Every day is an Ode to Joy
The planet will be fine... and so will your site
Santos
Jabba the Hutt
*****
Offline Offline

Posts: 562


WWW
« Reply #1 on: November 28, 2001, 03:08:00 PM »

*poke poke*

Wake up web man its time to be a man and install Norton  

Just kiddin, but thats pretty sad that such a common virus doews not get detected by latest defenitions. BLEH.
Logged

Smile, it makes people wonder what you're up to...
TWebMan
Quantum Encyclopedia Writer
*****
Offline Offline

Posts: 3112



WWW
« Reply #2 on: November 28, 2001, 03:32:00 PM »

What got me was their home page saying in big letters that the dat file I have included it!
In the "old (read 'chain-smoking in front of a C prompt') days", I used Norton for everything.  I remember 'changing' SimCity to give myself like 60 million dollars with the File Editor.  Anyway, I lost faith in Norton when I saw it do horrible things to peoples' computers that in some cases only a format would cure, and I lost faith in their AV capabilities when I learned that their active email scanner leaves port 110 wide open all the time.  Not that somebody could hit it, but it shows winhack that there's something there...and an open port.

[ November 28, 2001: Message edited by: TWebMan ]

Logged

"Computers cause people to make more mistakes than any other invention in history, with the possible exception of handguns and tequila."  - Unknown
"Liberty of any kind is seldom lost all at once." - D. Hume
Every day is an Ode to Joy
The planet will be fine... and so will your site
Santos
Jabba the Hutt
*****
Offline Offline

Posts: 562


WWW
« Reply #3 on: December 01, 2001, 07:14:00 PM »

quote:

"old (read 'chain-smoking in front of a C prompt') days



You some kind of a Jay Leno, that was HILLARIOUS man  
Logged

Smile, it makes people wonder what you're up to...
Pages: [1]   Go Up
  Print  
 
Jump to:  

Powered by MySQL Powered by PHP Powered by SMF 1.1.6 | SMF © 2006-2008, Simple Machines LLC

Valid XHTML 1.0! Valid CSS! Dilber MC Theme by HarzeM