Reseller Hosting, Shared Hosting, Dedicated Hosting by Vortech Inc.

Go Back   Reseller Hosting, Shared Hosting, Dedicated Hosting by Vortech Inc. > >> General Public > Chit Chat Public
User Name
Password
Register FAQ Members List Calendar Search Today's Posts Mark Forums Read

Chit Chat Public Talk about any thing you want! This forum is public.

Reply
 
Thread Tools Search this Thread Display Modes
  #1  
Old 07-26-2004, 04:16 PM
dpyers's Avatar
dpyers dpyers is offline
Vortech Inc. Customer
Vortech Inc. Customer
 
New Mydoom variant

Apparently google got wacked by it today. According to Symantec, it was encoded in such a way as to prevent them from catching it.
Good time to do an AV update.
http://quote.bloomberg.com/apps/news...p_world _news
__________________
Reply With Quote
  #2  
Old 07-26-2004, 07:57 PM
generic's Avatar
generic generic is offline
guess who.. :)
Vortech Inc. Customer
 
Location: chicago
mcafee's update is ready.
__________________
goodbye idevaffiliate, you can kiss my @$* with your poor support and broken script, I am now using post affiliate pro 3
Reply With Quote
  #3  
Old 07-26-2004, 08:57 PM
Silverbug's Avatar
Silverbug Silverbug is offline
Custom Built Solutions
Vortech Inc. Customer
 
Location: AK, New Zealand
Send a message via ICQ to Silverbug Send a message via MSN to Silverbug Send a message via Skype to Silverbug
Thanks for the heads up
__________________
Paul Foley
Sniper Systems Ltd

Reply With Quote
  #4  
Old 07-26-2004, 10:17 PM
Vixen's Avatar
Vixen Vixen is offline
Twisted Administrator
Admin
 
Location: Orlando, FL
Send a message via ICQ to Vixen
Now I know why my Norton's was updating today instead of Wednesday.
__________________
~Vixen~





Team Warped MySpace



View Team Warped's Profile


**If you want something done right, get a woman to do it.**


All questions, comments, concerns, complaints, frustrations, irritations, aggravations, insinuations, allegations, accusations, contemplations, consternations, or input should be directed elsewhere.
Reply With Quote
  #5  
Old 07-27-2004, 09:30 AM
dpyers's Avatar
dpyers dpyers is offline
Vortech Inc. Customer
Vortech Inc. Customer
 
Updated my AV definitions just before I made that post. About 5 min later it caught a MyDoom.M in the inbox. Spread fast! Apparently faster that the upstream AV lists could be updated.

Virus propagation takes minutes these days instead of hours or days. Apparently in the very near future substantial propagation by instant messenger facilities may take less than 30 seconds.

While I don't use any IM, and have two forms of virus checking plus vortech's upstream stuff, it's just a matter of time before one slips through and prangs me.

Time to rethink the backup/recovery process for the local machines.
__________________
Reply With Quote
  #6  
Old 07-27-2004, 02:55 PM
Brian Brian is offline
Vortech Inc. Customer
Vortech Inc. Customer
 
Location: Ontario, Canada
I've lost track of which virus does what... is Mydoom the one that is sending all the .pif files right now?

On another virus note, I think that a browser hijacker got past my Adaware at home... can anyone recommend some decent, and current hijacker removal tools / procedures? My browser is occasionally going to res:cgvbs.dll/index.html?#27983 or something like that.... very annoying.
Reply With Quote
  #7  
Old 07-27-2004, 03:44 PM
dpyers's Avatar
dpyers dpyers is offline
Vortech Inc. Customer
Vortech Inc. Customer
 
Apparently, it can send a variety of executeables, including pif's. You might want to check out http://www.computercops.us for good info on various tools and removing specific hijacks.
__________________
Reply With Quote
  #8  
Old 07-27-2004, 07:22 PM
Silverbug's Avatar
Silverbug Silverbug is offline
Custom Built Solutions
Vortech Inc. Customer
 
Location: AK, New Zealand
Send a message via ICQ to Silverbug Send a message via MSN to Silverbug Send a message via Skype to Silverbug
Quote:
anyone recommend some decent, and current hijacker removal tools / procedures?
yes, its a program that ships with dos 6.22 called format.com. usage: format c: /q/u/s/autotest that should stop your browser going to that site...mind you that should stop your browser all together...

But seriously, I usually just go and download the latest version of adaware and let it remove them.
__________________
Paul Foley
Sniper Systems Ltd

Reply With Quote
  #9  
Old 07-28-2004, 04:13 AM
cambodia's Avatar
cambodia cambodia is offline
Vortech Inc. Customer
Vortech Inc. Customer
 
Location: Phnom Penh . Cambodia
Send a message via ICQ to cambodia Send a message via AIM to cambodia Send a message via Yahoo to cambodia Send a message via Skype to cambodia
i just saw it on msn.com this morning too about mydoom is back ( remind me about jimmy is back ) ha ha need to update my antivirus too
__________________
I Love Cambodia
Reply With Quote
  #10  
Old 07-28-2004, 11:10 PM
mresell's Avatar
mresell mresell is offline
ePerson
Vortech Inc. Customer
 
Location: Around the \bin
Brian,
Try safer-networking.net spybot S&D. If it is the coolweb variant you could be in trouble.
Does many things, but I believe it exploits ms java vm. Try clean up and then maybe disable java and activex. Firefox isn't a problem. IE is so not worth the hijacking issues. They need to totally revamp the design. This new variant gets around home page locking. First rename that .dll and make it archive read only while in safe mode. May help.
Reply With Quote
  #11  
Old 07-30-2004, 08:21 AM
Brian Brian is offline
Vortech Inc. Customer
Vortech Inc. Customer
 
Location: Ontario, Canada
Thanks dpyers!

I went to computercops.us and spent an evening reading about these various hijacks and such, and how to remove them.

I had thought I was doing pretty good with Adaware, and Ad-watch, but after following some of their procedures with several different tools, I was able to remove a whole lot of stuff that was missed.

My IE browser is behaving like a fresh install now! And some of the things that affected my IE browser, also were affecting Opera too. But its all fixed now. Fast, no pop-ups, no changing my homepage, etc... Very good tip! Thanks!
Reply With Quote
  #12  
Old 07-30-2004, 10:34 AM
dpyers's Avatar
dpyers dpyers is offline
Vortech Inc. Customer
Vortech Inc. Customer
 
The thing about spyware is that no one tool catches its all. Takes a lot of work. Computer cops has a program that can log certain types of system/browser start-up activity and you can compare it against what's supposed to be happening.

In the past, I've found that Opera,
Mozilla, and Firefox on WinXP all got hit at one time or another.
__________________
Reply With Quote
Reply


Currently Active Users Viewing This Thread: 1 (0 members and 1 guests)
 
Thread Tools Search this Thread
Search this Thread:

Advanced Search
Display Modes

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

vB code is On
Smilies are On
[IMG] code is On
HTML code is Off
Forum Jump

Similar Threads
Thread Thread Starter Forum Replies Last Post
E-mail worm alert: Mydoom/Novarg.A alexc News and Announcements 55 03-03-2004 02:48 PM
Clean up MyDoom infections!!! Vantage Chit Chat Public 0 02-12-2004 03:46 PM
Microsoft / MyDoom Vantage Chit Chat Public 1 02-02-2004 11:47 PM


All times are GMT -5. The time now is 04:20 AM.


Powered by vBulletin Version 3.5.2
Copyright ©2000 - 2008, Jelsoft Enterprises Ltd.
Vortech Inc. ©2005
Page generated in 0.73646 seconds with 21 queries
[Output: 97.35 Kb. compressed to 89.89 Kb. by saving 7.45 Kb. (7.66%)]