PDA

View Full Version : Thought I would share my SIX days of VIRUS hell with you!


InFinRetirement
21st Apr 2001, 22:45
This is actually a lesson I have seriously be taught - THE HARD WAY.

On Friday of last week I received TWO viruses, didn't know they were until my virus checker caught one but not the other - even though they were both the same > "SNOW WHITE AND THE SEVEN DWARFS - THE REAL STORY!" What happened after that I have no idea but I quarantined another FIVE - yep FIVE! The virus checker got those, but here was the catch. They replicated themselves like aliens! Two begot four and four begets eight and so on. Ther is NO way to remove them. PC-Cillin said there was but it didn't work.

Programmes were crashing all around me. IE Explorer, Outlook Express, Dial-up Networking and other start-up programmes. Because that is where the KAK worms had embedded themselves.

The result? I had to format "C" drive and when finished, do it again. Good advice I received from a friend. Other good advice came from one within PPRuNe and I eventually got all sorted TODAY - seven days later.

I backed up but it never quite works out the way you like to when you put them back, because not all the system files follow the progs, so that's another problem to watch out for.

Another piece of advice was to get rid of PC-Cillin, that had to all intents and purposes, served me well for a year or more but which let me down. I have now downloaded McAfee and it lists in IT's virus list all the ones that infected my machine, while PC-Cillin did not. That is just not good enough. And I will NOT let Norton near my machine since it is my opinion that their stuff creates more problems than it cures.

The moral to this sad tale is to be very aware that these sick people who contrive to make our computing lives miserable do just that. And oft times these monsters invade machines via e-mails - mine did and I now know where they came from. But he didn't know he had them, but did wonder why his computer was constantly crashing. So watch your mails, if it has NO subject it needs care, but we do not always have a subject do we! But if you don't know who sent it DO NOT OPEN IT!!!!

Well after 70 hours of hard work I am about to get p****d, I deserve it and I'm gonna have it.

Be wary folks, it's bad news.

FJJP
22nd Apr 2001, 11:55
InFin,

I have not had a virus, but had hell with compatability problems with McAfee. Until I removed every single bit of the McAfee software, I kept having problems with freezing, crashing, boot-up, shut-down and so on. I now have Norton Antivirus 2000 (downloaded version), which gets updated every 10 days. You don't say if you had PC-illin updated regularly. Some PCs are just bitches with the odd bit of software

InFinRetirement
22nd Apr 2001, 12:35
FJJP. I did get updates automatically from PC-Cillin but it certainly didn't help.

Norton or McAfee! Here we have our own opinions. As I said I wouldn't let Norton near my machine. So far McAfee is fine but I do think that setup is important. Like most progs if you don't set it right it will crash.

However, I am already in back-up mode and will put most things on CD. However, I discovered a pitfall with that too! If you don't get ALL the files, when you restore it still won't work.

I can also opt for a full system backup to my D drive. Can't see anything that can cause a problem there. But with computers how can you tell?

18Wheeler
22nd Apr 2001, 16:13
The easiest way is to NOT use that screaming P.O.S. email program made by Microsoft.
Get a decent one, such as Eudora.
I've been running Eudora since 1995 and have *never* been hit by a virus.

pied piper
22nd Apr 2001, 23:29
>>"I've been running Eudora since 1995 and have *never* been hit by a virus."<<

Is your e-mail programme a virus guard application as well?

you know it realy hurts when you think you are so clean and green, and then wham! a virus yuch! it happened to me a while ago

what is your e-mail address again?.... ;-)

18Wheeler
23rd Apr 2001, 03:01
Nope, I don't have the virus checker running in Eudora, I just use a seperate checker (Kaperski's Anti Virus Tookit Pro - excellent!) to check everything that comes in, including downloads from the Net.

Feline
26th Apr 2001, 00:50
IFR - Yeah! Velvet and I went through the same hell some time last year with The Love Bug. But can't agree with you on Norton - I get the Snow White bug at least once a week, and Norton nails it stone dead as soon it hits my mail queue. I am still using an oldish version of Norton Anti-Virus which is excellent and I still get free definition updates on a regular basis. But I would agree that the Norton Utilities Monitor programme is certainly a piece of software that needs to be switched OFF.
While I realise that you're not the greatest Norton fan, and in no way wishing to antagonise you, you might just want to look at (ahem!) Norton Ghost which will store a disk image of your hard drive elsewhere, and makes re-installation of a complete working system very easy indeed. Haven't used it in anger yet, but did a practise run to see whether it could restore my Libretto - and no problem!

18wheeler - Yupp! Eudora is a great piece of s/w - and I use use Eudora EIS very successfully on my Palm IIIc to access my e-mail via a cell phone when I'm in the back of beyond.

------------------
Feline
(I Sit, I Watch, I Smile)

ExSimGuy
26th Apr 2001, 11:06
I've had the "Snow White" in my inbox twice this week, once in English and one that was (I think) the Spanish translation. That means it came to my office desktop, my laptop, and my home machine.

But I didn't run the executable - so no infection, even though the machine at home isn't currently running any scanner (I use McAfee online on the other 2 machines)

Okay - so I'm a sm2rt@rse - I know better than to run executables unless I'm certain of them.

I recently had an email from a good friend in South Africa, with an executable, and a message that looked quite appropriate for the guy who (apparently) sent it. Before running it I emailed him to check that he sent it to me - he didn't and is now sending a circular to everyone on his mailing list warning them not to run the file that he might have sent them too!

Don't open or run attachments unless you are 101% sure of them!

InFinRetirement
26th Apr 2001, 12:05
FELINE.

I accept your comments. Probably a case of what's good for one.....etc.,

However, I have heard about the GHOST programme - didn't realise it was Norton, but ANYTHING to stop me formatting my data! Can you e-mail me some details please?

ESG.

I also had Snow White a further three times this week and McAfee nailed them. But, as you say, don't open them - I just deleted them. But then I knew about them didn't I??

Coming to the BASH June 9th????

IFR

woftam
26th Apr 2001, 16:25
ESG,
Couldn't agree more.
NEVER open an executable file unless you are 100% sure of it's origin and contents!
That will go a long way towards avoiding viruses.
I adopted the "no executable" policy a few years back after copping a virus from one.
:)

mik
26th Apr 2001, 18:34
And don't forget that Micro$haft define executables as including M$word documents, $pread$heet$, plus lots of other file types I've never heard of (and I've only been using computers for 23 years...)

:mad:

[This message has been edited by mik (edited 26 April 2001).]

Canuck_AV8R
26th Apr 2001, 18:44
IFR:

I too use PC-Cillin and have been very happy with it. I just checked the PC-Cillin site at http://www.antivirus.com and found at least 4 references to the Snow White worm, it is just not listed as that in the encyclopedia under that name, here are a few of the aliases it can go by "Snow White, I-Worm.Hybris, W32/Hybris@M, Win32.Hybris.Gen, TROJ_HYBRIS.A, TROJ_HYBRIS.D, TROJ_HYBRIS.B, TROJ_HYBRIS.C, TROJ_HYBRIS.E, TROJ_HYBRIS.GEN, TROJ_HYBRIS.DLL, TROJ_HYBRIS.PX
I am using PC-Cillin 2000 with pattern file 882 is that the same as what you were using??

I also tried both McAfee and Norton and found both to be system hogs so I trashed them. I have been very happy with PC-Cillin and have used it since ver. 2 about 5 years ago and have never had it miss a virus yet (fingers crossed)

Cheers and good luck staying virus free.

http://indigo.ie/~owenc/starwars/images/pint1.gif

Sensible
27th Apr 2001, 05:12
I was recently sent a cocktail of Win95/MTX viruses either contained in a photo or attached to a photo by somebody who I knew and trusted but who had themselves received the virus without knowing. I have no way of checking how it was actually sent since I deleted every attachment once I realised how the virus was transmitted. Even after running an anti virus programme 'Command.com' (thanks again PPRuNe Dispatcher) it has taken me quite some time to restore the workings of my computer after replacing many files which the MTX worm had infected and caused the anti virus to delete. |I had previously thought that viruses were something only for paranoid people to worry about. Not so now!

I have to comment that the Command.com anti-virus software seems to run invisibly on my computer so I shall continue to subscribe to it.

Squiddley
27th Apr 2001, 07:26
Although it's not a big favourite, I'm very pleased with Norton Antivirus's efforts. It has the option to scan email after it's downloaded, but before it's displayed in the Eudora in box. It's simultaneous, and has caught a few things.

Learned the hard way too, after being scuppered by the CIH bug that went round about 18 months or so more ago.

Stay healthy!

Flyswift
27th Apr 2001, 22:33
Another TOP virus checker is SOPHOS. Rated one of the worlds best. Check out their web site.

IFR this is for you, for all those hours you spent recovering the beast.........

http://www.stopstart.fsnet.co.uk/mica/MiscPC.gif

InFinRetirement
27th Apr 2001, 23:26
Flyswift - LOL's. Well at least now it is!

I never want to go through that again. Unfortunately it IS the second time, so I am gonna have to tighten up my actions more than just the little bit.

Anon-x
30th Apr 2001, 20:30
Even though I have been caught out, I don’t have a virus checker on my computer as I find everything slows down too much. Something I have recently started to do if I am uncertain of an attachment is to send it to my Yahoo email address and let Yahoo check it out for me.

Does anyone have any thoughts on this? Is the Hotmail virus checker any better or are there some other sites that you can scan your email + attachments through before opening?

KwikPhix
4th May 2001, 22:38
Hi Ho Hi Ho, It'll never happen to me! or so I thought until 2 hours ago. I think that it is uncanny that I visit this forum fairly infrequently but I had a good read last night, I'm glad that I did. I check my mail today and Norton A-V 2000 have put a great big 'RED ALERT you have a virus' banner on my desktop, Large panic then, hold on a mo I've read about that somewhere? anyway, I don't have enough experience to know which are the best Virus scanners but what i do know is that McAfee seemed very 'heath robinson' well the user interface was just too...Busy, also my system crashed all the time when I had it installed but very rarely after I removed it, who know's.I'm finding Norton 2000 user freindly, easy updates(while You sleep) and it works. Well anyway thanks for the info hopefully I won't see too much of W95.Hybris.worm again. Anyway it's off to work I go.

[This message has been edited by KwikPhix (edited 04 May 2001).]