Virus Warning
Moderator: Wiz Feinberg
-
Mark Ardito
- Posts: 899
- Joined: 9 Aug 1999 12:01 am
- Location: Chicago, IL, USA
Virus Warning
OK it is that time again...another bad one is going around. Just when you thought you were done with the Klez virus...here comes BugBear.
This one is pretty bad and is being spread fast. 13 people at my company this morning!
Tons of details are involved in this virus. I will let you read them here.
What is basically does is again grab your address book and mail everyone in it, but it also opens up backdoors on your machine so http port 80 is open to hackers. It also tries to stop your firewall and antivirus applications. It looks for files such as zonealarm.exe and vshield.exe and attempts to stop them every 30 seconds. This one is bad. Luckily Symantec has already come out with a removal tool. You can down load it here.
One word of advice. If you are a forumite with a broadband connection (DSL or Cable Modem), please use a firewall. I really like ZoneAlarm and you can download a free version of it from ZoneLabs. Also please visit the Microsoft website and update your operating system. Your operating system is just like your antivirus. It needs constant updating. You can either visit http://windowsupdate.microsoft.com/ or if you have Internet Explorer, you can go to the *Tools* menu and then scroll down to *Windows Update*.
Again, I will stress that it is important to update you OS and your Browser. You can get updates for Internet Explorer from the Windows Update website.
If anyone has ANY questions please feel free to post here or if you do not wish to post, you can always email me directly. I have a open email policy. If you need help with any computer support I will try and get you straightened out via email or sometimes I have even called people on the phone. Please lets all practice safe computing. I would hate to see more forumite's lose their computers to a stupid virus.
Mark
------------------
Sho~Bud Pro I, Fender D-8 (C6&E13) http://www.darkmagneto.com
This one is pretty bad and is being spread fast. 13 people at my company this morning!
Tons of details are involved in this virus. I will let you read them here.
What is basically does is again grab your address book and mail everyone in it, but it also opens up backdoors on your machine so http port 80 is open to hackers. It also tries to stop your firewall and antivirus applications. It looks for files such as zonealarm.exe and vshield.exe and attempts to stop them every 30 seconds. This one is bad. Luckily Symantec has already come out with a removal tool. You can down load it here.
One word of advice. If you are a forumite with a broadband connection (DSL or Cable Modem), please use a firewall. I really like ZoneAlarm and you can download a free version of it from ZoneLabs. Also please visit the Microsoft website and update your operating system. Your operating system is just like your antivirus. It needs constant updating. You can either visit http://windowsupdate.microsoft.com/ or if you have Internet Explorer, you can go to the *Tools* menu and then scroll down to *Windows Update*.
Again, I will stress that it is important to update you OS and your Browser. You can get updates for Internet Explorer from the Windows Update website.
If anyone has ANY questions please feel free to post here or if you do not wish to post, you can always email me directly. I have a open email policy. If you need help with any computer support I will try and get you straightened out via email or sometimes I have even called people on the phone. Please lets all practice safe computing. I would hate to see more forumite's lose their computers to a stupid virus.
Mark
------------------
Sho~Bud Pro I, Fender D-8 (C6&E13) http://www.darkmagneto.com
-
Colin Keyworth
- Posts: 95
- Joined: 20 Jun 2002 12:01 am
- Location: Derbyshire, England
I recieved an e-mail last night with an attachment & the subject "welcome to outlook express". It claimed to be from outlook express support team but the e-mail address was msoe@yahoo.com which is strange coming from Microsoft. Luckily hotmail use mcKafee so i could not download the attachment. Just thought i'de make you aware of this -regards- Col
------------------
Sho-Bud LDGsp,levinson Blade,Peavey session 400 Limited,Boss GT-3
------------------
Sho-Bud LDGsp,levinson Blade,Peavey session 400 Limited,Boss GT-3
-
CrowBear Schmitt
- Posts: 11624
- Joined: 8 Apr 2000 12:01 am
- Location: Ariege, - PairO'knees, - France
-
Johan Jansen
- Posts: 3333
- Joined: 4 Aug 1998 11:00 pm
- Location: Europe
There is another virus going round, dangerous/
It can be detected , but hard to remove. It's a networkvirus, that places a file in your registry that triggers a server to put on a new one, as soon as you remove it. It's called opaserv.exe.
It also makes your PC used as a calculating engine, and slows down your pc, because it eats your memory.
You only can remove it by disconnect all wires in the network, it's so clever it can hide anywhere, under other names. scrsvr.exe It took me a week to get rid of it.
http://www.computing.net/security/wwwboard/forum/2548.html
As soon as you managed to, close port 139. (works for now)<FONT SIZE=1 COLOR="#8e236b"><p align=CENTER>[This message was edited by Johan Jansen on 08 October 2002 at 10:19 AM.]</p></FONT>
It can be detected , but hard to remove. It's a networkvirus, that places a file in your registry that triggers a server to put on a new one, as soon as you remove it. It's called opaserv.exe.
It also makes your PC used as a calculating engine, and slows down your pc, because it eats your memory.
You only can remove it by disconnect all wires in the network, it's so clever it can hide anywhere, under other names. scrsvr.exe It took me a week to get rid of it.
http://www.computing.net/security/wwwboard/forum/2548.html
As soon as you managed to, close port 139. (works for now)<FONT SIZE=1 COLOR="#8e236b"><p align=CENTER>[This message was edited by Johan Jansen on 08 October 2002 at 10:19 AM.]</p></FONT>
-
Mark Ardito
- Posts: 899
- Joined: 9 Aug 1999 12:01 am
- Location: Chicago, IL, USA
Johan,
Thanks for posting that information!
Yeah, I can not stress enough about having a firewall setup on either your machine or now I see that a company Linksys makes routers with a firewall built right onto it. Your computer has thousands of ports on it. Mainly you use 3 ports 80(which is http or the www) 110(which is POP3 or receiving email) and 25 (which is SMTP or sending email). Other people may use FTP or TELNET for other situations, but then you ask...what do the other ports do? Not much. Basically they leave your computer wide open for hackers.
I have already received a lot of emails from forumites regarding the ZoneAlarm firewall and other security issues. Would it be helpful if put up on my website a place for instructions on setting up security on your PC and helpful hints on configuring your ZoneAlarm firewall? Let me know if this would help and I will do it. Basically, I want to see a show of hands before I spend the time to set up the help pages.
Let me know!
Thanks,
Mark
------------------
Sho~Bud Pro I, Fender D-8 (C6&E13) http://www.darkmagneto.com
Thanks for posting that information!
Yeah, I can not stress enough about having a firewall setup on either your machine or now I see that a company Linksys makes routers with a firewall built right onto it. Your computer has thousands of ports on it. Mainly you use 3 ports 80(which is http or the www) 110(which is POP3 or receiving email) and 25 (which is SMTP or sending email). Other people may use FTP or TELNET for other situations, but then you ask...what do the other ports do? Not much. Basically they leave your computer wide open for hackers.
I have already received a lot of emails from forumites regarding the ZoneAlarm firewall and other security issues. Would it be helpful if put up on my website a place for instructions on setting up security on your PC and helpful hints on configuring your ZoneAlarm firewall? Let me know if this would help and I will do it. Basically, I want to see a show of hands before I spend the time to set up the help pages.
Let me know!
Thanks,
Mark
------------------
Sho~Bud Pro I, Fender D-8 (C6&E13) http://www.darkmagneto.com
-
Bill Ford
- Posts: 3862
- Joined: 13 Dec 1999 1:01 am
- Location: Graniteville SC Aiken
-
Steve Feldman
- Posts: 3345
- Joined: 5 Dec 1999 1:01 am
- Location: Central MA USA
Sure! I think this would be very useful, but I think the show of hands is a good idea. This is where we need a Forum archive, or FAQ, or something like we have discussed (elsewhere) previously. I'm afraid you'd go to the trouble to put something together and then it would just drift away. Thanks Mark.<SMALL>Would it be helpful if put up on my website a place for instructions on setting up security on your PC and helpful hints on configuring your ZoneAlarm firewall? Let me know if this would help and I will do it.</SMALL>
-
Fred Shannon
- Posts: 3363
- Joined: 27 Sep 2002 12:01 am
- Location: Rocking "S" Ranch, Comancheria, Texas, R.I.P.
-
Lyle Bradford
- Posts: 1047
- Joined: 16 Dec 1998 1:01 am
- Location: Gilbert WV USA (deceased)
-
John P. Phillips
- Posts: 2532
- Joined: 20 Oct 2000 12:01 am
- Location: Folkston, Ga. U.S.A., R.I.P.
-
Ron Page
- Posts: 5725
- Joined: 4 Aug 1998 11:00 pm
- Location: Penn Yan, NY USA
-
Gene Jones
- Posts: 6870
- Joined: 27 Nov 2000 1:01 am
- Location: Oklahoma City, OK USA, (deceased)
