 |
|
 |
|
Next: Demo - Venak and Avenak Detection Malware Scanner..
|
| Author |
Message |
External

Since: Dec 16, 2007 Posts: 3
|
(Msg. 1) Posted: Sun Dec 16, 2007 2:45 pm
Post subject: Virus active but not found by A/V or malware removal apps Archived from groups: alt>comp>virus (more info?)
|
|
|
Received in news group, an apparently joke post with link to humorous web
site. Offered download of a *.jpg (expedit.jpg.zip). Concealed file name
included .vbs. Purports or pretends to alter system files; calls for repair
with Win XP Home disk. A/V and other programs find no virus. Anyone who
knows how to get rid if it, please advise.
--
R Tin
Address anti-spammed >> Stay informed about: Virus active but not found by A/V or malware removal apps |
|
| Back to top |
|
 |  |
External

Since: Jun 01, 2006 Posts: 165
|
(Msg. 2) Posted: Sun Dec 16, 2007 11:27 pm
Post subject: Re: Virus active but not found by A/V or malware removal apps [Login to view extended thread Info.] Archived from groups: per prev. post (more info?)
|
|
|
|
|
| Back to top |
|
 |  |
External

Since: Dec 20, 2007 Posts: 22
|
(Msg. 3) Posted: Sun Dec 16, 2007 11:27 pm
Post subject: Re: Virus active but not found by A/V or malware removal apps [Login to view extended thread Info.] Archived from groups: alt>comp>virus, others (more info?)
|
|
|
Dustbin Cook wrote:
> "R Tin" <rfox24x.RemoveThis@xcox.net> wrote in
> news:W7g9j.10391$pq.10334@newsfe24.lga:
>
> > Received in news group, an apparently joke post with link to humorous
> > web site. Offered download of a *.jpg (expedit.jpg.zip). Concealed
> > file name included .vbs. Purports or pretends to alter system files;
> > calls for repair with Win XP Home disk. A/V and other programs find no
> > virus. Anyone who knows how to get rid if it, please advise.
> >
>
> If you'd care to send a sample of the file you downloaded/received along to
> my email address (instructions provided on site) I may be able to assist in
> it's removal.
>
*HAHAHA* Yes keep up the act Dustbin,
you've got Liarthos convinced you are
"One of the good guys""...
Is Stormtrooper cooked and baked yet?
*wink*
4Q >> Stay informed about: Virus active but not found by A/V or malware removal apps |
|
| Back to top |
|
 |  |
External

Since: Jun 01, 2006 Posts: 165
|
(Msg. 4) Posted: Mon Dec 17, 2007 1:19 am
Post subject: Re: Virus active but not found by A/V or malware removal apps [Login to view extended thread Info.] Archived from groups: alt>comp>virus (more info?)
|
|
|
|
|
| Back to top |
|
 |  |
External

Since: Jun 01, 2006 Posts: 165
|
(Msg. 5) Posted: Mon Dec 17, 2007 1:28 am
Post subject: Re: Virus active but not found by A/V or malware removal apps [Login to view extended thread Info.] Archived from groups: per prev. post (more info?)
|
|
|
"Beauregard T. Shagnasty" <a.nony.mous.RemoveThis@example.invalid> wrote in
news:7Zj9j.271671$kj1.54281@bgtnsc04-news.ops.worldnet.att.net:
> Dustin Cook wrote:
>
>> "R Tin" wrote:
>>> Received in news group, an apparently joke post with link to humorous
>>> web site. Offered download of a *.jpg (expedit.jpg.zip). Concealed
>>> file name included .vbs. Purports or pretends to alter system files;
>>> calls for repair with Win XP Home disk. A/V and other programs find
>>> no virus. Anyone who knows how to get rid if it, please advise.
>>
>> If you'd care to send a sample of the file you downloaded/received
>> along to my email address (instructions provided on site) I may be
>> able to assist in it's removal.
>
> hxxp:// www. webklik. nl/users/ dutchsecurety/
> osamebinladenphoto.jpg.zip
>
> Fix the obvious munging. ("dutchsecurety" is really misspelled in the
> link)
>
> Caution: OE/IE users - do *NOT* go to this link.
Thanks man.
I've taken a quick look at it. it's a worm, written in vbs. No encryption
that I could find, but it does contain a denial of service attack towards
a particular website; and it has a creation date. It's new evidently.
Seems to overwrite? pre existing vbs/vbe files with it's own code. Makes
registry entries to try and ensure it'll startup with windows, and it's a
mass mailer....
BugHunter now offers detection and optional removal.
--
Dustin Cook, Author of BugHunter - MalWare Removal Tool - v2.2d
Email.: bughunter.dustin.RemoveThis@gmail.com
Web...: http://bughunter.it-mate.co.uk
Pad...: http://bughunter.it-mate.co.uk/pad.xml
PGP...: http://bughunter.it-mate.co.uk/bughunter.dustin.txt >> Stay informed about: Virus active but not found by A/V or malware removal apps |
|
| Back to top |
|
 |  |
External

Since: Jun 01, 2006 Posts: 165
|
(Msg. 6) Posted: Mon Dec 17, 2007 1:30 am
Post subject: Re: Virus active but not found by A/V or malware removal apps [Login to view extended thread Info.] Archived from groups: per prev. post (more info?)
|
|
|
"R Tin" <rfox24x RemoveThis @xcox.net> wrote in
news:W7g9j.10391$pq.10334@newsfe24.lga:
> Received in news group, an apparently joke post with link to humorous
> web site. Offered download of a *.jpg (expedit.jpg.zip). Concealed
> file name included .vbs. Purports or pretends to alter system files;
> calls for repair with Win XP Home disk. A/V and other programs find no
> virus. Anyone who knows how to get rid if it, please advise.
>
BugHunter is now able to deal with one known variant? of this worm. Please
scan your system using the utility and report back your results. You can
find the utility and the entire documentation online for it at the url
listed in my signature below.
--
Dustin Cook, Author of BugHunter - MalWare Removal Tool - v2.2d
Email.: bughunter.dustin RemoveThis @gmail.com
Web...: http://bughunter.it-mate.co.uk
Pad...: http://bughunter.it-mate.co.uk/pad.xml
PGP...: http://bughunter.it-mate.co.uk/bughunter.dustin.txt >> Stay informed about: Virus active but not found by A/V or malware removal apps |
|
| Back to top |
|
 |  |
External

Since: Aug 01, 2004 Posts: 496
|
(Msg. 7) Posted: Mon Dec 17, 2007 6:06 pm
Post subject: Re: Virus active but not found by A/V or malware removal apps [Login to view extended thread Info.] Archived from groups: per prev. post (more info?)
|
|
|
R Tin wrote:
> As an OE user, Thanks again Beauregard. Apparently Bughunter is
> disfavored here.
You're welcome.
Bughunter is only disfavored by a few who don't like author Dustin and
his former occupation. I don't think you will have any problem using it.
So ... now what are your thoughts on upgrading your email/newsreader
application to something not vulnerable?
--
-bts
-Friends don't let friends drive Vista >> Stay informed about: Virus active but not found by A/V or malware removal apps |
|
| Back to top |
|
 |  |
External

Since: Dec 16, 2007 Posts: 3
|
(Msg. 8) Posted: Tue Dec 18, 2007 11:06 am
Post subject: Re: Virus active but not found by A/V or malware removal apps [Login to view extended thread Info.] Archived from groups: per prev. post (more info?)
|
|
|
"Beauregard T. Shagnasty" <a.nony.mous.TakeThisOut@example.invalid> wrote in message
news:%Uy9j.54978$MJ6.47929@bgtnsc05-news.ops.worldnet.att.net...
|R Tin wrote:
|
| > As an OE user, Thanks again Beauregard. Apparently Bughunter is
| > disfavored here.
|
| You're welcome.
|
| Bughunter is only disfavored by a few who don't like author Dustin and
| his former occupation. I don't think you will have any problem using it.
|
| So ... now what are your thoughts on upgrading your email/newsreader
| application to something not vulnerable?
|
| --
| -bts
| -Friends don't let friends drive Vista
Hello, Beauregard. I haven't been thinking about a replacement for OE, but
if you have a recommendation, I'd like to look at it and maybe even bestir
myself into making a decision.
I'm used to OE and lazy about such onerous chores as reading the f-ing
manual for new apps.
--
R Tin
Address anti-spammed >> Stay informed about: Virus active but not found by A/V or malware removal apps |
|
| Back to top |
|
 |  |
External

Since: Dec 16, 2007 Posts: 3
|
(Msg. 9) Posted: Thu Dec 20, 2007 2:05 pm
Post subject: Re: Virus active but not found by A/V or malware removal apps [Login to view extended thread Info.] Archived from groups: per prev. post (more info?)
|
|
|
Thanks, Dustin. I unchecked ddosattacker in msconfig, and no more file
security messages. Removed that file and expedit.jpg.vbs, and ran system
file checker, which completed in half an hour but gave no report or any info
about files more recent than those installed. Guess that's standard, but
don't know. First running of sfc /scannow.
--
R Tin
Address anti-spammed
"Dustin Cook" <bughunter.dustin.RemoveThis@gmail.com> wrote in message
news:Xns9A08D041DD9D2HHI2948AJD832@69.28.186.121...
| "R Tin" <rfox24x.RemoveThis@xcox.net> wrote in
| news:W7g9j.10391$pq.10334@newsfe24.lga:
|
| > Received in news group, an apparently joke post with link to humorous
| > web site. Offered download of a *.jpg (expedit.jpg.zip). Concealed
| > file name included .vbs. Purports or pretends to alter system files;
| > calls for repair with Win XP Home disk. A/V and other programs find no
| > virus. Anyone who knows how to get rid if it, please advise.
| >
|
| The file I have doesn't appear to cause much mischief, it's a vbs worm
| however. And it does have a denial of service payload. I will add it to
| BugHunter.
|
| --
| Dustin Cook, Author of BugHunter - MalWare Removal Tool - v2.2d
| Email.: bughunter.dustin.RemoveThis@gmail.com
| Web...: http://bughunter.it-mate.co.uk
| Pad...: http://bughunter.it-mate.co.uk/pad.xml
| PGP...: http://bughunter.it-mate.co.uk/bughunter.dustin.txt >> Stay informed about: Virus active but not found by A/V or malware removal apps |
|
| Back to top |
|
 |  |
External

Since: Dec 29, 2007 Posts: 3
|
(Msg. 10) Posted: Sat Dec 29, 2007 6:36 pm
Post subject: Re: Virus active but not found by A/V or malware removal apps [Login to view extended thread Info.] Archived from groups: per prev. post (more info?)
|
|
|
Hi Dustin,
I've got a file that I think is malware that I'd like you to look at if you
would. It's causing my pc to ask for a password when I wake it from
'sleeping' and won't let me run the antivirus or any malware scanners. I
tried to send you an email to the buhunter.dustin address but it came back.
Do you think you could have a look at it and perhaps tell me how I can sort
it out?
Thanks,
Alexandra
"Dustin Cook" <bughunter.dustin.DeleteThis@gmail.com> wrote in message
news:Xns9A08BD5D3FA05HHI2948AJD832@69.28.186.121...
> "R Tin" <rfox24x.DeleteThis@xcox.net> wrote in
> news:W7g9j.10391$pq.10334@newsfe24.lga:
>
>> Received in news group, an apparently joke post with link to humorous
>> web site. Offered download of a *.jpg (expedit.jpg.zip). Concealed
>> file name included .vbs. Purports or pretends to alter system files;
>> calls for repair with Win XP Home disk. A/V and other programs find no
>> virus. Anyone who knows how to get rid if it, please advise.
>>
>
> If you'd care to send a sample of the file you downloaded/received along
> to
> my email address (instructions provided on site) I may be able to assist
> in
> it's removal.
>
>
> --
> Dustin Cook, Author of BugHunter - MalWare Removal Tool - v2.2d
> Email.: bughunter.dustin.DeleteThis@gmail.com
> Web...: http://bughunter.it-mate.co.uk
> Pad...: http://bughunter.it-mate.co.uk/pad.xml
> PGP...: http://bughunter.it-mate.co.uk/bughunter.dustin.txt >> Stay informed about: Virus active but not found by A/V or malware removal apps |
|
| Back to top |
|
 |  |
External

Since: Jun 01, 2006 Posts: 165
|
(Msg. 11) Posted: Sat Dec 29, 2007 10:50 pm
Post subject: Re: Virus active but not found by A/V or malware removal apps [Login to view extended thread Info.] Archived from groups: per prev. post (more info?)
|
|
|
|
|
| Back to top |
|
 |  |
| Related Topics: | Complete Removal of Active X - I know that Active X is a path for viruses to get into a computer. I am using Win98se and IE 5.x. I disabled Active X in IE and now I get a message popping up all the time saying I am encountering and unsafe Active X bla bla bla.... So now I got to kee...
Is it a virus problem? Apps are killed automatically - Hi, When I browse the web for some time (10 min or so, IE6, XP), all the apps are killed automatically except the Windows Explorer. If you don't run the IE, there is no such a problem. What's the problem and how to fix it? Thanks, Sean
worm/virus closing anti-virus apps ??? - Hi! I am having strange effects on a WINDOWS XP Home machine, Norton Anitivurs gets terminated soon after startup, also AntiVir Personal Edition. when I start the registry editor, it also closes after a few seconds. some keys on the keybaord produce..
Virus scanning apps that can be started from the DOS prompt? - This question is related to my other post re: virsu scanning apps. Is there a free virus scanning apps that I can be run from a DOS prompt? Thanks for any advice.
new worm/virus active - Seems like a new worm/virus is active. I am getting udp packets on ports 1026 and 1027. from different source computers and source ports. Since a couple of days. Anybody know what new worm this is ? ( I have also seen the new BlackIce worm active fro... |
|
You can post new topics in this forum You can reply to topics in this forum You cannot edit your posts in this forum You cannot delete your posts in this forum You cannot vote in polls in this forum
|
|
|
|
 |
|
|