 |
|
 |
|
Next: Avast On Demand Scanner
|
| Author |
Message |
External

Since: Feb 21, 2004 Posts: 40
|
(Msg. 1) Posted: Fri Feb 13, 2004 1:32 am
Post subject: anti malware malware Archived from groups: alt>comp>virus (more info?)
|
|
|
Well, somebody suggested earlier in this newsgroup that someone ought to
create a worm that would uninstall mydoom. Well, it's happenning.
First, there was doomjuice. Now I'm reading on Symantec's website about
Doomhunter and w32.hllw.deadhat.b, both of which will install themselves
to an infected computer, then disinfect the MyDoom virus. WTF. Can't
the VX-ers come up with something a little more originial then this.
--
William
If it don't work, hit it.
If it still doesn't work, kick it.
If it works after hitting it and kicking it, then it doesn't matter if
hitting it or kicking it helped, what's important is it worked. >> Stay informed about: anti malware malware |
|
| Back to top |
|
 |  |
External

Since: Feb 18, 2004 Posts: 29
|
(Msg. 2) Posted: Fri Feb 13, 2004 3:03 pm
Post subject: Re: anti malware malware [Login to view extended thread Info.] Archived from groups: per prev. post (more info?)
|
|
|
On Fri, 13 Feb 2004 01:32:06 -0800, Big Will
<spamWspamispamlspamlspamBspam4spamespamvspaaaammespammityrspam.TakeThisOut@nidontlikespametzero.net>
wrote:
>Well, somebody suggested earlier in this newsgroup that someone ought to
>create a worm that would uninstall mydoom. Well, it's happenning.
>First, there was doomjuice. Now I'm reading on Symantec's website about
>Doomhunter and w32.hllw.deadhat.b, both of which will install themselves
>to an infected computer, then disinfect the MyDoom virus. WTF. Can't
>the VX-ers come up with something a little more originial then this.
it surely isnt VX-ers behind these "White Worms" now is it ? >> Stay informed about: anti malware malware |
|
| Back to top |
|
 |  |
External

Since: Jul 04, 2003 Posts: 1566
|
(Msg. 3) Posted: Fri Feb 13, 2004 3:03 pm
Post subject: Re: anti malware malware [Login to view extended thread Info.] Archived from groups: per prev. post (more info?)
|
|
|
sam1967.TakeThisOut@hetnet.nl wrote:
> On Fri, 13 Feb 2004 01:32:06 -0800, Big Will
>>Well, somebody suggested earlier in this newsgroup that someone ought to
>>create a worm that would uninstall mydoom. Well, it's happenning.
>>First, there was doomjuice. Now I'm reading on Symantec's website about
>>Doomhunter and w32.hllw.deadhat.b, both of which will install themselves
>>to an infected computer, then disinfect the MyDoom virus. WTF. Can't
>>the VX-ers come up with something a little more originial then this.
>
>
> it surely isnt VX-ers behind these "White Worms" now is it ?
sure it is... who did you think was behind it?
--
"we're the first ones to starve, we're the first ones to die
the first ones in line for that pie in the sky
and we're always the last when the cream is shared out
for the worker is working when the fat cat's about" >> Stay informed about: anti malware malware |
|
| Back to top |
|
 |  |
External

Since: Feb 18, 2004 Posts: 29
|
(Msg. 4) Posted: Fri Feb 13, 2004 4:33 pm
Post subject: Re: anti malware malware [Login to view extended thread Info.] Archived from groups: per prev. post (more info?)
|
|
|
On Fri, 13 Feb 2004 10:42:17 -0500, kurt wismer <kurtw.TakeThisOut@sympatico.ca>
wrote:
>sam1967@hetnet.nl wrote:
>
>> On Fri, 13 Feb 2004 01:32:06 -0800, Big Will
>
>>>Well, somebody suggested earlier in this newsgroup that someone ought to
>>>create a worm that would uninstall mydoom. Well, it's happenning.
>>>First, there was doomjuice. Now I'm reading on Symantec's website about
>>>Doomhunter and w32.hllw.deadhat.b, both of which will install themselves
>>>to an infected computer, then disinfect the MyDoom virus. WTF. Can't
>>>the VX-ers come up with something a little more originial then this.
>>
>>
>> it surely isnt VX-ers behind these "White Worms" now is it ?
>
>sure it is... who did you think was behind it?
it makes no logical sense for them to download m$ patches to the
infected machines and remove all traces of MyDoom does it ?
who is behind it ? god knows ? >> Stay informed about: anti malware malware |
|
| Back to top |
|
 |  |
External

Since: Jul 04, 2003 Posts: 1566
|
(Msg. 5) Posted: Fri Feb 13, 2004 4:33 pm
Post subject: Re: anti malware malware [Login to view extended thread Info.] Archived from groups: per prev. post (more info?)
|
|
|
sam1967.TakeThisOut@hetnet.nl wrote:
> On Fri, 13 Feb 2004 10:42:17 -0500, kurt wismer <kurtw.TakeThisOut@sympatico.ca>
>>sam1967@hetnet.nl wrote:
>>>On Fri, 13 Feb 2004 01:32:06 -0800, Big Will
>>
>>>>Well, somebody suggested earlier in this newsgroup that someone ought to
>>>>create a worm that would uninstall mydoom. Well, it's happenning.
>>>>First, there was doomjuice. Now I'm reading on Symantec's website about
>>>>Doomhunter and w32.hllw.deadhat.b, both of which will install themselves
>>>>to an infected computer, then disinfect the MyDoom virus. WTF. Can't
>>>>the VX-ers come up with something a little more originial then this.
>>>
>>>
>>>it surely isnt VX-ers behind these "White Worms" now is it ?
>>
>>sure it is... who did you think was behind it?
>
> it makes no logical sense for them to download m$ patches to the
> infected machines and remove all traces of MyDoom does it ?
patches? what patches? mydoom doesn't use any bugs in windows, there
are no patches...
does it make sense for the vx to make a worm or virus that disinfects
mydoom? sure it does... some vx'ers compete with each other, some have
rivalries, and some think they can make 'good' viruses and/or worms...
it's happened in the past, it will most likely happen again in the
future...
also, don't assume people (vx'ers included) always behave in a
'logical' manner...
--
"we're the first ones to starve, we're the first ones to die
the first ones in line for that pie in the sky
and we're always the last when the cream is shared out
for the worker is working when the fat cat's about" >> Stay informed about: anti malware malware |
|
| Back to top |
|
 |  |
External

Since: Jul 04, 2003 Posts: 1566
|
(Msg. 6) Posted: Fri Feb 13, 2004 4:33 pm
Post subject: Re: anti malware malware [Login to view extended thread Info.] Archived from groups: per prev. post (more info?)
|
|
|
sam1967.DeleteThis@hetnet.nl wrote:
> On Fri, 13 Feb 2004 12:21:27 -0500, kurt wismer <kurtw.DeleteThis@sympatico.ca>
>>sam1967@hetnet.nl wrote:
>>>On Fri, 13 Feb 2004 10:42:17 -0500, kurt wismer <kurtw.DeleteThis@sympatico.ca>
>>>>sam1967@hetnet.nl wrote:
[snip]
>>>>>it surely isnt VX-ers behind these "White Worms" now is it ?
>>>>
>>>>sure it is... who did you think was behind it?
>>>
>>>it makes no logical sense for them to download m$ patches to the
>>>infected machines and remove all traces of MyDoom does it ?
>>
>>patches? what patches?
>
>
> i was referring to Nachia-B (Welchia-B) which makes use of the various
> RPC bugs to propagate and once propagated downloads patches to the
> computer (only English, Korean and Chinese - not Japanese) and applies
> them.
ok, but those patches have nothing to do with mydoom (the only thing
mydoom exploits is user gullibility and there's no patch for that)...
nor do they have anything to do with the security holes that welchia.b
itself exploits... i have no idea why the worm applies the patches it
does, but i see no reason to believe that it was the work of anyone
outside of the vx...
--
"we're the first ones to starve, we're the first ones to die
the first ones in line for that pie in the sky
and we're always the last when the cream is shared out
for the worker is working when the fat cat's about" >> Stay informed about: anti malware malware |
|
| Back to top |
|
 |  |
External

Since: Mar 19, 2004 Posts: 31
|
(Msg. 7) Posted: Fri Feb 13, 2004 5:00 pm
Post subject: Re: anti malware malware [Login to view extended thread Info.] Archived from groups: per prev. post (more info?)
|
|
|
>Well, somebody suggested earlier in this newsgroup that someone ought to
>create a worm that would uninstall mydoom.
Was probably me "earlier in this newsgroup", but the idea is not so
new really.
> Well, it's happenning.
>First, there was doomjuice. Now I'm reading on Symantec's website about
>Doomhunter and w32.hllw.deadhat.b, both of which will install themselves
>to an infected computer, then disinfect the MyDoom virus. WTF. Can't
>the VX-ers come up with something a little more originial then this.
Honestly, as long as those specific worms don't spread by e-mail I
care not too much. Of course provided this does not lead to attacking
machines which are not already infected! And, provided one is lucky
enough to be catched by a "white" worm, would that not still be better
than if those machines get to know Doomjuce?
I fully agree though that people should run AV software on their
machines and otherwise take care not to get caught by malware. Still,
there is the fact that there are thousand over thousands machines out
there now with an open backdor - thanks to MyDoom.A.
It's obvious that many poeple will try to abuse all those machines.
Not really too surprizing - wether we like it or not.
Markus >> Stay informed about: anti malware malware |
|
| Back to top |
|
 |  |
External

Since: Feb 18, 2004 Posts: 29
|
(Msg. 8) Posted: Fri Feb 13, 2004 7:59 pm
Post subject: Re: anti malware malware [Login to view extended thread Info.] Archived from groups: per prev. post (more info?)
|
|
|
On Fri, 13 Feb 2004 14:30:47 -0500, kurt wismer <kurtw.RemoveThis@sympatico.ca>
wrote:
>sam1967@hetnet.nl wrote:
>> On Fri, 13 Feb 2004 12:21:27 -0500, kurt wismer <kurtw.RemoveThis@sympatico.ca>
>>>sam1967@hetnet.nl wrote:
>>>>On Fri, 13 Feb 2004 10:42:17 -0500, kurt wismer <kurtw.RemoveThis@sympatico.ca>
>>>>>sam1967@hetnet.nl wrote:
>[snip]
>>>>>>it surely isnt VX-ers behind these "White Worms" now is it ?
>>>>>
>>>>>sure it is... who did you think was behind it?
>>>>
>>>>it makes no logical sense for them to download m$ patches to the
>>>>infected machines and remove all traces of MyDoom does it ?
>>>
>>>patches? what patches?
>>
>>
>> i was referring to Nachia-B (Welchia-B) which makes use of the various
>> RPC bugs to propagate and once propagated downloads patches to the
>> computer (only English, Korean and Chinese - not Japanese) and applies
>> them.
>
>ok, but those patches have nothing to do with mydoom
true . but welchia-b (nachia-b) cleans up mydoom from infected
computers and applies the microsoft patches listed above.
that is pretty strange behaviour for vx-ers. no ?
> (the only thing
>mydoom exploits is user gullibility and there's no patch for that)...
lol. >> Stay informed about: anti malware malware |
|
| Back to top |
|
 |  |
External

Since: Jul 04, 2003 Posts: 1566
|
(Msg. 9) Posted: Fri Feb 13, 2004 7:59 pm
Post subject: Re: anti malware malware [Login to view extended thread Info.] Archived from groups: per prev. post (more info?)
|
|
|
sam1967.TakeThisOut@hetnet.nl wrote:
[snip]
> true . but welchia-b (nachia-b) cleans up mydoom from infected
> computers and applies the microsoft patches listed above.
> that is pretty strange behaviour for vx-ers. no ?
no... like i said, it's been done before and it will probably be done
again... anti-virus viruses have been around for more than 10 years...
its not new or strange, it's just infrequent...
--
"we're the first ones to starve, we're the first ones to die
the first ones in line for that pie in the sky
and we're always the last when the cream is shared out
for the worker is working when the fat cat's about" >> Stay informed about: anti malware malware |
|
| Back to top |
|
 |  |
External

Since: Feb 14, 2004 Posts: 6
|
(Msg. 10) Posted: Sat Feb 14, 2004 8:55 pm
Post subject: Re: anti malware malware [Login to view extended thread Info.] Archived from groups: per prev. post (more info?)
|
|
|
Big Will wrote:
> Well, somebody suggested earlier in this newsgroup that someone ought to
> create a worm that would uninstall mydoom. Well, it's happenning.
> First, there was doomjuice. Now I'm reading on Symantec's website about
> Doomhunter and w32.hllw.deadhat.b, both of which will install themselves
> to an infected computer, then disinfect the MyDoom virus. WTF. Can't
> the VX-ers come up with something a little more originial then this.
>
Well, let's see, who would benefit from the mydoom worms being knocked
out so that they can no longer bombard SCO and Microsoft web sites?
Beats me.
--
Adrian S
"I am not a number, I am a free man!"
"You are 127.0.0.1" >> Stay informed about: anti malware malware |
|
| Back to top |
|
 |  |
| Related Topics: | some sort of malware, I think - Can someone help me figure this out? Occosainally, I get NAV disabled (even though firewall is still up). Here's my hijackthis log. Norton is up2date, and I use up2date defs from spybot s&d and adaware and they can't find NEthing. -- William
Are these viruses? Malware? Junk??? - Have had two friends computers crash this morning. One at boot up comes up with "Web Power Scan" then the "blue screen of death" on Win 2000. The other one has this "Web Power Scan" and something called When USearch. The ...
REQ: Anti-Trogan key - hello. i'm wondering if anyone has an unlock key for the anti-trogan program? TIA?
Best Anti Virus - I know its an oft asked Q But is Kaspersky TRULY the NO 1 I have a 90 day trial of Norton 2003 After that should i puchase kaspersky TRev
anti-virus for NT? - Hi, Anybody knows a descent free anti-virus that will work on NT? I can't find on Grisoft's web site if the free version of AVG will work on NT or not. Thanks. Bear Foot |
|
You can post new topics in this forum You can reply to topics in this forum You cannot edit your posts in this forum You cannot delete your posts in this forum You cannot vote in polls in this forum
|
|
|
|
 |
|
|