View Full Version : **** VIRUS ALERT - TROJ_NIMDA.A - PLEASE READ IMMEDIATELY ****


JohnR
09-19-2001, 07:37 AM
Please be aware that there is a new computer virus out there with potentially bad results. Assuming Norton Anti-virus, if you have definitions dated 9/18/01 then you are protected. If your virus definitions are earlier than this, you are not protected.

From the Symantec site:
Users visiting compromised Web servers will be prompted to download an .eml (Outlook Express) email file, which contains the worm as an attachment.

If you are visiting a Web site and you are prompted to download anything, do not do so unless you have the up to date definitions AND you need to download something. If you just visit a site and it prompts you to download without you requesting it, DO NOT download it!

The servers that operate this site ARE NOT impacted by this work and ARE NOT capable of spreading it so there is no worry from this site....

Thanks,
John

Got Stripers
09-19-2001, 07:56 AM
Who in their right mind would download any file without knowing what it is? I have the best virus protection you could have, I don't open anything, so don't send me any attachments :). My wife get's upset that I haven't opened a single joke, picture, story or whatever she's forwarded to me over the years. She's finally smartened up and doesn't send me anything. If it's business related, I will first call the sender to confirm it was actually sent, before I will touch the attached file.

Patrick82
09-19-2001, 03:03 PM
I'm updating our virus "definitions" as we speak.

I would love to get my hands on the people who do this.

JohnR
09-19-2001, 03:08 PM
What would you do? Write them a letter of disenchantment? A case of the best defense is a good offense. Keep you're virus defs up to date and be wary of what you open or download...

Patrick82
09-19-2001, 03:28 PM
Well here is some bad news.

I just updated my virus definitions and it reboots my machine. It came up that my "load.exe" file is infected. So Nortons gives me a chance to repair the file. Couldn't repair it. So it then recommends that I quarantine it. Did that. Rebooted the machine again and it says it can't find "load.exe". Now what the heck can I do? I'm looking at the symantec website. I guess I need to give them a ring and see what I can do. Unless I can get someone who has the healthy Load.exe file and I can just throw that into the place where it says it's missing.

I really need to keep my mom off this thing. My dad and I won't download anything. She does. She downloads every mail her friends send her. I trust her friends but they aren't computer savy and I doubt they have any protection on their machines. God knows where they downloaded it from.

Patrick82
09-19-2001, 03:48 PM
Well I emailed Symantec. I don't have the money to call them for immediate help. If my dad chooses to do that, that's up to him. This is his toy.

Guys, we just purchased Norton Utilities. I would suggest you do the same. It's a great program and it blows everything else we've used out of the water. Definitely worth the money and I don't think I'll run a computer without it ever again.

Please be careful guys and explain to all the people that use your computer to be very careful.

Oh and John, I believe creating a computer virus is a felony I believe. I wish I could get my hands on them and turn them over to the FBI.

Mr. Sandman
09-19-2001, 04:59 PM
Virus suggestion:

While there are many decent anti-virus programs out there, I feel compelled to tell you about the program I use which has been nothing short of outstanding.

First I have a rather complex home network consisting of 9 machines with a number of OS's consisting of Red hat UNIX, IRIX, Win NT, 98 and Me. These are all tied to a server machine that connects to a cable modem box. As the "sys Admin" for my family, I was spending quailty fishing time repairing damaged (infected) machines. One took me a week to track down. It was a nightmare. Anyway, I had to do something and I came accross this product called WinPoxy, it lets you share a internet connection (much better then Windows does) and it allows for virus scanning and site filtering . The best thing is that all this is done at the server or local host before it gets in to the network...and if ANYONE requests a web page or a downloads a file that has a firus, an email is sent to me and the file is stripped of the virus and the user gets a message that this file has virus. Further, this program updates itself everyday, both for virus and filter engines.

This thing has saved me countless hours. look into it IMO it is one of the best values out their and it really works well even if you have just one machine.

www.winproxy.com

check it out!

you can run this on a single machine and expand your license as your network grows.

Don't assume you can get a virus just from opening something from someone you do not know..my neighbor had been sending out a virus that she did not know she had and infecting others. This software tells you the incomming mail has a virus and strips it out and sends an alert to your log file, email and even a pager.

take a look at their page if your:

a) fed up with this virus crap.
b) wish to share a network connect with other machines
c) want to control the type of matrial you kids view (filters: sex, hate etc)
d) provides full stealth firewall protection (windows is a joke and cable and DSL are wide open to penatrate with ease...I bet a dozen live eels that if you don't have a firewall I could hack into your machine) ( I wouldn't though...I am a good citizen) :)

Once you set this up (and it is ultra straight forward and clear)...you really never worry about it again...

Think your secure....go to the site below to check your sytem for open holes:

https://grc.com/x/ne.dll?bh0bkyd2

tests your fire wall and security. click on test my shields and test my ports. If you don't see full stealth...you have a hole.

Patrick82
09-19-2001, 05:51 PM
Well more problems on the Virus front. Can't open Microsoft outlook. (We don't even use outlook, I don't know why that is our main email program). Also, can't save in Microsoft Word. It seems like my virus pal has done away with my Riched20.dll file. Now I get another error when I click on a sites, "Email us" button saying we don't have enough memory to do these tasks.

I have a feeling I need to reload windows 98.

Remember the days when you could fix anything with a hammer? Hmmmm, I wonder. ;)

I just ran that scan that Sandman put up. I'm happy to report that all of the ports scanned came up as Stealth, saying they don't exist or they came up as closed. As in they know there is a port there but it's not open for business.

That's good I guess.

Patrick82
09-19-2001, 07:07 PM
Just an update. I ran Nortons again, found 41 infected files. Couldn't repair a single one of them. They've all be quarantined. I have no clue what to do with these quarantined files. I'll let my dad deal with it. It's his toy.

redcrbbr
09-19-2001, 07:34 PM
thats a good idea patrick. good luck.

JohnR
09-19-2001, 10:10 PM
Sandman - we'll need to duel networks ;) !!! You got me beat by one machine (well there are a couple of clunker 486 boxes down stairs I suppose) - I haven't done a shields up in a while - thanks for jogging the memory - only port bounced through was telnet (yes I access that from time to time, haven't set up SSH yet)... This prompted me to ask: Who else has almost as much an addiction to comps as fishing (it's really not that close but Ice Fishing is so friekin' cold in the winter I need something else to do)?

OS's running: 98, NT4,2000, NetWare5, RH 7 & 7.1 and I've got a machine to try Solaris on for grins & giggles...

Anyone need a MIS manager/geek in the RI area??

Here are a couple pics of my home net:

http://www.striped-bass.com/images/cpu1.jpg

CPU1
AMD 1.4Ghz 512ram - gaming, 32video, video editiing 98/2000

http://www.striped-bass.com/images/cpu2.jpg
CPU2
AMD 850 256ram - RH7.1 Server

CPU3
DUAL Celeron 533 192 ram NW5

http://www.striped-bass.com/images/cpu5.jpg
CPU4 (black one)
IBM Dual 333 RH 7 (need to reinstall power supply) water damaged but repaired
CPU5
ABIT/PIII500 2000 but going back to 98 for sale to coworker
CPU6
http://www.striped-bass.com/images/cpu4.jpg
Wifey's Dell 400 running NT 4.0 and IIS :rolleyes:
CPU7
500 somewhat parted not running anything until one of those hard drives on the floor goes in - probably will run Solaris for Intel or maybe BSD
CPU8
Dell 350 water damaged but repaired (in closet

Patrick82
09-19-2001, 11:25 PM
Woah. Is that so you can play like, 7 games of solitaire at a time?

The most computers we have had in our house is two. They weren't hooked up to each other. One was my brother's one was my dads. My bro moved out so his computer is with him.

The system I'm on now is pretty old school. We don't upgrade much. It's good for our purposes.

433 mhz PII or PIII, can't remember which.
8 gig-ish harddrive.
Cable Modem
200-something RAM.
16 meg Video Card.
CD burner
an additional CD-ROM
One of the Soundblaster cards, can't remember which.

For peripheals we have,
a Scanner
Printer
two Digital Cameras. (One is a Nikon and one is the Clever Cam that we found really cheap)
A Quickcam live webcam,
an MS joystick with the throttle controls.
Cordless Mouse
These SWEET labtec speakers
and a Zip drive.

If we plug anything else into this, it'll blow up. Would like to get the motherboard upgraded some day. It's up to him though. He runs the show.

Oh and the program we use for Security is Black Ice. Nice simple program. It sits in our systray until someone tries to break in. Then it pops up with the severity of the attack. Yellow, Orange and Red, from least severe to most. Don't get many Code Reds thank God. We can also see their IP address and DNS numbers. Don't know what to do with them really. We just let them try to attack.

Mr. Sandman
09-20-2001, 07:55 AM
That looks like my computer room downstairs. We must have a similar twisted gene. (bass fishing and computers??? weird!)

This time of year I focus on fishing, my wife and kids know this, that from mid Sept to late Nov I fish a lot....after Xmas till spring , I focus on network build out. (with a few ski trips tossed in for fun) .
Plans for this year: wide screen HDTV and a hot machine with HDTV vidieo support. All tied in to the network. My kids have already told me they want the Xbox for Xmas with the game chairs...(game chairs have build in surround sound and shake when you hit something) I hope the market comes back.....

Time to resume fishing thoughts.....

JohnR
09-20-2001, 08:44 AM
Patrick - Not Solitare - In the first pic you can just make out the throttle/weapons control and in the second pic the programable joystick. What is not evident is the rudder pedals under the floor. I have a second set sans rudder pedals for in-house gaming. Otherwise, I just take to the friendly skies and whack punk kids who'd rather play games than get a job...

Although, quite often I run into a true military professional online and the fights over REAL quick with my screen reading "Game Over". Still learing to fight in the vertical and energy management....

I'm a ways off from the HDTV. My next major PC project will occur when I get a boat. I'll have an onboard system to coordinate all of the electronics that make boat fishing easier that surfcasting :rolleyes: ... (But I'll still be surfcasting :D )

Fishpart
09-20-2001, 08:57 AM
You mean I can beg rides to the places I can't park:D How about adding some 3/4" 316SS hull plates before the electrics.

JohnR
09-20-2001, 09:29 AM
No - the boat is not going to be used for surfing/ferrying some people into Fresh Pond Rocks or the end of Naps...

Patrick82
09-20-2001, 02:22 PM
I see the case of Tums. You need them in a case that says, "Break incase of blue screen".

I'm not into the flight sim thing. I've played Search and Rescue 2 where you get to fly a replica of a Dolphin aircraft. Just like the USGC uses. Hard as HECK to fly. I just gave up on that. My game of choice is Soldier of Fortune. I play that online. Not lately though. It's a wicked game though. I'm incredibly good. I can't wait for SOF2 to come out. I also play Delta Force 2 online. Nothing like running out 1000 yards and picking off some guys with a .50 cal sniper rifle. The game is cool but too many people cheat. If you play those games, look for a character named KaBoom. That's my handle.

Speaking of flight sims, one of the news programs had a trained pilot use MS Flight Sim, the one where you control a Boeing 757. They had the guy crash the plane into the WTC. I think that was sickening. Too lifelike to recreate. I don't blame MS for any of this but the news got on their case because they had the GPS numbers for national landmarks. :rolleyes: Like those guys couldn't figure it out without the GPS numbers.

Do you ever worry about having the case off the sides? We usually have it on except for the hottest days of summer or if my dad is working on it. We worry about stuff getting in there and shorting something out.

Well as an update, my dad loaded Win98 again and ran the virus scan again. All things are clean. Thank God. My mom used Microsoft Office at home as part of her job. Of course Nortons came up and said files were trying to copy themselves. I think that was just a false error though do to my dad reloading Win98.

TheSpecialist
09-20-2001, 02:34 PM
Jeesh, got mouse? I think we are a compulsive bunch. I was on Nova logic last night playing with my F-16 Multirole fighter against others. It's been a while so I know what ya mean John, "SPecialist should have pulled up sooner", " Thrasher made Specialist eat metal". I need more practice good thing I am off till monday.

JohnR
09-20-2001, 02:35 PM
I like Norton's products for the most part - especially Anti-virus CE which I run here at work. One of the biggest complaints I get from my users on their home machine is "Norton Utilities said I didn't need that" followed up by "My machine is slower now" also caused by Norton... I DO NOT LIKE Norton Utilities and I've seen it screw up many a machine. If you keep the machine clean (software wise) and patch the system (frequently) - you will often do better with less hassle than running Norton Utilities...

Clean Sweep ARGHHHHH!!!!! :mad: :mad: :mad:

Yes, you can do that on FS. You can also try to land the Concorde at Block Island - doesn't work too well... But FS did get me thinking that the best aircraft fot me to get where I want to fish is a Helicopter :D ;)

Specialist - Got Six?
We'll need to fly h2h sometime...
Janes USAF(weak), F15(awesome), F18(good)
Microporse Falcon 4(awesome)
And the mutha of all cool Mplayer Flightsims EF2000

Jenn
09-20-2001, 07:10 PM
John...do you know what OCD is???? it CAN be treated you know......;)