Emergency Help Needed!
Viruses got you down? Spyware making your system sluggish? Post here for support on all your security needs.

Moderators: Management, Forum Experts

Postby purplehawk on Sat Jan 11, 2003 9:27 pm

Good Lord! John, I was going to PM you and ask how things went with the virus... I think I'll pass after reading this thread. I'm in trouble here, too, but with a different Windows twist. I'll post separately for help.
purplehawk
 

Postby purplehawk on Sat Jan 11, 2003 10:04 pm

I'm running Trend Micro now. It found and cleaned something called "malware.WORM_SAMBUD.A." Norton has no record of this worm, which apparently comes through the net.
purplehawk
 

Postby SCgone on Sat Jan 11, 2003 10:24 pm

Sheri, my eTrust InoculateIT has popped up a warning on that one a couple of times lately on certain web pages. It must be making the rounds now. The VET engine that eTrust uses will catch worms like that. When I used Norton, I don't remember it doing too well on those.

purplehawk wrote:I'm running Trend Micro now. It found and cleaned something called "malware.WORM_SAMBUD.A." Norton has no record of this worm, which apparently comes through the net.
SCgone
PRO ELITE
PRO ELITE
 
Posts: 12847
Joined: Thu Mar 14, 2002 7:59 pm
Location: South Carolina, USA

Postby purplehawk on Sat Jan 11, 2003 10:44 pm

Apparently, Bob... I searched Symantec's site thoroughly and there is no reference to it anywhere in their database. Disheartening, actually.
purplehawk
 

Postby SCgone on Sat Jan 11, 2003 10:57 pm

Worm/P2P.Sambud.A uses the file exchange P2P network Kazaa to trick users into downloading itself.

If executed, the worm copies itself in the \windows\system32\ directory under the filename "Turbo_forKazaa.exe".

It then creates a couple registry key entries so that it enables the Kazaa shared files and where to direct the shared folders, including:

HKEY_CURRENT_USER\Software\Kazaa\LocalContent
"dir99"="012345:C:\\WINDOWS\\sys32"
SCgone
PRO ELITE
PRO ELITE
 
Posts: 12847
Joined: Thu Mar 14, 2002 7:59 pm
Location: South Carolina, USA

Postby kanaloa on Sat Jan 11, 2003 11:39 pm

Update:

I'm back up and running with a fresh install of XP. GRRR at the virus. I'm installing a new AV program now, and will make sure that d*mn thing is gone.
"With realization of one's own potential and self-confidence in one's ability, one can build a better world." -Dalai Lama
Image

Follow me on Twitter: http://twitter.com/JCDerrick
User avatar
kanaloa
President
 
Posts: 24896
Joined: Sat Mar 09, 2002 9:18 pm
Location: Columbia, SC
Real Name: John Derrick

Postby Yappinator on Sat Jan 11, 2003 11:41 pm

oh uh

Who is in trouble?

I'm here if ya need me


Yaps
To err is human, to really foul things up requires a computer.
Failure is not an option. It comes bundled with the software
Quoting one is plagiarism; Quoting many is research
Frogs have it easy; they can eat what bugs them..

Image
User avatar
Yappinator
Banned
 
Posts: 849
Joined: Thu Jul 04, 2002 11:12 pm
Location: On. Canada

Postby kanaloa on Sun Jan 12, 2003 12:19 am

I think we're all good now. Cept Purp... but I doubt there is anything you can do for that.

I got bombed earlier with a bad virus. Killed my XP.
"With realization of one's own potential and self-confidence in one's ability, one can build a better world." -Dalai Lama
Image

Follow me on Twitter: http://twitter.com/JCDerrick
User avatar
kanaloa
President
 
Posts: 24896
Joined: Sat Mar 09, 2002 9:18 pm
Location: Columbia, SC
Real Name: John Derrick

Postby Yappinator on Sun Jan 12, 2003 12:22 am

Awwww

U had to reformat John? that sux

I hope Bessie Gets better

Yaps
To err is human, to really foul things up requires a computer.
Failure is not an option. It comes bundled with the software
Quoting one is plagiarism; Quoting many is research
Frogs have it easy; they can eat what bugs them..

Image
User avatar
Yappinator
Banned
 
Posts: 849
Joined: Thu Jul 04, 2002 11:12 pm
Location: On. Canada

Postby Pot8oHead on Tue Jan 14, 2003 1:23 am

A friend of mine got hit with a virus a couple of weeks ago and that key in the registry that deals with how to handle .exe files was modified the way RIP! mentioned... for that particular virus, the instructions from Symantec included this:

Start the computer in Safe mode, then

Click Start>Run type cmd

If you aren't already in your Windows folder (the folder name before your flashing cursor... eg. C:\Windows) you'll need to go there. To do that, type "cd \" (without the quotes)hit enter, then type "cd windows" (again, no quotes) and hit enter again.

Type "ren regedit.exe regedit.com" ( -quotes) and hit enter. Now type "regedit" and the registry editor *should* open and you can do whatever editing you need to do.

This should work for any virus/trojan that modifies how Windows handles .exe files, but if it also modified how .com files are handled, this won't help.

Hopefully this information will be useless and no one here will get another virus. :blink

Steve
Image
User avatar
Pot8oHead
PRO Level 7
PRO Level 7
 
Posts: 271
Joined: Thu Mar 14, 2002 6:28 pm
Location: Lethbridge, Alberta

PreviousNext

Return to Security & Virus

Who is online

Users browsing this forum: No registered users and 1 guest