PowWeb Forums - The Perfect Community for the Perfect Host  

Register now to interact with over 11,000 members! Registered users have Posting Privileges, free access to Private Messaging, Email Notifications and more.

Go Back   PowWeb Community Forums > Other Forums > Computer Help
User Name
Password
Register FAQ Members List Search Today's Posts Mark Forums Read

Closed Thread
 
Thread Tools Search this Thread
Old 10-1-02, 09:38 PM   #1
MarkHutch
 
Join Date: Feb 2002
Location: Waco, Tx Usa
Posts: 581
Reputation: 5
New Virus - Nasty Like Klez

Here's a new virus that's just been upgraded via Norton. We got a few copies of this one today. Scanner stopped them, but it might be a good time to upgrade your definations.

New Virus
MarkHutch is offline  
Old 10-2-02, 09:14 AM   #2
teamantivir
Living at command prompt
 
teamantivir's Avatar
 
Join Date: Feb 2002
Posts: 157
Reputation: 5
Mark,

There are two really nasty ones going around W32/Bugbear, and w32/OPASOFT.A. In both cases, all the major, and most minor vendors have detection out as of yesterday. Key is to keep your Anti-Virus software up-to-date and follow some simple safe hex proceedures, and you will be safe.
__________________
Kenneth L, Bechtel, II
Team Anti-Virus
PGP Footprint: 969E 2A27 3042 EE52 AEFB 6FF0 2711 9467 D38C 5C0F
teamantivir is offline  
Old 10-2-02, 09:54 AM   #3
paulselhi
Cockney Red
 
paulselhi's Avatar
 
Join Date: Feb 2002
Location: London UK
Posts: 2,875
Reputation: 15
stealth

if a virus gets in before you have updated your def's can it do it's nasties then clean itself out and leave nasties behind, so that when you update and scan it is not seen?

if so how would you go about detecting this, would you see the damage from a scan shoeing a file has changed?

and what if the nasty leaves a bat file or exe file that are not viruses as such but do naughty things, these won't usually show up as a virus will they ?
__________________
Paul Selhi
Colorize Your Black and White Images
www.black-and-white-to-color.com
paulselhi is offline  
Old 10-2-02, 02:34 PM   #4
MarkHutch
 
Join Date: Feb 2002
Location: Waco, Tx Usa
Posts: 581
Reputation: 5
Usually the anti-virus software companies know which files are created and left behind on any virus. It's best to keep your definations up to date and not get one in the first place, but if you do new definations should detect the virus and get rid of it.

Also, Norton has a feature called Bloodhound. If enable, it checks computer code looking for viruses that may not yet be in the definations. Most viruses have similar type of activity and this feature looks for that activity and warns you if a program seems to be up to no good. I have this feature set as high as it goes.
MarkHutch is offline  
Old 10-2-02, 06:27 PM   #5
teamantivir
Living at command prompt
 
teamantivir's Avatar
 
Join Date: Feb 2002
Posts: 157
Reputation: 5
Re: stealth

Quote:
Originally posted by paulselhi
if a virus gets in before you have updated your def's can it do it's nasties then clean itself out and leave nasties behind, so that when you update and scan it is not seen?

if so how would you go about detecting this, would you see the damage from a scan shoeing a file has changed?

and what if the nasty leaves a bat file or exe file that are not viruses as such but do naughty things, these won't usually show up as a virus will they ?

The best thing to do after an infection is to boot off a know clean boot disk (CD or Diskette) then run a full virus scan on every file on the machine, and then after cleaned, scan all files on any network drives. Of course the best is a full restore from a known clean backup, but realism is that most people don't have backups.
__________________
Kenneth L, Bechtel, II
Team Anti-Virus
PGP Footprint: 969E 2A27 3042 EE52 AEFB 6FF0 2711 9467 D38C 5C0F
teamantivir is offline  
Old 10-2-02, 06:42 PM   #6
paulselhi
Cockney Red
 
paulselhi's Avatar
 
Join Date: Feb 2002
Location: London UK
Posts: 2,875
Reputation: 15
backups

of course i have backups

there they are on top of the fireplace, under the magnets next to the window in the sun lounge
__________________
Paul Selhi
Colorize Your Black and White Images
www.black-and-white-to-color.com
paulselhi is offline  
Old 10-2-02, 10:47 PM   #7
(jj)
 
(jj)'s Avatar
 
Join Date: Feb 2002
Location: n/a
Posts: 7,279
Reputation: 202
? teamantivir ?

Teamantivir,

What ever happened to the old way of having a clean boot disk that could also have a small AV program to clean the boot sector of a hard drive?

I may be too far back in time with my thinking, but I think that there could still be such a program that did not require a CD or massive space to help remove viri from an infected system.

I know that virus definitions have grown so large that a complete set would be too much for a single floppy, but would you need a complete definition database of ALL viri.

Just random thoughts and wonderments
__________________
If silence is golden, then I must be worth million$

(jj)
Jack
(jj)'s Playground
(jj) is offline  
Old 10-3-02, 08:05 AM   #8
paulselhi
Cockney Red
 
paulselhi's Avatar
 
Join Date: Feb 2002
Location: London UK
Posts: 2,875
Reputation: 15
yet again the yanks save us at the last moment

thanks guy's just updated my def's last night and caught the bugbear this morning. I have it in a bottle and am about to drop a couple of really mean spiders in
__________________
Paul Selhi
Colorize Your Black and White Images
www.black-and-white-to-color.com

Last edited by paulselhi : 10-3-02 at 08:08 AM.
paulselhi is offline  
Old 10-3-02, 08:54 AM   #9
teamantivir
Living at command prompt
 
teamantivir's Avatar
 
Join Date: Feb 2002
Posts: 157
Reputation: 5
Re: ? teamantivir ?

Quote:
Originally posted by (jj)

What ever happened to the old way of having a clean boot disk that could also have a small AV program to clean the boot sector of a hard drive?

I may be too far back in time with my thinking, but I think that there could still be such a program that did not require a CD or massive space to help remove viri from an infected system.

I know that virus definitions have grown so large that a complete set would be too much for a single floppy, but would you need a complete definition database of ALL viri.

Just random thoughts and wonderments

As you pointed out, the virus databases have grown so large that it's impossible to put them on diskette. However, there are several companies (NAI and F-Prot come to mind) that have either a scaled down, or manner to scale down the signatures so they can fit on a single floppy. In this case both scan only the critical systems areas, and files, the do not look for Macro and some script files. Another company Command Software has a Linux CD with a Linux Scanner that can do most Window machines. This may be the path of the future.

This was one of the dicussions we had in New Orleans last week. One researcher predicted that some signature databases would be 10M by the end of 2003, which strengthens my possition that the current vendors HAVE to do something to improve performance.
__________________
Kenneth L, Bechtel, II
Team Anti-Virus
PGP Footprint: 969E 2A27 3042 EE52 AEFB 6FF0 2711 9467 D38C 5C0F
teamantivir is offline  
Old 10-3-02, 08:56 AM   #10
teamantivir
Living at command prompt
 
teamantivir's Avatar
 
Join Date: Feb 2002
Posts: 157
Reputation: 5
Re: yet again the yanks save us at the last moment

Quote:
Originally posted by paulselhi
thanks guy's just updated my def's last night and caught the bugbear this morning. I have it in a bottle and am about to drop a couple of really mean spiders in

If you haven't gotten rid of it, I know we're all still trying to get a handle on it, we're looking to see if it mutates or not, have you sent it to any of the AV vendors? Virus_research@nai.com, support@sophos.com, or even mine vsample@teamanti-virus.org will make sure the sample gets to all the industry researchers. Thsi could be a big help. Thanks.
__________________
Kenneth L, Bechtel, II
Team Anti-Virus
PGP Footprint: 969E 2A27 3042 EE52 AEFB 6FF0 2711 9467 D38C 5C0F
teamantivir is offline  
Old 10-3-02, 09:03 AM   #11
paulselhi
Cockney Red
 
paulselhi's Avatar
 
Join Date: Feb 2002
Location: London UK
Posts: 2,875
Reputation: 15
Sorry

i killed it, if i get another i quarantine it and let you know

nav 4.04 spotted it
__________________
Paul Selhi
Colorize Your Black and White Images
www.black-and-white-to-color.com
paulselhi is offline  
Closed Thread


Thread Tools Search this Thread
Search this Thread:

Advanced Search

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

vB code is On
Smilies are On
[IMG] code is Off
HTML code is Off
Forum Jump


All times are GMT -4. The time now is 09:40 PM.


Contents ©PowWeb, Inc. ~ vBulletin, Copyright © 2000-2007 Jelsoft Enterprises Limited.