ChristiansUnite Forums
October 23, 2025, 08:05:51 PM *
Welcome, Guest. Please login or register.

Login with username, password and session length
News: Our Lord Jesus Christ loves you.
 
   Home   Help Search Login Register  
Pages: 1 [2]   Go Down
  Print  
Author Topic: Computer & ISP Problems  (Read 15588 times)
Whitehorse
Gold Member
*****
Offline Offline

Posts: 1441


I'll think of something.


View Profile
« Reply #15 on: January 30, 2004, 11:10:40 PM »

Here's another alert for everyone, too.

VIRUS ALERT! Win32/Mydoom.A@mm
January 27, 2004 - RAV AntiVirus Team is alerting all computer users
that a dangerous Internet worm, called Win32/Mydoom.A@mm,  is
reported to have a high infection level in the last 24 hours. This
worm is classified as "Potentially destructive" by RAV Team
and its spreading process has been carefully followed in the last 24
hours.

The signature of Win32/Mydoom.A@mm is included in the database of RAV
Engine starting with January 27, 2004. All RAV AntiVirus products
using daily updates after this date are able to detect and clean the
worm.

A short description of the worm is available below.

1. Description
2. How to recognize the worm
3. How to disinfect your computer
4. Evilness
5. More info


1. Description
Win32/Mydoom.A@mm is a highly spreading mass mailer internet worm,
with a complex structure and is also able to spread using Kazza file
sharing network. It is packed with UPX and its size is about 22.5Kb
long packed and about 33Kb long unpacked.

The worm is able to spread using Kazaa file sharing network, and will
try to copy itself in the Kazaa Shared Folder using one of the name:
"winamp5", "icq2004-final",
"strip-girl-2.0bdcom_patches", "rootkitXP",
"office_crack", "nuke2004" and one of the
extension: ".pif", ".scr", ".exe",
".bat".

To be less suspicious, when is executed will drop a file named
"message" with random content, and will spawn a
"notepad.exe" process to open that file.

The worm will create a mutex object called "SwebSipcSmtxS0"
to avoid running more than one copy of itself in the same time. In
the "%system%" folder will be dropped and then loaded a
library named "shimgapi.dll". Also Win32/Mydoom.A@mm will
copy itself as "taskmon.exe" in the "%system%"
folder. The "shimgapi.dll" library will then set itself,
using specific registry key, to be loaded by "explorer.exe"
at each computer restart. To be started each time Windows starts, a
new entry called "TaskMon" will be created in the
"Software\Microsoft\Windows\CurrentVersion\Run" registry
key, with the "taskmon.exe" path as value.

Depending on the current time, the Win32/Mydoom.A@mm will try to
initiate a DoS attack to www.sco.com by sending at regular time
intervals HTTP GET requests from up to 63 threads simultaneous. Also,
depending on the current system time the worm will not spread any
more.

Win32/Mydoom.A@mm will listen for connections from a large range of
ports, working this way as a proxy server.

For a complete description of the worm, please read http://www.ravantivirus.com/virus/showvirus.php?v=205



2. How to recognize the worm
The worm can arrive as a mail attachment, with double extension. The
first extension can be ".txt" followed by a big number of
spaces and the second extension can be: ".pif",
".exe", ".cmd", ".scr",
".bat". The file name will be randomly chosen from one of
the following:
- "document",
- "readme",
- "doc",
- "text",
- "file",
- "data",
- "test",
- "message",
- "body".
The attachment can also be present as a zip archive.

Both the "from" and "to" fields will be spoofed
and randomly set to one of the combinations from the worm hard-coded
list.

The "Subject" field will be set to one of the possible
values:
- "test",
- "hi",
- "hello",
- "Mail Delivery System",
- "Mail Transaction Failed",
- "Server Report",
- "Status",
- "Error".
And the message body can contain one of the following :
- "test",
- "The message cannot be represented in 7-bit ASCII encoding and
has been sent as a binary attachment.",
- "The message contains Unicode characters and has been sent as
a binary attachment.",
- "Mail transaction failed. Partial message is available.".


3. How to disinfect your computer
a. click Start>Run and type "regedit";
b. browse to
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run] OR
to [HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run]
and delete the following registry key:  
"d3update.exe" = "%system%\bbeagle.exe"
c. update your RAV AntiVirus software;
d. scan and delete all files reported by your RAV AntiVirus product
as infected with Win32/Mydoom.A@mm.
e. restart your computer.

Note1: Incorrect changes to the registry could result in permanent
data loss or corrupted files. We strongly recommend that you back up
your system registry before making any change.
Note2: If you are using Windows Millennium Edition (ME) or Windows
XP, you should disable the System Restore feature before scanning the
system with RAV AntiVirus and re-enable it afterwards. Please contact
your system administrator for information on how to disable this
feature.


4. Evilness
Potentially destructive (corrupts data while replicating).


5. More info
The latest details about Win32/Mydoom.A@mm and a complete description
can be found on our website:

http://www.ravantivirus.com/virus/showvirus.php?v=205

Logged

JudgeNot
Gold Member
*****
Offline Offline

Posts: 1993


Jesus, remember me... Luke 23:42


View Profile WWW
« Reply #16 on: January 31, 2004, 11:32:19 AM »

Ya'll hear that deafening sonic boom from the far west?  That was the biggest part of Whitehorse's post going right over my head at extremely high speed...
 Grin
Logged

Covering your tracks is futile; God knows where you're going and where you've been.
JPD
Forrest
Gold Member
*****
Offline Offline

Posts: 537



View Profile
« Reply #17 on: February 01, 2004, 02:37:32 AM »

      BEP;
    Sorry to hear that you were hit, but glad that you are up and posting agein. I've got norton with my E-mail settings set at the highest no e-mail enters my puter if the addy not in myaddres book, allso earthlink has started scaning all mail to earthlink users I've had 5 in the past 2 weeks with subject heading of microw windows patch.
Logged

Your Brother In Christ
          Forrest              
ROM 12:5 So we, [being] many, are one body in Christ, and every one members one of another.
nChrist
Global Moderator
Gold Member
*****
Offline Offline

Posts: 64256


May God Lead And Guide Us All


View Profile
« Reply #18 on: February 01, 2004, 09:21:01 PM »

     BEP;
    Sorry to hear that you were hit, but glad that you are up and posting agein. I've got norton with my E-mail settings set at the highest no e-mail enters my puter if the addy not in myaddres book, allso earthlink has started scaning all mail to earthlink users I've had 5 in the past 2 weeks with subject heading of microw windows patch.

Oklahoma Howdy to Forrest,

Brother, it is great to see you back on the forum. I missed you.

I think that I have most of it cleaned up now. From everything that I'm reading, I might have gotten hit with more than one kind of virus. I don't have any hint that my computer infected any of my friends, family members, etc. I do have confirmation that this specific virus did hit me, but so many other weird things happened that I'm almost positive I got hit with other stuff too. My Christian and Law Enforcement web site makes me a fairly regular target.

Love In Christ,
Tom
Logged

Paul2
Gold Member
*****
Offline Offline

Posts: 531



View Profile
« Reply #19 on: February 02, 2004, 07:30:52 PM »

    I'm testing my signature graphics, test one
Logged

Paul2
Gold Member
*****
Offline Offline

Posts: 531



View Profile
« Reply #20 on: February 02, 2004, 07:59:02 PM »

test 2


Logged

Paul2
Gold Member
*****
Offline Offline

Posts: 531



View Profile
« Reply #21 on: February 02, 2004, 08:07:37 PM »

test3
Logged

Paul2
Gold Member
*****
Offline Offline

Posts: 531



View Profile
« Reply #22 on: February 02, 2004, 08:16:22 PM »

test4
Logged

Paul2
Gold Member
*****
Offline Offline

Posts: 531



View Profile
« Reply #23 on: February 02, 2004, 08:22:41 PM »

   It works! sorry it took so long to figure it out.

                                                Paul2
Logged

Paul2
Gold Member
*****
Offline Offline

Posts: 531



View Profile
« Reply #24 on: February 02, 2004, 08:27:33 PM »

   It stopped working! whats going on here?
Logged

Paul2
Gold Member
*****
Offline Offline

Posts: 531



View Profile
« Reply #25 on: February 02, 2004, 08:29:30 PM »

      it works when you go to the actual post pages but not when you look at "top ten posts", I get now. Sorry everybody Wink
Logged

Reba
Guest
« Reply #26 on: February 02, 2004, 09:20:44 PM »

LMHO
Logged
JudgeNot
Gold Member
*****
Offline Offline

Posts: 1993


Jesus, remember me... Luke 23:42


View Profile WWW
« Reply #27 on: February 02, 2004, 09:51:34 PM »

I'm getting queezy...
Logged

Covering your tracks is futile; God knows where you're going and where you've been.
JPD
Forrest
Gold Member
*****
Offline Offline

Posts: 537



View Profile
« Reply #28 on: February 28, 2004, 08:46:12 PM »

AMISH VIRUS:



You have just received the Amish Virus. Since we do not have electricity nor computers, you are on the honor system.
Please delete all of your files.

Thank thee.
Logged

Your Brother In Christ
          Forrest              
ROM 12:5 So we, [being] many, are one body in Christ, and every one members one of another.
nChrist
Global Moderator
Gold Member
*****
Offline Offline

Posts: 64256


May God Lead And Guide Us All


View Profile
« Reply #29 on: February 28, 2004, 11:18:21 PM »

AMISH VIRUS:



You have just received the Amish Virus. Since we do not have electricity nor computers, you are on the honor system.
Please delete all of your files.

Thank thee.

Oklahoma Howdy to Brother Forrest,

 Grin   Grin  Thanks, I needed that laugh.

I only have one question. Since my only computer is an abacus, I guess that means I have to go in and move all the beads around, right?   Grin

I just got another laugh thinking some of the younger folks won't have a clue what an abacus is...........  Forrest, I'll tell you a secret, but don't tell anyone else. I have all of my files backed up on a second abacus.  

Love In Christ,
Tom
Logged

Pages: 1 [2]   Go Up
  Print  
 
Jump to:  

Powered by MySQL Powered by PHP Powered by SMF 1.1 RC2 | SMF © 2001-2005, Lewis Media Valid XHTML 1.0! Valid CSS!