Go Back  British Expats > Living & Moving Abroad > Australia
Reload this Page >

Possible virus??

Wikiposts

Possible virus??

Thread Tools
 
Old Feb 7th 2004 | 8:59 pm
  #1  
Wol's Avatar
Wol
Thread Starter
Lost in BE Cyberspace
 
Joined: Mar 2003
Posts: 9,400
Wol has a reputation beyond reputeWol has a reputation beyond reputeWol has a reputation beyond reputeWol has a reputation beyond reputeWol has a reputation beyond reputeWol has a reputation beyond reputeWol has a reputation beyond reputeWol has a reputation beyond reputeWol has a reputation beyond reputeWol has a reputation beyond reputeWol has a reputation beyond repute
Default Possible virus??

Can one of you IT guys help? (I think everyone on here but me and the nurses going to Perth is an IT guy <g>)

I've just come on after leaving the comfuser connected all night, and just glancing at the result of the midnight virus scan see that a folder wasn't openable for it. It's labelled Phoenix.

When I check on this - it's in C\Windoze\Application data - it contains all sorts of folders and files. I opened a couple of the text files and found listings of all my bookmarks and each one has "Password" against it plus a whole load of other text and numbers.

Also, the whole folder was generated last night.

Should I be scared?
 
Old Feb 7th 2004 | 9:09 pm
  #2  
Pollyana's Avatar
Home and Happy
 
Joined: Dec 2002
Posts: 94,307
From: Keep true friends and puppets close, trust no-one else...
Pollyana has a reputation beyond reputePollyana has a reputation beyond reputePollyana has a reputation beyond reputePollyana has a reputation beyond reputePollyana has a reputation beyond reputePollyana has a reputation beyond reputePollyana has a reputation beyond reputePollyana has a reputation beyond reputePollyana has a reputation beyond reputePollyana has a reputation beyond reputePollyana has a reputation beyond repute
Default

Dunno Roger, someone like Bondipom could tell you. Sounds dodgy though....has the fingerprints of a virus all over it ( ).

Hope it doesn't turn out to be too nasty.
 
Old Feb 7th 2004 | 9:13 pm
  #3  
ABCDiamond
Guest
 
Posts: n/a
Default

I just did a google search of Windoze, got a lot of info, but can't make out if it is a virus, or a hack or just some rubbish.

I can't locate the name on a direct search of my anti virus site.
 
Old Feb 7th 2004 | 9:33 pm
  #4  
Nibbs's Avatar
BE Enthusiast
 
Joined: Feb 2003
Posts: 495
From: Perth
Nibbs is on a distinguished road
Default Re: Possible virus??

Originally posted by Rog Williams
Can one of you IT guys help? (I think everyone on here but me and the nurses going to Perth is an IT guy <g>)

I've just come on after leaving the comfuser connected all night, and just glancing at the result of the midnight virus scan see that a folder wasn't openable for it. It's labelled Phoenix.
...snipped
Should I be scared?
It doesn't sound good. There is a virus group known as Phoenix originating in Belgium.

First step is to try a virus scanner. Try http://housecall.trendmicro.com/ for a free web based tool.

Let us know
 
Old Feb 7th 2004 | 9:54 pm
  #5  
fishyben's Avatar
Adelaide bound
 
Joined: Jan 2003
Posts: 96
From: Aldinga beach, SA
fishyben is just really nicefishyben is just really nicefishyben is just really nicefishyben is just really nicefishyben is just really nicefishyben is just really nicefishyben is just really nicefishyben is just really nicefishyben is just really nicefishyben is just really nice
Default

This may help.

http://hq.mcafeeasap.com/dispVirus.asp?virus_k=931

But the best way to avoid a virus is to get a Apple mac
 
Old Feb 7th 2004 | 11:27 pm
  #6  
Timber Floor Au's Avatar
Banned
 
Joined: Jan 2004
Posts: 10,138
From: Morayfield - The Posh Part
Timber Floor Au has a reputation beyond reputeTimber Floor Au has a reputation beyond reputeTimber Floor Au has a reputation beyond reputeTimber Floor Au has a reputation beyond reputeTimber Floor Au has a reputation beyond reputeTimber Floor Au has a reputation beyond reputeTimber Floor Au has a reputation beyond reputeTimber Floor Au has a reputation beyond reputeTimber Floor Au has a reputation beyond reputeTimber Floor Au has a reputation beyond reputeTimber Floor Au has a reputation beyond repute
Default Re: Possible virus??

Originally posted by Rog Williams
Can one of you IT guys help? (I think everyone on here but me and the nurses going to Perth is an IT guy <g>)

I've just come on after leaving the comfuser connected all night, and just glancing at the result of the midnight virus scan see that a folder wasn't openable for it. It's labelled Phoenix.

When I check on this - it's in C\Windoze\Application data - it contains all sorts of folders and files. I opened a couple of the text files and found listings of all my bookmarks and each one has "Password" against it plus a whole load of other text and numbers.

Also, the whole folder was generated last night.

Should I be scared?

Ok its of low danger it attacks the command.com,

there are removal tools and quarranteen tools.

http://hq.mcafeeasap.com/dispVirus.asp?virus_k=931

Its an old virus about 14 years old !!

To remedy the virus, you need to reinstall your DAT files.

This is straightforward but if your not computer literate it may be easier to take to a dealer.

Alternatively:
Use this mcafee stinger to check your system, it may locate and offer a removal tool :

http://antivirus.about.com/cs/evaluations/a/stinger.htm

good luck Steve
 
Old Feb 8th 2004 | 12:24 am
  #7  
scutterUK's Avatar
life begins again...
 
Joined: Jul 2003
Posts: 1,790
From: doncaster..then scunny... now canberra.
scutterUK is a name known to allscutterUK is a name known to allscutterUK is a name known to allscutterUK is a name known to allscutterUK is a name known to allscutterUK is a name known to allscutterUK is a name known to allscutterUK is a name known to allscutterUK is a name known to allscutterUK is a name known to allscutterUK is a name known to all
Default

Originally posted by fishyben
But the best way to avoid a virus is to get a Apple mac
isn't that a bit like saying the best way to avoid a car crash is to use a bicycle?
 
Old Feb 8th 2004 | 12:59 am
  #8  
Wol's Avatar
Wol
Thread Starter
Lost in BE Cyberspace
 
Joined: Mar 2003
Posts: 9,400
Wol has a reputation beyond reputeWol has a reputation beyond reputeWol has a reputation beyond reputeWol has a reputation beyond reputeWol has a reputation beyond reputeWol has a reputation beyond reputeWol has a reputation beyond reputeWol has a reputation beyond reputeWol has a reputation beyond reputeWol has a reputation beyond reputeWol has a reputation beyond repute
Default

Thanks guys!

Strange things have been happening for a day or so, too. Some keys seem to do different things to that which they should - for example, the "Tab" key started to close the window. And my Bookmarks in the "Firebird" browser have disappeared just now - also the toolbar.

How do I reload the DAT files?
 
Old Feb 8th 2004 | 5:40 am
  #9  
Wol's Avatar
Wol
Thread Starter
Lost in BE Cyberspace
 
Joined: Mar 2003
Posts: 9,400
Wol has a reputation beyond reputeWol has a reputation beyond reputeWol has a reputation beyond reputeWol has a reputation beyond reputeWol has a reputation beyond reputeWol has a reputation beyond reputeWol has a reputation beyond reputeWol has a reputation beyond reputeWol has a reputation beyond reputeWol has a reputation beyond reputeWol has a reputation beyond repute
Default

I've now had a look at my .dat files - there are about 20 in the system. The dates on them - or at least the command.com ones - show they were last modified at my last reformat, so I reckon they should be OK.

The keyboard seems normal now, so perhaps I was getting paranoid.

Could be as a result of selling the house contents over a period of four hours on Friday! Most of the furniture left the same afternoon, and we're living on borrowed camp chairs, a bed and a TV until 22nd March.............
 
Old Feb 8th 2004 | 7:35 am
  #10  
 
Joined: Aug 2003
Posts: 11,149
bondipom is an unknown quantity at this point
Default

I have not seen that one but something you can do is create a set of floppy rescue disks from your anti-virus program. You can then boot your system with these and perform a thorough check. In theory the windoze folder whould be readable.

Have you been trying any of the alternative web browsers such as Mozilla or Firebird?

Finally what OS are you using ie win98, win ME, win 2000 or win XP?
 
Old Feb 8th 2004 | 11:49 am
  #11  
Wol's Avatar
Wol
Thread Starter
Lost in BE Cyberspace
 
Joined: Mar 2003
Posts: 9,400
Wol has a reputation beyond reputeWol has a reputation beyond reputeWol has a reputation beyond reputeWol has a reputation beyond reputeWol has a reputation beyond reputeWol has a reputation beyond reputeWol has a reputation beyond reputeWol has a reputation beyond reputeWol has a reputation beyond reputeWol has a reputation beyond reputeWol has a reputation beyond repute
Default

Originally posted by bondipom
I have not seen that one but something you can do is create a set of floppy rescue disks from your anti-virus program. You can then boot your system with these and perform a thorough check. In theory the windoze folder whould be readable.

Have you been trying any of the alternative web browsers such as Mozilla or Firebird?

Finally what OS are you using ie win98, win ME, win 2000 or win XP?
BP: It gets stranger by the hour!

I'm on 98SE, using Firebird as the browser. Firebird has now lost all its bookmarks except the basic defaults, and I have just had to log on here (usually the browser logs on for me).

I thought I had the solution earlier on when the C Drive showed "full". I got rid of several big files and retrieved about 140MB, then decided to defrag to clean up the drive. It seemed to go on a long time then I noticed it started yet again with a message "A program is writing to disc - restarting"! This despite having use EnditAll before beginning.....

Prior to all this I did notice a prog called "Packager" riunning when I C-A-Deleted: no idea what this was.

Sometimes you just want to put a hammer through the thing,,and then fly to Seattle with the hammer.....
 
Old Feb 8th 2004 | 12:00 pm
  #12  
 
Joined: Aug 2003
Posts: 11,149
bondipom is an unknown quantity at this point
Default

My 98 SE box is dying but as well. The reason I ask is that phoenix is the name of Mozilla prior to firebird so you may have some legacy from that. I have downloaded firebird at work to check it out and I am impressed with the redraw rates. I will come back if I find anything relevant.

My advice Rog is to think about going XP. In the short run run the emergency rescue AV disks and Spybot search and destroy. Win 98 has very little life left.

If you need to defrag try to do so in VGA mode or safe mode as any services such as AV programs maybe using the disk that is being defragged.

Anyone who thinks MAC OS is not vulnerable to hacks and viruses has their head in the sand. Macs need AV software and security updates. Luckily for Mac owners the malware writers have their eyes on redmond.
 
Old Feb 8th 2004 | 1:44 pm
  #13  
Wol's Avatar
Wol
Thread Starter
Lost in BE Cyberspace
 
Joined: Mar 2003
Posts: 9,400
Wol has a reputation beyond reputeWol has a reputation beyond reputeWol has a reputation beyond reputeWol has a reputation beyond reputeWol has a reputation beyond reputeWol has a reputation beyond reputeWol has a reputation beyond reputeWol has a reputation beyond reputeWol has a reputation beyond reputeWol has a reputation beyond reputeWol has a reputation beyond repute
Default

Originally posted by bondipom
My 98 SE box is dying but as well. The reason I ask is that phoenix is the name of Mozilla prior to firebird so you may have some legacy from that. I have downloaded firebird at work to check it out and I am impressed with the redraw rates. I will come back if I find anything relevant.

My advice Rog is to think about going XP. In the short run run the emergency rescue AV disks and Spybot search and destroy. Win 98 has very little life left.

If you need to defrag try to do so in VGA mode or safe mode as any services such as AV programs maybe using the disk that is being defragged.

Anyone who thinks MAC OS is not vulnerable to hacks and viruses has their head in the sand. Macs need AV software and security updates. Luckily for Mac owners the malware writers have their eyes on redmond.

Thanx again BP.

I use 98SE because my comfuser isn't up to XP! I'm not into games more violent or demanding than Tetris, and can't honestly see why one should have to buy a comfuser ten times more powerful every eighteen months just so that Master Gates (Well, it rhymes...) can stuff it all up with unused and unwanted "features" aka bugs!

Bring back RISCOS..........
 
Old Feb 8th 2004 | 1:51 pm
  #14  
 
Joined: Aug 2003
Posts: 11,149
bondipom is an unknown quantity at this point
Default

To be fair win98 is 6 years old but your point is what is driving the company I work for towards unix/linux .

I will probably buy another 256mb so I have 500mbs of RAM on an Athlon Gig processor. It won't be a rocket but hopefully it will be rock solid.
 
Old Feb 8th 2004 | 10:32 pm
  #15  
Wol's Avatar
Wol
Thread Starter
Lost in BE Cyberspace
 
Joined: Mar 2003
Posts: 9,400
Wol has a reputation beyond reputeWol has a reputation beyond reputeWol has a reputation beyond reputeWol has a reputation beyond reputeWol has a reputation beyond reputeWol has a reputation beyond reputeWol has a reputation beyond reputeWol has a reputation beyond reputeWol has a reputation beyond reputeWol has a reputation beyond reputeWol has a reputation beyond repute
Default

BP and others:

I think I have it sorted out. My C Drive was full - I think that was causing the program anomalies. Jumping to the conclusion I had something nasty in the woodshed, when BP mentioned that Firebird / Mozilla came from Phoenix I put two and two together! Unfortunately I had already deleted the Phoenix files thinking they were a nasty, so lost my bookmarks - and since the drive was full they went forever!!

Thanks all. Back to the drawing board.
 

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is On
HTML code is Off
Trackbacks are Off
Pingbacks are Off
Refbacks are Off



Contact Us - Archive - Advertising - Cookie Policy - Privacy Statement - Terms of Service - Your Privacy Choices

Copyright © 2026 MH Sub I, LLC dba Internet Brands. All rights reserved. Use of this site indicates your consent to the Terms of Use.