Go Back  British Expats > Living & Moving Abroad > Australia
Reload this Page >

Possible virus??

Possible virus??

Thread Tools
 
Old Feb 8th 2004, 8:59 am
  #1  
Wol
Lost in BE Cyberspace
Thread Starter
 
Wol's Avatar
 
Joined: Mar 2003
Posts: 9,397
Wol has a reputation beyond reputeWol has a reputation beyond reputeWol has a reputation beyond reputeWol has a reputation beyond reputeWol has a reputation beyond reputeWol has a reputation beyond reputeWol has a reputation beyond reputeWol has a reputation beyond reputeWol has a reputation beyond reputeWol has a reputation beyond reputeWol has a reputation beyond repute
Default Possible virus??

Can one of you IT guys help? (I think everyone on here but me and the nurses going to Perth is an IT guy <g>)

I've just come on after leaving the comfuser connected all night, and just glancing at the result of the midnight virus scan see that a folder wasn't openable for it. It's labelled Phoenix.

When I check on this - it's in C\Windoze\Application data - it contains all sorts of folders and files. I opened a couple of the text files and found listings of all my bookmarks and each one has "Password" against it plus a whole load of other text and numbers.

Also, the whole folder was generated last night.

Should I be scared?
Wol is offline  
Old Feb 8th 2004, 9:09 am
  #2  
Home and Happy
 
Pollyana's Avatar
 
Joined: Dec 2002
Location: Keep true friends and puppets close, trust no-one else...
Posts: 93,814
Pollyana has a reputation beyond reputePollyana has a reputation beyond reputePollyana has a reputation beyond reputePollyana has a reputation beyond reputePollyana has a reputation beyond reputePollyana has a reputation beyond reputePollyana has a reputation beyond reputePollyana has a reputation beyond reputePollyana has a reputation beyond reputePollyana has a reputation beyond reputePollyana has a reputation beyond repute
Default

Dunno Roger, someone like Bondipom could tell you. Sounds dodgy though....has the fingerprints of a virus all over it ( ).

Hope it doesn't turn out to be too nasty.
Pollyana is offline  
Old Feb 8th 2004, 9:13 am
  #3  
ABCDiamond
Guest
 
Posts: n/a
Default

I just did a google search of Windoze, got a lot of info, but can't make out if it is a virus, or a hack or just some rubbish.

I can't locate the name on a direct search of my anti virus site.
 
Old Feb 8th 2004, 9:33 am
  #4  
BE Enthusiast
 
Nibbs's Avatar
 
Joined: Feb 2003
Location: Perth
Posts: 495
Nibbs is on a distinguished road
Default Re: Possible virus??

Originally posted by Rog Williams
Can one of you IT guys help? (I think everyone on here but me and the nurses going to Perth is an IT guy <g>)

I've just come on after leaving the comfuser connected all night, and just glancing at the result of the midnight virus scan see that a folder wasn't openable for it. It's labelled Phoenix.
...snipped
Should I be scared?
It doesn't sound good. There is a virus group known as Phoenix originating in Belgium.

First step is to try a virus scanner. Try http://housecall.trendmicro.com/ for a free web based tool.

Let us know
Nibbs is offline  
Old Feb 8th 2004, 9:54 am
  #5  
Adelaide bound
 
fishyben's Avatar
 
Joined: Jan 2003
Location: Aldinga beach, SA
Posts: 96
fishyben is just really nicefishyben is just really nicefishyben is just really nicefishyben is just really nicefishyben is just really nicefishyben is just really nicefishyben is just really nicefishyben is just really nicefishyben is just really nicefishyben is just really nice
Default

This may help.

http://hq.mcafeeasap.com/dispVirus.asp?virus_k=931

But the best way to avoid a virus is to get a Apple mac
fishyben is offline  
Old Feb 8th 2004, 11:27 am
  #6  
Banned
 
Timber Floor Au's Avatar
 
Joined: Jan 2004
Location: Morayfield - The Posh Part
Posts: 10,138
Timber Floor Au has a reputation beyond reputeTimber Floor Au has a reputation beyond reputeTimber Floor Au has a reputation beyond reputeTimber Floor Au has a reputation beyond reputeTimber Floor Au has a reputation beyond reputeTimber Floor Au has a reputation beyond reputeTimber Floor Au has a reputation beyond reputeTimber Floor Au has a reputation beyond reputeTimber Floor Au has a reputation beyond reputeTimber Floor Au has a reputation beyond reputeTimber Floor Au has a reputation beyond repute
Default Re: Possible virus??

Originally posted by Rog Williams
Can one of you IT guys help? (I think everyone on here but me and the nurses going to Perth is an IT guy <g>)

I've just come on after leaving the comfuser connected all night, and just glancing at the result of the midnight virus scan see that a folder wasn't openable for it. It's labelled Phoenix.

When I check on this - it's in C\Windoze\Application data - it contains all sorts of folders and files. I opened a couple of the text files and found listings of all my bookmarks and each one has "Password" against it plus a whole load of other text and numbers.

Also, the whole folder was generated last night.

Should I be scared?

Ok its of low danger it attacks the command.com,

there are removal tools and quarranteen tools.

http://hq.mcafeeasap.com/dispVirus.asp?virus_k=931

Its an old virus about 14 years old !!

To remedy the virus, you need to reinstall your DAT files.

This is straightforward but if your not computer literate it may be easier to take to a dealer.

Alternatively:
Use this mcafee stinger to check your system, it may locate and offer a removal tool :

http://antivirus.about.com/cs/evaluations/a/stinger.htm

good luck Steve
Timber Floor Au is offline  
Old Feb 8th 2004, 12:24 pm
  #7  
life begins again...
 
scutterUK's Avatar
 
Joined: Jul 2003
Location: doncaster..then scunny... now canberra.
Posts: 1,790
scutterUK is a name known to allscutterUK is a name known to allscutterUK is a name known to allscutterUK is a name known to allscutterUK is a name known to allscutterUK is a name known to allscutterUK is a name known to allscutterUK is a name known to allscutterUK is a name known to allscutterUK is a name known to allscutterUK is a name known to all
Default

Originally posted by fishyben
But the best way to avoid a virus is to get a Apple mac
isn't that a bit like saying the best way to avoid a car crash is to use a bicycle?
scutterUK is offline  
Old Feb 8th 2004, 12:59 pm
  #8  
Wol
Lost in BE Cyberspace
Thread Starter
 
Wol's Avatar
 
Joined: Mar 2003
Posts: 9,397
Wol has a reputation beyond reputeWol has a reputation beyond reputeWol has a reputation beyond reputeWol has a reputation beyond reputeWol has a reputation beyond reputeWol has a reputation beyond reputeWol has a reputation beyond reputeWol has a reputation beyond reputeWol has a reputation beyond reputeWol has a reputation beyond reputeWol has a reputation beyond repute
Default

Thanks guys!

Strange things have been happening for a day or so, too. Some keys seem to do different things to that which they should - for example, the "Tab" key started to close the window. And my Bookmarks in the "Firebird" browser have disappeared just now - also the toolbar.

How do I reload the DAT files?
Wol is offline  
Old Feb 8th 2004, 5:40 pm
  #9  
Wol
Lost in BE Cyberspace
Thread Starter
 
Wol's Avatar
 
Joined: Mar 2003
Posts: 9,397
Wol has a reputation beyond reputeWol has a reputation beyond reputeWol has a reputation beyond reputeWol has a reputation beyond reputeWol has a reputation beyond reputeWol has a reputation beyond reputeWol has a reputation beyond reputeWol has a reputation beyond reputeWol has a reputation beyond reputeWol has a reputation beyond reputeWol has a reputation beyond repute
Default

I've now had a look at my .dat files - there are about 20 in the system. The dates on them - or at least the command.com ones - show they were last modified at my last reformat, so I reckon they should be OK.

The keyboard seems normal now, so perhaps I was getting paranoid.

Could be as a result of selling the house contents over a period of four hours on Friday! Most of the furniture left the same afternoon, and we're living on borrowed camp chairs, a bed and a TV until 22nd March.............
Wol is offline  
Old Feb 8th 2004, 7:35 pm
  #10  
 
Joined: Aug 2003
Posts: 11,149
bondipom is an unknown quantity at this point
Default

I have not seen that one but something you can do is create a set of floppy rescue disks from your anti-virus program. You can then boot your system with these and perform a thorough check. In theory the windoze folder whould be readable.

Have you been trying any of the alternative web browsers such as Mozilla or Firebird?

Finally what OS are you using ie win98, win ME, win 2000 or win XP?
bondipom is offline  
Old Feb 8th 2004, 11:49 pm
  #11  
Wol
Lost in BE Cyberspace
Thread Starter
 
Wol's Avatar
 
Joined: Mar 2003
Posts: 9,397
Wol has a reputation beyond reputeWol has a reputation beyond reputeWol has a reputation beyond reputeWol has a reputation beyond reputeWol has a reputation beyond reputeWol has a reputation beyond reputeWol has a reputation beyond reputeWol has a reputation beyond reputeWol has a reputation beyond reputeWol has a reputation beyond reputeWol has a reputation beyond repute
Default

Originally posted by bondipom
I have not seen that one but something you can do is create a set of floppy rescue disks from your anti-virus program. You can then boot your system with these and perform a thorough check. In theory the windoze folder whould be readable.

Have you been trying any of the alternative web browsers such as Mozilla or Firebird?

Finally what OS are you using ie win98, win ME, win 2000 or win XP?
BP: It gets stranger by the hour!

I'm on 98SE, using Firebird as the browser. Firebird has now lost all its bookmarks except the basic defaults, and I have just had to log on here (usually the browser logs on for me).

I thought I had the solution earlier on when the C Drive showed "full". I got rid of several big files and retrieved about 140MB, then decided to defrag to clean up the drive. It seemed to go on a long time then I noticed it started yet again with a message "A program is writing to disc - restarting"! This despite having use EnditAll before beginning.....

Prior to all this I did notice a prog called "Packager" riunning when I C-A-Deleted: no idea what this was.

Sometimes you just want to put a hammer through the thing,,and then fly to Seattle with the hammer.....
Wol is offline  
Old Feb 9th 2004, 12:00 am
  #12  
 
Joined: Aug 2003
Posts: 11,149
bondipom is an unknown quantity at this point
Default

My 98 SE box is dying but as well. The reason I ask is that phoenix is the name of Mozilla prior to firebird so you may have some legacy from that. I have downloaded firebird at work to check it out and I am impressed with the redraw rates. I will come back if I find anything relevant.

My advice Rog is to think about going XP. In the short run run the emergency rescue AV disks and Spybot search and destroy. Win 98 has very little life left.

If you need to defrag try to do so in VGA mode or safe mode as any services such as AV programs maybe using the disk that is being defragged.

Anyone who thinks MAC OS is not vulnerable to hacks and viruses has their head in the sand. Macs need AV software and security updates. Luckily for Mac owners the malware writers have their eyes on redmond.
bondipom is offline  
Old Feb 9th 2004, 1:44 am
  #13  
Wol
Lost in BE Cyberspace
Thread Starter
 
Wol's Avatar
 
Joined: Mar 2003
Posts: 9,397
Wol has a reputation beyond reputeWol has a reputation beyond reputeWol has a reputation beyond reputeWol has a reputation beyond reputeWol has a reputation beyond reputeWol has a reputation beyond reputeWol has a reputation beyond reputeWol has a reputation beyond reputeWol has a reputation beyond reputeWol has a reputation beyond reputeWol has a reputation beyond repute
Default

Originally posted by bondipom
My 98 SE box is dying but as well. The reason I ask is that phoenix is the name of Mozilla prior to firebird so you may have some legacy from that. I have downloaded firebird at work to check it out and I am impressed with the redraw rates. I will come back if I find anything relevant.

My advice Rog is to think about going XP. In the short run run the emergency rescue AV disks and Spybot search and destroy. Win 98 has very little life left.

If you need to defrag try to do so in VGA mode or safe mode as any services such as AV programs maybe using the disk that is being defragged.

Anyone who thinks MAC OS is not vulnerable to hacks and viruses has their head in the sand. Macs need AV software and security updates. Luckily for Mac owners the malware writers have their eyes on redmond.

Thanx again BP.

I use 98SE because my comfuser isn't up to XP! I'm not into games more violent or demanding than Tetris, and can't honestly see why one should have to buy a comfuser ten times more powerful every eighteen months just so that Master Gates (Well, it rhymes...) can stuff it all up with unused and unwanted "features" aka bugs!

Bring back RISCOS..........
Wol is offline  
Old Feb 9th 2004, 1:51 am
  #14  
 
Joined: Aug 2003
Posts: 11,149
bondipom is an unknown quantity at this point
Default

To be fair win98 is 6 years old but your point is what is driving the company I work for towards unix/linux .

I will probably buy another 256mb so I have 500mbs of RAM on an Athlon Gig processor. It won't be a rocket but hopefully it will be rock solid.
bondipom is offline  
Old Feb 9th 2004, 10:32 am
  #15  
Wol
Lost in BE Cyberspace
Thread Starter
 
Wol's Avatar
 
Joined: Mar 2003
Posts: 9,397
Wol has a reputation beyond reputeWol has a reputation beyond reputeWol has a reputation beyond reputeWol has a reputation beyond reputeWol has a reputation beyond reputeWol has a reputation beyond reputeWol has a reputation beyond reputeWol has a reputation beyond reputeWol has a reputation beyond reputeWol has a reputation beyond reputeWol has a reputation beyond repute
Default

BP and others:

I think I have it sorted out. My C Drive was full - I think that was causing the program anomalies. Jumping to the conclusion I had something nasty in the woodshed, when BP mentioned that Firebird / Mozilla came from Phoenix I put two and two together! Unfortunately I had already deleted the Phoenix files thinking they were a nasty, so lost my bookmarks - and since the drive was full they went forever!!

Thanks all. Back to the drawing board.
Wol is offline  

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is On
HTML code is Off
Trackbacks are Off
Pingbacks are Off
Refbacks are Off



Contact Us - Archive - Advertising - Cookie Policy - Privacy Statement - Terms of Service -

Copyright © 2024 MH Sub I, LLC dba Internet Brands. All rights reserved. Use of this site indicates your consent to the Terms of Use.