VIRUS ALERT!!! and ways to protect your pc

K

KenKnightJack

There is a bad virus out called worm doom (see info here:

http://tinyurl.com/26xtv


some free antivirus solutions are AVG free
http://www.grisoft.com/us/us_dwnl_free.php

download install and update it, its free!

and another free online web based scanner is this:
http://us.mcafee.com/root/mfs/default.asp


-Kenny S


Description:
As of January 26, 2004 1:47 PM (US Pacific Time), TrendLabs has declared a
yellow alert to control the spread of WORM_MYDOOM.A (previously known as
WORM_MIMAIL.R).
This mass-mailing worm selects from a list of email subjects, message
bodies, and attachment file names for its email messages. It spoofs the
sender name of its messages so that they appear to have been sent by
different users instead of the actual users on infected machines.
It can also propagate through the Kazaa peer-to-peer file-sharing network.
It performs a denial of service (DoS) attack against the software business
site www.sco.com. It attacks the site if the system date is February 1, 2004
or later. It ceases attacking the site and running most of its routines on
February 12, 2004.
It runs a backdoor component, which it drops as the file SHIMGAPI.DLL. The
backdoor component opens port 3127 to 3198 to allow remote users to access
and manipulate infected systems. Note that it allows remote access even
after February 12, 2004.
This worm runs on Windows 95, 98, ME, NT, 2000, and XP.
Please refer to the Technical Details section for more information on this
malware.
doom doom doom


Solution:
AUTOMATIC REMOVAL INSTRUCTIONS
To automatically remove this malware from your system, please use TREND
MICRO Damage Cleanup Services.
MANUAL REMOVAL INSTRUCTIONS
Identifying the Malware Program
Before proceeding to remove this malware, first identify the malware
program.
Scan your system with TREND MICRO antivirus and NOTE all files detected as
WORM_MYDOOM.A. To do this, TREND MICRO customers must download the latest
pattern file and scan their system. Other Internet users can use HouseCall,
TREND MICRO's free online virus scanner.
Terminating the Malware Program
This procedure terminates the running malware process from memory. You will
need the name(s) of the file(s) detected earlier.
Open Windows Task Manager.
On Windows 95/98/ME systems, press
CTRL+ALT+DELETE
On Windows NT/2000/XP systems, press
CTRL+SHIFT+ESC, then click the Processes tab.
In the list of running programs*, locate the malware file or files detected
earlier.
Select one of the detected files, then press either the End Task or the End
Process button, depending on the version of Windows on your system.
Do the same for all detected malware files in the list of running processes.
To check if the malware process has been terminated, close Task Manager, and
then open it again.
Close Task Manager.
*NOTE: On systems running Windows 95/98/ME, Task Manager may not show
certain processes. You may use a third party process viewer to terminate the
malware process. Otherwise, continue with the next procedure, noting
additional instructions.
Removing the Backdoor DLL File
To be able to remove the DLL file, you need to terminate the EXPLORER.EXE
process first.
Click Start>Run. Type COMMAND and press Enter.
Terminate EXPLORER.EXE.
On Windows NT/2000/XP
Open Windows Task Manager. Press CTRL+SHIFT+ESC and click the Processes tab.
In the list of running programs, select EXPLORER.EXE.
Right-click EXPLORER.EXE and click End Process Tree.
On Windows 9x/ME
Download and install a third-party process viewer like Process Explorer.
Run process viewer.
In the list of running programs, select and terminate the process
EXPLORER.EXE.
Close the process viewer.
Switch to the command prompt. Hold the ALT key then continue pressing TAB
until you arrive at the command prompt window.
Enter the following on the command prompt:
del %System%\shimgapi.dll
Restart the EXPLORER.EXE process by entering EXPLORER.EXE on the command
prompt.
Close command prompt.
Removing Autostart Entries from the Registry
Removing autostart entries from the registry prevents the malware from
executing during startup.
Open Registry Editor. To do this, click Start>Run, type REGEDIT, then press
Enter.
In the left panel, double-click the following:
HKEY_LOCAL_MACHINE>Software>Microsoft>
Windows>CurrentVersion>Run
In the right panel, locate and delete the entry or entries:
TaskMon = %System%\taskmon.exe
(Note: %System% is the Windows system folder, which is usually
C:\Windows\System on Windows 95, 98 and ME, C:\WINNT\System32 on Windows NT
and 2000, and C:\Windows\System32 on Windows XP.)
(Note: Some registry entries may point to a legitimate Windows utility with
the same file name, TASKMON.EXE, and that can be found in the Windows folder
on some systems.)
Removing Other Malware Entries from the Registry
Still in Registry Editor, in the left panel, double click the following:
HKEY_CLASSES_ROOT>CLSID>{E6FB5E20-DE35-11CF-9C87-00AA005127ED}>
InProcServer32
In the right panel, locate and delete the entry:
(Default) = "%System%\shimgapi.dll"
Close Registry Editor.
NOTE: If you were not able to terminate the malware process from memory as
described in the previous procedure, restart your system.
Additional Windows ME/XP Cleaning Instructions
Running TREND MICRO Antivirus
Scan your system with TREND MICRO antivirus and delete all files detected as
WORM_MYDOOM.A. To do this, TREND MICRO customers must download the latest
pattern file and scan their system. Other Internet users can use HouseCall,
TREND MICRO's free online virus scanner.
NOTE: For product specific solutions, please refer to Solution 18309 of the
TREND MICRO Knowledge Base.
 
L

Lynn W

Does the AVG software work with OE. It states on their site that it works
with Outlook but I realise that isn't the same as Outlook Express
 
W

Wesley Vogel

Lynn;
Yes, AVG works with OE. I have both.
However you are better off
to turn off the E-mail scanning option in AVG. This
goes for all Anti Virus software. I have the E-mail option
turned off as well.

You are still protected with that option turned off. With it
turned on it can cause problems with OE.
 
W

Wesley Vogel

Jack;

Suit yourself.

But, I would STRONGLY suggest you update
NOW!!!

Latest>>>>
Virus Database : 365
Release Date : 1/30/2004

You're over two weeks behind. There were updates yesterday
and today.
 
M

mrtee

Jack, set AVG to update daily! Go to the AVG control panel, set it there.

--
Just my 2¢ worth
Jeff
__________in response to__________
| it works with OE just fine...
|
|
| ---
| Outgoing mail is certified Virus Free.
| Checked by AVG anti-virus system (http://www.grisoft.com).
| Version: 6.0.561 / Virus Database: 353 - Release Date: 1/13/2004
|
|
 
L

Lynn W

It still scans incoming mail though? I would obviously want to be protected
from an email containing a virus. What does the email scanning option do
then?
 
K

KenKnightJack

AVG free edition has an outlook express option that scans all incoming and
outgoing email. If an email does have a virus attachment it automatically
removes the attachment and puts is in a virus vault or deletes it
automatically.
It works great. You will have to put a checkmark on the "oulook express
plugin" in the programs options.
Just have it updated because there are new viruses around.

Kenny


Lynn W said:
It still scans incoming mail though? I would obviously want to be protected
from an email containing a virus. What does the email scanning option do
then?
 
A

artemis jackson

I've already been sent 12 emails with the sucker today.If it weren't for my
excellent NOD 32 virus scanner that deletes 'em as it finds'em,my hard drive
would be toast by now.

People who write viruses should be strung up by the ghoulies(Hi giselle!! I
used 'the word' just for you!!!!)
;-)
 
W

Wesley Vogel

Lynn;
Yes, AVG will still scan mail. It will scan everything on your machine.
You do not turn off AVG itself, just the scan E-mail option. AVG
will still run in the background.

From AVG HELP:
[[The AVG E-mail Scanner
The AVG E-mail Scanner is a resident program, installed during the AVG
installation process. It is automatically started with the Windows operating
system and supports the Microsoft Outlook e-mail client.
The program checks all incoming and outgoing email attachments for the
presence of any virus threats.
Virus Detection
Incoming Mail- if the AVG E-mail Scanner detects incoming mail with
attachments infected by a virus, it removes the infected files automatically
and puts them into the AVG Virus Vault .
In the body of the offending e-mail, a message is inserted to inform you
about the virus threat.]]

The key here is that you do not get a message inserted into the body of an
infected E-mail with this option turned off. What you DO get, if there is
an infected E-mail, is a pop-up alert instead. You are still protected, the
biggest difference is the method of how you are alerted.

From Tom Koch @ http://insideoe.tomsterdam.com/problems/bugs.htm

One problem that can happen is [Messages in Inbox or
other mail folders disappear.] [...or simply disable both the email and
Internet download scan modules in VirusScan. These are not necessary to
protect your computer if you still have VirusScan running in the background
and scanning executable files as they are opened. In fact, the only real
reason to use email and download scanning is to make you feel more secure.
If this is the cause of your problem, I am sorry to say your messages are
irretrievably lost.]

There has been some debate about the scan E-mail option.
I have been won over from the other side. I have mine turned off.
And virus scanning in the background still does a bang-up job.


No matter what else you do, keep whatever AV software
you end up using up to date. Otherwise it's like having a gun with
no bullets. Useless.

I hope that I've answered your questions.
 
M

mrtee

Darn! Don't know what happened. Looks right here.

By the way, congratulations! I got an e-mail too but didn't make the cut. There's always nest year. :)

--
Just my 2¢ worth
Jeff
__________in response to__________
| Hi Jeff;
| I noticed that your 2¢ worth has changed to 2" worth.
| Inflation? :blush:)
|
| --
| Hope this helps. Let us know.
| Wes
 
W

Wesley Vogel

Hi Jeff;
Thank you. I don't know exactly what criteria is used.

It was on my end. Operator error. I had another DA attack.
OE | Tools | Options | Read |
I have Read all messages in plain text checked.
But for some unknown reason I changed: International
Settings to: Use default encoding for all incoming
messages.

I changed that back and now ¢ shows fine again. :blush:)
I just have to fiddle with things.

Wes

In
 
M

mrtee

Fiddling with things is so much fun! :)

That's how we learn what & what not to do.

--
Just my 2¢ worth
Jeff
__________in response to__________
| Hi Jeff;
| Thank you. I don't know exactly what criteria is used.
|
| It was on my end. Operator error. I had another DA attack.
| OE | Tools | Options | Read |
| I have Read all messages in plain text checked.
| But for some unknown reason I changed: International
| Settings to: Use default encoding for all incoming
| messages.
|
| I changed that back and now ¢ shows fine again. :blush:)
| I just have to fiddle with things.
|
| Wes
 

Ask a Question

Want to reply to this thread or ask your own question?

You'll need to choose a username for the site, which only take a couple of moments. After that, you can post your question and our members will help you out.

Ask a Question

Top