Close

Results 1 to 16 of 16
  1. #1
    DF VIP Member Spennyboy's Avatar
    Join Date
    Sep 2003
    Location
    Stock Exchange
    Posts
    11,193
    Thanks
    221
    Thanked:        121
    Karma Level
    1113

    Default Tale of a virus...

    Hey guys,

    Been battling a couple of viruses this week.

    w32.rontokbro - this ones real clever, once infected it disabled pretty much everything that you could do to cure it.

    Control panel, regedit, cmd, internet etc etc.

    Had to format in the end

    w32.ircbot - basically a remote trojan that can be used via mIRC. copies itself everywhere including all usb sticks that are plugged in. start.exe and isass.exe are how you find it on the machine.

    chess.exe - this one still has me, titled w32.orgid by most of the web. Replaces your drives with the chess icon. Latest definitions etc dont clean it.

    fun fun fun

    The end.

  2. #2
    R.I.P. the_wizzard's Avatar
    Join Date
    Oct 2000
    Location
    in the outside
    Posts
    5,297
    Thanks
    0
    Thanked:        2
    Karma Level
    609

    Default Re: Tale of a virus...

    have you tried using RRC? and if u can find the exe's then upload em to virustotal and all def's will get updated!


    have you tryed this sandboxie

    or maybe you could try using vmware

  3. #3
    DF VIP Member Spennyboy's Avatar
    Join Date
    Sep 2003
    Location
    Stock Exchange
    Posts
    11,193
    Thanks
    221
    Thanked:        121
    Karma Level
    1113

    Default Re: Tale of a virus...

    Not done the above, will do tho - cheers

  4. #4
    DF VIP Member
    liveseytowers's Avatar
    Join Date
    Aug 2007
    Location
    Bristol, Unite
    Posts
    7,756
    Thanks
    495
    Thanked:        251
    Karma Level
    644

    Default Re: Tale of a virus...

    If you are getting so many infections it might be best as wizzard says, get VMWare and install on a virtual machine first and nuke it if it goes tits up. Just don't get an infection when you download a dodgy copy of vmware lol

  5. #5
    DF VIP Member
    jaguar982's Avatar
    Join Date
    Jul 2001
    Location
    Planet ZOD
    Posts
    2,105
    Thanks
    387
    Thanked:        188
    Karma Level
    463

    Default Re: Tale of a virus...

    What a/v are you using that it got past, could be useful to know cheers

    jag


    I'm not racist i hate everybody

  6. #6
    DF VIP Member
    tombott's Avatar
    Join Date
    Oct 2002
    Location
    Hereford
    Posts
    5,697
    Thanks
    507
    Thanked:        571
    Karma Level
    723

    Default Re: Tale of a virus...

    As jaguar982 said it would be interesting to hear what AV you had running.
    Also if you do go down the Virtual route VM does a free version of VMServer so no need to download anything cracked.
    Digital-Forums IRC Last.FM duckduckgo
    Guns don't kill people rappers do, I'm a fucking rapper and I might kill you.

  7. #7
    DF VIP Member Spennyboy's Avatar
    Join Date
    Sep 2003
    Location
    Stock Exchange
    Posts
    11,193
    Thanks
    221
    Thanked:        121
    Karma Level
    1113

    Default Re: Tale of a virus...

    Its Symantec updated to the 22nd October.

    It picks up and cleans the first 2, just not the chess.exe even if you scan the file directly.

    I have plenty of test terminals to try various methods on so VM is not needed.

  8. #8
    DF VIP Member
    tombott's Avatar
    Join Date
    Oct 2002
    Location
    Hereford
    Posts
    5,697
    Thanks
    507
    Thanked:        571
    Karma Level
    723

    Default Re: Tale of a virus...

    Quote Originally Posted by Spennyboy View Post
    Its Symantec updated to the 22nd October.

    It picks up and cleans the first 2, just not the chess.exe even if you scan the file directly.

    I have plenty of test terminals to try various methods on so VM is not needed.
    You running the Corporate version?

    We have Symantec Endpoint 11 here so would be interesting to know if I need to look out for these.
    Digital-Forums IRC Last.FM duckduckgo
    Guns don't kill people rappers do, I'm a fucking rapper and I might kill you.

  9. #9
    DF VIP Member Spennyboy's Avatar
    Join Date
    Sep 2003
    Location
    Stock Exchange
    Posts
    11,193
    Thanks
    221
    Thanked:        121
    Karma Level
    1113

    Default Re: Tale of a virus...

    Corp 10.2 i believe - would have to double check.

    Well i have plenty of infected USBs i could send you to try

    Chess.exe is some shitty p2p virus. Massive links to limewire, emule etc etc etc.

  10. #10
    DF VIP Member
    Nibb's Avatar
    Join Date
    May 2001
    Location
    Cymru
    Posts
    16,864
    Thanks
    554
    Thanked:        1,118
    Karma Level
    1743

    Default Re: Tale of a virus...

    Symantec...FFS m8, how long have you been on this forum!

    Its gotta be NOD32 & malwarebytes as a minimum!
    "Where you are is what you eat. When I'm in London I'll have beans on toast for lunch. On holiday � what? Tapas? Go on then I'll have a bit. You eat whatevers in that area"
    Karl Pilkington

  11. #11
    DF VIP Member
    tombott's Avatar
    Join Date
    Oct 2002
    Location
    Hereford
    Posts
    5,697
    Thanks
    507
    Thanked:        571
    Karma Level
    723

    Default Re: Tale of a virus...

    Quote Originally Posted by Spennyboy View Post
    Corp 10.2 i believe - would have to double check.

    Well i have plenty of infected USBs i could send you to try

    Chess.exe is some shitty p2p virus. Massive links to limewire, emule etc etc etc.
    lol, upgraded from that version two weeks ago.
    You got upgrade protection with Symantec?
    If so get the latest version down, it now includes Anti-Spyware, Firewall etc.
    Digital-Forums IRC Last.FM duckduckgo
    Guns don't kill people rappers do, I'm a fucking rapper and I might kill you.

  12. #12
    DF VIP Member Spennyboy's Avatar
    Join Date
    Sep 2003
    Location
    Stock Exchange
    Posts
    11,193
    Thanks
    221
    Thanked:        121
    Karma Level
    1113

    Default Re: Tale of a virus...

    Quote Originally Posted by Nibb View Post
    Symantec...FFS m8, how long have you been on this forum!

    Its gotta be NOD32 & malwarebytes as a minimum!
    Its at work mate, not my personal machine.

  13. #13
    DF VIP Member
    tombott's Avatar
    Join Date
    Oct 2002
    Location
    Hereford
    Posts
    5,697
    Thanks
    507
    Thanked:        571
    Karma Level
    723

    Default Re: Tale of a virus...

    Quote Originally Posted by Nibb View Post
    Symantec...FFS m8, how long have you been on this forum!

    Its gotta be NOD32 & malwarebytes as a minimum!
    Symantec Corp edition is a world away from the version 'home users' get, and I'd you'd be hard pushed to find better.
    Digital-Forums IRC Last.FM duckduckgo
    Guns don't kill people rappers do, I'm a fucking rapper and I might kill you.

  14. #14
    DF VIP Member Spennyboy's Avatar
    Join Date
    Sep 2003
    Location
    Stock Exchange
    Posts
    11,193
    Thanks
    221
    Thanked:        121
    Karma Level
    1113

    Default Re: Tale of a virus...

    Quote Originally Posted by tombott View Post
    lol, upgraded from that version two weeks ago.
    You got upgrade protection with Symantec?
    If so get the latest version down, it now includes Anti-Spyware, Firewall etc.
    Not sure i'll have to check exactly what were covered for - i believe our licence expired or is about to.

    Im off for a week now anyway so fuck it

    Roll on London

  15. #15
    DF VIP Member
    Nibb's Avatar
    Join Date
    May 2001
    Location
    Cymru
    Posts
    16,864
    Thanks
    554
    Thanked:        1,118
    Karma Level
    1743

    Default Re: Tale of a virus...

    Quote Originally Posted by Spennyboy View Post
    Its at work mate, not my personal machine.
    Quote Originally Posted by tombott View Post
    Symantec Corp edition is a world away from the version 'home users' get, and I'd you'd be hard pushed to find better.
    Fair enough then!
    "Where you are is what you eat. When I'm in London I'll have beans on toast for lunch. On holiday � what? Tapas? Go on then I'll have a bit. You eat whatevers in that area"
    Karl Pilkington

  16. #16
    DF Rookie allanj's Avatar
    Join Date
    May 2008
    Location
    st helens
    Posts
    16
    Thanks
    0
    Thanked:        0
    Karma Level
    194

    Default Re: Tale of a virus...

    Quote Originally Posted by Nibb View Post
    Symantec...FFS m8, how long have you been on this forum!

    Its gotta be NOD32 & malwarebytes as a minimum!
    I agree 100% also try "Trojan Remover"

Similar Threads

  1. nhl 2003 - razor - crack.exe is a script virus?
    By petegas in forum PC Gaming
    Replies: 1
    Last Post: 6th October 2002, 10:29 PM
  2. Virus Warning
    By sligoman in forum Digital Satellite TV
    Replies: 7
    Last Post: 6th October 2002, 02:50 PM
  3. The tale of sooty
    By skooby in forum Funny Pictures
    Replies: 6
    Last Post: 22nd September 2002, 09:29 PM
  4. a fishy tale
    By wonkyfox in forum Funny Pictures
    Replies: 5
    Last Post: 5th September 2002, 07:18 PM

Social Networking Bookmarks

Posting Permissions

  • You may not post new threads
  • You may not post replies
  • You may not post attachments
  • You may not edit your posts
  •