PDA

View Full Version : Virus how?


johnsmatrix
March 27th, 2004, 08:49 AM
I have been downloading movies and TV programs off of Kazaa and Ares. I've been haviing viruses pop up on my computer lately so I checked all file extentions ie: Avi, mpeg..... no .exe or anything wierd... I wake up this morning and i have 9 new viruses... mostly OBCD43EE.class and .exe trojan byte verify

Running XP with its firewall, and a 98 thru active X proxy....


Any idea's on this? I thought it was not possible to get viruses thru video's...

Omyn
March 27th, 2004, 09:29 AM
Well you probably executed a file like this.

RandomCopyrightedMove.avi.exe

If you have your windows set to dont show known file names it would appear like this:

"RandomCopyrightedMovie.avi"

Also have you applied the latest windows patches and what anti-virus programs do you have running?

downloadalot
March 27th, 2004, 09:33 AM
I've got this virus that would corrupt all my mp3s. They were all turning to script files of 11k. As I was opening folders and files, I could see right in front of my eyes, my winanp logos turning script. I made it worst by clicking few times and lost a portion of my mp3 collection. It was in the beginning of kazaa-morpheus. I think I got it from a video.

downloadalot
March 27th, 2004, 09:35 AM
I'm not an expert, but can't video files make you connect to a web site? From there, a virus could be downlaoded.

fireforce555
March 27th, 2004, 09:36 AM
I had one that was called Troj_Play.A. It was detected by housecall online scanner and killed easily. As of yet I have no idea what it could have done or how I got it. I wasnt using P2P in the days up to that and I scanned everyday so I just got infected apparently THAT day. I just dont know. Its the only virus I have ever had, knock on wood.

RACKnRAIL
March 27th, 2004, 10:31 AM
I have been downloading movies and TV programs off of Kazaa and Ares. I've been haviing viruses pop up on my computer lately so I checked all file extentions ie: Avi, mpeg..... no .exe or anything wierd... I wake up this morning and i have 9 new viruses... mostly OBCD43EE.class and .exe trojan byte verify

Running XP with its firewall, and a 98 thru active X proxy....


Any idea's on this? I thought it was not possible to get viruses thru video's...Scan the file before opening it and keep your AV/windows up-to-date at all times. As for the damage already done...I would try an online virus scan and/or go to Symantec's site for removal instructions. You more than likely got them as mentioned above movie.mpeg.exe or avi.exe, etc. Check the full extention before downloading.

shawners
March 27th, 2004, 01:28 PM
I had programs i download that would attach itself to the file, and then spread through the shared files directory.. Its often said that it would cause programs not to run normal, and wont work properly.. I never had an infected movie file.

Miniver
March 27th, 2004, 02:11 PM
There have been a few threads about this b4. I'd just like to say this. Media files cannot contain viruses. Yes they can bring up browser windows through which feasibly you could get a virus through some new exploit, but they themselves can never be viruses and can never contain them. It's simply this, a virus needs to be executed, without the proper extension this will not happen. As omyn said if windows is not displaying all file extensions you could foolishly execute a virus by clicking an apparently innocuous file. This is because it does have an executable extension it is just hidden from your view, not windows'.

johnsmatrix
March 27th, 2004, 05:51 PM
Ok, I'm using Norton Antivirus...

1. I look at the extentions in kazaa, no .exe..........

2. I download a few shows... no programs that i know of

3. go to bed

4. Wake up and click ok on 9 norton quarantined virus notifications..

5. Delete viruses and watch video....


It happens every night..... I cant figure it out....

It's not from email and norton always does a great job at real time action for viruses....

crackerjacker
March 27th, 2004, 06:07 PM
There is this free program that I use. Its called script defender and its a freeware program.
I suggest you go to this site to read more about it.
http://www.analogx.com/contents/dow...tem/sdefend.htm (http://www.analogx.com/contents/download/system/sdefend.htm)

It intercepts certain file types and prevents them from running on your computer. You can always undue the script defender if you need a file type on your computer. Like I said its free. try it
__________________

Heres more information about it.
I'm sure that by now everyone has heard about email viruses; most people probably have either experienced one themselves or know someone who has. The latest batch of viruses have become more adept than ever at getting people to execute them unintentionally - that's where AnalogX Script Defender comes in!
AnalogX Script Defender will intercept any request to execute the most common scripting types used in virus attacks, such as Visual Basic Scripting (.VBS), Java Script (.JS), etc and can even be configured to intercept new script extensions as needed! It's very simple to use and helps to ensure that you do not inadvertently run a script no matter what email program you use, or even if you get it via another method.

johnsmatrix
March 27th, 2004, 08:11 PM
I'll try it but letme tell you.. I just cleared all temp files, cache, etc..
I have kazaa open and area but im not downloading and have sharing disabled.
I'm talking to my friend on the phone and then boom again...
Norton has found OPENME.exe and spybot worm blahh,,,,...

dj blunt man
March 28th, 2004, 04:09 AM
I've had the same problem in the past, i reformatted and still the virus remained. check that extra hdd's on your computer don't contain the virus, and secondly check your other networked computer for the virus with norton. I had the same problem with blaster worm a few months back and it took ages for me to work the thing out. good luck :aim

Miniver
March 28th, 2004, 05:45 AM
Make sure that u are not sharing your folder through windows file sharing

johnsmatrix
March 28th, 2004, 09:54 AM
Ok, I do have a networked cpu and i do share a folder so last night...

I turned off the network cpu
and turned off and p2p software..
I have 1 hard drive...

Then boom All these viruses( 13 to be exact) pop up at 8:18am this morning. ...I went to bed at 1 am so I wonder if there is something on my system that is phoning out and downloading these things... I will try spy bot and adaware i guess... Zonealarm is blocking all non essential ports...

johnsmatrix
March 29th, 2004, 09:52 AM
Today, 15 viruses detected...Again at 8:26 am same time as before...I ran spybot and adware...any clues?

Greylin
March 29th, 2004, 11:15 AM
I would disable my connection to the network and the internet overnight. If you still get Norton popping up telling you that you have "x" amount of virii then try out two programs Trojan Defense Suite (http://tds.diamondcs.com.au/) and Wormgaurd (http://wormguard.diamondcs.com.au/).

broadwayrock
March 29th, 2004, 03:19 PM
Its seems your main problem is kazaa.

Its like playing russian roulette whenever you download.

I agree with Greylin about trying TDS. You will need a seperate anti trojan app alongside a antivirus app, this is because antivirus programs tend to focus on viruses and the well known trojans.

PestPatrol is another good app.

You can never have enough protection when using kazaa.