Infected!

Please use this forum for general discussions or questions related to Carvoeiro life ONLY
Ellie
CVO Oracle
CVO Oracle
Posts: 8886
Joined: Thu Jan 22, 2004 5:16 pm
Location: Londoner in the Wolds,Lincs
Contact:

Infected!

Post by Ellie »

Not me but my P.C! :(
Computer mechanic came today and has just carted off the 'tower'....found over 400 files infected with I-WORM/BAGLE.Q(he said he'd never seen it before..completely new to him)and hes an expert of years experience and gives advice on radio programme too....it even stopped the AVG working.....
He said its worse hes seen..previous one being 96 files
He hopes to save my document files if not infected..but all else will be lost!
Im not a happy bunny this morning and feel enraged at the 'infection/the people who do this,theyre the real 'infection' :x :evil:
i had trouble sending my work this week..publisher said it was probably Trojan horse worm....got rid of that..and work went off ok yesterday..thank God & all saved.
The Computer chap said business colleague of his had his p.c gutted last week..lost everything ....
and recently the National Coastguards system was put out of action...terrible isnt it..that there evil people who get their kicks out of this sort of thing :?: My troubles are small compared to this.
Im so grateful I have my laptop to continue working on..and to stay in touch on here :)
Hope you're having a better day than me so far!
Guest

Post by Guest »

Hi Ellie
You are having a bad day aren't you?. Hope it improves soon.
I know little about computers but isn't that why we pay for antivirus software to stop this kind of thing happening, I know you've got it.
Did the repairman give any clues as to where it had come from?

Cheer up, go and plant a bush

Tricky
Guest

Post by Guest »

well just shows the stupidity of modern life in relying on computers..there is a large builders merchants in messines.with 25 vehicles and about 30 staff and NOT one computer in the place..and guess what? it all works wonderfully..always next day delivery and no confusion about the order.

i wonder how did business survive before computers????
Ellie
CVO Oracle
CVO Oracle
Posts: 8886
Joined: Thu Jan 22, 2004 5:16 pm
Location: Londoner in the Wolds,Lincs
Contact:

Post by Ellie »

Well..thanks a bundle Guest...thats helped& cheered me up no end :x
Fortunately( or as you see it) unfortunately..the computer world is a way of life now......
and though I do a great deal of work the hard way/long hand..Im grateful I can send my work in this way and have online facilities for research...and don't forget..if we didn't have this..there would be no CVO.COM...and all the good stuff it brings with it...making friendships for example.
I was very hesitant about 2 years ago ..in using a p.c..having only used electric typewriter then wordprocessor....but I wouldnt want to go back to that now.....
and living a rural life..I love the fact that I can log on..and instantly be in touch with the world at large..well Algarve world :)
for that..Im grateful
and the way our postal systems becoming..certainly wouldnt want to rely on that anymore :roll:
P.S. couldnt plant a bush or anything today....heavy rain/storms :(
don't use computers in my line of business..but weather dictates!
Lesley Jean
CVO Legend
CVO Legend
Posts: 4118
Joined: Tue Feb 24, 2004 4:07 pm
Location: Somerset. and Lombos
Contact:

Post by Lesley Jean »

:lol: Hi Ellie, like you I am new to computers and still trying to get the hang of them. But I do find them invaluable for research and information, what is so wrong in a buisness keeping up with modern life and using a computer? We can't go back to the 'old days' or we will be in a state of confusion!
Guest, if a company does not want to use a computer and would rather use pen and paper then fine, but those who do have the ability to, do a lot more buisness, thereby employing more people and helping to keep the ecconomy going in their area.
Hope your day has ended better than it started Ellie, and boy, I don't know about where you are, but have we had rain and strong winds down here in Somerset, we have had trees down and lanes blocked, just like winter again, gone are the t shirts and back on with jumpers. Oh to be in Portugal!! 8)
Ellie
CVO Oracle
CVO Oracle
Posts: 8886
Joined: Thu Jan 22, 2004 5:16 pm
Location: Londoner in the Wolds,Lincs
Contact:

Post by Ellie »

Evening Lesley..and thanks for a sympathetic ear :)
well....computer fella had to strip it all down....lost quite a bit of stuff...including a couple big excerpts from my book (docus & floppy discs infected)...which has left me a bit down tonight. I do have them printed off but don't relish re-typing 12,500 words :(
so had to send to publishers..for them to send copies back to me for my own records.
What with that and the weather :shock: Been same here Lesley....I got caught out in bad storm.....in countryside....fled into nearest store of tescos....where bad lightning caused blackouts....lord what a day..should have stayed in bed!
Sounds worse in west country....you say youve had trees ripped up :shock: ......lord my Sept. CVO hol seems an awful long way off :cry:
But they say itll be warming up by Friday :)
petermeachem
CVO Senior
CVO Senior
Posts: 253
Joined: Thu Oct 09, 2003 10:32 am

Post by petermeachem »

I know virii are a pain and I'm very sympathetic, but...
This virus has been around since March 18 and so should be picked up by any decent AV programme. Which programme do you use and are the definitions up to date?
tricky
CVO Legend
CVO Legend
Posts: 3054
Joined: Mon Jun 02, 2003 11:05 pm
Location: Cheshire & Mateo serro

Post by tricky »

Hiya, don't want to rub it in, Ellie & Lesley Jean
but I'm off to CVO in the morning for four computer-free days
(even better, child free days as well)
Will be thinking of you when I'm sat on the beach....in the sun.....

Bye
Tricky
SHOWWWY

Post by SHOWWWY »

Sorry to hear about your virus Ellie.

AVG is reputed to be a good program. I have used it for years on my other PC. But, of course, it does have to be updated. And lately the updates have been coming quite frequently.

Oh well, that's modern life isn't it! First, robots in the super, now little green meanies in the PC. :shock:

For those of you who may be interested, a good site for keeping up to date on security issues and other stuff too is:

http://forums.techguy.org/

A good free firewall is zone alarm

8)
Ellie
CVO Oracle
CVO Oracle
Posts: 8886
Joined: Thu Jan 22, 2004 5:16 pm
Location: Londoner in the Wolds,Lincs
Contact:

Post by Ellie »

Hi Peter,
Its Windows 2000....and hes installed AVG 6 today.
I wonder how he hadnt heard of that one if its been around since March?
Should I get a more up to date mechanic next time d'you think? :)
P.S. Hows the house coming along?
SHOWWWY

Just in case your mechanic needs help

Post by SHOWWWY »

# To manually delete WORM_BAGLE.X entries on the computer:

1. Terminating the malware program:

1. Open Windows Task Manager:

On Windows 95/98/ME systems, press CTRL+ALT+DELETE.
On Windows NT/2000/XP systems, press CTRL+SHIFT+ESC, then click the Processes tab.

2. In the list of running programs, locate the Drvsys.exe process.

3. Select the detected file, then press either the End Task or End Process button, depending on the version of Windows on your system.

4. To check if the malware process has been terminated, close Task Manager, and then open it again.

5. Close Task Manager.

2. Removing autostart entries from the registry:

Important: Before editing the registry, make sure you understand how to restore it if a problem occurs. For more information, view the Restoring the Registry Help topic in Regedit.exe or Restoring a Registry Key Help topic in Regedt32.exe. Making incorrect changes to your registry can cause serious system problems. Always make a backup copy before making any registry changes.

1. Click the My Computer icon on the desktop.

2. Go to the %Windows% folder and right-click the Regedit.exe file.

Note: %Windows% is the Windows folder, which is usually C:\Windows or C:\WINNT.

3. In the left panel, double-click the following:

HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run

4. In the right panel, locate and delete the entry:

Drvsys.exe = "%System%\ Drvsys.exe"

Note: %Windows% is the Windows folder, which is usually C:\Windows or C:\WINNT.

5. In the left panel, double-click the following:

HKEY_USER\.DEFAULT\Software\MicrosoftWindows\CurrentVersion\Run

6. In the right panel, locate and delete the entry:

Drvsys.exe = "%System%\ Drvsys.exe"

Note: %Windows% is the Windows folder, which is usually C:\Windows or C:\WINNT.

7. Close Registry Editor.

Note: If you were not able to terminate the malware process from memory as described in the previous procedure, restart your system.

3. Deleting a malware file:

1. Left-click Start then click Search… or Find… depending on your version of Windows.

2. In the Search for files or folders named: box, locate the files detected with WORM_BAGLE.X.

3. In the Look In drop-down list, select the drive which contains Windows, then press Enter.

4. Once located, select the files then hit Delete.
Ellie
CVO Oracle
CVO Oracle
Posts: 8886
Joined: Thu Jan 22, 2004 5:16 pm
Location: Londoner in the Wolds,Lincs
Contact:

Post by Ellie »

Iwas going to say good evening SHOWWWY..or is it afternoon where you are..its nearly half midnight here :)
Well..he put AVG 6 on today..is that the latest?
and thanks for the website !
Getting some shut eye now..its been a loooonng day.....
Boa noite all :)
P.S have a great time Tricks....and dont forget to bring some sunshine back with you flower :)
SHOWWWY

FYI

Post by SHOWWWY »

This advice is reposted from the advice given by Tony Klein, the acknowledged spyware & malware expert who supports many forums on the net.

I have added a few minor updates to it

You usually get infected because your security settings are too low.

Here are a number of recommendations that will help tighten them, and which will contribute to making you a less likely victim:

1) Watch what you download!
Many freeware programs, and P2P programs like Grokster, Imesh, Kazaa and others are amongst the most notorious, come with an enormous amount of bundled spyware that will eat system resources, slow down your system, clash with other installed software, or just plain crash your browser or even Windows itself.

2) Go to IE > Tools > Windows Update > Product Updates, and install ALL Security Updates listed.
It's important to always keep current with the latest security fixes from Microsoft. Install those patches for Internet Explorer, and make sure your installation of Java VM is up-to-date. There are some well known security bugs with Microsoft Java VM which are exploited regularly by browser hijackers.

3) Go to Internet Options/Security/Internet, press 'default level', then OK.
Now press "Custom Level."
In the ActiveX section, set the first two options ("Download signed and unsigned ActiveX controls) to 'prompt', and 'Initialize and Script ActiveX controls not marked as safe" to 'disable'.

Now you will be asked whether you want ActiveX objects to be executed and whether you want software to be installed.
Sites that you know for sure are above suspicion can be moved to the Trusted Zone in Internet Option/security.

So why is activex so dangerous that you have to increase the security for it?
When your browser runs an activex control, it is running an executable program. It's no different from doubleclicking an exe file on your hard drive.
Would you run just any random file downloaded off a web site without knowing what it is and what it does?

And some more advice:

4) Install Javacool's SpywareBlaster It will protect you from all spy/foistware in it's database by blocking installation of their ActiveX objects.
Download and install, download the latest updates, and you'll see a list of all spyware programs covered by the program (NOTE: this is NOT spyware found on your computer)
Press "select all", then "kill all checked", and you're done.
The spyware that you told Spywareblaster to set the "kill bit" for won't be a hazard to you any longer.
Although it won't protect you from every form of spyware known to man, it is a very potent extra layer of protection.
Don't forget to check for updates every week or so.

Let's also not forget that SpyBot Search and Destroy has the Immunize feature which works roughly the same way.
It can't hurt to use both.

5) Another brilliant program by Javacool we recommend is SpywareGuard.
It provides a degree of real-time protection solution against spyware that is a great addition to SpywareBlaster's protection method.

An anti-virus program scans files before you open them and prevents execution if a virus is detected - SpywareGuard does the same thing, but for spyware! And you can easily have an anti-virus program running alongside SpywareGuard. It now also features Download Protection and Browser Hijacking Protection!

6) IE-SPYAD puts over 5000 sites in your restricted zone, so you'll be protected when you visit innocent-looking sites that aren't actually innocent at all.

7) The IE hosts file blocks ads, banners, cookies, web bugs, and even most hijackers. This is accomplished by blocking the Server that supplies these little gems.
Example - the following entry 127.0.0.1 ad.doubleclick.net blocks all files supplied by the DoubleClick Server to the web page you are viewing. This also prevents the server from tracking your movements.It Now includes most major parasites, hijackers and unwanted Search Engines!
In many cases this can speed the loading of web pages by not having to wait for these ads, banners, hit counters, etc. to load.
This also helps to protect your Privacy by blocking servers that track your viewing habits, known as "click-thru tracking".

However as time has progressed the focus of this project has changed from blocking ads/banners to protecting the user from the many parasites that now exist on the Internet. It doesn't serve much purpose if you block the ad banner from displaying, but get hijacked by a parasite from an evil script or download contained on the web site. The object is to surf faster while preserving your Safety, Security and Privacy.

Incidentally, another site with an enormous amount of information on computer security, and which is well worth a visit is http://www.wilders.org/

Finally, after following up on all these recommendations, why not run Jason Levine's Browser Security Tests.
They will provide you with an insight on how vulnerable you might still be to a number of common exploits.

And make sure your Antivirus and firewall is switched on and kept updated
__________________
Derek

My new website http://www.thespykiller.co.uk contains up to date versions of Hijackthis & cwshredder and other useful downloads

If I have helped you with your problem, please help me with the Hedgehog Rescue centre. We urgently need donations to stay running.
http://www.thehedgehog.co.uk
Gerry Cullen
CVO Master
CVO Master
Posts: 774
Joined: Thu Jan 16, 2003 12:39 am
Location: Southern Ireland

Post by Gerry Cullen »

having just read through this post i am thinking to my self would it not be a good idea if users of this site posted perhaps areas of expertise on which they could be contacted when all else fails...eg ellie say on gardening...im not suggesting we could all badger the bejaysus out of someone in lieu of paying for professional advice..but im sure if i asked ellie for a bit of advice on what to plant under a large shady laural tree she would...if she had time..be happy to reply.If i had known of showwwys interest i could have saved myself hours of sleepless prowling.... sat afternoon whilst trying to clear away all the crap ,branches etc from under a recently trimmed laural tree we cane across a hedgehog snuggled under the leaves not only that but with baby in tow...we kept an eye on the pair all day and when i got in from work that nite went to check up only to find mammy gone ..not to worried.. but by noon next day baby still alone ..got a tad concerned..that nite still no show and at this stage searching the garden with torches...anyway between the jigs and the reels tues morn baby also gone...found out from a mate this morning all this is quite normal... wish id known sat nite...anyway just a thought...oh and by the way thanks for the info on the viruses and worms and stuff.
gerry
Guest

Post by Guest »

Yeah youre right Gerry...that you can get so much help here whatever the problem..gteat isnt it?
Im no expert believe me...just a jobbing gardener..and awful lot I dont know & yet to learn..and you can never know it all :)
I dont as a rule plant under trees..I keep the ground clear about a foot radius...but you cant go wrong with bulbs..whatevers your favourite...and plants like hostas do well in shady spots....
But in saying that..I do have a little wooded corner..where I plant bluebells and violets etc.
What sort of laurel is it...cherry ?
Love the story of the hedgehog! :)
P.C going ok..just about..but have feeling will have to fork out for new one soon!
Post Reply