PDA

View Full Version : Re: I do but don't have a virus, what's up?


Steve N.
February 10th 04, 03:43 PM
The alert clearly shows there was an infected .tmp file on your local
drive. I recommend using Mailwasher to delete/bounce suspicious email at
the server BEFORE it gets dl'd to your local drive. That will also speed
up you getting the mail you do want by eliminating all the crap.

Steve

mmm, Pie wrote:
> LOL yeah, no nudity on that site there heh.
>
> I never use system restore, so yes, it IS turned OFF.
>
>

mmm, Pie
February 10th 04, 06:25 PM
Okay thanks, i'll check it out. The e-mails are just piling up and I really
gotta download em.

I'll let you know what's up.

mmm, Pie
February 10th 04, 07:06 PM
Sweet, it worked perfectly. Does the whole bouncing thing really work
though? I mean, have you noticed less spam because of it? I'm just a little
skeptical that it really works.

Steve Nielsen
February 10th 04, 07:22 PM
Cool, glad to hear it helped.

It may take a while for the spambots to nuke your address from their DBs
but yeah it should help cut it down some. Some won't ever give up but
there's nothing you can do about that short of getting a new email
address and NEVER using it online and ONLY give it to those you really
want mail from and pray they practice safe computing, too.

Steve

mmm, Pie wrote:

> Sweet, it worked perfectly. Does the whole bouncing thing really work
> though? I mean, have you noticed less spam because of it? I'm just a little
> skeptical that it really works.
>
>

mmm, Pie
February 10th 04, 08:44 PM
Yeah, I know the routine, my personal e-mail is pretty good, considering
it's ahotmail account too, I only get a couple of spams a week. I used to
give the addy out like crazy since I had an account with my ISP, but it
turned out my ISP sold their lists and I got unbelievable amounts of spam on
it unlike my hotmail which I was giving out as my potential spam account :)

thanks again.

mmm, Pie
February 10th 04, 10:04 PM
Okay, the mail washer program is great and all, but I already have a good
working spam filter locally. I know I'm gonna get spam, so I'm not too
worried about bouncing and stuff. I'm still getting the virus alert error,
and it is not downloading my messages still. The MW was a cool quick
solution, but why all of a sudden did this start happening? is the mydoom
worm affecting server side downloads or what? Why is it preventing me from
downloading my messages?

Steve Nielsen
February 10th 04, 11:22 PM
Of course Mailwasher won't prevent you from downloading another infected
message and getting re-infected. That suggestion was soley to get your
server-side junk messages cleared up before downloading the whole
shebang all over again.

If it's the same NAV alert that you posted before then you are getting
re-infected.

Try using a mail program other than Outlook and see what happens. I
don't use Outlook, however I recall reading that with some infected
emails merely having the preview pane enabled and clicking on a message
can infect the machine.

Steve

mmm, Pie wrote:

> Okay, the mail washer program is great and all, but I already have a good
> working spam filter locally. I know I'm gonna get spam, so I'm not too
> worried about bouncing and stuff. I'm still getting the virus alert error,
> and it is not downloading my messages still. The MW was a cool quick
> solution, but why all of a sudden did this start happening? is the mydoom
> worm affecting server side downloads or what? Why is it preventing me from
> downloading my messages?
>
>

mmm, Pie
February 11th 04, 12:42 AM
Yeah, well I never use the preview pane. I think I'll head over to the
outlook forums and go from there.

thanks, atleast there's mail washer for now :)

Steve Nielsen
February 11th 04, 01:03 AM
Ok, that was just a thought.

It still seems to me that somehow the infection keeps recurring or NAV
would not keep giving that alert and that needs to be addressed. How is
the virus getting back in?

Not meaning to be insulting but I presume you have read how mydoom
infects haven't you?

Steve

mmm, Pie wrote:

> Yeah, well I never use the preview pane. I think I'll head over to the
> outlook forums and go from there.
>
> thanks, atleast there's mail washer for now :)
>
>

Rod Potter
February 11th 04, 08:01 AM
Steve and MMM: Sometimes it also resides as part of system restore, then
you have to turn system restore off, reboot to clear all sys rest files,
then turn sys res back on again.
"Steve Nielsen" > wrote in message
...
> Ok, that was just a thought.
>
> It still seems to me that somehow the infection keeps recurring or NAV
> would not keep giving that alert and that needs to be addressed. How is
> the virus getting back in?
>
> Not meaning to be insulting but I presume you have read how mydoom
> infects haven't you?
>
> Steve
>
> mmm, Pie wrote:
>
> > Yeah, well I never use the preview pane. I think I'll head over to the
> > outlook forums and go from there.
> >
> > thanks, atleast there's mail washer for now :)
> >
> >
>

kurttrail
February 11th 04, 10:23 PM
mmm, Pie wrote:

> Okay, right when I clicked send receive in outlook I got that alert
> again so yeah, it's something to do with the e-mail. And that's gotta
> be part of the reason it's taking so long to try and download
> messages.
>
> Here's a snap of the nav alert
>
> http://www.wowcentral.com/random/nav_alert.gif

http://www.sophos.com/support/disinfection/mydooma.html

http://vil.nai.com/vil/stinger/

http://www.europe.fsecure.com/v-descs/novarg.shtml#disinf

http://www.microsoft.com/downloads/details.aspx?FamilyID=c14bfbe4-3d50-464d-a26c-9c287f8a08c5&displaylang=en

Here is a list of different MyDoom removal tools, but follow the
instructions very carefully.

--
Peace!
Kurt
Self-anointed Moderator
microscum.pubic.windowsexp.gonorrhea
http://microscum.com
"Trustworthy Computing" is only another example of an Oxymoron!
"Produkt-Aktivierung macht frei!"

kurttrail
February 12th 04, 12:22 PM
mmm, Pie wrote:

> Oh, about the e-mails scanning, this is an entirely different message
> then normal.
>
> I always have it scanning e-mails but I have it on silent delete mode
> so I don't have to tell it what to do for each e-mail.
>
> This message that I'm receiving is in a red window and the only
> option is okay or the x on the top right corner.
>
> My friends and I joke about this all the time...
>
> [norton antivirus 2003] [X]
> /!\ NAV has detected a virus on your system.
> [OK][Cancel]
>
> It's like, great! maybe if I click cancel it will go away? : P

When you ran the Tool from Symantec, did you disable the System Restore
feature in Windows XP?

--
Peace!
Kurt
Self-anointed Moderator
microscum.pubic.windowsexp.gonorrhea
http://microscum.com
"Trustworthy Computing" is only another example of an Oxymoron!
"Produkt-Aktivierung macht frei!"

Steve Nielsen
February 12th 04, 05:44 PM
Rod,

Earlier in the thread OP said he never uses system restore and it is
turned off.

Steve

Rod Potter wrote:
> Steve and MMM: Sometimes it also resides as part of system restore, then
> you have to turn system restore off, reboot to clear all sys rest files,
> then turn sys res back on again.
> "Steve Nielsen" > wrote in message
> ...
>
>>Ok, that was just a thought.
>>
>>It still seems to me that somehow the infection keeps recurring or NAV
>>would not keep giving that alert and that needs to be addressed. How is
>>the virus getting back in?
>>
>>Not meaning to be insulting but I presume you have read how mydoom
>>infects haven't you?
>>
>>Steve
>>
>>mmm, Pie wrote:
>>
>>
>>>Yeah, well I never use the preview pane. I think I'll head over to the
>>>outlook forums and go from there.
>>>
>>>thanks, atleast there's mail washer for now :)
>>>
>>>
>>
>
>

Steve Nielsen
February 15th 04, 04:22 PM
Hehheh... our school district has internet filtering:

"You cannot access the following Internet address:
http://www.wowcentral.com/random/nav_alert.gif

The site you requested is blocked under your organization's filtering
policy. It fits into the following filtering category(ies) that your
organization has chosen to block:
Nudity"

Not to be alarmed though - it often spits out false alarms. I'll check
out the screen shot from home.

Steve

mmm, Pie wrote:
> Okay, right when I clicked send receive in outlook I got that alert again so
> yeah, it's something to do with the e-mail. And that's gotta be part of the
> reason it's taking so long to try and download messages.
>
> Here's a snap of the nav alert
>
> http://www.wowcentral.com/random/nav_alert.gif
>
>

Google