• If you would like to get your account Verified, read this thread
  • Check out Tickling.com - the most innovative tickling site of the year.
  • The TMF is sponsored by Clips4sale - By supporting them, you're supporting us.
  • >>> If you cannot get into your account email me at [email protected] <<<
    Don't forget to include your username

Info and safeguards for the current virus going around

TicklingDuo

3rd Level Yellow Feather
Joined
Oct 23, 2001
Messages
3,733
Points
0
As I posted last evening, we have again been infected by the virus that's going around. I'm about to wipe my system again. But, before I did, I went through and did some exploring, both of security sites and my own system. I thought I'd share what I discovered so that others may benefit from it and help prevent infection of other systems.

What we've learned about the virus....

1) It morphs (changes itself) to avoid detection by antivirus software. Our scan comes up clean. Yet, we can see that it's there doing damage, updating itself and sending itself out.

2) It mails itself out to people in your addres book. This can either show up as being from you or from someone else in your address book.

3) It can change your firewall settings. We had everything blocked and it no longer is. Access was reopened to those programs that it morphed into.

4) It creates duplicates of exe programs and uses them to update and spread itself...(IE, RealPlayer, Microsoft Word, etc.).

5) It attaches itself at random to files being sent via e-mail and FTP (including forwarded mail).

6) It reopens or creates new ports to use as a backdoor for internet access.

I'm sure there is much more we'll find out about this damned thing. But, that's what we've learned so far...after having been infected 4 times now!

Here are some safeguards that are recommended to help stem the spread of the virus...

1) Eliminate your active addres book. Save your necessary addresses to a text file from which you can get them when you need them. It's an inconvenience, but keeps it from spreading through you to your online contacts.

2) Do not upload or e-mail files to others unless you absolutely have to. If you really have to send a file out, note the exact size of the file in the description or within the test of the e-mail and instruct the recipient to not open it unless the size matches what's shown.

3) Even if an e-mail appears to be from someone you know, don't open any files unless you know they sent it to you. Set the e-mail aside and check first if you aren't sure.

4) Come up with a "code" that can be put in the subject line of all e-mails you send out. For example...put "!" in front of the subject. Then, let everyone you send mail to know to delete (without opening) any mail from you that does not have that code in it. The simple act of opening the e-mail can release this virus into your system with no outward appearance of anything being wrong.

5) Eliminate the remote access option on your system. This can be used by the virus to access your computer from outside OR access other computers from your own system.

6) For site owners - Check your sites on a regular basis to be sure that a file hasn't been changed since you put it up.

7) For those with firewalls (hopefully everyone) re-check your settings daily to be sure they haven't been changed to lower your defenses. Disable all unused ports and keep watch for new ones showing up. (maiking a note of which programs use which ports by default will aid in this.)

BTW....the only way to get this damned thing off your system is to wipe and reformat your harddrive. The security systems haven't come up with anything to fix it yet because of the fact that it morphs. So, if you think you're infected, wipe and reformat.

(As Venray has now posted below, symantec fiinally came up with a possible fix for this thing. So, wiping may now prove unnecessary. See his link for more info.)

OK, that's it for now. I hope this information helps. If we all pay attention and use the safeguards, maybe we'll finally beat this stupid thing!

Ann
 
Last edited:
Hmmm...Wonder if this was the cause of my meltdown last month...Thx, Duo.

Rxx
 
It morphs?This sounds like the IT equivalent of the AIDS virus.😡
 
Another problem is that this virus can attach itself to web pages and
spread through that method as well. Looking into some detection methods that may help.

Ven
 
ANN!

Thanks so much for sharing your wisdom.

Some people are just worthless. Too much time on their hands or SOMETHING. I can't believe you've been through this 4times. Bless your heart!!

Good luck..and again MANY thanks!
Joby
 
JoBelle said:
ANN!
Thanks so much for sharing your wisdom.
Some people are just worthless. Too much time on their hands or SOMETHING. I can't believe you've been through this 4times. Bless your heart!!
Good luck..and again MANY thanks!
Joby

Thanks Joby! Actually, other than proving to be a general nuissance and causing more work, we haven't lost anything that can't easily be replaced. In one respect, we should thank this jerk for helping us learn so much about security and viruses. Ray and I have been combining our efforts accross the board and connecting with others to help inform people (if they'd read the damned posts!) and help stop this thing in it's tracks. It's going to take EVERYONE paying attention and watching out for this thing in order to stop the spread. I can clean my system 10 times a day and still have to do it again because so many people are unwittingly sending it back in e-mails and infected sites. We WILL prevail, however!!!

Ann
 
Got that right sweetie.......

We will......
 
Evil vs Good

I always forget...which team am I on now?

ALD.gif
 
Higher Powers?

As long as you don't count on divine intervention ONLY...sometimes even higher powers may need you to do a few basic things...lol. Sounds like you're tightening up nicely though. Woe to the next attacker....

flameon.gif
 
Each attempt brings us closer and closer too............

hanged.gif
*

Ven *No smileys or emoticons were actually harmed in the creation of this thread*
 
Last edited:
You're silly..lol..

dragonball-wishdragon.gif


Here...replace that snake with something with a bit more ooomph..

browsmiley.gif
This smilie is my personal caricature...amazing resemblance to me. Q
 
Re: Oomph huh......

venray1 said:

Ha! That's just a spider..that dragon, though, isn't called the Eternal Dragon for nothin. He'd eat your itsy, bitsy spider. lol
 
Re: Re: Oomph huh......

jason19tk said:


Ha! That's just a spider..that dragon, though, isn't called the Eternal Dragon for nothin. He'd eat your itsy, bitsy spider. lol

Nah its a deadly tarantula which could creep under even that dragons defenses and kill it with one bite...the subtle approach..

Ven
 
What's New

2/24/2025
Visit the TMF Welcome Forum and say hello!
Door 44
Live Camgirls!
Live Camgirls
Streaming Videos
Pic of the Week
Pic of the Week
Congratulations to
*** brad1701 ***
The winner of our weekly Trivia, held every Sunday night at 11PM EST in our Chat Room
Back
Top