Club Cobra Keith Craft Motorsports  

Go Back   Club Cobra > Cobra Talk Areas > ALL COBRA TALK

Keith Craft Racing
Nevada Classics
MMG Superformance
Main Menu
Module Jump:
Nevada Classics
Nevada Classics
MMG Superformance
Advertise at CC
Banner Ad Rates
MMG Superformance
Keith Craft Racing
MMG Superformance
January 2025
S M T W T F S
      1 2 3 4
5 6 7 8 9 10 11
12 13 14 15 16 17 18
19 20 21 22 23 24 25
26 27 28 29 30 31  

Kirkham Motorsports

Reply
 
LinkBack Thread Tools Display Modes
  #1 (permalink)  
Old 01-26-2004, 05:20 PM
mrmustang's Avatar
CC Member/Contributor
Visit my Photo Gallery
Gold Star Contributor
 
Join Date: Feb 2000
Location: Greenville, SC
Cobra Make, Engine: 70 Shelby convertible, ERA-289 FIA, 65 Sunbeam Tiger, mystery Ford powered 2dr convertible
Posts: 12,734
Not Ranked     
Exclamation Update Your Virus Definitions!!!!!!

Ok Folks, you've got a great computer, have your anti virus software installed, but when is the last time you forced an update of your system software????? Today I've noticed a significant increase in the spam and virus filled emails two of my open accounts receive. Just downloaded 2.68 megs of new virus definitions this evening (and I had just done an update on Friday of last week). So just a friendly warning, no matter how good a piece of software is, if you do not constantly seek available updates (check at least once a week), your leaving your computer open to a wide assortment of new bugs and viruses currently out on the web...................

Hope some of you find this helpful.

Sincerely,

Bill S.
Reply With Quote
  #2 (permalink)  
Old 01-26-2004, 05:33 PM
Chaplin's Avatar
Senior Club Cobra Member
Visit my Photo Gallery

 
Join Date: Mar 2002
Location: God's country, ME
Cobra Make, Engine: Original ERA 427sc, Powered by Gessford
Posts: 2,678
Not Ranked     
Default

I don't think I'm running any anti-virus software . What do you guys suggest? Also, will any of it cut down on pop ups? I seem to be inundated with pop ups lately. I downloaded one of the free pop of blockers, which is a temporary fix (it expires in 30 days unless I buy it), but need something better long term.
__________________
Replica is not a dirty word.

"If you can't be a good example, then you'll just have to be a horrible warning."
Reply With Quote
  #3 (permalink)  
Old 01-26-2004, 05:44 PM
mrmustang's Avatar
CC Member/Contributor
Visit my Photo Gallery
Gold Star Contributor
 
Join Date: Feb 2000
Location: Greenville, SC
Cobra Make, Engine: 70 Shelby convertible, ERA-289 FIA, 65 Sunbeam Tiger, mystery Ford powered 2dr convertible
Posts: 12,734
Not Ranked     
Default

Chaplin,

Send me an email.


Bill S.
__________________
Instead of being part of the problem, be part of a successful solution.

First time Cobra buyers-READ THIS
Reply With Quote
  #4 (permalink)  
Old 01-26-2004, 05:56 PM
CC Member
Visit my Photo Gallery

 
Join Date: Jul 2002
Location: rocky river, Oh
Cobra Make, Engine: Unique 289FIA / SA 351W / a truly glorious machine
Posts: 3,949
Not Ranked     
Default

Bill,

I just started getting back e-mails that were undeliverable that I didn't send.....
Just started within the last three hours....
Got a strange e-mail that I was hesitant to open but the name sounded somewhat familiar and I went for it... against my better judgement...
Let's see what I have on my machine tomorrow a.m....

Any help on updates would be appreciated.
Reply With Quote
  #5 (permalink)  
Old 01-26-2004, 06:08 PM
computerworks's Avatar
Senior Club Cobra Member
Visit my Photo Gallery
Lifetime Contributor
 
Join Date: Mar 2001
Location: Northport, NY
Cobra Make, Engine: Kirkham, KMP178 / '66 GT350H, 4-speed
Posts: 10,362
Not Ranked     
Default

At this point, there is no need to go crazy about new definitions...although if you have AV software, you should be doing live updates on a regular basis...

What you are experiencing is a new mass-mailing worm called W32.Novarg.A@mm. It was discovered today and more info is coming as we speak.

THE KEY THING TO LOOK FOR is an attachment that is 22k in size; it may be a .bat, .cmd, .exe, .pif, .scr, or .zip file.

It also may look like a returned-undeliverable e-mail.

The subject of the e-mail may be one of these:
-test
-hi
-hello
-Mail Delivery System
-Mail Transaction Failed Server

Just delete it ...don't peek at the attachment...and you will be fine.
Reply With Quote
  #6 (permalink)  
Old 01-26-2004, 06:10 PM
computerworks's Avatar
Senior Club Cobra Member
Visit my Photo Gallery
Lifetime Contributor
 
Join Date: Mar 2001
Location: Northport, NY
Cobra Make, Engine: Kirkham, KMP178 / '66 GT350H, 4-speed
Posts: 10,362
Not Ranked     
Default

Quote:
Originally posted by Chaplin


I don't think I'm running any anti-virus software
Shame on you!

The best to buy is Norton Antivirus... no contest.

The best free downloadable one is AVG.
Reply With Quote
  #7 (permalink)  
Old 01-26-2004, 06:28 PM
CC Member
Visit my Photo Gallery

 
Join Date: Jul 2002
Location: rocky river, Oh
Cobra Make, Engine: Unique 289FIA / SA 351W / a truly glorious machine
Posts: 3,949
Not Ranked     
Default

Quote:
Originally posted by computerworks


At this point, there is no need to go crazy about new definitions...although if you have AV software, you should be doing live updates on a regular basis...

What you are experiencing is a new mass-mailing worm called W32.Novarg.A@mm. It was discovered today and more info is coming as we speak.

THE KEY THING TO LOOK FOR is an attachment that is 22k in size; it may be a .bat, .cmd, .exe, .pif, .scr, or .zip file.

It also may look like a returned-undeliverable e-mail.

The subject of the e-mail may be one of these:
-test
-hi
-hello
-Mail Delivery System
-Mail Transaction Failed Server

Just delete it ...don't peek at the attachment...and you will be fine.

I think I just got screwed..... Tried to open a .zip file about that size... Didn't get it opened... but started getting returned mail that I didn't send...

What's the next move????

Did I just hand over my address book???
Reply With Quote
  #8 (permalink)  
Old 01-26-2004, 06:34 PM
CC Member
Visit my Photo Gallery

 
Join Date: Jul 2002
Location: rocky river, Oh
Cobra Make, Engine: Unique 289FIA / SA 351W / a truly glorious machine
Posts: 3,949
Not Ranked     
Default

Also got an e-mail from Amazon for a salesconfirm but I deleted that one only because we didn't order anything from them...
My wife just yelled up that she had heard about that one last week.
Reply With Quote
  #9 (permalink)  
Old 01-26-2004, 06:43 PM
clayfoushee's Avatar
CC Member
Visit my Photo Gallery

 
Join Date: Nov 2003
Location: Annapolis, MD
Cobra Make, Engine: Unique, 427SO, it runs
Posts: 2,636
Not Ranked     
Default

Yep....Norton anti-virus is worth the price 10-fold. Even if you're infected, there is a good chance it will fix it. It also notifies you when you need to do a live update to handle a new virus def.

Buy it!
__________________
Clay
Reply With Quote
  #10 (permalink)  
Old 01-26-2004, 07:08 PM
Doug I's Avatar
CC Member
Visit my Photo Gallery

 
Join Date: Sep 2002
Location: Baton Rouge, Louisiana, La.
Cobra Make, Engine: Waiting to Order a BDR, engine to be a SA C408. TKO to hook it up.
Posts: 1,259
Not Ranked     
Default

I've just had a spike in emails with .exe .pif .scr etc files attached. Well actually this is the first time I've been getting them. One tried to get my email client to act as a relay or something. Panda & Zonealarm figured out what was going on and kept this under control. The email came from a norcal-saac.org address. Never had or sent an email to that address before.

Heads up ya'll

regards
Doug I
__________________
Pull a gear .... drop the hammer .... and enjoy the Drive !!
Reply With Quote
  #11 (permalink)  
Old 01-26-2004, 08:46 PM
computerworks's Avatar
Senior Club Cobra Member
Visit my Photo Gallery
Lifetime Contributor
 
Join Date: Mar 2001
Location: Northport, NY
Cobra Make, Engine: Kirkham, KMP178 / '66 GT350H, 4-speed
Posts: 10,362
Not Ranked     
Default

(Sorry for the long-winded, techie stuff here, but this worm may get epidemic in the next few days).

As of this evening, both McAfee and Trend Micro Antivirus software will detect and fix this worm, as well as Norton. McAfee recognizes it as W32/Mydoom@MM and Trend sees it as WORM_MIMAIL.R.

If you did open the attachment, it did the following:

It creates the following files:

"shimgapi.dll" in %System%
"Message" in %temp%. This file is full of random letters and is displayed via Notepad.
"taskmon.exe" in %System%. If a copy of taskmon.exe exists in the %System%, it is overwritten and replaced by this copy of the worm.


Shimgapi.dll acts as a proxy server. It opens TCP ports in the range of 3127 to 3198 for listening.


Adds the value
TaskMon = %System%\taskmon.exe
to the registry keys
HKEY_CURRENT_USER\Software\Microsft\Windows\Curren tVersion\Run
and
HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\Curr entVersion\Run


Can perform a Denial of Service against www.sco.com. Creates 64 threads which send GET requests. The DoS is active between February 1, 2004 and February 12, 2004.


Creates the following registry keys:

HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\Curr entVersion\
Explorer\ComDlg32\Version
and
HKEY_CURRENT_USER\Software\Microsoft\Windows\Curre ntVersion\
Explorer\ComDlg32\Version


Searches for email addresses in files with the following extensions. It ignores addresses which end in ".edu".

.htm
.sht
.php
.asp
.dbx
.tbb
.adb
.pl
.wab
.txt


Attempts to send emails by using its own SMTP engine. It performs a lookup of the mail server of the recipient in order to send. If it is unsuccessful it will use the local mail server.


The email will have the following characteristics:

From: may be a spoofed from address
Subject:
test
hi
hello
Mail Delivery System
Mail Transaction Failed
Server Report
Status
Error

Message:
Mail transaction failed. Partial message is available.
The message contains Unicode characters and has been sent as a binary attachment.
The message cannot be represented in 7-bit ASCII encoding and has been sent as a binary attachment.

Attachment:
document
readme
doc
text
file
data
test
message
body

with one of the following suffixes:
pif
scr
exe
cmd
bat
zip


Copies itself to KaZaA download directory as one of the following files:

winamp5
icq2004-final
activation_crack
strip-girl-2.0bdcom_patches
rootkitXP
office_crack
nuke2004

with a file extension of pif or scr or bat

To get rid of it

Update your virus defitions, disconnect from the internet, scan and delete any file that is found to be infected.

Then, CAREFULLY edit the Registry to remove the starter files:
(If you have never edited the Registry, and are unsure of what you are doing, as for help from someone who can do it)

Click Start, and then click Run. (The Run dialog box appears.)
Type regedit

Then click OK. (The Registry Editor opens.)

Navigate to the keys:

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\Curr entVersion\Run
and
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\Curre ntVersion\Run

In the right pane, delete the value:

"Taskmon"="%System%\taskmon.exe"


Navigate to the key

HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\Curr entVersion\
Explorer\ComDlg32\Version

and delete it.


Navigate to the key

HKEY_CURRENT_USER\Software\Microsoft\Windows\Curre ntVersion\
Explorer\ComDlg32\Version

and delete it.

Exit the Registry Editor.
Reply With Quote
  #12 (permalink)  
Old 01-26-2004, 08:54 PM
Jamo's Avatar
Super Moderator
Visit my Photo Gallery
Lifetime Contributor
 
Join Date: May 2001
Location: Fresno, CA
Cobra Make, Engine: KMP 184/482ci Shelby
Posts: 14,448
Not Ranked     
Default

Or pound your fist on the keyboard a half dozen times...much more satisfying.
__________________
Jamo
Reply With Quote
  #13 (permalink)  
Old 01-26-2004, 08:57 PM
computerworks's Avatar
Senior Club Cobra Member
Visit my Photo Gallery
Lifetime Contributor
 
Join Date: Mar 2001
Location: Northport, NY
Cobra Make, Engine: Kirkham, KMP178 / '66 GT350H, 4-speed
Posts: 10,362
Not Ranked     
Default

...that'll help.

Real-time updates as more about this worm is discovered can be found here:

http://securityresponse.symantec.com...varg.a@mm.html
Reply With Quote
  #14 (permalink)  
Old 01-26-2004, 08:59 PM
CC Member
Visit my Photo Gallery

 
Join Date: Jul 2002
Location: rocky river, Oh
Cobra Make, Engine: Unique 289FIA / SA 351W / a truly glorious machine
Posts: 3,949
Not Ranked     
Default

Ron,

Just spent an hour surfing the registry to get rid of that worm..
Actually, I found another virus while searching this one out..
I had some help navigating the registry and had to back out on several occasions.... No way I could have done it without help.
Your explanation is right on the money...

Bill S.

Thanks for the heads-up early in the evening... Just missed your warning by about an hour...



al
Reply With Quote
  #15 (permalink)  
Old 01-27-2004, 08:12 AM
Roscoe's Avatar
CC Member
Visit my Photo Gallery

 
Join Date: Mar 2000
Location: Fairfield, NJ, USA, NJ
Cobra Make, Engine: A & C, 351W, Tremec 3550. Exiled Member: Club Cranky
Posts: 5,897
Send a message via ICQ to Roscoe
Not Ranked     
Default

My isp strips out most, if not all viruses. Had two attempts by the new Doom today. What the isp does not catch McAfee gets.

Roscoe
__________________
Roscoe
"Crisis occurs when women and cattle get excited!"....James Thurber
Reply With Quote
  #16 (permalink)  
Old 01-27-2004, 08:29 AM
rdorman's Avatar
Renegade Nuns on Wheels
Visit my Photo Gallery

 
Join Date: Aug 2001
Location: columbus, Oh
Cobra Make, Engine: Unique 427 roadster with 351C-4B
Posts: 5,129
Not Ranked     
Default

SPYBOT is freeware that will help with the popups, amongst other things.

Ron, Computerworks, I use Norton Anti-virus (and yes folks, it is good), actually I have Nortons firewall and complete set of system tools, and I have a questions about spyware/adware. I searched Nortons sight with little help found. I want to be sure that Norton is taking care of spyware/adware. I want to be able to scan for these using Norton. And how in the HE!! do you get the &^%&ing Ad Trashcan to work!

Any help would be appreciated.

For those with Norton, set up the live update. When ever you are on it will check for updates for you.

Thanks
Rick
__________________
Proud owner of Shelby Cobra "Tribute" car!

OhioCobraClub.com
LondonCobraShow.com
Reply With Quote
  #17 (permalink)  
Old 01-27-2004, 08:36 AM
computerworks's Avatar
Senior Club Cobra Member
Visit my Photo Gallery
Lifetime Contributor
 
Join Date: Mar 2001
Location: Northport, NY
Cobra Make, Engine: Kirkham, KMP178 / '66 GT350H, 4-speed
Posts: 10,362
Not Ranked     
Default

Rick..
..only the newest version of Norton (2004) deals with ad/spyware. I am not convinced they have it right yet.

I use three tools:

1. AdAware (Lavasoft) as a first pass. We leave it on the system, since it is the most 'end-user friendly' program of the bunch.

2. Spybot Search and Destroy for the second pass. CAUTION...don't wholesale delete everything that Spybot finds. It will detect legitimate software that 'talks' to the Internet as well as the bad stuff. Scroll thru it's results and uncheck the programs that you think should remain. e.g. It detects components of MS Works as spyware.

3. Finally, a program called Cool Web Shredder, that is designed to specifically remove and repair any browser hijacks, i.e., things that change your home page or your search page in MSIE.
Reply With Quote
  #18 (permalink)  
Old 01-27-2004, 08:42 AM
Turk's Avatar
CC Member
Visit my Photo Gallery

 
Join Date: Jun 1999
Location: Bay Area, FL
Cobra Make, Engine: What Cobra?
Posts: 7,193
Send a message via Yahoo to Turk
Not Ranked     
Default

Norton Antivirus wouldn't have helped in this case.
The virus was out before there was a fix.
If you were infected before the cure, there wasn't a whole lot AV programs could have done.

Its worst danger is that it opens up a TCP port somewhere in the 3000 range that would allow someone to remotely adminster the computer.

I got infected when Norton was already aware of it, but didn't have a fix for it until later in the day.

Best advice is NOT to open attachments that look suspicious.

TURK

POP-UPS: If you are already using Google Tool bar (hopefully downloaded directly from Google website) it has a Pop Up blocking feature that is 100% effective,
__________________
OBAMA IN in 2012

Last edited by Turk; 01-27-2004 at 08:45 AM..
Reply With Quote
  #19 (permalink)  
Old 01-27-2004, 09:27 AM
CC Member
Visit my Photo Gallery

 
Join Date: Jul 2003
Location: Fort Pierce, FL
Cobra Make, Engine:
Posts: 141
Not Ranked     
Default

Thanks for the timely info guys. I got one this morning entitled test with a sent date of 1/26/04. I knew something was awry because I didn't send it. There was no attachment though because we strip all files with the afore mentioned extensions from all SMTP traffic.

Then a user called saying that someone outside the organization had received something from her entitled hello. I ran a scan with PANDA and found nothing.

A few minutes later I spotted this thread and, voila!

By the way, according to Symantec, this thing is set to launch a Denial of Service attack on Feb. 1, 2004. It also has a trigger date to stop spreading on Feb. 12, 2004.

Last edited by Bill V; 01-27-2004 at 11:01 AM..
Reply With Quote
  #20 (permalink)  
Old 01-27-2004, 09:46 AM
Jamo's Avatar
Super Moderator
Visit my Photo Gallery
Lifetime Contributor
 
Join Date: May 2001
Location: Fresno, CA
Cobra Make, Engine: KMP 184/482ci Shelby
Posts: 14,448
Not Ranked     
Default

David Kirkham thought my computer sent something out. I've checked my registry...nada. Norton is kept up to date via Live Update, but as Turk suggested, that was behind the times a little. But I downloaded the fix per Ron's/Norton's route, and ran it through.

Obviously, it's using whatever names it can find in someone's address book...so it may not come from the person who's name appears to be the sender.

At least it's an attachment based worm...if you don't open, it shouldn't be a problem. AOL always asks if you even want to open an e-mail if it doesn't recognize the address, and does it again if you try to open the attachment. If you're MSN, turn off the automatic opening feature!
__________________
Jamo
Reply With Quote
Reply


Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is On
HTML code is Off
Trackbacks are On
Pingbacks are On
Refbacks are On



All times are GMT -7. The time now is 02:58 AM.


Powered by vBulletin® Version 3.8.0
Copyright ©2000 - 2025, Jelsoft Enterprises Ltd.
Search Engine Friendly URLs by vBSEO 3.6.0
The representations expressed are the representations and opinions of the clubcobra.com forum members and do not necessarily reflect the opinions and viewpoints of the site owners, moderators, Shelby American, any other replica manufacturer, Ford Motor Company. This website has been planned and developed by clubcobra.com and its forum members and should not be construed as being endorsed by Ford Motor Company, or Shelby American or any other manufacturer unless expressly noted by that entity. "Cobra" and the Cobra logo are registered trademarks for Ford Motor Co., Inc. clubcobra.com forum members agree not to post any copyrighted material unless the copyrighted material is owned by you. Although we do not and cannot review the messages posted and are not responsible for the content of any of these messages, we reserve the right to delete any message for any reason whatsoever. You remain solely responsible for the content of your messages, and you agree to indemnify and hold us harmless with respect to any claim based upon transmission of your message(s). Thank you for visiting clubcobra.com. For full policy documentation refer to the following link: CC Policy
Links monetized by VigLink