w00t!!! my first comp virus :P

Paulson

Elite Member
Feb 27, 2001
10,689
0
0
www.ifixidevices.com
Well, good ol' norton is telling me that I have an infected file.

Hopefully it will burn it all to hell, because I really don't want to re-install.

Well, wish me luck...
 

Pyxis

Platinum Member
Jan 28, 2001
2,554
0
76
Congratulations:)

Good luck getting rid of it. I got a virus last year when I didn't have my anitvirus running and I had to do a fresh install of my os:(
 

IJump

Diamond Member
Feb 12, 2001
4,640
11
76
I haven't seen any good viruses lately. Only remakes of the crappy old Melissa and I Love You viruses. Can't these people be more creative? ;)
 

Goldfish

Platinum Member
Jun 10, 2001
2,157
0
0
Congrats on getting a virus, lol. I've (knock on wood) never had one in my length of computer usage. I guess thats what I get for being carefull and avoiding doing stupid stuff.
 

kvelouria

Member
Jun 18, 2001
54
0
0
Personally installing my first trojan was a lot more enlightening than getting my first virus.

Tip: If you download a file that ends with .mpg but the icon looks like an executable, it's not real bright to go ahead and run it anyway.
 

Whitecloak

Diamond Member
May 4, 2001
6,074
2
0
oops, i think deleting wininit.exe might have been a mistake. i am not sure but i think when windows starts up, wininit is called.
 

Russ

Lifer
Oct 9, 1999
21,093
3
0


<< Hopefully the file wininit.exe isn't important, because I deleted it. >>



EDIT: Just checked. The one that is in windows\system is the culprit and fine to nuke. The one in windows needs to remain. Bymer is not even harmful, though.

BTW, the only way you can get Bymer is if you have open, unprotected shares. You need to tighten your security.

Russ, NCNE
 

FelixDeCat

Lifer
Aug 4, 2000
31,254
2,780
126
Ive had a few virii before. I ghost my hd frequently to a separate backup hd so I really dont care. They are actually kind of funny. Im glad I can laugh at these things.
 

GT1999

Diamond Member
Oct 10, 1999
5,261
1
71
Set a password on your shared hard drives / devices. Install a firewall.

You should be fine..
 

Russ

Lifer
Oct 9, 1999
21,093
3
0
Paulson,

It means your system is:

a. Accepting connections on port 139 (NetBIOS)
b. You have file and print sharing enabled and bound to TCP/IP
c. You have not password protected the drive.

Go to http://www.grc.com and run Shields Up on the system that got the infestation.

Russ, NCNE
 

rc5

Platinum Member
Oct 13, 1999
2,464
1
0
If you are using win2k, the opportunity of infecting virus is much smaller than staying with win9x.

Dos was the heaven of viruses.
 

Russ

Lifer
Oct 9, 1999
21,093
3
0
HMM...I just port scanned your IP address (at least the one that was in the last eMail I got from you), and port 139 comes up stealth. You have a bunch of server related ports open, but that's to be expected.

Sure you haven't had this a while, and just discovered it? Do you have another system connected that might have gotten it and and it moved over? Or, are we talking about a different system then the one you send mail from?

Or maybe this puppy can come in through other ports?

Russ, NCNE
 

Paulson

Elite Member
Feb 27, 2001
10,689
0
0
www.ifixidevices.com
Well, i have some idea as to how I may have gotten it.

I have the DMZ host set to port 192.168.1.21 on my router (my server internal IP addy) which I shouldn't have done in the first place. Well, my ip's got switched around, and my new comp was the DMZ host, which isn't good at all.

Needless to say, no computer is the DMZ host anymore...