![]() |
Quote:
Had to lock down zone alarm and track down the rogue program. Luckily it was not an essential ms file (like blast). Put the file on a disk and then got restarted. Its a powerful mailer. My 600k connection and AMD2400 managed to send about 150mails in the 2 minutes it was running. Bit worried about this trojan thing. Is that killed off once the file is deleted and the registary updated? I've run the Norton cleaner, and PCCillin says I'm clean, but when I start up I get some strange message still. |
Care to elaborate on the strange bootup messages? I may be able to help
|
Quote:
A message box about 2in square - no title. Foreign chars then w32.sobig.f.exe or something like that. An OK box. Press OK and it goes away. Parts of PCCillin are also displaying in foreign chars at the mo also. I'm running the comp copy that came with my ASUS mobo. Properly registered and free updates for a year. Even with the POP2Trap it still missed it as I was an early adopter. PCCillin and Norton say I don't have the virus, but as you can see I did a bit of a manual removal. Dare I say I should close my internet connection, reinstall the virus and then remove it again? Would give you a screen shot with the ox, but I am not on that PC. |
not a chance
Take a look in the registry though in the sections HKey_Current_User/Software/Microsoft/Windows/Currentversion/Run and any other Run keys in the registry, also search for w32.sobig.f.exe in the registry assuming you are on Windows XP disable System Restore and then delete the contents of the c:\windows\prefetch folder too |
Was nothing in the reigistarywhen I did the manual removal - will recheck tonight.
Where do you disable system restore. I've been fortunate enough not to need to use it so far so have not seen how restore / roll back works. |
Right click on My Computer, click on Properties then on the System Restore tab
The reason being that if the virus was there when the system created a restore point then the virus may have been backed up along with the system files :D |
SMHarman I just found something for you
http://securityresponse.symantec.com...oval.tool.html Its a removal tool that should sort out the damage caused by the worm as well :) More info on the site. |
See Post 16. I've run that. It says I don't have the virus.
Which I don't I can see that there is no / limited traffic on my connection when I am not doing anything and its all inbound not outbound. With Sobig running the red bar on ZA is maxed out permanently. |
Am I paying for ignorant userâ₠¬Ã¢â€žÂ¢s using up our bandwidth ?
Is NTL doing anything about it ? Can I name and shame ignorant userâ₠¬Ã¢â€žÂ¢s ? Originally posted on guess who Sorry about this: but is the issue is being addressed. I think NOT ! Fr4nk |
Quote:
Incog.:) |
Hmm, NTL could do a network scan for the vulnerable PC's, then force them to be redirected to a page (like they do with autoreg) informing the customers that they are vulnerable and giving links/instructions on what to do about it :)
|
Apparently that is what is happening.
Incog. |
1 Attachment(s)
Still getting hammered on port 135
see records on log1.zip & log2.zip Fr4nk |
1 Attachment(s)
log2.zip
|
Getting hammered here, Causing CI's (Connection inturuptions) in games (I presume).. One every 2-3 seconds or so.
|
| All times are GMT +1. The time now is 00:52. |
Powered by vBulletin® Version 3.8.11
Copyright ©2000 - 2026, vBulletin Solutions Inc.
All Posts and Content are © Cable Forum