FSIC Messageboard
  SDOE General
  Silence is NOT Golden

Post New Topic  Post A Reply
profile | register | preferences | faq | search

UBBFriend: Email This Page to Someone! next newest topic | next oldest topic
Author Topic:   Silence is NOT Golden
Da Jug head
Pilot
posted 10-05- 03:21 PM     Click Here to See the Profile for Da Jug head   Click Here to Email Da Jug head     Edit/Delete Message   Reply w/Quote
Posting this from somewhere else.

For those who have sent me e-mails and are waiting for files.

A worm got past my virus scanner and firewall ( I was using mozilla mail, the virus scanner is compatible with Netscape mail, but mozilla mail is just different enough that it doesn't autoscan the e-mail files). It also managed to slip into the most recent restore point under WinME. Herein lies the problem. Removing the infected files causes WinMe to restore the infected files from the most recent system restore on the next reboot. If I reply to any e-mails or post any files, it will hitch a ride.

The anti-virus company is trying to help me with this, the problem is MS gives no options to delete the restore point or turn restore off, and none of the restore files can be viewed in a file manager, so I can't delete them that way either. WinME also refuses to let the virus software delete the infected restore point (Thanks again for taking away control from the user MS jack****s). Although this is a known worm, this is the first time they've seen it buried in a system restore file.

I can't wipe the drive as I need some of the files off it and if I back them up this thing will go with the backup. I have to get this puppy disinfected first.

Since I don't wish to pass this headache on to anyone else, nobody will get a e-mail reply from me until this is fixed (it's recommended to NOT use webmail as I can still send this along, especially when uploading files).

This is a unique case caused by a combination of events, so it's a learning experience for everyone involved.

IP: Logged

roadtoad
Pilot
posted 10-05- 03:53 PM     Click Here to See the Profile for roadtoad   Click Here to Email roadtoad     Edit/Delete Message   Reply w/Quote
Can appreciate your problem. I let my virus defs get too old and a new variant started eating my exefiles.
..I was noodling towarda return to making SDOE stuff, but OPS was one of the files eaten, and OPS seems to not only have disappeared from where it was (no downloads anyway), but everywhere. I did modwork before it appeared, but I just don't have the time or energy to go that routine again.

IP: Logged

Sv
JAG
posted 10-05- 05:03 PM     Click Here to See the Profile for Sv   Click Here to Email Sv     Edit/Delete Message   Reply w/Quote
OPS can be found here:
http://www.fightersquadron.com/opstudio/

------------------
-Sv

Wings with Wires

IP: Logged

Snickers
Pilot
posted 10-05- 05:35 PM     Click Here to See the Profile for Snickers   Click Here to Email Snickers     Edit/Delete Message   Reply w/Quote
Actually, none of the download links are valid.... If you needs OPS let me know and I can email it to you (virus scanned )

[This message has been edited by Snickers (edited 10-05-2001).]

IP: Logged

Pete Hawk
Pilot
posted 10-05- 06:27 PM     Click Here to See the Profile for Pete Hawk   Click Here to Email Pete Hawk     Edit/Delete Message   Reply w/Quote
Actually Snick, move your mouse over "Downloads" and then current version (1.2.1) and it will download fine. (top menu bar)

IP: Logged

roadtoad
Pilot
posted 10-05- 07:15 PM     Click Here to See the Profile for roadtoad   Click Here to Email roadtoad     Edit/Delete Message   Reply w/Quote
Thanks guys! Got it just like Pete said

Hey Jug - I had some experience with the SirCam worm; and even though Norton quarantined it, it was still busy mailing evil while I was reading the info at SARC before deleting it(!) I found it was working from a hidden folder in the recycle bin. From a DOS window do a "dir /ah" in c:\recycled. If anything but "desktop.ini" shows, do "attrib -h c:\recycled\" and then delete it/them. While you're at it, do a full drive search for hidden folders from the c:\ prompt "dir *. /ah /p"

IP: Logged

Snickers
Pilot
posted 10-05- 11:21 PM     Click Here to See the Profile for Snickers   Click Here to Email Snickers     Edit/Delete Message   Reply w/Quote
Actually I did before I made my previous post and it never worked... (What you think I am dumb? Wait, dont answer that ...)

IP: Logged

Sv
JAG
posted 10-06- 08:22 AM     Click Here to See the Profile for Sv   Click Here to Email Sv     Edit/Delete Message   Reply w/Quote
What does it do Snickers?

IP: Logged

All times are CT (US)

next newest topic | next oldest topic

Administrative Options: Close Topic | Archive/Move | Delete Topic
Post New Topic  Post A Reply
Hop to:

Contact Us | Fighter Squadron Information Center

(This site Copyright (c) 1999 Inertia LLC)

Powered by Infopop www.infopop.com © 2000
Ultimate Bulletin Board 5.45c