IWETHEY v. 0.3.0 | TODO
1,095 registered users | 0 active users | 0 LpH | Statistics
Login | Create New User
IWETHEY Banner

Welcome to IWETHEY!

New Virus Q.
A friend (local airport manager) has Win98. When he connects to his ISP (a dial-up) almost instantly Norton Anti-Virus starts scanning outbound mail. Norton blocks the sending of the mail because of a "virus in the attachment". I run the scan on the drive, doing all the files and yet I cannot seem to get the mail from going out. It's like, Norton properly identifies the outbound mail as having a virus, but cannot identify the virus on the box that is causing all the mail to be sent in the first place.

He's running OE and I managed to get the "Preview Pane" closed. But the mail starts sending whenever the dial-up is connected (i.e. nothing else needs to be open). That implies (at least to me) that the virus is resident as soon as the machine turns on. So, has he got a virus that Norton's latest strings don't identify that is sending email with attachments that Norton's latest strings can identify? It appears so to me. Any ideas?
"It is very difficult to explain to an Iraqi that a man fighting from his own town with a Kalashnikov or RPG launcher is a 'coward' and a 'war criminal' (because, apparently, he should go out into the desert and wait to be annihilated from the sky) but that someone dropping 2000-pound bombs on residential areas or shooting at ambulances because they may have guns in them (even though they usually don't) is a hero and is following the laws of war."

- Rahul Mahajan
New OT request
Can you please put an < hr > or some other separator at the top of your .sig so it doesn't flow along with the rest of your post? I've read the start of that .sig so many times now you'd think I'd learn...But apparently I'm now too old for that. ;-)
-YendorMike

[link|http://www.hope-ride.org/|http://www.hope-ride.org/]
New Or change the font, size, attributes, ANYTHING! TanK Ewe.
New Maybe add one of those Niteowl lines [hr] or something. ;-)
New Suugestion for Admin
How about automatically including the
whenever anyone has a sig?
New Disagree
If we did that, I couldn't do something like this.

===

Implicitly condoning stupidity since 2001.
New Concur.
Regards,

-scott anderson

"Welcome to Rivendell, Mr. Anderson..."
New Sorry. Meant to do that yesterday.
bcnu,
Mikem
New Check for spyware
Run Stinger, Dump OE, run windows update.
-----------------------------------------
It is much harder to be a liberal than a conservative. Why?
Because it is easier to give someone the finger than it is to give them a helping hand.
Mike Royko
New Will do. Thanks.
bcnu,
Mikem
New MSFT to Dump OE itself ;-)
It might be the world's most widely distributed e-mail client, but Microsoft has confirmed that it has no intention of further developing Outlook Express.

"[Outlook Express] just sits where it is," said Dan Leach, lead product manager for Microsoft's information worker product management group. "The technology doesn't go away, but no new work is being done. It is consumer e-mail in an early iteration, and our investment in the consumer space is now focused around Hotmail and MSN. That's where we're putting the emphasis in terms of new investment and new development work."

[link|http://www.zdnet.com.au/news/business/0,39023166,20277192,00.htm|http://www.zdnet.com...6,20277192,00.htm]
bcnu,
Mikem
New All your email are beling to MS
===

Implicitly condoning stupidity since 2001.
New Just because they're not developing on OE
doesn't mean they're gonna drop it. Heck, NotePad and Paint are the most pitiful packages out there, but they'll continue to be packaged with Windows.
New I meant "drop development".
My guess is that they want everyone to pay for Outlook. Peronally, I wouldn't use Out-anything - except here at work, where I haven't a choice. :-(
bcnu,
Mikem
New Possible that NAV is infected somehow
Run this on the system:

[link|http://housecall.trendmicro.com/|http://housecall.trendmicro.com/]

See if it turns up anything.

If Windows is majorly infected, try this Ultimate Boot CD and run a DOS scanner on the hard drive:
[link|http://www.ultimatebootcd.com/|http://www.ultimatebootcd.com/]

Of course a safer way is to make a modifed Knoppix Boot CD with F-Prot AntiVirus on it:
[link|http://www.cs.bsu.edu/homepages/gjjones/administrivia/stories/2003/06/24/fprotVirusScanningWithAModifiedKnoppixCd.html|http://www.cs.bsu.ed...iedKnoppixCd.html]

If it has NTFS neither of those two CDs will clean the virus(es), create a BartPE disk to clean NTFS hard drives using McAfee AV on it using PE Builder:
[link|http://www.nu2.nu/pebuilder/|http://www.nu2.nu/pebuilder/]

It will require a copy of Windows XP (Home or Pro) with SP1 or 2003 Server to create the BartPE boot CD.

Another method is to mount the infected hard drive on another machine and then Virus scan it and never run anything from the infected hard drive.

Once you remove the virus out of the system, it should be safe to scrub out your email that is being sent. Do not click on the attachments and remove all emails in the Outbox folder. It might be a good idea to remove all emails in the sent folder in case one got through somehow?



"What's the use of saving life when you see what you do with it?" - Corbin Dallas "The Fifth Element"

Expand Edited by orion April 29, 2004, 12:02:43 PM EDT
     Virus Q. - (mmoffitt) - (14)
         OT request - (Yendor) - (6)
             Or change the font, size, attributes, ANYTHING! TanK Ewe. -NT - (jbrabeck) - (4)
                 Maybe add one of those Niteowl lines [hr] or something. ;-) -NT - (Another Scott) - (3)
                     Suugestion for Admin - (jbrabeck) - (2)
                         Disagree -NT - (drewk) - (1)
                             Concur. -NT - (admin)
             Sorry. Meant to do that yesterday. -NT - (mmoffitt)
         Check for spyware - (Silverlock) - (5)
             Will do. Thanks. -NT - (mmoffitt)
             MSFT to Dump OE itself ;-) - (mmoffitt) - (3)
                 All your email are beling to MS -NT - (drewk)
                 Just because they're not developing on OE - (ChrisR) - (1)
                     I meant "drop development". - (mmoffitt)
         Possible that NAV is infected somehow - (orion)

One shall be the number of Mojo Jojos in the world, and the number of Mojo Jojos in the world shall be one. Two Mojo Jojos is too many, and three is right out!
61 ms