View previous topic :: View next topic |
Author |
Message |
bassexpander
Joined: 13 Sep 2007 Location: Someplace you'd rather be.
|
Posted: Wed Nov 05, 2008 5:14 pm Post subject: So we've had this virus at school... |
|
|
One of the reasons I've been experimenting with anti-virus programs is because we've got issues with a sneaky .vbs script called "tracker.vbs" that is floating around here.
So far, it's snuck past AVAST at my home, and Ahn Labs V3. The only anti-virus that catches it is NOD32 so far. I read online that Kaspersky may also be able to catch it. Hotmail catches it if I try to send it through there. I have sent the file on to AVAST so they can add it to their definitions. Was having a devil of a time getting it to them, though, and not quite sure it actually did yet. They have responded to my original inquiry, but the problem is that I couldn't find an e-mail address that didn't want to filter out the virus.
I wrote to some other teachers here, and asked them to push administration to update to a different antivirus program. Ahn Labs sucks.
Also, it's not at all out of the realm of possibility that some student is using this virus to capture professor passwords and change grades (we're web-based).
Tracker.vbs has been screwing with my drive partitions, memory key, and possibly tracking keystrokes. |
|
Back to top |
|
 |
I_Am_The_Kiwi

Joined: 10 Jun 2008
|
Posted: Wed Nov 05, 2008 8:57 pm Post subject: |
|
|
good idea then to keep all work at school work related and stay away from things like net banking, forum logons anything that requires a password or contains sensitive information. |
|
Back to top |
|
 |
bassexpander
Joined: 13 Sep 2007 Location: Someplace you'd rather be.
|
Posted: Thu Nov 06, 2008 4:39 am Post subject: |
|
|
Well, AVAST got back to me, and said it's a variant of VBS:Solow. I'm assuming they will add the new strain to their database now. |
|
Back to top |
|
 |
Bread

Joined: 09 Oct 2008
|
Posted: Thu Nov 06, 2008 9:14 am Post subject: |
|
|
In the future, if you want to send a virus through webmail that blocks it, there's a way that should work fine.
Put it in a zip/rar file and password protect it. Give them the password when you send it. |
|
Back to top |
|
 |
blackjack

Joined: 04 Jan 2006 Location: anyang
|
Posted: Thu Nov 06, 2008 4:53 pm Post subject: |
|
|
Bread wrote: |
In the future, if you want to send a virus through webmail that blocks it, there's a way that should work fine.
Put it in a zip/rar file and password protect it. Give them the password when you send it. |
Gmail often blocks zip files as well rar always seems to work |
|
Back to top |
|
 |
bassexpander
Joined: 13 Sep 2007 Location: Someplace you'd rather be.
|
Posted: Thu Nov 06, 2008 9:57 pm Post subject: |
|
|
How do you lock a .zip? Need a special program? |
|
Back to top |
|
 |
chevro1et

Joined: 01 Feb 2007 Location: Busan, ROK
|
Posted: Fri Nov 07, 2008 12:54 am Post subject: |
|
|
blackjack wrote: |
Bread wrote: |
In the future, if you want to send a virus through webmail that blocks it, there's a way that should work fine.
Put it in a zip/rar file and password protect it. Give them the password when you send it. |
Gmail often blocks zip files as well rar always seems to work |
In one of my uni classes, we had to submit VB projects via email. We would zip the file, then change the file extension to .zipp and the prof would rename the file extension when he recieved it. That worked fine. |
|
Back to top |
|
 |
bassexpander
Joined: 13 Sep 2007 Location: Someplace you'd rather be.
|
Posted: Tue Nov 11, 2008 6:26 pm Post subject: |
|
|
Well, I've been testing AVAST, and it will also find this virus now. They recommend doing a boot scan detection and clean, so it whacks the virus before it gets a chance to load in Windows. That's one thing I love about AVAST is its ability to do a boot scan. Many other programs won't do that.
Kaspersky finds it and deletes it.
NOD32 finds it and says it deletes it, but it often comes back because it's imbedded in the restore sequence somewhere. NOD has excellent/fast detection, but can't clear well. |
|
Back to top |
|
 |
|