Search Members Help

» Welcome Guest
[ Log In :: Register ]

Mini-ITX Boards Sale, Fanless BareBones Mini-ITX, Bootable 1G DSL USBs, 533MHz Fanless PC <-- SALE $200 each!
Get The Official Damn Small Linux Book. DSL Market , Great VPS hosting provided by Tektonic
Pages: (2) </ [1] 2 >/

[ Track this topic :: Email this topic :: Print this topic ]

reply to topic new topic new poll
Topic: Saved by the DSL..., ...again!< Next Oldest | Next Newest >
dslfool Offline





Group: Members
Posts: 105
Joined: April 2004
Posted: July 08 2004,01:21 QUOTE

Friend's WinXP PC, unable to connect to Symantec via LiveUpdate for virus definitions or to Symantec's web site for manual virus def downloading (later figured out that malware had redirected access to Symantec addresses to a false address).

Popped in DSL with firefox.ci, browsed to Symantec, downloaded virus defs, copied to USB flash drive, rebooted to WinXP, copied defs from USB drive, and BOO-YAH!

I love it.


--------------
Toshiba Portege 7200CTe notebook, 600MHz PIII, 8GB CF as HD, 320MB RAM
DSL 4.2.5 (frugal toram)
...and the picture is of Fuad Ramses from the film "Blood Feast".
Back to top
Profile PM 
ke4nt1 Offline





Group: Members
Posts: 2329
Joined: Oct. 2003
Posted: July 08 2004,02:06 QUOTE

Great story!

What software detected/removed the malware ?
What was the malware called ?

Thanks for sharing...

73
ke4nt
Back to top
Profile PM 
dslfool Offline





Group: Members
Posts: 105
Joined: April 2004
Posted: July 08 2004,05:44 QUOTE

I never did find out exactly what software did the damage - Symantec AntiVirus didn't identify any infections or modified files, so either it couldn't see the malware or the malware was gone. I fixed the problem (per a Windows forum topic I found) by manually editing a file called HOSTS which lists specific locations for addresses (in this case, symantec.com and related addresses were referred to IP 127.0.0.0, so neither LiveUpdate nor a web browser could get to Symantec for updates). I edited out these references and Symantec was once again reachable.

(If I had known this before I did the DSL/update thing I wouldn't have had to use DSL to get the new virus definitions, but at the time I thought my first priority was to, by hook or by crook, run a scan with updated definitions, and DSL allowed me to do that with tools I could fit in my shirt pocket. Fun as all get out.)

Although I never identified the malware (or found out how to prevent it from striking again), it just occurs to me that I was getting a skijillion pop-ups in Internet Explorer for McAffee anti-virus products and services. Coincidence???


--------------
Toshiba Portege 7200CTe notebook, 600MHz PIII, 8GB CF as HD, 320MB RAM
DSL 4.2.5 (frugal toram)
...and the picture is of Fuad Ramses from the film "Blood Feast".
Back to top
Profile PM 
ke4nt1 Offline





Group: Members
Posts: 2329
Joined: Oct. 2003
Posted: July 08 2004,06:04 QUOTE

Quote
it just occurs to me that I was getting a skijillion pop-ups in Internet Explorer for McAffee anti-virus products and services. Coincidence???


Reverse logic.....

" Nope, Internet Explorer makes for a fine outstanding pop-up server! "   :D

...I'm sure mcafee knows this as well as anyone...

Tnx again,

73
ke4nt
Back to top
Profile PM 
AwPhuch Offline





Group: Members
Posts: 1404
Joined: April 2004
Posted: July 08 2004,14:09 QUOTE

I run two things

1st being Spybot-S&D

2nd being Adaware 6.0

Run  them just like that and it will clean up all your spyware/malware and all that...

I also recommend Antivirus Personal Edition and f-prot antivirus

That keeps me pretty protected

Brian
AwPhuch


--------------
http://www.frappr.com/dsl <-- Where do you use DSL?
http://www.smoothwall.org <-- Ultimate firewall for the world!
http://boinc.mundayweb.com/one/stats.php/userID:6107 <--My BOINC stats!
./S99LinuxRevolution start
Back to top
Profile PM WEB 
8 replies since July 08 2004,01:21 < Next Oldest | Next Newest >

[ Track this topic :: Email this topic :: Print this topic ]

Pages: (2) </ [1] 2 >/
reply to topic new topic new poll
Quick Reply: Saved by the DSL...

Do you wish to enable your signature for this post?
Do you wish to enable emoticons for this post?
Track this topic
View All Emoticons
View iB Code