Author |
Topic: MSInit virus |
Jim Palenscar
From: Oceanside, Calif, USA
|
Posted 15 Jan 2001 8:35 pm
|
|
I recently discovered that my computer had become infected with a virus that infects the MSInit.exe file. It was vey stubborn to get rid of and I'm hopefully rid of it now but only by changing win.ini,the registry, startup in msconfig, and deleting a couple of files. Gheesh folks- this was a bit of a toughy! Seems it's a worm that has a number of variants and aliases such as win32.funlove.4009, w32.hllw.bymer, w32.kriz.family, and w32/msinit.worm.b. Besides getting annoying messages alerting me to it's presence and adding .vbs files to the startup, it caused me to go through 3 virus checkers to finally get rid of it. I used McAfee, Innoculate, and finally Norton- all the most current versions. I don't ever open anything from anyone I don't know and occasionally chat on mirc (supposedly a common place to this guy to progagate from) but only with folks that I know, and am on ICQ 3-4 times a week- but, again- only with folks I know. So there :~). Jim |
|
|
|
Ernie Renn
From: Brainerd, Minnesota USA
|
Posted 15 Jan 2001 8:54 pm
|
|
Jim;
I have got in the habit of not opening "any" attachments. I have mailed a few people who were in the habit of just forwarding mail, that They should copy and paste the information into a new mail. Some of these viruses will attach themselves to stuff without you knowing it.
Two tips for Outlook Express:
1. Turn off the preview window. For some viruses, that's all that is required to get infected. For example: KAK. It attaches itself to every mail you send out as a signature.
2. Switch to plain text. You can always switch back for a mail or two, here or there. It makes it just a little harder for the virus to spread.
------------------
My best,
Ernie
The Official Buddy Emmons Website
www.buddyemmons.com
|
|
|
|
Jim Palenscar
From: Oceanside, Calif, USA
|
Posted 16 Jan 2001 8:43 pm
|
|
I think I found out why the virus continued to infect my computer after I performed all the steps necessary to clean it. There is a program called "Wormfree" the analyzed my box and reported that I was sharing both of my hard drives. I did that 10 days ago for my son when we wanted to get some files from my computer to his laptop by networking them and I forgot to turn off the file sharing feature when we were done. Ordinarily this would not have been much of a problem but I have a cable modem connection and I'm connected to the internet 24/7. The virus is a "worm" virus and pokes around finding open ports and, as in good old southern hospitality fashion, comes on in and makes itself a home- regardless of whether or not I'm sleeping or at work. Anyway- hope it's fixed now as I'm no longer sharing these drives. Gheesh! |
|
|
|
John Gretzinger
From: Canoga Park, CA
|
Posted 18 Jan 2001 5:10 pm
|
|
Jim -
If you don't have Zone Alarm or some other personal firewall, you need to get one. Zone is free for personal use and as a DSL user, I wouldn't be without it.
jdg
------------------
MSA D-10
'63 Gibson Hummingbird
16/15c Hammered Dulcimer
|
|
|
|
Jim Smith
From: Midlothian, TX, USA
|
Posted 18 Jan 2001 6:41 pm
|
|
Has Zone Alarm made any improvements regarding shared computers? I run Internet Connection Sharing for my roommate's computer. I installed Zone Alarm a year or so ago but got alarms every time he clicked on anything. According to the help file, almost all the alarms had to be turned off to support sharing.  |
|
|
|
Jim Palenscar
From: Oceanside, Calif, USA
|
Posted 18 Jan 2001 7:48 pm
|
|
I'm now using BlackIce and gheesh!- it's reporting that someone's knocking on the door to get into my computer about every 20 - 30 minutes! Amazing! |
|
|
|
Mark Ardito
From: Chicago, IL, USA
|
Posted 19 Jan 2001 2:11 pm
|
|
Regarding that zone alarm issue when accessing a shared computer. I have a peer to peer network set up at home and then down loaded zone alarm on all the computers. All of a sudden my network was gone. Seems that you have to buy the full version in order to keep your peer to peer network or to keep network printers.
Mark
|
|
|
|