View Full Version : Virus detected, ack . . .
Mandi
02-08-2001, 10:57 PM
My Norton's alerted on an email virus today, and asked me right away what to do with it . . . it appears that it infected all of my inbox (Netscape Mail) but none of the subfolders within that inbox.[nbsp][nbsp]I can "see" all of the subject lines in the Inbox, but it tells me Couldn't Find the Folder when I try to click on an email.[nbsp][nbsp]I don't actually get a display of the contents.
Norton log says, C:\Program Files\Netscape\Users\mandi\mail\Inbox
was infected with the WScript.KakWorm virus.
The file was deleted.
OMG, I think I deleted a BUNCH of important mail with that . . . gulp . . . but better gone then infected, of course . . . but any thoughts on how to recover my Inbox itself??
I have Inbox functionality for new mails (having just sent myself a successful test mail) but I can't view anything that predates the virus mail . . . and I can't even delete it all (or drag it to another folder).
I guess I should be glad this is one area I have LITTLE experience in, huh???
Tibbits
02-09-2001, 05:32 PM
Kakworm adds itself to the outlook (express?) signature on an infected computer, and stops the computer booting n a certain day each month.
I put my antivirus to work while I slept last night and found I had a virus, too!!!
JS.Seeker ????? The profile said it was rare but I have no idea what it could be doing. The program quarantined it and then I removed the file? Wrong thing to do?
I always thought it wouldn't happen to me.
Tatu :P
Shalazar
02-09-2001, 08:08 PM
JS.Seeker:
http://vil.mcafee.com/dispVirus.asp?virus_k=98882&
Kakworm:
http://vil.mcafee.com/dispVirus.asp?virus_k=10509&
Shalazar!!!!! THANK YOU!!!
It was at McAfee all along.
-Tatu
EDIT: I was guessing it was a trojan, but since I am paranoid I imagined credit card numbers and passwords distributed online. It was just altering the default and home pages and search pages in IE. Which it in fact really did one day last week but I just changed it to a pay per click search engine / GoTo because it had happened to me before. Blah...
[This message has been edited by Tatu (edited 02-09-01@9:33 pm)]
YFS200
02-10-2001, 04:06 AM
I have not used Netscape mail in a long time, but from what you are saying, it sounds like Netscape is storing all your emails in one file!!
(checking this out now)
Not a good idea. Back up your email often. And find a better email program.
WScript.KakWorm I get this alot. When you get a virus, quarantined it first. Then check out the stats on that virus. Make a backup, then try to clean it out. Most of the time, it will work.
YFS200
YFS200
02-10-2001, 04:09 AM
Dup post.[nbsp]
[This message has been edited by YFS200 (edited 02-10-01@03:10 am)]
YFS200
02-10-2001, 04:49 AM
Just checked. Netscape does store all your entire inbox in one file called inbox.(duh) Your outbox is stored in outbox...etc.
It's just a text file, so even if you had an infected version, you can edit out the infected part with notepad.
But I am guessing you don't make backups often. A file recovery program might still get it out of the system. Lest most of it. You might just get what you need by viewing the recovered file in notepad.
Storing all your email in one file is risky at best. I suggest getting another email program that stores each email in it's own file. Then at most, you loose one email. I know PMMail does this. I am sure others do to.
Don't use Outlook or IE for email. How do you think the virus got to you?[nbsp][nbsp]Every virus I have even gotten came from Outlook. :)
YFS200[nbsp]
Tibbits
02-10-2001, 11:59 AM
Don't use Outlook or IE for email. How do you think the virus got to you?[nbsp][nbsp]Every virus I have even gotten came from Outlook
That's like saying don't have a barbeque because you know it's going to rain (well, it always happens to me..). There are mosr virus that attack OE simply beause it the most popular email package, and one of the most fully-featured (read, more features, more things for virus writers to make use of)
I never caught the kakworm when it was sent to me because Outlook Express rejected it.
YFS200
02-11-2001, 01:12 AM
Not quite. It's more like having a BBQ in the rain and handing all your guest umbrella so they don't get wet. All cause your gas grill has a hotdog rack. You could use your indoor electric grill and hold the BBQ in the heated and dry rec room. But no hot dog rack. :(
Mandi is using netscape mail!! Any two bit email program will have more features then that.
Hmm, I bet a full 90% of people that use OE, don't use it because it's "the most fully-featured" client. Try the word "free".
As for the other 10%. Have at it. I will let you know when you send me a virus. :)
YFS200
tedloh
02-11-2001, 01:37 AM
2 nearly foolproof methods to prevent viruses:
1.[nbsp][nbsp]Use Eudora and don't accept attachments - or don't click on them if you don't know where they came from.
2.[nbsp][nbsp]Use Windows2000 or WindowsNT.
Of course, you could always invest in an always-on virus scanner... I recommend Sophos (www.sophos.com (http://www.sophos.com)), or for live updating features, Norton Systemworks or Norton Antivirus.
I am NOT a fan of McAfee.
Mandi
02-11-2001, 12:00 PM
I can't believe I never realized that the email files were txt files, duh . . . I probably could have salvaged some of it that way.
Anyway, I store my important "save" email in subfolders, and they were salvageable.[nbsp][nbsp]Subfolders write to their own files.
The only thing lost was email I hadn't responded to yet (and was yes, still in the Inbox.)[nbsp][nbsp]Deleting the infected file left behind the email info that displays the list of email - ya know, subject line/ sender/ timestamp/ etc.[nbsp][nbsp]So at least I could see who sent me email, and committing to paper quickly what I remembered of the email, will at least allow me to try and respond.[nbsp][nbsp]Much of it were simple submissions for my site, and I'll just have to post a note apologizing for the lost data, and hope people resend.[nbsp][nbsp]I mean . . . OMG . . . I had a personal email from the Master Chief Petty Officer of the Coast Guard (our E-10 guy, top enlisted CG member) that I hadn't responded to yet . . . arrrgggghhhhhhh!!!![nbsp][nbsp]I need a smoking-ears icon!!
Most frustrating, is I cannot delete those headers (I know headers means something else in email, I am not sure what those little data lines are really called.)[nbsp][nbsp]I have ended up creating a fresh profile, importing all my clean mail, bookmarks, etc. and am going to delete the old profile shortly.[nbsp][nbsp]What a pain.
I certainly am aware of the "don't open attachments from senders you don't know" practice . . . this wasn't an attachment, it was simply the email itself.[nbsp][nbsp]It sat there looking like an unread email, I clicked on it, and zap . . . here came Norton's.
Does Eudora store each email as a separate file?[nbsp][nbsp]It does seem like that is a more secure method.[nbsp][nbsp]This is the first time I've ever been frustrated by NS Mail, I have to say.
sheila
02-11-2001, 12:47 PM
I know that Pegasus stores each mail in a separate file, if that's what you're looking for.
and Pegasus is free.
http://www.pmail.com
I use Pegasus, and it's protected by Norton. It's OK...
Not quite. It's more like having a BBQ in the rain and handing all your guest umbrella so they don't get wet. All cause your gas grill has a hotdog rack. You could use your indoor electric grill and hold the BBQ in the heated and dry rec room. But no hot dog rack. :( It's a shame what people outsides of Florida have to go through. I hate (or love) to rub this is most of your noses ( :D j/k ) but we're having an outdoor bbq in a few minutes. According to weather.com ( http://www.weather.com/weather/local/33467 ), it's 80 degrees ("feels like 84"), a UV index of 5, and unlimited visibility. :) :) I love it.
Guys, just help and bear with me. Obviously I have a problem with veering threads off-track if not completely hi-jacking them for no reason at all. :)
-Tatu :(
tedloh
02-11-2001, 06:12 PM
Eudora, unfortunately, stores each mailbox in a single file.[nbsp][nbsp]That is a weakness - or strength - depending on how you look at it.
------------------
Ted (Chief Do-It-All)
Got2Bet.com - The Net's Winner's Circle
http://www.got2bet.com
ted@tygresystems.com
Mandi
02-12-2001, 12:23 AM
So, in configuring this new profile (NS) . . . I imported my old profile's address book.[nbsp][nbsp]It's giving me email addys that are at least a year or two old![nbsp][nbsp]How could it have an old "copy" of itself inside there?[nbsp][nbsp]I know I selected the right file to import.[nbsp][nbsp]Grrrr.
Off to have a close look at Pegasus email.[nbsp][nbsp]Am about ready to call a halt to the technilogical revolution all together.[nbsp][nbsp]I am thinking of learning to send and read smoke signals.
Mandi
02-15-2001, 11:00 AM
<voice sound=loud screaming>Insert Banshee Noises Here</voice>
I got another one this morning.
This time, all it did was land in my Inbox.[nbsp][nbsp]I did not click it, view it, or otherwise interact with it . . . but zap, once again my inbox is gone (courtesy Norton's virus cleaner, not the virus itself.)
I am getting Pegasus Mail right now.
I have been getting email since about 1993 and I have NEVER HAD A VIRUS.
My helpful husband is wanting me to explain how this is happening.[nbsp][nbsp]I have no *$%#@ idea how or why, just that it is.[nbsp][nbsp]I told him losing my email feels is just like if someone torched his medical books, but he still had to practice and treat and prescribe :(
vBulletin® v3.6.8, Copyright ©2000-2009, Jelsoft Enterprises Ltd.