BLU Discuss list archive
[Date Prev][Date Next][Thread Prev][Thread Next][Date Index][Thread Index]
[Discuss] virus?
- Subject: [Discuss] virus?
- From: adler at stephenadler.com (Stephen Adler)
- Date: Tue, 28 Oct 2014 10:47:36 -0400
- In-reply-to: <74F3CFED-2AE4-427B-BB3F-B508E45F07F1@geekcq.com>
- References: <544EC564.3050307@stephenadler.com> <17ff09e3fd184c0ab6fadb7440277c74@BN3PR0401MB1204.namprd04.prod.outlook.com> <74F3CFED-2AE4-427B-BB3F-B508E45F07F1@geekcq.com>
Thanks everyone for you comments on this. As it turns out, I can't reinstall the OS since its a laboratory equipment and I need to do my best otherwise. So... I ran clamscan as suggested on the two files and here's what clam scan reports.... [root at localhost ~]# clamscan virus/ LibClamAV Warning: ************************************************** LibClamAV Warning: *** The virus database is older than 7 days! *** LibClamAV Warning: *** Please update it as soon as possible. *** LibClamAV Warning: ************************************************** virus/Autorun.inf: Worm.Autorun-3966 FOUND virus/rundll.exe: Worm.VB-269 FOUND ----------- SCAN SUMMARY ----------- Known viruses: 3418320 Engine version: 0.98.4 Scanned directories: 1 Scanned files: 2 Infected files: 2 Data scanned: 0.04 MB Data read: 0.04 MB (ratio 1.00:1) Time: 9.878 sec (0 m 9 s) So I go off and do a google search for Worm.VB-269 and I don't really find anything on it that tells me anything of what the worm does... I was hoping to find like a wiki page details all known viruses, what they do and how to eliminate them. Can anyone give me some pointers on how to find out what Worm.VB-269 does? Thanks! On Tue, 2014-10-28 at 12:07 +0000, Tim Lyons wrote: > On October 28, 2014 7:18:06 AM EDT, "Edward Ned Harvey (blu)" wrote: > "The only effective defense is to completely nuke the affected systems after infection (reinstall the OS)." > > FWIW - I could not agree more wholeheartedly with Ed's statement. There is just no way to know what else was delivered in the payload. Wiping and reinstalling with a CURRENT (supported) OS version is the only way to sleep soundly. > > Tim > > > -- > Sent from my Android device with K-9 Mail. Please excuse my brevity.
- Follow-Ups:
- [Discuss] virus?
- From: blu at nedharvey.com (Edward Ned Harvey (blu))
- [Discuss] virus?
- From: richard.pieri at gmail.com (Richard Pieri)
- [Discuss] virus?
- From: bill.n1vux at gmail.com (Bill Ricker)
- [Discuss] virus?
- References:
- [Discuss] virus?
- From: adler at stephenadler.com (Stephen Adler)
- [Discuss] virus?
- From: blu at nedharvey.com (Edward Ned Harvey (blu))
- [Discuss] virus?
- From: lyons at geekcq.com (Tim Lyons)
- [Discuss] virus?
- Prev by Date: [Discuss] virus?
- Next by Date: [Discuss] virus?
- Previous by thread: [Discuss] virus?
- Next by thread: [Discuss] virus?
- Index(es):