Film-Tech Cinema Systems
Film-Tech Forum ARCHIVE


  
my profile | my password | search | faq & rules | forum home
  next oldest topic   next newest topic
» Film-Tech Forum ARCHIVE   » Community   » Film-Yak   » New virus (Page 2)

 
This topic comprises 2 pages: 1  2 
 
Author Topic: New virus
Bob Healey
Film Handler

Posts: 93
From: Milford, CT
Registered: Sep 2001


 - posted 04-15-2002 11:18 PM      Profile for Bob Healey   Email Bob Healey   Send New Private Message       Edit/Delete Post 
An annoying hoax that has caused me several hours of headaches trying to fix at work is one that says sulflnbk.exe in the c:\windows\command directory is a virus and to delete it immedietly. Interesting things happen when this file is delete and Windows 9x gets rebooted and it can't find the file.

 |  IP: Logged

Darryl Spicer
Film God

Posts: 3250
From: Lexington, KY, USA
Registered: Dec 2000


 - posted 04-15-2002 11:56 PM      Profile for Darryl Spicer     Send New Private Message       Edit/Delete Post 
usually nothing happens when that file is deleted.

however it does have something to do with identifying files with longer than 8 character names or something to that effect.

That subject was brought up on another thread on here somewhere.

 |  IP: Logged

Ron Lacheur
Jedi Master Film Handler

Posts: 650
From: British Columbia, Canada
Registered: Feb 2002


 - posted 04-16-2002 03:02 AM      Profile for Ron Lacheur   Email Ron Lacheur   Send New Private Message       Edit/Delete Post 
Bob,

If Windows is looking for that specific file on boot up, then it has associated it in the registry.

 |  IP: Logged

Dave Williams
Wet nipple scene

Posts: 1836
From: Salt Lake City, UT, USA
Registered: Jan 2000


 - posted 04-16-2002 05:08 AM      Profile for Dave Williams   Author's Homepage   Email Dave Williams   Send New Private Message       Edit/Delete Post 
I have only once had a virus let loose on my system, and that is because I put it there on purpose. I use to write viruses in my spare time to test my ability to do so. The best viruses are the most simple because they often are overlooked as a virus and do more damage in a shorter period of time.

Although I never loosed them on anyone else, I am just not that mean.

Dave

 |  IP: Logged

Paul G. Thompson
The Weenie Man

Posts: 4718
From: Mount Vernon WA USA
Registered: Nov 2000


 - posted 04-16-2002 01:11 PM      Profile for Paul G. Thompson   Email Paul G. Thompson   Send New Private Message       Edit/Delete Post 
Check the win.ini file in the windows directory. Look under the load= and see if there is a reference to the file you deleted. If there is, delete that reference.

Back up the win.ini file first.



 |  IP: Logged

Bernard Tonks
Jedi Master Film Handler

Posts: 619
From: Cranleigh, Surrey, England
Registered: Apr 2001


 - posted 04-22-2002 06:22 AM      Profile for Bernard Tonks   Email Bernard Tonks   Send New Private Message       Edit/Delete Post 
Another virus hoax I received but fortunately I didn't fall for it this time by checking the McAfee site first. Brought up before, fully reproduced after the notice.

AVERT HOAX Notice!!
McAfee AVERT Labs would like to inform you of a new email HOAX.
This email message is just a HOAX. Although, the SULFNBK.EXE file may become infected by a number of valid viruses (most commonly W32/MAGISTr@MM , the details of this HOAX message are not based on actual events.
We are advising users who receive the email to delete the message and DO NOT pass it on as this is how an email HOAX propagates.
SULFNBK.EXE is a Microsoft Windows utility that is used to restore long file names

Below is the actual text from the message that may be received via email. There are numerous variations on these messages.
..................................................................

I found the "sulfnbk virus" in my computer, which McAfee did not detect. It sends itself to all the addresses in the address book of the computer it has arrived at. Since you are in our address book I thought you might want to check for this. The virus hides in the computer for 2 weeks & then damages the hard drive irreparably, so I'm told.
1. go to "Start" & click "Find"
2. in the box "find files or folders" type sulfnbk.exe which is the name of the virus
3. make sure you are searching in the hard or c-drive
4. click "find"
5. if the file is found, you will see an ugly black icon with name sulfnbk.exe , the file is a program. DO NOT OPEN IT.!!
6. click on the RIGHT button of the mouse, on the ugly black file icon, & then click on "delete" with the LEFT button on the mouse.
7. you will be asked if you want to send the file to the wastebasket/recycling bin. respond "yes".
8. go to the Desktop, open the wastebasket/recycling bin & eliminate the file, manually or by emptying the entire basket/bin.
9. if you find this virus in your computer, send this e-mail to all the people in your address book, because the virus is transmitted this way & if you don't warn them, aside from ruining their hard drive, it will come back to you if you are in their address books.


 |  IP: Logged

Dave Macaulay
Film God

Posts: 2321
From: Toronto, Canada
Registered: Apr 2001


 - posted 04-22-2002 07:54 AM      Profile for Dave Macaulay   Email Dave Macaulay   Send New Private Message       Edit/Delete Post 
There is a huge clue there that it's a hoax.
You are told to delete the file then immediately empty the trash or permanently delete the file from the trashbin.
Files in the trash can NOT be executed, trying only brings up the properties window for the file. The only reason for insisting on permanently deleting it is malicious - so you can't just replace it when you realize you were suckered. (plus - right click then shift-delete will permanently delete a file and bypass the trashbin. A big AV company should know that!)
But these things aren't targeted at people who know that kind of stuff I suppose.

 |  IP: Logged

Ian Price
Phenomenal Film Handler

Posts: 1714
From: Denver, CO
Registered: Jun 99


 - posted 04-22-2002 05:45 PM      Profile for Ian Price   Email Ian Price   Send New Private Message       Edit/Delete Post 
On Friday April 16th I got a notice from AVG anti-virus program that there was a new patch to protect against this worm virus. I downloaded it.

On Monday April 22 it found a worm virus in an email sent to our public account. I deleted it without a problem. I also forwarded it to abuse@earthlink.net but I suspect that they will not be able to do anything about it.

This is the first virus I have received from an anonymous source. The previous viruses first attacked our company servers and attached themselves to outgoing emails. My anti-virus program caught them too.

Ooh, I feel all dirty.

My only advice is to keep your anti-virus programs current.

Mighty Mouse is here to save the day!


 |  IP: Logged

Joe Redifer
You need a beating today

Posts: 12859
From: Denver, Colorado
Registered: May 99


 - posted 04-22-2002 06:27 PM      Profile for Joe Redifer   Author's Homepage   Email Joe Redifer   Send New Private Message       Edit/Delete Post 
I have not read this thread in it's entirety, so forgive me if I bring up something that has already been discussed.

Lately I have been getting a bunch of e-mails with files attached. Usually they are .HTML, .JPG, .EXE, and .BAT files. There is no text whatsoever in the e-mails. Of course the JPG files are not really JPG files since they won't open in my graphics programs on my Mac. These are not HTML mails I am receiving, either. Definitely viruses attached, and there seems to be a ton of 'em! The mail usually comes from someone I've never heard of and they have odd subjects like "NAV Bottom". That's about the closest thing to a pattern I can see.

Of course being on a Mac I am not affected, except that I get a lot of these e-mails. But it sure is annoying!

 |  IP: Logged

Paul G. Thompson
The Weenie Man

Posts: 4718
From: Mount Vernon WA USA
Registered: Nov 2000


 - posted 04-22-2002 07:46 PM      Profile for Paul G. Thompson   Email Paul G. Thompson   Send New Private Message       Edit/Delete Post 
We got hit again with the sircam and ninja stuff at the radio station. Scanning the boss's machine, there were over 450 files that were plowed. I am going to have to format the drive.

All this stuff is coming through Outlook Express. I can just look at the monitor, and out of nowhere, all these EML files just pop up on the monitor.

Now I have a suspicion why my computer sees and stops lots of port scan attacks. The other machines on the network don't have that software installed to see and block them.

I have to find a firewall program that will work with our old clunkers, as they are P-133's, and some of the anti-virus software slows those already painfully slow machines to a dead crawl.

 |  IP: Logged

Darryl Spicer
Film God

Posts: 3250
From: Lexington, KY, USA
Registered: Dec 2000


 - posted 04-22-2002 10:46 PM      Profile for Darryl Spicer     Send New Private Message       Edit/Delete Post 
Go online to www.housecall.antivirus.com THis is a good site for checking your system for viruses, worms and all kinds of junk.

 |  IP: Logged

Leo Enticknap
Film God

Posts: 7474
From: Loma Linda, CA
Registered: Jul 2000


 - posted 04-23-2002 03:20 AM      Profile for Leo Enticknap   Author's Homepage   Email Leo Enticknap   Send New Private Message       Edit/Delete Post 
Paul - the resident process for the free version of Zonealarm only claims to be eating 72k in the task manager. If your old P133s have plenty of memory I doubt if it would slow them down too much.

 |  IP: Logged

Adam Martin
I'm not even gonna point out the irony.

Posts: 3686
From: Dallas, TX
Registered: Nov 2000


 - posted 06-15-2002 12:32 AM      Profile for Adam Martin   Author's Homepage   Email Adam Martin       Edit/Delete Post 
This Klez crap is getting out of hand. Now I'm getting emails that say this:

quote:

Klez.E is the most common world-wide spreading worm.It's very dangerous by corrupting your files. Because of its very smart stealth and anti-anti-virus technic,most common AV software can't detect or clean it. We developed this free immunity tool to defeat the malicious virus.
You only need to run this tool once,and then Klez will never come into your PC.
NOTE: Because this tool acts as a fake Klez to fool the real worm,some AV monitor maybe cry when you run it. If so,Ignore the warning,and select 'continue'. If you have any question,please (email tag deleted) mail to me.

Hmmm... lessee ... if my AV monitor says it blocked the Klez virus, exactly why would I want your program to do the same thing?! Dumkopf.


 |  IP: Logged

Aaron Sisemore
Flaming Ribs beat Reeses Peanut Butter Cups any day!

Posts: 3061
From: Rockwall TX USA
Registered: Sep 1999


 - posted 06-15-2002 04:07 AM      Profile for Aaron Sisemore   Email Aaron Sisemore   Send New Private Message       Edit/Delete Post 
Those 'Klez innoculator' emails usually contain the genuine Klez worm anyways.

They are both a hoax and a threat.

-Aaron

 |  IP: Logged



All times are Central (GMT -6:00)
This topic comprises 2 pages: 1  2 
 
   Close Topic    Move Topic    Delete Topic    next oldest topic   next newest topic
 - Printer-friendly view of this topic
Hop To:



Powered by Infopop Corporation
UBB.classicTM 6.3.1.2

The Film-Tech Forums are designed for various members related to the cinema industry to express their opinions, viewpoints and testimonials on various products, services and events based upon speculation, personal knowledge and factual information through use, therefore all views represented here allow no liability upon the publishers of this web site and the owners of said views assume no liability for any ill will resulting from these postings. The posts made here are for educational as well as entertainment purposes and as such anyone viewing this portion of the website must accept these views as statements of the author of that opinion and agrees to release the authors from any and all liability.

© 1999-2020 Film-Tech Cinema Systems, LLC. All rights reserved.