ABXZone Computer  Forums



Welcome to the ABXZone Computer Forums forums.

You are currently viewing our boards as a guest which gives you limited access to view most discussions and access our other features. By joining our free community you will have access to post topics, communicate privately with other members (PM), respond to polls, upload content and access many other special features. Registration is fast, simple and absolutely free so please, join our community today!

If you have any problems with the registration process or your account login, please contact contact us.

Reply
 
LinkBack Thread Tools Display Modes
Old 12-09-2004, 12:24 PM   #1
Resident ABX Wizard
 
Fraoch's Avatar
 
Join Date: May 2003
Location: London, Ontario
Posts: 8,814
Thumbs up First time AV kicked in


I've been using AV products since I first got into Windows computing back in 1998.

Today is the first time my AV scanner actually tripped. I received an e-mail infected with the W32-NetSky worm. avast! kicked in and told me about it, so I deleted the attachment.

Then I deleted the e-mail (now marked as infected and stripped of its payload attachment).

In all these years, this is the first time any AV has ever kicked in. Good to know all my attention to this stuff finally paid off.

...although I would never have opened it anyway as it was from an unknown sender with the subject "hi" and the message body reading "Important informations attached".

(Offline)   Reply With Quote
Old 12-09-2004, 12:58 PM   #2
Remembering TQ
 
k0NG0's Avatar
 
Join Date: Mar 2001
Location: Sweden
Posts: 13,627
Classic worm mail, that.

I've had my AV tripped a few times by false positives and a few times by some web page-related obscurity. I've never been infected with a virus or worm. Then again, I've always been equipped with a healthy paranoia regarding these things .
__________________

Use Firefox - "the one that blocks all the schmutz"
Feeling multicore elation? Remember this correlation: Amdahl's Law.
(Offline)   Reply With Quote
Old 12-09-2004, 01:03 PM   #3
Resident ABX Wizard
 
Fraoch's Avatar
 
Join Date: May 2003
Location: London, Ontario
Posts: 8,814
Quote:
Originally Posted by kONGO
I've always been equipped with a healthy paranoia regarding these things .
I firmly believe you can't be too paranoid about computer security as there are just so many exploits out there it's mind-blowing.

Perhaps I'm wearing the computer equivalent of a "tin foil hat" but unlike real life, they really can get you remotely in the computer world.
(Offline)   Reply With Quote
Old 12-09-2004, 01:11 PM   #4
Remembering TQ
 
k0NG0's Avatar
 
Join Date: Mar 2001
Location: Sweden
Posts: 13,627
Ah, the classic Aluminum Foil Deflector Beanie....

http://zapatopi.net/afdb.html

__________________

Use Firefox - "the one that blocks all the schmutz"
Feeling multicore elation? Remember this correlation: Amdahl's Law.
(Offline)   Reply With Quote
Old 12-09-2004, 01:16 PM   #5
I'm gettin' dizzy!
 
Bofinn's Avatar
 
Join Date: Jan 2004
Location: Chicagoland
Posts: 11,035
I "accidently" ummm yeah that's it, was surfing porn a few weeks ago. I hit a few sites that NAV stopped about 6 trojan's in a row. Had to click 6 times, closed the site, scanned and cleaned system.


I think it was a russian site...
__________________
---------- JimBo -----------



When in doubt, smack it!
(Offline)   Reply With Quote
Old 12-09-2004, 05:44 PM   #6
Resident ABX Wizard
 
Fraoch's Avatar
 
Join Date: May 2003
Location: London, Ontario
Posts: 8,814
Watch out for that Russian porn Bofinn!

(Offline)   Reply With Quote
Old 12-09-2004, 06:35 PM   #7
Unscanable!!! Tatoo???
 
Deer Slayer's Avatar
 
Join Date: Dec 2002
Location: Howell Michigan
Posts: 3,843
Talking I still don't have any AV software installed.

I very rarely get viruses too. My e-mail gets scanned by my isp, so I really don't want or need redundant protection on my puter. Then my firewall and the cc box keep other bs from getting in. When I do get viruses it's some worm from some stupid security hole in windows that the AV products don't catch because it's too new and wouldn't stop it anyway. The only other situation is when I download something questionable and I know I have to check it out first. I had a version of mydoom get by my isp when it first came out, but it didn't look like something legit anyway so I deleted it. I scan my puter with panda's active scan every once in a while, usually after I've been up to no good.
(Offline)   Reply With Quote
Old 12-09-2004, 09:07 PM   #8
Resident ABX Wizard
 
Fraoch's Avatar
 
Join Date: May 2003
Location: London, Ontario
Posts: 8,814
I get my mail from Yahoo! and they're supposed to scan, so I wonder how something so common could get through.
(Offline)   Reply With Quote
Old 12-17-2004, 03:39 PM   #9
Resident ABX Wizard
 
Fraoch's Avatar
 
Join Date: May 2003
Location: London, Ontario
Posts: 8,814
Got two more in the past few days.

One was someone I could potentially have communicated with, but one was a spammer with an e-mail address like "he5yt35yym4hvbn@domain.ext" I hope this doesn't mean I'm on some spam list somewhere.
(Offline)   Reply With Quote
Old 12-17-2004, 03:47 PM   #10
Never Ending
 
wayne_abx's Avatar
 
Join Date: Jul 2002
Location: Vancouver, Washington (State)
Posts: 4,188
I thought @domain.ext was a redirect?

-wayne
__________________
System-1 (primary)
Intel D875PBZLK FMB 1.5 > Pentium 4/ 3.0E (D0) > Crucial Ballistix 512mb PC4000 (Dual Channel) > ATI Radeon 9500 Pro (128) > Audigy 2 Platinum > Thermaltake P4 Spark 7+ (Xaser Edition) - Antec 80x80mm x5 > 1x 80GB WD SE - 2x Seagate 200GB 7200RPM Barracuda 7200.7 Plus SATA > Lite-On LDW811s dvd +/- Tashiba SDM1712 DvD > Antec 430 TP > WinXP W/SP-2

Gigabit Network, Linksys WRT54GS, Linksys EG008W 8-port gigabit switch, ximeta network storage, Motorola SB4200
(Offline)   Reply With Quote
Old 12-17-2004, 04:03 PM   #11
Resident ABX Wizard
 
Fraoch's Avatar
 
Join Date: May 2003
Location: London, Ontario
Posts: 8,814
Quote:
Originally Posted by wayne
I thought @domain.ext was a redirect?

-wayne
No, I just used "domain.ext" as an example. It was something.ch.
(Offline)   Reply With Quote
Old 12-17-2004, 04:11 PM   #12
Resigned
 
Join Date: Nov 2002
Location: CO, Denver
Posts: 2,593
Quote:
Originally Posted by Fraoch
I've been using AV products since I first got into Windows computing back in 1998.
...
In all these years, this is the first time any AV has ever kicked in. Good to know all my attention to this stuff finally paid off.
...
so all these years your pc's were spending its resources for av and it finally paid-off by catching infected email? Way too small pay-off, IMHO. By using hotmail with it's internal av u could have eliminated even that...
__________________
P4S8X , PSU , RAID , XP SP2
(Offline)   Reply With Quote
Old 12-17-2004, 04:16 PM   #13
Resident ABX Wizard
 
Fraoch's Avatar
 
Join Date: May 2003
Location: London, Ontario
Posts: 8,814
Quote:
Originally Posted by borodar
so all these years your pc's were spending its resources for av and it finally paid-off by catching infected email? Way too small pay-off, IMHO. By using hotmail with it's internal av u could have eliminated even that...
I prefer to have AV/firewalling under my own direct control, not Hotmail's.

Resources are there to be used. What good is continually having massive amounts of resources free if it's never used for anything? I've tried to trim as much bloat from my system as possible but security is a very wise use of it in my opinion.
(Offline)   Reply With Quote
Old 12-17-2004, 04:17 PM   #14
Never Ending
 
wayne_abx's Avatar
 
Join Date: Jul 2002
Location: Vancouver, Washington (State)
Posts: 4,188
Quote:
Originally Posted by Fraoch
No, I just used "domain.ext" as an example. It was something.ch.
It is a popular redirect cookie, did you pull that name out of the air?

-wayne
__________________
System-1 (primary)
Intel D875PBZLK FMB 1.5 > Pentium 4/ 3.0E (D0) > Crucial Ballistix 512mb PC4000 (Dual Channel) > ATI Radeon 9500 Pro (128) > Audigy 2 Platinum > Thermaltake P4 Spark 7+ (Xaser Edition) - Antec 80x80mm x5 > 1x 80GB WD SE - 2x Seagate 200GB 7200RPM Barracuda 7200.7 Plus SATA > Lite-On LDW811s dvd +/- Tashiba SDM1712 DvD > Antec 430 TP > WinXP W/SP-2

Gigabit Network, Linksys WRT54GS, Linksys EG008W 8-port gigabit switch, ximeta network storage, Motorola SB4200
(Offline)   Reply With Quote
Old 12-17-2004, 04:24 PM   #15
Resident ABX Wizard
 
Fraoch's Avatar
 
Join Date: May 2003
Location: London, Ontario
Posts: 8,814
Quote:
Originally Posted by wayne
It is a popular redirect cookie, did you pull that name out of the air?

-wayne
Yeah I did...I just used it to stand for "domain" as in any domain and "ext" as in any extension.

It's just dumb luck on my part.
(Offline)   Reply With Quote
Reply


Thread Tools
Display Modes

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

vB code is On
Smilies are On
[IMG] code is On
HTML code is Off
Trackbacks are On
Pingbacks are On
Refbacks are On



Powered by vBulletin® Copyright ©2000 - 2008, Jelsoft Enterprises Ltd.
Search Engine Optimization by vBSEO 3.0.1
vBulletin Skin developed by: vBStyles.com