[identity profile] jahbulon.livejournal.com posting in [community profile] techrecovery
That nasty bastard of a virus I had was the Tibick.A

For all you ISP support peeps :
Symptoms : Cannot browse to antivirus sites, window closes.
Cannot search for antivirus products, window closes.
Cannot access Processes window in task manager, it comes up blank.
Cannot access msconfig.
Cannot access regedit.
Cannot access SP2 firewall or security settings.

http://www3.ca.com/securityadvisor/virusinfo/virus.aspx?id=39924

Spreads via P2P file-sharing. Smart little bastard.
From: [identity profile] irishmasms.livejournal.com
smart people do not use P2P, they find other ways to share with friends ;)


Smart people also use an OS other than WinDoz. =D

torkell: (Default)
From: [personal profile] torkell
Smart people stay with Windows, but lock it down somewhat and still know how to kill it themselves and save a virus the trouble (done that a few times).

I hadn't spotted that regedit was blocked - if it was by the policy setting, my favourite trick is to hex-edit regedit.exe to remove that ability (search for the registry key and mangle the name so it doesn't get found. Don't forget to update/remove the file checksum as well else windows won't run it). The same trick can also be done with taskmgr.exe and cmd.exe. I've got copies of all three mangled for Win2k and WinXP, and they come in handy occassionally.

a better answer

Date: 2004-10-11 02:46 pm (UTC)
From: [identity profile] irishmasms.livejournal.com
smart people use the right tool (the right operating system) for the job at hand, and stay away from OS wars.



Re: a better answer

Date: 2004-10-11 04:14 pm (UTC)
From: [identity profile] irishmasms.livejournal.com
Actually, none of the above - but clearly you are a wanker noob who gets their WinDoz infucted up, bitch & complain, but refuse to try anything else. It is not like we hear this same crap over & over - this is the [livejournal.com profile] techsupport community is it not? the same crap is posted every day!

You attitude is disheartening (http://www.amishrakefight.org/gfy/), as a ignorant, biased windoz zealot. Het over it will ya? Your life & stress level will be much better for it.

(You clearly did not see the sarcasm in the original comments posted, and the flame war commenced. You can get over it now - I am.)

Date: 2004-10-11 02:53 pm (UTC)
From: [identity profile] loosechanj.livejournal.com
So hmm, how did you come to get infected anyway. Smart people (gotta go with the meme) virus scan their cracks and keygens.

Date: 2004-10-11 03:53 pm (UTC)
From: [identity profile] loosechanj.livejournal.com
Let this be a lesson to you! :-P Seriously, I've infected myself once and knew it immediately. Didn't need an AV to tell me, and first thing I did was look in the reg to see what had been thrown into "Run".

Date: 2004-10-11 03:36 pm (UTC)
From: [identity profile] gravito.livejournal.com
Don't rely on the Windows.

Not the OS, I mean the windows themselves. Get PSkill from foundstone and use that rather than the task manager.

Date: 2004-10-11 05:01 pm (UTC)
From: [identity profile] residentgeek.livejournal.com
You're really persistent to be able to track that down. I'm not sure I would have put the effort into it. Glad you finally solved it, though.

Date: 2004-10-11 05:09 pm (UTC)
From: [identity profile] residentgeek.livejournal.com
Yeah, that's a good point. I do support for a college campus, but mostly instructors. We've got images of nearly every setup, so if it gets really, really nasty, I just kill it. If I were to track it back to filesharing, though, I could get them fired :o) Woohoo!

Date: 2004-10-11 09:25 pm (UTC)
ximinez: (Default)
From: [personal profile] ximinez
This has nothing (IMHO) to do with Windows, warez, or P2P file sharing networks. (Disclosure: I work for a P2P software company, but I'm not going to say which one.)

This has to do with running arbitrary executable files without first verifying their authenticity beyond a file name.

The same thing could happen on any OS with any file transfer method. Including private transfers between friends. It only takes one person stupid enough to run it the first time...

Date: 2004-10-11 10:01 pm (UTC)
ximinez: (Default)
From: [personal profile] ximinez
Sarcasm noted.

But, OTOH, you're the one who got infected.

Antivirus software is nice, but, well, to use a bad metaphor, the flu vaccine isn't going to protect you for very long if you dig through dumpsters and stick every needle you find into your arm.

Well said

Date: 2004-10-12 03:52 am (UTC)
From: [identity profile] markiemole.livejournal.com
I myself work as tech support and I find the info that you have put in very interesting and helpful, I read this journal every day and have noted that everyone tells everyone else stuff that the average 10 year old knows, also these OS flame wars that go on are stupid, windows does what it say's on the tin, Linux works ok depending on what you what to do with it and mac, well it's just Mac

Date: 2004-10-12 09:41 am (UTC)
ximinez: (Default)
From: [personal profile] ximinez
Ok, this'll be my last post on this subject.

This has nothing to do with any agenda I may or may not have. The fact is that you're focusing on the wrong problem, and blaming the messenger (P2P in this case).

The basic problem is allowing stuff to run on your computer without knowing what it is. We see it when people open random attachments, we see it when people download warez. Hell, if some stranger walked up to you on the street, handed you a floppy disk (or unlabeled CD-ROM) and said, "Dude, run this on your computer," would you? You may as well, because you did the same damn thing when you ran that program you downloaded.

That's why I say this has nothing to do with Windows, warez, or P2P. You could easily download a cracked copy of VMWare for linux, and have it turn out to be a linux virus/worm, for example.

There have been documented cases of professional software products shipping with viruses on the CD-ROM. However, people don't call you stupid when that happens, because a supposedly reliable organization vouched for the disk when you bought it.

Who vouches for warez?

That's why I say this has nothing to do with P2P. P2P is just the transport.

Next point: there is a distinct and non-zero amount of time between when a new virus is released into the wild and when the latest AV software update can detect and stop it. So claiming that you forgot to install AV software as your excuse is meaningless. You could have had AV software installed and updated, and still have caught this thing. Why? Back to my fundamental point: you allowed stuff to run on your computer without knowing what it is.

I'm not even trying to help you, and I never was. I saw from the original message that you had fixed the problem. I was curious as to how a virus could spread through P2P, so I read the linked article and concluded, "P2P is a red herring; this is another stupidity virus, just like I Love You, Klez, Blaster, and a thousand others." So I thought I'd post a clarification, both to you, and to everybody here who said to run Linux (which I do at home) or Firefox (which I do exclusively): it doesn't matter what OS or browser you're running if you still run random executables. Yeah, Linux and Firefox and Thunderbird etc. will protect you from most exploits, and certain kinds of mistakes, but there has not been a program written yet that can stop a determined user from screwing themselves over if they really want to...

Next point: Obviously, the things I'm telling you are not things you've known since you were twelve, or else you never would have been infected in the first place...

That's enough - rant off. I'm done.

Profile

techrecovery: (Default)
Elitist Computer Nerd Posse

April 2017

S M T W T F S
      1
2345678
91011121314 15
16171819202122
23242526272829
30      

Most Popular Tags

Style Credit

Expand Cut Tags

No cut tags
Page generated Mar. 20th, 2026 12:39 am
Powered by Dreamwidth Studios