Tjek evt. på http:\\housecall.antivirus.com hvis du altså ikke lige har et anti-virus program liggende i forvejen. Dén side er bare en online version af et AV-program, og giver selvfølgelig ikke 100% sikkerhed, men næsten.
Hvis du ikke er så skrap til engelsk, så hent AntiVir på dansk her: http://www.avirus.dk/startantivir.htm Det er et fremragende freewareprogram med gratis opdateringer, man skal dog selv lige gøre dette ved taste et par gange via ikonet.
jefa > Ja, selvfølgelig er programmet AntiVir det samme på dit link, men du kommer jo da ind på et engelsk site, ik', så derfor det danske link : ) Hvis man ikke er så skrap til engelsk, er det nu meget rart, at kunne læse alt om AntiVir. Der skal jo også vælges version, afhængig af OS.
Hvis der er "magistr" har jeg allerede postet svar!
flere detaljer omkring magistr:
Virus Characteristics:
W32/Magistr@MM is a combination of a files infector virus and e-mail worm. - The viral code infects 32 bit PE type files (.exe) files in the WINDOWS directory and subdirectories. - It uses mass mailing techniques to send itself to email addresses stored in several places. - It installs itself to run at each system startup.
Five minutes after the virus is run, it attempts a mailing routine. Email addresses are gathered from the Windows Address Book, Outlook Express mailboxes, and Netscape mailboxes (address found in email messages within existing mailboxes are gathered), and these file locations and addresses are saved to a hidden .DAT file somewhere on the hard disk (varies). The messages sent by the worm contain varying subject headings, body text, and attachments. The body of the message is derived from the contents of other files on the victim's computer. It may send more than one attachment and may include non .EXE or non-viral files along with an infectious .EXE file. The second letter of the e-mail address in the From field is often changed by the virus. As a result, replying to the message will fail due to the invalid address.
The virus proceeds by infecting 32 bit PE (Portable Executable) type .EXE files found in the WINDOWS SYSTEM directory and subdirectories. The viral code is encrypted, polymorphic, and uses anti-debugging techniques to make it difficult to detect. Email addresses have been seen encrypted in infected files. These addresses are believed to represent other users that have also been infected from the same point of origin.
In the decrypted body of the virus code, the following comments exist:
ARF! ARF! I GOT YOU! v1rus: Judges Disemboweler. by: The Judges Disemboweler. written in Malmo (Sweden)
W32/Magistr@MM has a payload routine that, on some systems, may result in cmos/bios info being erased as well as destroying sectors on the hard disk. Indications Of Infection:
- Icons on the desktop move when the mouse cursor passes over them - Increase in size of .EXE files (adds 24Kb or more) - Infected files use a modified access date of the time of the infection - Presence of a newly created .DAT file containing email addresses (representing those users which were sent the virus) -Entry in WIN.INI RUN=(App) -Entry in Registry, run key value: HKLM\Software\Microsoft\Windows\CurrentVersion\ Run\AppName (varies)=C:\WINDOWS\SYSTEM\(App).EXE (varies)
yeti> Ja det er det samme antivirusprogram, som det engelske link. Selve AntiVir køre med engelsk tekst, men der er en udførlig vejledning på dansk på mit link
Godaften de herrer. Til orientering ser det ud som om Magistr er undervejs igen i b-varianten (den polymorfiske). Jeg ved ikke om de eventuelt skriver mere om det, men Safe2day har skrevet om det idag.
P.S. Er det så afgørende om vejledende tekst er på engelsk eller dansk ?
Tilladte BB-code-tags: [b]fed[/b] [i]kursiv[/i] [u]understreget[/u] Web- og emailadresser omdannes automatisk til links. Der sættes "nofollow" på alle links.