Cobra Club Forums
Cobra Club Forums

Welcome to the Cobra Club Forums forums.

You are currently viewing our boards as a guest which gives you limited access to view most discussions and access our other features. By joining our free community you will have access to post topics, communicate privately with other members (PM), respond to polls, upload content and access many other special features. Registration is fast, simple and absolutely free so please, join our community today!

If you have any problems with the registration process or your account login, please contact contact us.

Go Back   Cobra Club Forums > General Discussion > Feedback, Membership and Help
Home Forums Blogs Videos Gallery Cobra Marques Info Groups Classifieds Gallery Arcade Shopping
Register FAQ Members List Calendar Search Today's Posts Mark Forums Read

Reply
 
LinkBack Thread Tools Display Modes
  #1 (permalink)  
Old 27-08-04, 09:41 PM
maxGD059's Avatar
Senior Member
 
Join Date: May 2002
Location: Leicestershire, UK.
Posts: 1,300
Backdoor netscape virus

It's friday afternoon, I'm on my own at work (buisness partner holidaying in france). Its busy, no infact it's frantic & what happens, well sh** actually. The network goes down with the above mentioned virus. How its happened well GOK but it has. The usual spyware kit can isolate it but can I get into the Registry to delete it? By heck I can. As soon as I go into the Register Editor then the Editor closes before any chance to sort it. Frustrating or what. At least I've got 3 days to forget today which may as well have been friday 13th. Any ideas guys, to make tuesday morning half bearable?
__________________
Richard (-the one with 3 mad Wheaten Terriers)
Digg this Post!Add Post to del.icio.usBookmark Post in TechnoratiFurl this Post!
Reply With Quote
Sponsored Links
Advertisement
  #2 (permalink)  
Old 27-08-04, 10:12 PM
wilf's Avatar
Club Supporter
 
Join Date: Jan 2001
Location: On the naughty step
Posts: 8,145
Re: Backdoor netscape virus

nope - you are shafted. LOL

let's go for a beer instead.
__________________
My opinion is worth exactly what you paid for it.

CRENDON - go on, you know you want to!
Digg this Post!Add Post to del.icio.usBookmark Post in TechnoratiFurl this Post!
Reply With Quote
  #3 (permalink)  
Old 27-08-04, 10:16 PM
maxGD059's Avatar
Senior Member
 
Join Date: May 2002
Location: Leicestershire, UK.
Posts: 1,300
Re: Backdoor netscape virus

Done that already, x3 infact as I've realised my local has got Tanglefoot as a guest beer. Oh, and also had an excellent curry but not from the pub. Feeling better now -sod work.

Talking of which Wilf, how's tricks?
__________________
Richard (-the one with 3 mad Wheaten Terriers)
Digg this Post!Add Post to del.icio.usBookmark Post in TechnoratiFurl this Post!
Reply With Quote
  #4 (permalink)  
Old 27-08-04, 11:27 PM
wilf's Avatar
Club Supporter
 
Join Date: Jan 2001
Location: On the naughty step
Posts: 8,145
Re: Backdoor netscape virus

Richard - you have email.
__________________
My opinion is worth exactly what you paid for it.

CRENDON - go on, you know you want to!
Digg this Post!Add Post to del.icio.usBookmark Post in TechnoratiFurl this Post!
Reply With Quote
  #5 (permalink)  
Old 28-08-04, 10:20 AM
maxGD059's Avatar
Senior Member
 
Join Date: May 2002
Location: Leicestershire, UK.
Posts: 1,300
Re: Backdoor netscape virus

Wilf

Good to hear from you & have returned your email. It's amazing stuff that Tanglefoot. It made me forget I'd actually had 4 or was it 5 of them, & then typed in the virus name incorrectly
Its the Backdoor Netsnake virus.

(rather appropriate on the CRC forum!)

Probably just as much of a case of FUBAR methinks though
__________________
Richard (-the one with 3 mad Wheaten Terriers)
Digg this Post!Add Post to del.icio.usBookmark Post in TechnoratiFurl this Post!
Reply With Quote
  #6 (permalink)  
Old 28-08-04, 12:16 PM
kdavies3's Avatar
Senior Member
 
Join Date: May 2004
Location: Broughton nr Cowbridge, Vale of Glamorgan, South Wales.
Posts: 3,126
Re: Backdoor netscape virus

Here is some infomation you may find helpful: from: http://www.sophos.com/virusinfo/anal...netsnakeh.html

Troj/Netsnake-H is a backdoor Trojan.

In order to run automatically when Windows starts up the Trojan copies
itself to the file iexplore.exe in the Windows system folder and adds the following registry entry pointing to this file:

HKLMSoftwareMicrosoftWindowsCurrentVersionRunmssys int

Troj/Netsnake-H also drops the file psinthk.dll into the Windows system folder.

i guess you are tryin to remove this registory entry:

HKEY_LOCAL_MACHINE entry:

HKLMSoftwareMicrosoftWindowsCurrentVersionRunmssys int


but as for the registry closing on its own thats a puzzler.

Which Anti-Virus Program are you running?
__________________
Kev Davies
South Wales
DAX, 383 Chevy Stroker,
Digg this Post!Add Post to del.icio.usBookmark Post in TechnoratiFurl this Post!
Reply With Quote
Sponsored Links
Advertisement
  #7 (permalink)  
Old 28-08-04, 07:43 PM
maxGD059's Avatar
Senior Member
 
Join Date: May 2002
Location: Leicestershire, UK.
Posts: 1,300
Re: Backdoor netscape virus

Kev

Thanks for your thoughts. Think we run Mcafee at work which is now a zillion miles away as its bank holiday w/e thank goodness. Looks like the brown stuff will hit the fan on tuesday, but till then, well, I think I do some fly scraping of the screen in preparation for donnington!!
__________________
Richard (-the one with 3 mad Wheaten Terriers)
Digg this Post!Add Post to del.icio.usBookmark Post in TechnoratiFurl this Post!
Reply With Quote
  #8 (permalink)  
Old 28-08-04, 08:31 PM
robert's Avatar
Administrator
 
Join Date: Jan 1999
Location: Northampton, Northampton, UK.
Age: 38
Posts: 8,610
Re: Backdoor netscape virus

Richard

Give me a call on the number in the mag, I can point you in the right direction. :thumb:

HTH
__________________
Best Regards

Robert

My Son had a toy steering wheel which he used to spin furiously, making loads of go-faster noises, leaning into all the tight corners, perhaps running the government feels a bit like that. You make all the noises, but when you stop you haven't really gone anywhere.
Digg this Post!Add Post to del.icio.usBookmark Post in TechnoratiFurl this Post!
Reply With Quote
  #9 (permalink)  
Old 28-08-04, 09:21 PM
Miket's Avatar
Fully Paid Up Grandad
 
Join Date: Jul 2001
Location: Newton Abbot, Devon, UK. (God's waiting room)
Age: 60
Posts: 10,277
Re: Backdoor netscape virus

Quote:
Originally Posted by robert
Richard

Give me a call on the number in the mag, I can point you in the right direction. :thumb:

HTH
Where to, Donnington :thumb: :thumb:
__________________
AK 427 FOR SALE


PistonHeads AK for sale


Mike
AK Sportscars
355 Hauser Chevy

The old believe everything, the middle-aged suspect everything, the young know everything.


Digg this Post!Add Post to del.icio.usBookmark Post in TechnoratiFurl this Post!
Reply With Quote
  #10 (permalink)  
Old 29-08-04, 11:25 AM
maxGD059's Avatar
Senior Member
 
Join Date: May 2002
Location: Leicestershire, UK.
Posts: 1,300
Re: Backdoor netscape virus

Thanks Rob. I wasn't looking forward to tuesday!
__________________
Richard (-the one with 3 mad Wheaten Terriers)
Digg this Post!Add Post to del.icio.usBookmark Post in TechnoratiFurl this Post!
Reply With Quote
Sponsored Links
Advertisement
Reply

Thread Tools
Display Modes

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

vB code is On
Smilies are On
[IMG] code is On
HTML code is Off
Trackbacks are On
Pingbacks are On
Refbacks are On

Similar Threads
Thread Thread Starter Forum Replies Last Post
Virus - Help RamSC427 Feedback, Membership and Help 23 13-09-05 03:14 PM
virus W32/Elkern.C rich Feedback, Membership and Help 9 06-04-05 07:03 PM
Virus Miket The Cockpit 3 07-03-05 04:39 PM
virus craigh General Cobra Discussion 6 05-03-04 10:18 PM
Virus I think! rocket General Cobra Discussion 13 26-09-03 11:38 AM


All times are GMT. The time now is 02:07 PM.


Powered by vBulletin® Version 3.7.0 Beta 4
Copyright ©2000 - 2008, Jelsoft Enterprises Ltd.
Search Engine Optimization by vBSEO 3.2.0