To register for an Internet.com membership to receive newsletters and white papers, use the Register button ABOVE.
To participate in the message forums BELOW, click here

WinDrivers Computer Tech Support Forums  

Go Back   WinDrivers Computer Tech Support Forums > For Techs Only > Spyware & Antivirus - Security

Spyware & Antivirus - Security Discuss all system security, spyware, adware and malware issues here.

Reply
 
Thread Tools Search this Thread Display Modes
Old February 7th, 2001, 09:38 AM   #1
gpint
Registered User
 
Join Date: Aug 2000
Location: Minnesota
Posts: 198
Question null@192.168.0.20

Does anyone know anything about an email that is received with the return address of null@192.168.0.20 (this is the ip address of the machine that sent the email).

Is this a virus? I searched the different antivirus sites and have not found anything.
gpint is offline   Reply With Quote
Old February 7th, 2001, 09:47 AM   #2
SiCkNuT
Guest
 
Posts: n/a
Post

Ummm I think when I had a customers PC that was infected with the KAK virus, it had originated from an email that appeared to be sent from a NULL address. Be careful because if it IS KAK then it's a real bugger to get rid of. It causes Internet Explorer to crash when you visit the antivirus research centre (www.sarc.com) so I guess that's one way of finding out if you've got it or not! Happy virus hunting!!

------------------
[ i N S A N i T Y 2 0 o 1 ]
  Reply With Quote
Old February 7th, 2001, 10:11 AM   #3
gpint
Registered User
 
Join Date: Aug 2000
Location: Minnesota
Posts: 198
Post

Thanks for the quick response. I wasnt familliar with this version of the KAK virus, I checked the registry on the infected machine and it was there. Thanks for your help
gpint is offline   Reply With Quote
Old February 7th, 2001, 03:21 PM   #4
GirlGeek
Guest
 
Posts: n/a
Post

KAK is fairly easy to get rid of if you remember to fdisk /mbr with a clean, protected boot disk after you clean the system.

------------------
Sarchasm: The gulf between the author of sarcastic wit, and
the recipient who doesn't get it.
  Reply With Quote
Old February 8th, 2001, 11:10 AM   #5
gpint
Registered User
 
Join Date: Aug 2000
Location: Minnesota
Posts: 198
Post

I just found that this is not the KAK virus, but is W95.Hybris.Gen.dr

I couldnt find anything about it at sarc, does anyone know anything about this virus.
What it does, and how to get rid of it.
gpint is offline   Reply With Quote
Old February 8th, 2001, 12:20 PM   #6
Jeff the Brit
Registered User
 
Join Date: Aug 2000
Location: Saltburn, Cleveland, United Kingdom
Posts: 632
Post

Go here for info : http://vil.nai.com/vil/dispVirus.asp?virus_k=98873

Free virus checkers that will cure your problem include F-Prot ( www.complex.is/f-prot ) and InnoculateIT ( www.cai.com )

Good luck !

------------------
Still scrambling up the learning curve ...
__________________
I think I know just enough to know how much I don't know... I think...
Jeff the Brit is offline   Reply With Quote
Old February 9th, 2001, 08:54 PM   #7
jfesler
Guest
 
Posts: n/a
Post

W95.Hybris is a worm that spreads by email as an attachment to outgoing emails. It was discovered in late September of 2000. Although very few reports of infection were reported in October 2000 when the worm was discovered, the worm is becoming more common in November and December

The message may include the text "Snow White and the Seven dwarves" and the attachment may have one of several different names, including, but not limited to:

anpo porn(.scr
atchim.exe
branca de neve.scr
dunga.scr
dwarf4you.exe
enano porno.exe
joke.exe
midgets.scr
sexy virgin.scr

Use Norton AntiVirus to repair the infected WSOCK32.DLL. Other files detected as W95.Hybris contain only the virus body and must be deleted.

http://www.sarc.com/avcenter/venc/da...ybris.gen.html



------------------
Everywhere you go, there you are...
  Reply With Quote
Reply

Bookmarks

Thread Tools Search this Thread
Search this Thread:

Advanced Search
Display Modes

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is On
HTML code is Off
Forum Jump


All times are GMT -5. The time now is 04:51 PM.



Acceptable Use Policy

internet.comMediabistrojusttechjobs.comGraphics.com

WebMediaBrands Corporate Info


Advertise | Newsletters | Feedback | Submit News

Legal Notices | Licensing | Permissions | Privacy Policy

Powered by vBulletin® Version 3.7.3
Copyright ©2000 - 2009, Jelsoft Enterprises Ltd.