Blasted computer virus!

This topic doesn't directly relate to Escape Velocity, but since I currently have graphic projects relating to many of you EVers, it'd be a good idea to let you all know.

As you all know, my G3 has been down. But right now as I type, my dad and I have been trying to rid the infected computer of a virus known as "666" (That's right... The number of the future antichrist and the devil ;)). Not only that, but the virus is very smart. We've run numerous Norton utilities over the computer (which we have managed to start up), and we've been told everything is fine. We then restart the computer, and everything is once again screwed. Why? The virus reinstalls itself! It has corrupted our system folder...

The only thing I can think of to get the G3 working again is to downgrade to system 9.0 (which should replace the old system file with a new one), and then upgrade again to 9.1. This worked before on a similar virus months ago. It takes a lot of time, but it's our best shot. Just thought I'd let you all know.

The only good news I can give you is that the virus has NOT affected the hard drive in any way. In other words, I haven't lost any of my year's worth of graphics, or Infini-D (thank goodness), or any other major applications. Just hope we can get everything fixed, 'kay? 😉

Also, be on the lookout for this virus. I know I didn't get it through a download file, but instead through e-mail. Be sure that the e-mail files you open are safe. Graphic attachments can NOT have virus attached to them, but .sit files sometimes (but rarely) can. All you Boozerama participants know I hunt down anyone who mocks the name of Dr. Pepper, and I'm going to hunt down the idiot who sent me the virus. 😉

------------------
-Cap'n Skyblade
(url="http://"http://www.saberstudios.f2s.com")Saber Studios(/url) - Your source for original EV/O/N graphics.
the Confederation Graphics Expansion Set: Coming soon

(This message has been edited by Captain Skyblade (edited 10-01-2001).)

I had the virus a few years ago. It is a nasty one. It creates an invisible extension in the extentions folder that infects whatever you open. I may be wrong, but it is a good idea to not open any files that you don't want destroyed. So it was with strain that I had, anyways. I somehow got rid of it. I think it was disinfectant or some other anti-virus program that got rid of it, and then told me to delete a list of all the files that I had opened during time of infection.

Good luck with your computer, and good luck hunting down the perp. 🙂

------------------
--ares
"If a woman has to choose between catching a fly ball and saving an infant's life, she will choose to save the infant's life without even considering if there are men on base." -- Dave Barry
Check out my EV website: (url="http://"http://home.cfl.rr.com/aresev/")The Legion(/url).

ares: You've had a virus before as well? Thay aren't any fun... I got the "hanson" one on my iMac months back, but I already knew of this virus, and immediately deleted the e-mail. It wasn't able to affect my machine.

As for an update:

Good news: My G3 is now up and running, the virus taken care of.

Bad news: My dad is going to need both of our G3s for awhile, so I might not get much time to do graphics.

------------------
-Cap'n Skyblade
(url="http://"http://www.saberstudios.f2s.com")Saber Studios(/url) - Your source for original EV/O/N graphics.
the Confederation Graphics Expansion Set: Coming soon

Geeez, maybe my project is cursed 😉

I'm glad you took care of the virus. Yes, I did have had Sevendust (ie 666) before. It was not very fun, but I think we took care of it before it did too much damage.

I have spoke with several people who are battling Sevendust. How exactly did you get rid of it? Delete infected files, reinstall system....?

------------------
--ares
"If a woman has to choose between catching a fly ball and saving an infant's life, she will choose to save the infant's life without even considering if there are men on base." -- Dave Barry
Check out my EV website: (url="http://"http://home.cfl.rr.com/aresev/")The Legion(/url).

Quote

Originally posted by ares1:
**Geeez, maybe my project is cursed;)

I'm glad you took care of the virus. Yes, I did have had Sevendust (ie 666) before. It was not very fun, but I think we took care of it before it did too much damage.

I have spoke with several people who are battling Sevendust. How exactly did you get rid of it? Delete infected files, reinstall system....?

**

Heh, yeah. Your project is cursed after all. 😉 We'll try to make the best of it, though...

The solution I mentioned before worked. My dad first downgraded our operating system to 9.0, which replaced the corrupted preference file with the older version. We then re-upgraded to version 9.1, which gave us our old system folder, only this time it wasn't corrupted. It took about three hours in all, but it was worth the time.

"Sevendust?" Interesting. Do you have any idea how computers contact this virus? I believe I got it through e-mail, but download files is also possible...

------------------
-Cap'n Skyblade
(url="http://"http://www.saberstudios.f2s.com")Saber Studios(/url) - Your source for original EV/O/N graphics.
the Confederation Graphics Expansion Set: Coming soon

Like most virii, it is contracted from infected files. IE, if you have the virus and run a file, thus making it infected with the self-replicating virus, and then send that file to a friend who opens it, it will replicate itself and infect their system as well.

The virus is called Sevendust, but got the name 666 by the extension file that it creates that carrys that name. It's a very dangerous and malicious virus.

Someone must have sent you a file that was infected. It was, very likely, unknowingly. You aren't the kind of guy who people send viruses to on purpose.

------------------
--ares
"If a woman has to choose between catching a fly ball and saving an infant's life, she will choose to save the infant's life without even considering if there are men on base." -- Dave Barry
Check out my EV website: (url="http://"http://home.cfl.rr.com/aresev/")The Legion(/url).

Quote

Originally posted by ares1:
**
Someone must have sent you a file that was infected. It was, very likely, unknowingly. You aren't the kind of guy who people send viruses to on purpose.

**

Yeap, this virus sounds very similar to "hanson" and "melissa." These also operated the same way.

Actually, there are people out there who would intentionally infect my computer. I won't give names, but certain people even here at the Ambrosia forums would do anything to ruin my day...

------------------
-Cap'n Skyblade
(url="http://"http://www.saberstudios.f2s.com")Saber Studios(/url) - Your source for original EV/O/N graphics.
the Confederation Graphics Expansion Set: Coming soon

Quote

Originally posted by Captain Skyblade:
**Yeap, this virus sounds very similar to "hanson" and "melissa." These also operated the same way.

Actually, there are people out there who would intentionally infect my computer. I won't give names, but certain people even here at the Ambrosia forums would do anything to ruin my day...

**

That's odd to hear. Deny some people your graphics services or something? What would make them want to ruin your day?

------------------
--ares
"If a woman has to choose between catching a fly ball and saving an infant's life, she will choose to save the infant's life without even considering if there are men on base." -- Dave Barry
Check out my EV website: (url="http://"http://home.cfl.rr.com/aresev/")The Legion(/url).

Quote

Originally posted by ares1:
**That's odd to hear. Deny some people your graphics services or something? What would make them want to ruin your day?

**

forge, for example, hates almost everybody for no reason at all. But every since I jumped on him for his downright immature moderator behavior, he's had me on his "most wanted" list. 😉 When he gets mad, he'll do anything he can to make sure you get the message. Nothing against him, but that's just forge...

And if anyone did do this on purpose, they should know that this also really messed up my dad's business.

------------------
-Cap'n Skyblade
(url="http://"http://www.saberstudios.f2s.com")Saber Studios(/url) - Your source for original EV/O/N graphics.
the Confederation Graphics Expansion Set: Coming soon

I wouldn't really know, but I thought forge was an older guy who was just very strict and tended to hold grudges. I can't imagine a moderator sending out virii, but I don't really know him. All I know is that he booted me out of #ev3 for no discernable reason, and that he dislikes one of the most helpful and charitable people on the boards.

I don't want to talk about him and his actions too much, for fear of retribution, but has anyone talked to andrew about his rogue ways? 🙂

------------------
--ares
"If a woman has to choose between catching a fly ball and saving an infant's life, she will choose to save the infant's life without even considering if there are men on base." -- Dave Barry
Check out my EV website: (url="http://"http://home.cfl.rr.com/aresev/")The Legion(/url).

Quote

Originally posted by ares1:
**I wouldn't really know, but I thought forge was an older guy who was just very strict and tended to hold grudges. I can't imagine a moderator sending out virii, but I don't really know him. All I know is that he booted me out of #ev3 for no discernable reason, and that he dislikes one of the most helpful and charitable people on the boards.

I don't want to talk about him and his actions too much, for fear of retribution, but has anyone talked to andrew about his rogue ways? 🙂

**

I do respect forge as the moderator he is, but I was really just a little surprised at what he pulled at the Banter and Brawl. It's not my place to talk about him, so I won't say anymore...

Mac has also said he's been booted from #ev3 for very odd reasons.

You say I'm one of the most helpful people here? Heh, I take that as a huge compliment. Thanks.

I threatened to take the situation to andrew months back, but forge seemed to cool down after soon after.

------------------
-Cap'n Skyblade
(url="http://"http://www.saberstudios.f2s.com")Saber Studios(/url) - Your source for original EV/O/N graphics.
the Confederation Graphics Expansion Set: Coming soon

What exactly did he pull at the B&B; forum? I thought I heard something about nasty pictures, but that might have been about someone else on some other board.

And, hey, do you know what has been happening to The Space Between's karma? It dropped 2 points in one night, and I think he was only deserving of maybe one. He is saying that a mod told him that if he ever posted the word "karma" again it would be lowered again, and he claimed he was chased off the boards by the mod, who he didn't name. But TSB does have a bit of a tendancy to exagerate and get worked up over nothing...

------------------
--ares
"If a woman has to choose between catching a fly ball and saving an infant's life, she will choose to save the infant's life without even considering if there are men on base." -- Dave Barry
Check out my EV website: (url="http://"http://home.cfl.rr.com/aresev/")The Legion(/url).

About virii, I am having a lot of truoble with my mac. It's a Power Macintosh, 6500/250, and it won't load. I keep getting bus errors. I have tried loading with extensions and without the restore disk, but I still get the same thing. I don't know if it's a virus or not, but it's really starting to annoy me since I haven't had the chance to play EV in 3 weeks, or download the EVula plugin, or figure out why GS wouldn't load. And even worse, I can't think about it because of school. Can anyone help me?

------------------
It's all fun and games until the cat knocks the Nitroglicerine over.

Quote

Originally posted by Captain Skyblade:
**forge, for example, hates almost everybody for no reason at all. But every since I jumped on him for his downright immature moderator behavior, he's had me on his "most wanted" list.;) When he gets mad, he'll do anything he can to make sure you get the message. Nothing against him, but that's just forge...
**

Ya'know, that was the first name that popped into my mind too, maybe because of that #ev3 kick for me a while back. I'm sure Skyblade remembers what I mean.

forge is kind of an odd guy. His off-beat cynical humor is very good at times, but when you start to get to know him better, the personality just grates a bit. I'm none to fond of him myself of course after the #ev3 incident.

Much as I'd like to discuss this bit about forge more with some of you guys, this really isn't the place... we could maybe do it at Boozerama, or better yet by e-mail if you guys are interested. This isn't the place for talking about TSB either. So ares, Skyblade, if you want to talk about it more, let me know either by Boozerama or e-mail.

Just one question: Does anyone know what he moderates? I can't find him listed as a mod on any of the Ambrosia boards.

And ares, remember, your project isn't entirely cursed, because I think I'll be able to work again. 🙂

------------------
- Macavenger | e-mail: (url="http://"mailto:e-gamerguy1@home.com")mailto:e-gamerguy1@home.com(/url)e-gamerguy1@home.com

Quote

Originally posted by Macavenger:
**Ya'know, that was the first name that popped into my mind too, maybe because of that #ev3 kick for me a while back. I'm sure Skyblade remembers what I mean.

forge is kind of an odd guy. His off-beat cynical humor is very good at times, but when you start to get to know him better, the personality just grates a bit. I'm none to fond of him myself of course after the #ev3 incident.

Much as I'd like to discuss this bit about forge more with some of you guys, this really isn't the place... we could maybe do it at Boozerama, or better yet by e-mail if you guys are interested. This isn't the place for talking about TSB either. So ares, Skyblade, if you want to talk about it more, let me know either by Boozerama or e-mail.

Just one question: Does anyone know what he moderates? I can't find him listed as a mod on any of the Ambrosia boards.

And ares, remember, your project isn't entirely cursed, because I think I'll be able to work again. 🙂

**

Don't think I mean forge is behind all this, he was just the first guy who came to mind when I mentioned the guys who don't particularly like me. 😉 As for continuation of this conversation, we'd probably be better off dropping it and minding our own business...

I also have never found the forum forge moderates.

------------------
-Cap'n Skyblade
(url="http://"http://www.saberstudios.f2s.com")Saber Studios(/url) - Your source for original EV/O/N graphics.
the Confederation Graphics Expansion Set: Coming soon

Quote

Originally posted by Captain Skyblade:
**...The solution I mentioned before worked. My dad first downgraded our operating system to 9.0, which replaced the corrupted preference file with the older version. We then re-upgraded to version 9.1, which gave us our old system folder, only this time it wasn't corrupted. It took about three hours in all, but it was worth the time.

"Sevendust?" Interesting. Do you have any idea how computers contact this virus? I believe I got it through e-mail, but download files is also possible...

**

That sounds like a lot of trouble. When I had Sevendust, I just ran Notron Antivirus and that cleaned things up. Took about 4 hours to check all seven computers in the shop. In my case, the virus came in a game I downloaded from a Hotline server. Didn't discover the virus for months, and by that time it had spread to 5 machines.

------------------
Joe Burnette
"I find that humans can be divided into only two meaningful categories: Decent Humans and Sonsofbitches; both types appear to be evenly distributed
among all shapes, colors, sizes, and nationalities." -- Keith Laumer

SevenDust comes in several strains. Some are dangerous and some are not (i had strain C which is not) but all can be removed by the same method, using freeware. If anyone still has it, then this is how i removed it:

(1) Get a freeware antivirus app. (i used Agax but there are others) Download it but DO NOT RUN IT.
(2) Restart from your system install CD (this clears Sevendust from memory and stops it reloading)
(3) Run Agax (or whatever) and get it to check all your files on your HD and any removables you have used recently.
(4)Delete the 666 extension from your extensions folder if it is visible (it is in earlier strains). If it is invisible, then rename your Extensions folder to something else create a new folder in your System Folder called Extensions. Drag everything you can see to the new folder (this should leave the 666 virus file behind).
(5) Trash the old extensions folder.
(6) Restart from your standard hard drive. Throw away any recently downloaded compressed files or email attachments with out opening them again to prevent reinfection.

Case closed. For me, anyway.

------------------
Mazca

I have often had to locate invisible files while rooting out viruses. An easy way to locate them is to bring up Sherlock (Command-F), then hold down Option while clicking the 'name' drop-down button under 'Find File.' This will add three new criteria to the list of things you can search for: name/icon lock, custom icon, and visibility. Choose visibility, and search for items whose 'visibility is invisible.'

------------------
world keeps turning

Quote

Originally posted by Macavenger:
Ya'know, that was the first name that popped into my mind too...

Nope, I don't think that it would have been him. Knowing forge better than most anyone else here (at least in this thread), I don't think that really fits with forge's sense of off-beat style. 🙂

Plus, how many files are you getting that you just open?

Quote

Originally posted by Joe Burnette:
In my case, the virus came in a game I downloaded from a Hotline server.

Isn't Hotline grand? 😉

Quote

Originally posted by Mazca:
Advice 1-6 <snip>

Yeah, thats what happened on Starlight (HL server I used to hang out at on a regular basis). What made it easier, however, was the fact that I had HD access and saw the 666 extension. All I had to do was delete it and let the server admin know what had happened. Funny in a "aww, shït..." way: I deleted the extension, but he didn't disinfect the computer, so several of us admins ended up deleting the recurring extensions, then doing the same thing on our own computers (I think I had it... must have been the strain that was harmless if I did).

------------------
EVula @ (url="http://"http://www.evula.com/")EVula.com(/url)
Your friendly self-promoting EV & EVO Boards/Addon/Newswire moderator

Hmm, interesting about the Starlight thing. As that's exactly where I got my Sevendust infection from - must have been the same copy. Sevendust is rather widespread.

Oh, by the way, do you know if Starlight still exists or what happened to it? Anyone?

------------------
Mazca