Skip to main content

Notice

Please note that most of the software linked on this forum is likely to be safe to use. If you are unsure, feel free to ask in the relevant topics, or send a private message to an administrator or moderator. To help curb the problems of false positives, or in the event that you do find actual malware, you can contribute through the article linked here.
Topic: Run a virus scanner (Read 4644 times) previous topic - next topic
0 Members and 1 Guest are viewing this topic.

Run a virus scanner

I have just been infected with the Colombia virus. My MP3's were all copied into 12kB VBS files (luckily I didn't lose them), and all my JPG files were lost (converted to 12kB VBS files). I have reason to believe this site may be the infection point. It's worth making sure that it isn't.

Run a virus scanner

Reply #1
Quote
Originally posted by NeoRenegade
I have just been infected with the Colombia virus. My MP3's were all copied into 12kB VBS files (luckily I didn't lose them), and all my JPG files were lost (converted to 12kB VBS files). I have reason to believe this site may be the infection point. It's worth making sure that it isn't.
Excuse me, but what reasons you have to believe this site is the infection point?? Only possible thing I can even think of would be the account confirmation by email, but I really think people would have noticed something by now if this was the case. I really dont think hydrogenaudio spreads any email worm...

VBS_COLOMBIA
Aliases:
COLOMBIA, vbs/plan.a, plan.a, VBS/LoveLetter.worm, Vbs.Plan.A, VBS.LoveLetter.Variant, VBS/Loveletter.AS

Description:
This VBScript virus is another variant of the infamous VBS_LOVELETTER virus and uses the Windows Scripting Host (WSH) CSCRIPT.EXE/WSCRIPT.EXE to run the program.  Once executed, it looks for files with specific file extensions and overwrites them with its codes. If the current system date is September 17, it displays a message and disconnects all network drives mounted by the user.
Juha Laaksonheimo


Run a virus scanner

Reply #3
Eh so? Did you get email from hydrogenaudio.org domain today or what? It's an email worm.
Juha Laaksonheimo

Run a virus scanner

Reply #4
Quote
Originally posted by NeoRenegade
Aside from www.winamp.com and www.audiograbber.com-us.net this is the only site I've been to today, literally.


This virus spreads via e-mail *only*. You should make sure you set up Outlook Express (since that's probably what you're using) to 'secure mode' or whatever it's called in the preferences.

Go Xing.

John

Run a virus scanner

Reply #5
Quote
Originally posted by Keynes

Go Xing.

Yes. Go Xing.

 

Run a virus scanner

Reply #6
Go Xing? You know where I want it to go

Run a virus scanner

Reply #7
I very possibly could have caught LoveLetter from here, because I have e-mail notification turned on and thus have opened 5+ e-mails from the hydrogenaudio mailer.

Run a virus scanner

Reply #8
Quote
Originally posted by NeoRenegade
I very possibly could have caught LoveLetter from here, because I have e-mail notification turned on and thus have opened 5+ e-mails from the hydrogenaudio mailer.


I seriously doubt this has anything to do with hydrogenaudio.  This site isn't run on windows or anything like that.  Admittedly I haven't really read up on this virus, but I think whatever place was sending out this virus would have to be infected by it, and it requires the windows scripting host, that means it'd have to be running windows, which pretty much eliminates this site as a possibility.

Run a virus scanner

Reply #9
Ok, good to know there's no problem with HydrogenAudio. The virus has been wiped from my computer, and the only remnant is the contents of My Computer looking odd when viewed "as a webpage"

Run a virus scanner

Reply #10
Microsoft strikes again!