mmamamel
Apr 13 2004, 02:34 AM

I have no idea how I got this, I never open attachements. I got a message from one of the site to scan for a virus cause they received one. So I came up with worm/bizex.j Anyone know anything about this? I am stil in the process of scanning and the system is saying i have it 3 times!!!!!!!!!!
I am REALLY ANGRY!
WHY IS SOMEONE DOING THIS?
Magnolia
Apr 13 2004, 06:15 AM
I got the same thing yesterday afternoon. My AVG caught it and I had to scan 3 times to get rid of it completley (I hope!!)
KnightAngel
Apr 13 2004, 06:56 AM
I got it too. AVG scanned and told me I had it. I wasn't sure if it actually deleted it or not so I went and ran scans at other different AV sites and it was never picked up again. I *think* I got it but I am running one more scan just to be sure.
BTW...I got it from a JungleCash link to a site called Surforhits. Where did you get it?
Ubekidn
Apr 13 2004, 06:56 AM
I know I got a virus from Jungle Cash, the ad with the Beach Boys playing. Took Norton forever to get rid of it. After updating again with adware, spybot and Norton, the next one, don't know what it was, for gone in the wind, thank goodness.
mmamamel
Apr 13 2004, 07:19 AM
| QUOTE |
| BTW...I got it from a JungleCash link to a site called Surforhits. Where did you get it? |
I think, It came from Hillbilly-Hangout. She sent an email saying that there was a virus, but I had just visited before I got the email. Did a scan and it came up with 3 of them, That was AVG. I then scanned with Macfee and had a trojan.
I reboot and I had the worm and I think it's deleted now.
I just got to work and changed all passwords on paypal and other important accounts.
This is a nightmare. Someone is going after all the sites with this $%@&!
jzacknae
Apr 13 2004, 08:13 AM
ok I am not very computer wise, so if this sounds stupid please forgive me, can they get passwords to bank accounts and c cards by just putting a trojan, worm, virus in your computer? Or do you have to actually use the password for them to get it. Makes me not want to even do my bill paying online now.
angi
Apr 13 2004, 08:28 AM
OK---at hillbilly--I just clicked straight into the regular url---no ref link--no pages--nothing extra--and got a "bugle" trojan alert.
went into the account using /pages/enter.php and it seems fine.
This is getting sickening----scared to open any programs for fear that I will open a can of worms...................
mmamamel
Apr 13 2004, 08:33 AM
| QUOTE (jzacknae @ Apr 13 2004, 10:13 AM) |
ok I am not very computer wise, so if this sounds stupid please forgive me, can they get passwords to bank accounts and c cards by just putting a trojan, worm, virus in your computer? Or do you have to actually use the password for them to get it. Makes me not want to even do my bill paying online now. |
Not sure how it''s done but that certain virus, that can take screen shots, track cookies and somehow get the info and some just distroy your computer.
mmamamel
Apr 13 2004, 08:35 AM
| QUOTE (angi @ Apr 13 2004, 10:28 AM) |
OK---at hillbilly--I just clicked straight into the regular url---no ref link--no pages--nothing extra--and got a "bugle" trojan alert.
went into the account using /pages/enter.php and it seems fine.
This is getting sickening----scared to open any programs for fear that I will open a can of worms................... |
If you read the mail from the site subjec Urgent. I wouldn't open the site till it's fixed, to late for me but not for you. LOL
angi
Apr 13 2004, 08:47 AM
no--I was going in to read my messages on site--lol
so yeah---I was a bit late---
atleast I am protected--but it would be better to TURN DOWN my speakers--so that my alarm wouldn't scare the beejeezers out of me---lmaooo---still waiting for normal heart rate--lol
doublet
Apr 13 2004, 09:20 AM
| QUOTE (mmamamel @ Apr 13 2004, 03:34 AM) |
I have no idea how I got this, I never open attachements. I got a message from one of the site to scan for a virus cause they received one. So I came up with worm/bizex.j Anyone know anything about this? I am stil in the process of scanning and the system is saying i have it 3 times!!!!!!!!!! I am REALLY ANGRY! WHY IS SOMEONE DOING THIS? |
I suspect this sucker appeared after clicking a Search Engine
I click much too fast so I'm not sure which PTR it really was from
It may have even come from one of the many Popups
AVG AntiVirus
----------------
Trojan Horse found in Windows/PUP.exe = Downloader.VB.C<-? (?-unknown letter was partially hidden and did not copy to my log file..)
Results of Complete Test, date and time 13/04/2004 10:40:40 :
Testing C:\WINDOWS
C:\WINDOWS\PUP.EXE repaired
Test finished, duration 00:14:40.6 s
12265 objects tested, 1 found infected
Anyone else get the same one?
allthegrrlshateher
Apr 13 2004, 10:51 AM
yep. i got the same one from a link at medusamails.
the lil crusader
Apr 13 2004, 10:56 AM
I ended up with a trojan called Revop.D in that same file (pup.exe)......What is pup.exe anyway?
I also found Revop.B in a file called do.exe -- I'm clueless on what that is as well.
(I'm also curious how I even got Revop.B since everything I've read says it doesn't affect Win98SE which is what I have.

)
doublet
Apr 13 2004, 11:07 AM
| QUOTE (the lil crusader @ Apr 13 2004, 11:56 AM) |
I ended up with a trojan called Revop.D in that same file (pup.exe)......What is pup.exe anyway?
I also found Revop.B in a file called do.exe -- I'm clueless on what that is as well. (I'm also curious how I even got Revop.B since everything I've read says it doesn't affect Win98SE which is what I have. ) |
pup.exe? Hmmm. Possibly the cover up name made up for a virus executionable file created by a very talented teenage adolesent who has not quite grown to full maturity yet..
mmamamel
Apr 13 2004, 11:24 AM
I just read something about revop.d on computer cops. Might be helpful.
http://www.computercops.biz/index.phpI am having another problem with my IE it frezzes. I can't use it, is anyone else having this problem?
mellymom
Apr 13 2004, 11:49 AM
I think I got it from Alienemail. I know that site has a ton of pop ups now, I canceled myself becuase of all the junk that was getting put on my machine from them
kittysdoc
Apr 13 2004, 11:55 AM
I got the worm Bizex.J yesterday from clicking an email on Clickingmoney4u..attached itself to Windows Media Player..did the AVG scan straight away and healed it..sent to vault..no problems after that..I contacted WM about it.
starplanet
Apr 13 2004, 12:02 PM
I ran AVG on my computer yesterday and it found 15+ trojans which more than likely came from PTR's and searches.
jg7
Apr 13 2004, 12:13 PM
| QUOTE (starplanet @ Apr 14 2004, 02:02 AM) |
| I ran AVG on my computer yesterday and it found 15+ trojans which more than likely came from PTR's and searches. |
mmamamel
Apr 13 2004, 01:05 PM
I have never seen so many viruses then at this moment. Some person with a chip on there shoulder appears to be targeting this industry.
disgruntled PTCer?
the lil crusader
Apr 13 2004, 01:26 PM
| QUOTE (mmamamel @ Apr 13 2004, 02:05 PM) |
I have never seen so many viruses then at this moment. Some person with a chip on there shoulder appears to be targeting this industry.
disgruntled PTCer? |
It sure seems that way doesn't it? Up until the last couple of days I'd only had 1 virus in 4+ years online - and that was in my early days when I was a total noob about everything.
Just this week alone, though, I've gotten 4 different trojans and had 16 separate files infected. And I know all of them had to have come from my PTR programs.
mvanantwerpen
Apr 13 2004, 01:45 PM
I have noticed this too! Up until about a week ago, I had no problems with spyware/viruses...Now all of a sudden I almost always get spyware when doing PTR programs and an occasional trojan!
angelique
Apr 13 2004, 01:51 PM
I got one from shanespaid4mail it come up the w32/baglex1proxy virus. ( I don't know anything about viruses that is what come up ) I ran a scan and come up with 21 infected files.
DGE1754
Apr 13 2004, 02:24 PM
| QUOTE (kittysdoc @ Apr 13 2004, 11:55 AM) |
| I got the worm Bizex.J yesterday from clicking an email on Clickingmoney4u..attached itself to Windows Media Player..did the AVG scan straight away and healed it..sent to vault..no problems after that..I contacted WM about it. |
I got that one twice yesterday even though I have a firewall and many other things to protect my puter...GEEZ what I pain
the lil crusader
Apr 13 2004, 02:29 PM
My poor 'puter is just about scanned out.....in the last 14 hours, I've run 3 different spyware scans (all of which had different results), 1 scan just for trojans, and 2 others for viruses/trojans/worms/mice/fleas, etc.
bbyboop1977
Apr 13 2004, 02:29 PM
I got a virus after opening up the Hillbilly site as well, and scanned 3 or 4 times before it left. Norton picked it up right away so I was able to get rid of it before it hit my hard drive...so good luck to all that got it and I hope you can get rid of it.
anneonline
Apr 13 2004, 03:11 PM
| QUOTE (jzacknae @ Apr 13 2004, 04:13 PM) |
ok I am not very computer wise, so if this sounds stupid please forgive me, can they get passwords to bank accounts and c cards by just putting a trojan, worm, virus in your computer? Or do you have to actually use the password for them to get it. Makes me not want to even do my bill paying online now. |
| QUOTE |
Captures information from the following active windows:
SUNCORP METWAY VeriSign Partner Manager VeriSign Personal Trust Service Commercial Electronic Office Sign On Wells Fargo - Small Business Home Page Merchant Administration American Express UK - Personal Finance Secure User Area Barclaycard Merchant Services Collegamento a Scrigno Home Page Banca Intesa Banque Tous les produits et services Banque en ligne Banamex.com CyberMUT Credit Lyonnais interacti Accueil Bred.fr > Espace Bred.fr Page d'accueil E*TRADE Log On LloydsTSB online - Welcome Acceso a Banca por Internet baNK e-gold Account Access
and stores it in the above .log files. |
anneonline
Apr 13 2004, 03:15 PM
| QUOTE (mmamamel @ Apr 13 2004, 07:24 PM) |
I am having another problem with my IE it frezzes. I can't use it, is anyone else having this problem? |
serenemom
Apr 13 2004, 03:17 PM
| QUOTE (the lil crusader @ Apr 13 2004, 10:56 AM) |
I ended up with a trojan called Revop.D in that same file (pup.exe)......What is pup.exe anyway?
I also found Revop.B in a file called do.exe -- I'm clueless on what that is as well. (I'm also curious how I even got Revop.B since everything I've read says it doesn't affect Win98SE which is what I have. ) |
Here is the definition of this file and the solution.
http://www.trendmicro.com/vinfo/virusencyc...me=TROJ_REVOP.AGood Luck in getting it removed and any other that you may come across.
A hint to anyone who does not know how to look these viruses up on their own. Go to google or whichever, big SE you prefer, not the PTC ones, and type in the file name ie) pup.exe make sure you look at more than one result and find something that defines it and gives you the tool to remove it, then follow the instructions carefully.
Symantic is fantastic and micro trends is very good too. I highly recommend them both for information and removal tools.
Patricia
mrssal
Apr 13 2004, 03:27 PM
| QUOTE (KnightAngel @ Apr 13 2004, 09:56 AM) |
I got it too. AVG scanned and told me I had it. I wasn't sure if it actually deleted it or not so I went and ran scans at other different AV sites and it was never picked up again. I *think* I got it but I am running one more scan just to be sure.
BTW...I got it from a JungleCash link to a site called Surforhits. Where did you get it? |
Yep same here for the Jungle cash one. I notified the owner but haven't heard anything back.
mmamamel
Apr 13 2004, 04:04 PM

I know I still have viruses on my computer I am trying micro trends now. Thanks
| QUOTE |
| Yes, they can, Bizex is a KEYLOGGER. Be careful |
Luckly I was able to change some of my passwords at work. I am not logging into anything till I know I've been cured. LOL
That's next on the list...Long night ahead of me.
mvanantwerpen
Apr 13 2004, 04:35 PM
| QUOTE (mmamamel @ Apr 13 2004, 06:04 PM) |
I know I still have viruses on my computer I am trying micro trends now. Thanks
| QUOTE | | Yes, they can, Bizex is a KEYLOGGER. Be careful |
Luckly I was able to change some of my passwords at work. I am not logging into anything till I know I've been cured. LOL
That's next on the list...Long night ahead of me. |
http://www.keywallet.comEncrypts your passwords and allows you to drag-and-drop them
Should protect keyloggers from getting your passwords.
http://www.zonelabs.comZoneAlarm should prevent these keyloggers from sending back information to their "masters"
mmamamel
Apr 13 2004, 04:46 PM
| QUOTE (mvanantwerpen @ Apr 13 2004, 06:35 PM) |
| QUOTE (mmamamel @ Apr 13 2004, 06:04 PM) | I know I still have viruses on my computer I am trying micro trends now. Thanks
| QUOTE | | Yes, they can, Bizex is a KEYLOGGER. Be careful |
Luckly I was able to change some of my passwords at work. I am not logging into anything till I know I've been cured. LOL
That's next on the list...Long night ahead of me. |
http://www.keywallet.comEncrypts your passwords and allows you to drag-and-drop them Should protect keyloggers from getting your passwords. http://www.zonelabs.comZoneAlarm should prevent these keyloggers from sending back information to their "masters" |
ZoneAlarm should prevent these keyloggers from sending back information to their "masters", how do I know if they already have? I think I got it in the AM but I might have had it longer for all I know. Is there anyway to know?
I am going to download this too.
cherylwaldrop
Apr 13 2004, 05:32 PM
This is cool stuff. It shows everything that loads at startup.
http://majorgeeks.com/download.php?det=3380 It helped me locate and delete this from my system. Hopefully it will help some of you too.......
Cheri
mmamamel
Apr 13 2004, 06:40 PM
Micro Trends said I had 2 Worm Blzex.B in C:\\windowssystem32\xasex . It said it was not Cleanable. I just found this if anyone has this virus. It explains what it does to your computer. I dont have ICQ and never did and I don't have egold. I don't know what else to do?
http://software.pcs.cz/dataguard/vircentrum/Bizex%20b/
cherylwaldrop
Apr 13 2004, 06:59 PM
You can't clean it until it's taken out of the startup, I think......

I deleted two files with it in there and i'm re-scanning now.
Just a reminder to everyone too - if you are running windows, please scan for windows updates and install them. I did and found three security updates that might have prevented this thingie from ruining my entire day.
Cheri
mvanantwerpen
Apr 13 2004, 07:04 PM
Install a firewall NOW. It will prevent any information the worm might have stolen from you from leaving your computer
http://www.zonelabs.com/
mrssal
Apr 13 2004, 07:09 PM
Well I followed the manual instructions and I can't find any of the things it is telling me to delete.

Now what? My firewall is working fine and I haven't let anything access the internet.
mvanantwerpen
Apr 13 2004, 07:11 PM
| QUOTE (mrssal @ Apr 13 2004, 09:09 PM) |
Well I followed the manual instructions and I can't find any of the things it is telling me to delete. Now what? My firewall is working fine and I haven't let anything access the internet. |
First of all, use an encrypted password manager:
http://www.keywallet.comIt features drag-and-drop also which will prevent PWs from being logged...
Second, if you use E-gold, use the SRK button located next to the passphrase entry field if you must use E-gold while you have the worm.
If you do these two things you could be safe even with the worm on your computer.
mrssal
Apr 13 2004, 07:12 PM
Doesn't look like it works with XP.
biidaaban
Apr 13 2004, 07:14 PM
Tech Guy post your problem at this forum and someone will be able to help you.
mvanantwerpen
Apr 13 2004, 07:28 PM
| QUOTE (mrssal @ Apr 13 2004, 09:12 PM) |
Doesn't look like it works with XP. |
Sent you a PM
anneonline
Apr 14 2004, 08:19 AM
| QUOTE (mvanantwerpen @ Apr 14 2004, 03:04 AM) |
Install a firewall NOW. It will prevent any information the worm might have stolen from you from leaving your computer
http://www.zonelabs.com/ |
Nope. Once the bizex worm becomes active, it can disable your firewall.
mmamamel
Apr 14 2004, 08:50 AM
Hi Chery
| QUOTE |
| Just a reminder to everyone too - if you are running windows, please scan for windows updates and install them. I did and found three security updates that might have prevented this thingie from ruining my entire day. |
I was updating after I read your post...turns out...the site I was visiting for Microsoft was NOT the correct site it was a dummy site. I had found though a forum and had bookmarked it a few weeks ago. When I went to do download the updates last night, I looked at the site and it looked a bit fuzzy, didn't look right. I looked at the address and noticed it had some kind of a code before microsoft.com ! So I deleted it from my favorites, then went to the real microsoft.com and downloaded my updates.
Is it poosible that I downloaded something from the dummy site a couple of weeks ago and it's just starting to act up now?
I also downloaded Zonelabs yesterday. I have to say I feel much more secure with it. I keep looking at the logs of what is trying to access my computer and am very happy I have this now.
| QUOTE |
| Nope. Once the bizex worm becomes active, it can disable your firewall. |
I will check on this when I get home but it seemed to be working last night.
I wanted to say thanks to everyone for there Help
the lil crusader
Apr 14 2004, 09:04 AM
It's possible that you did get something from that dummy site......In all of my various scans yesterday, I discovered that one of the final # of 7 nasties that had gotten me had created a fake Windows Update exe folder to live in.
It looked legit until I looked at it closely and realized it said INDOWS UPDATEW.EXE whereas the real thing is called WUPDMGR.EXE

Other fake files created by these trojans were things like EYBOARDK.EXE AND OUSEM.EXE -- which is pretty clever since most people would be reluctant to remove exe files like this out of fear they'd totally disable their keyboard or mouse despite the fact that the 1st letter is in the wrong place.
spike2004
Apr 14 2004, 09:06 AM
will AVG pick it up?
if so...go to
http://www.computeractive.co.ukits free to dl there
masterluke
Apr 14 2004, 10:20 AM
If you want to stop all this malicious nonsense use Opera as your default browser as I do, instead of that Microshaft Bloatware Explorer bu11shit with non-existent security.
cherylwaldrop
Apr 14 2004, 11:33 AM
Ok. I still have this thingie on my computer despite spending my entire day yesterday trying to kill it. If anyone has successfully removed it, please let me know how. Post instructions for Sweethearts, please !

I am running Norton Internet Security Pro, Norton Anti-Virus, AVG, and ZoneAlarm. I am also using Windows XP. Thanks all.
Cheri
mommab
Apr 14 2004, 11:57 AM
| QUOTE (angelique @ Apr 14 2004, 03:51 AM) |
| I got one from shanespaid4mail it come up the w32/baglex1proxy virus. ( I don't know anything about viruses that is what come up ) I ran a scan and come up with 21 infected files. |
I got the same worm yesterday evening from a link from shanes. It says it is in restore and cannot be put in vault. I disabled restore for now, until my son can go delete the file for me. After I disabled restore, I ran avg, and macafee and nothing was found. So, it is contained there until I can get it deleted. I don't know how to find the file:(
I sent shanes an email forwarding the email the link came from.
Isn't there a way the wm can scan these for virus before sending them out?
I run adaware 3 and 4 times a day and always find at least 5 and up spyware.
i run my avg twice a day now and do update every day. make sure you update your avg every day too, there has been a lot of uodates lately.
I need to find out if my fire wall is still working. Will most likely have my son check it for me.
poco75
Apr 14 2004, 12:22 PM
I just picked up something called exploit trojan. Does anyone know anything about this one and how to get rid of it. I found the files and deleted them but they just keep coming back.
This is a "lo-fi" version of our main content. To view the full version with more information, formatting and images, please
click here.