"On The Fly"......New virus??

Super6

Golden Member
Oct 11, 1999
1,054
0
0
Apparently picked up a new virus going around N. CA. So far Norton and McAfee don't see it. Under regedit, find, "fly", repeat until you either get "On The Fly" or finish. Delete it and it comes back.

No apparent damage yet but I'm not emailing at this time as I'm told by a local it tags along and not as an attachement.

Any info or ideas would be appreciated.

Super6
 

medic

Diamond Member
Oct 9, 1999
5,160
0
0
Hmmm...
I have "fly" and "On the Fly" in my Registry however it's part of Nero under the Burning Rom/CD Copy key for on the fly burning.

3 scanners and no virus's reported...

What scanner told them it's a virus?
 

Super6

Golden Member
Oct 11, 1999
1,054
0
0
I'll try to get more info. Of the reported dozen or so systems infected, I doubt if more than a couple have Nero. I do, so I'll take a closer look at mine. It would be an interesting coincidence.

Super6
 

Super6

Golden Member
Oct 11, 1999
1,054
0
0
The OnTheFly entry appears to be a coincidence as far as Nero is concerned. A techie in the next valley over is trying to clean up his system. Apparently it's a new variation of the ANNAKOURNIKOVA.JPG.VBS virus/worm. It can come as an attachement to an email or embedded in one (HTML?).

If your system is infected a format of a floppy will result in 1.38Mb. All his recent 98 boot floppies are infected. In the registry will be some off-the-wall reference to "fly" or "fly=...", or OnTheFly. Also, an entry MRU=....then a listing of your drives.

He was able to see some of the code in the attachment on one system via Excel....which also set it off. He thinks the initial entry is via an attachement then it grabs two addresses and embeds itself in the outgoing emails. It apparently also has infected his Adaptec burning software. He's concerned about a possible bios threat but hasn't been able to confirm or not.

My system seems ok as I have Nero but between the two of us we know of about a dozen systems up here in Northern Cal. which appear to be infected and don't have Nero.

This a grey area for me. He's been in touch with Symantec and McAfee but they're not much help as of yet.

I'll try to get him to sign up and post what he's found out when he's able.

Super6
 

Varmot

Senior member
Aug 12, 2000
201
0
0
That is strange.. I have NERO 5044 and don't have "on the fly" or "fly" in my registry.
 

Isaiah

Senior member
May 31, 2000
453
0
0
This is odd I just did a new install of windows and Nero, and I do have "OnTheFly" and "Fly" in the registry

Isaiah
 

Hector13

Golden Member
Apr 4, 2000
1,694
0
0


<< A techie in the next valley over is trying to clean up his system. Apparently it's a new variation of the ANNAKOURNIKOVA.JPG.VBS virus/worm. It can come as an attachement to an email or embedded in one (HTML?). >>


What kind of techie opens up an unkown email attachment??



<< He was able to see some of the code in the attachment on one system via Excel....which also set it off. >>


And then opens it in Excel?

This still sounds kind of odd to me.
 

Super6

Golden Member
Oct 11, 1999
1,054
0
0
Hector13;
I would've deleted it myself...don't know what he was thinking. Bottom line is about a dozen buggy systems in the area...some marginal and some down for the count and Norton and McAfee aren't picking it up.

My system appears ok and system 2 is never online, so it's clean. Will be getting requests for clean installs if no fix comes along. Hopefully format x: /u and/or fdisk eliminates any boot sector issues. Bios problems could be a killer on some of these no-name SiS chipset MB's.

If nothing else formatting a floppy to see if you come up with 1.38Mb might be the easiest check. If I learn more I'll post more. Viruses aren't an area I'm up to speed on.

Later,

Super6
 
sale-70-410-exam    | Exam-200-125-pdf    | we-sale-70-410-exam    | hot-sale-70-410-exam    | Latest-exam-700-603-Dumps    | Dumps-98-363-exams-date    | Certs-200-125-date    | Dumps-300-075-exams-date    | hot-sale-book-C8010-726-book    | Hot-Sale-200-310-Exam    | Exam-Description-200-310-dumps?    | hot-sale-book-200-125-book    | Latest-Updated-300-209-Exam    | Dumps-210-260-exams-date    | Download-200-125-Exam-PDF    | Exam-Description-300-101-dumps    | Certs-300-101-date    | Hot-Sale-300-075-Exam    | Latest-exam-200-125-Dumps    | Exam-Description-200-125-dumps    | Latest-Updated-300-075-Exam    | hot-sale-book-210-260-book    | Dumps-200-901-exams-date    | Certs-200-901-date    | Latest-exam-1Z0-062-Dumps    | Hot-Sale-1Z0-062-Exam    | Certs-CSSLP-date    | 100%-Pass-70-383-Exams    | Latest-JN0-360-real-exam-questions    | 100%-Pass-4A0-100-Real-Exam-Questions    | Dumps-300-135-exams-date    | Passed-200-105-Tech-Exams    | Latest-Updated-200-310-Exam    | Download-300-070-Exam-PDF    | Hot-Sale-JN0-360-Exam    | 100%-Pass-JN0-360-Exams    | 100%-Pass-JN0-360-Real-Exam-Questions    | Dumps-JN0-360-exams-date    | Exam-Description-1Z0-876-dumps    | Latest-exam-1Z0-876-Dumps    | Dumps-HPE0-Y53-exams-date    | 2017-Latest-HPE0-Y53-Exam    | 100%-Pass-HPE0-Y53-Real-Exam-Questions    | Pass-4A0-100-Exam    | Latest-4A0-100-Questions    | Dumps-98-365-exams-date    | 2017-Latest-98-365-Exam    | 100%-Pass-VCS-254-Exams    | 2017-Latest-VCS-273-Exam    | Dumps-200-355-exams-date    | 2017-Latest-300-320-Exam    | Pass-300-101-Exam    | 100%-Pass-300-115-Exams    |
http://www.portvapes.co.uk/    | http://www.portvapes.co.uk/    |