Teddy Bear Virus or hoax?

  • Thread starter Thread starter norm
  • Start date Start date
N

norm

An email from an institutional correspondent alerted me to
its discovery of the Teddy Bear virus and supplied
instructions for removing it from the hard drive. I found
three files, as follows:

c:\windows\Prefetch 4 kb Type cd Date Modified 7-23-
2003 11:46 AM ............This had what looked like a
yellow bullet facing right on a page with the upper right-
hand corner turned down............When I tried to copy
the picture I got a warning that I might be opening
something containing a virus. I cancelled the action and
dumped the file from my hard drive and then emptied the
Recycle Bin.

The following two had teddy bears.

C:\windows\system32 15 kb Application 1-28-2003 6:26 PM

c:windows\LastGood\Syste.15 KB Application 10-17-2002
9:44 PM

I did not do anything with these last two files. Should I?

A few months ago I got an alert about the Teddy Bear
virus, was advised to delete the files with a teddy bear
and, before I took action, I checked the internet and
found that it was a hoax, that deleting the files could be
harmful. My correspondent at the time then confirmed that
it was a hoax.

What's a person to do?
 
Norm;
***There are two variants of this, one is not a hoax***

If you received the message to delete the teddy bear icon:
Antivirus do not detect it because it is a hoax.
Whenever you get an E-Mail like that, check this link, near the bottom
in Reference Area, click on Hoaxes:
http://www.symantec.com/avcenter/

For Windows XP:
Go to this link, line 184 "Restore jdbgmgr.exe - Virus Hoax" to
replace jdbgmgr.exe:
http://www.kellys-korner-xp.com/xp_tweaks.htm
Place it in the C:\WINDOWS\SYSTEM32 directory.

For Windows 98/98SE:
Insert the Windows 98 CD.
Close any box that opens.
Start/Run
Type "SFC", press Enter.
Place bullet in "Extract..."
Type "jdbgmgr.exe" in the "Specify... box
Restore from "*:\WIN98" (*=CD Drive)
Save file in "C:\WINDOWS\SYSTEM"

There is also a Trojan called "jasmin".
The trojan takes advantage of this well known hoax
The Teddy bear icon is correct, the screwdriver is the virus file.
See these links for more details:
http://www.f-secure.com/v-descs/dasmin.shtml
http://www.f-secure.com/v-descs/recory.shtml

It is VERY IMPORTANT to run an updated virus scan once this issue is
resolved to ensure your computer is virus free.
Also run an updated virus scan at least weekly to reduce your chances
of getting a virus to near zero.
Forward these links to your friends that may have the same issue
 
Back
Top