[Date Prev][Date Next][Thread Prev][Thread Next][Date Index][Thread Index][Subject Index][Author Index]

Virus Hoax



Forgive the length of response from Symantec regarding the Teddy Bear
Virus message, but this should help if you already deleted the file.

Jdbgmgr.exe file hoax
        
Reported on: April 12, 2002
Last Updated on: March 20, 2003 10:50:15 AM

Symantec Security Response encourages you to ignore any messages
regarding this hoax. It is harmless and is intended only to cause
unwarranted concern.

Type: Hoax

This hoax, like the SULFNBK.EXE Warning hoax, tries to encourage you to
delete a legitimate Windows file from your computer. Jdbgmgr.exe is the
file to which the hoax refers, and it is the Microsoft Debugger
Registrar for Java. The Jdbgmgr.exe file may be installed when you
install Windows.

NOTE: Recent versions of this hoax take advantage of the recent outbreak
of the W32.bugbear@mm worm. The Jdbgmgr.exe file mentioned in the hoax
has a bear icon. The actual W32.bugbear@mm worm file is a .exe file and
does not have a bear icon.

The Windows Jdbgmgr.exe file has a teddy bear icon in the hoax, as
illustrated below:

CAUTION: A virus can infect Jdbgmgr.exe. The W32.Efortune.31384@mm
virus, in particular, targets this file. Norton AntiVirus has provided
protection against W32.Efortune.31384@mm since May 11, 2001.

NOTE: If you have already deleted the Jdbgmgr.exe file, in most cases,
you do not need to re-install it. The following quote is extracted from
the Microsoft Knowledge Base article, "Virus Hoax: Microsoft Debugger
Registrar for Java (Jdbgmgr.exe) Is Not a Virus (Q322993)."

      "The Microsoft Debugger Registrar for Java (Jdbgmgr.exe) is only
used by Microsoft Visual J++ 1.1 developers.

      If you follow the e-mail message instructions and delete this
file, you do not have to recover it unless you use Microsoft Visual J++
1.1 to develop Java programs on Windows XP, Windows NT 4.0, Windows 98
Second Edition, Windows 98, or Windows 95."


If you need to restore this file, follow the instructions in "Virus
Hoax: Microsoft Debugger Registrar for Java (Jdbgmgr.exe) Is Not a Virus
(Q322993)."


Hoax message
This hoax has appeared in several languages. Some examples of the exact
content, which is copied from the hoax message, are:

English, version 1
I found the little bear in my machine because of that I am sending this
message in order for you to find it in your machine. The procedure is
very simple:

The objective of this e-mail is to warn all Hotmail users about a new
virus that is spreading by MSN Messenger. The name of this virus is
jdbgmgr.exe and it is sent automatically by the Messenger and by the
address book too. The virus is not detected by McAfee or Norton and it
stays quiet for 14 days before damaging the system.

The virus can be cleaned before it deletes the files from your system.
In order to eliminate it, it is just necessary to do the following
steps:
1. Go to Start, click "Search"
2.- In the "Files or Folders option" write the name jdbgmgr.exe
3.- Be sure that you are searching in the drive "C"
4.- Click "find now"
5.- If the virus is there (it has a little bear-like icon with the name
of jdbgmgr.exe DO NOT OPEN IT FOR ANY REASON
6.- Right click and delete it (it will go to the Recycle bin)
7.- Go to the recycle bin and delete it or empty the recycle bin.

IF YOU FIND THE VIRUS IN ALL OF YOUR SYSTEMS SEND THIS MESSAGE TO ALL OF
YOUR CONTACTS LOCATED IN YOUR ADDRESS BOOK BEFORE IT CAN CAUSE ANY
DAMAGE.

English, version 2

Dear All

I'm sorry about this; but I received this E-mail from a client regarding
a virus that was inadvertently passed on to everyone in their address
book. I followed the instructions and YES, IT WAS ON MY COMPUTER.

Since you are in my address book, I am sending this on to you as a
precaution. NORTON 2002 DID NOT DETECT IT!

Here are the instructions on how to check for this virus and delete it
if you have it too. It only took a few minutes, following these
instructions. Be sure to notify all in your address book too (which will
take longer than deleting the virus from your computer).

Since you are in our address book, there is a good chance you will find
it in your computer too unless you have an Apple or MAC. The virus
(called jdbgmgr.exe) is not detected by Norton or McAfee anti-virus
systems. The virus sits quietly for 14 days before damaging the system.
It is sent automatically by messenger and by the address book, whether
or not you sent Emails to your contacts. Here's how to check for the
virus and how to get rid of it: 

YOU MUST DO THIS
1. Go to Start, Go to Find or Search option
2. In the File Folder option, type the name: jdbgmgr.exe
3. Be sure you search your C: drive and all sub-folders and any
otherdrives you may have.
4. Click "Find Now"
5. The Virus has a Teddy Bear icon with the name jdbgmgr.exe DO NOT
OPENIT
6. Go to Edit (on menu bar), choose "Select All" to highlight the file
without opening it.
7. Now go to File (on the menu bar) and select Delete. It will then go
to the Recycle Bin.
8. Go to the Recycle Bin and Delete it
IF YOU FIND THE VIRUS, YOU MUST CONTACT ALL THE PEOPLE IN YOUR ADDRESS
BOOK, SO THEY CAN ERADICATE IT IN THEIR OWN ADDRESS BOOKS.

To do this:
a) Open a new e-mail message
b) Click the icon of the address book next to the "TO"
c) Highlight every name and add to "BCC"
d) Copy this message enter subject paste to e-mail
Am very sorry about this nuisance. This age of technology is not that
great sometimes. We are victims!

English, version 3 (The BlankA version)

Dear All,

BlankA virus has been passed to me by a contact. My address book in turn
has been affected. Since you are in my address book there is a good
chance
you will find it in your computer too.

I followed the direction below and eradicated the virus easily. The
virus (called jdbgmgr.exe) is not detected by Norton or McAfee
anti-virus
systems. The virus sits quietly for 14 days before damaging the system.
It is sent automatically by messenger and by the address book whether or
not
you sent emails to your contacts.

Here is how you check for the virus and get rid of it.

1. Go to start, find or search option.

2. In the file/folders option, type the name: jdbgmgr.exe

3. Be sure to search your C: drive and all the subfolders and any other
drives you may have.

4. Click "find now"

5. The virus has a teddy bear icon with the name jdbgmgr.exe. DO NOT
OPEN IT

6. Go to edit (on the menu bar), choose "select all" to highlight the
file without opening it.

7. Now go to the file (on the menu bar) and select delete. It will then
go to the recycle bin.

8. Empty your recycle bin.

IF YOU FIND THIS VIRUS,YOU MUST CONTACT ALL THE PEOPLE IN YOUR ADDRESS
BOOK SO THEY CAN ERADICATE IT IN THEIR OWN ADDRESS BOOKS.

To do this:

(a) Open a new e-mail message

(b) Click on the icon of the address book next to the "TO"

(c) Highlight every name and add to "BCC"

(d) Copy this message above and paste to e-mail.

(e) Enter subject

Apologies for the inconvenience and to those of you who have had this
message several times from different people!


Czech
PROSÍM, ZKONTROLUJTE SI, ZDA NEMÁTE NA SVÉM POCÍTACI VIRUS !!!

Dozvedel jsem se, ze do meho adresare se dostal virus, proto posilam
tento email vsem adresam v souboru. Virus nazyvany "jdbgmgr.exe"
nenalezne Norton ani McAfee anti-virovy system. Virus je v klidu 14 dni
pred tim, nez znici system. Je sam automaticky rozesilan na
adresy v adresari, i kdyz je vy nekontaktujete. Zde je navod, jak
nelezt, zda virus mate a jak se ho zbavit:
1: Jdete na START, HLEDAT
2: V souborech a slozkach napiste jmeno viru - jdbgmgr.exe
3: Ujistete se, ze budete hledat na disku C:
4: Kliknete na NAJIT TED
5: Virus ma ikonu medvidka se jmenem jdbgmgr.exe NEOTEVIREJTE HO!!!!!
6: Hned kliknete a smazte ho. A pak jdete hned do kose (na C:)
7: Kliknete na nej a smazte ho.
Je to DULEZITE
Pokud virus najdete, musite kontaktovat vsechny adresy ve vasem
adresari, aby ho mohli odstranit. Je mi to lito, ale jsem si jist, ze
vsichni v adresari ho budou mit.

Danish
Hej alle

Advarsel!!! Tjek dette på jeres computere.

Vi har haft en virus på vores computer, som ikke kan spores af Norton
Antivirus eller McAffee. Viruset ligger skjult på computeren i 14 dage,
inden det ødelægger systemet. Det sendes automatisk af Messenger og af
adresselisten, UANSET OM MAN HAR SENDT EMAILS TIL SINE KONTAKTER ELLER
IKKE.

Vi har fundet og fjernet filen på vores computer i tide, og det vil vi
råde jer til også at gøre. I finder den således:

1. Tryk på "start", "søg", "filer eller mapper".
2. Søg efter filen jdbgmgr.exe
3. Kontroller at du er på C:drevet
4. Filen har en lille bjørn som ikon, ÅBEN DEN IKKE!!!
5. Click med HØJRE MUSEKNAP og vælg slet.
6. Tøm derefter papirkurven, så filen er helt væk fra computeren.

Hvis du finder filen på din computer, så bliver du nød til at kontakte
alle personer i din adressebog, så andre kan gøre det samme.


Dutch
Geachte heer/mevrouw,


Heden hebben wij een boodschap ontvangen dat ons adresboek geïnfecteerd
kan zijn door een virus. Deze wordt niet gedetecteerd door de Norton of
McAfee antivirus scanners. Het wordt automatisch doorgestuurd naar al uw
contacten of men nu wel of niet een email stuurt. We hebben het
gecontroleerd en het gevonden in
"c:\windows\system" en dit verwijderd. Wat moet u in ieder geval per
direct doen:

1 Ga in uw Windows Verkenner naar Extra, Zoeken, Bestanden of mappen.
2 In het "Naam:" venster schrijft u: "jdbgmgr.exe"
3 In het "Zoeken in:" venster gaat u naar "Drive_c (C:)"
4 Klik op "Nu zoeken"
5 Het virus heeft een klein beertje als icoon voor de naam
"jdbgmgr.exe" - OPEN DIT NIET !!!!!!
6 Aanklikken met uw RECHTER muisknop en verwijderen (het gaat dan naar
uw Prullenbak)
7 Ga naar uw Prullenbak en verwijder het bestand of maak uw
Prullenbak helemaal leeg

ALS U HET VIRUS VINDT, MOET U ALLE ADRESSEN UIT UW ADRESBOEK
WAARSCHUWEN, OOK AL HEEFT U ZE DE LAATSTE TIJD GEEN E-MAILS GESTUURD,
ZODAT ZIJ OP HUN BEURT HUN CONTACTEN KUNNEN WAARSCHUWEN.

Sorry voor het ongemak


French
JE VIENS D'ETRE INFECTE PAR UN DE MES FOURNISSEUR
FAITES CE QU'IL Y A D'ECRIT EN DESSOUS ET TOUT SE PASSERA BIEN LE NOM DU
VIRUS EST jdbgmgr.exe L'ICONE EST UN PETIT OURSON.IL EST TRANSMIS
AUTOMATIQUEMENT PAR LE CARNET D'ADRESSES.
LE VIRUS N'EST PAS DETECTE PAR VOTRE ANTIVIRUS ET RESTE EN SOMMEIL
PENDANT 14 JOURS AVANT DE S'ATTAQUER AU DISQUE DUR. IL PEUT DETRUIRE
TOUT= LE SYSTEME !!!
JE VIENS MOI MEME DE LE TROUVER SUR MON DISQUE DUR !!!AGISSEZ DONC TRES
V=ITE POUR L' ELIMINER COMME SUIT:
1. Aller dans DEMARRER, faire "RECHERCHER"
2. dans la fenetre FICHIERS-DOSSIERS taper le nom du virus: jdbgmgr.exe
3. Assurez vous de faire la recherche sur votre disque dur "C"
4. Appuyer sur "RECHERCHER MAINTENANT"
5. Si vous trouvez le virus L'ICONE EST UN PETIT OURSON son nom
"jdbgmgr.exe " ---> NE L'OUVREZ SURTOUT PAS!!!!!
6. Appuyer sur le bouton droit de la souris pour l'=E9liminer aller la
CORBEILLE) vous pouvez aussi l'effacer en appuyant sur SHIFT DELETE afin
qu'il ne reste pas dans la corbeille.
7. aller la CORBEILLE et l'effacer d=E9finitivement ou bien vider la
corbeille. Mais SURTOUT NE L'OUVREZ PAS , SUPPRIMER-LE DIRECTEMENT
!!!!=!

SI VOUS TROUVEZ LE VIRUS SUR VOTRE DISQUE DUR ENVOYEZ CE MESSAGE A TOUS
VOS CORRESPONDANTS FIGURANT SUR VOTRE CARNET D'ADRESSES CAR CE VIRUS
PASSE VRAIMENT PARTOUT ET TRES VITE !!! !!! !!! .


DESOLE POUR CET INCIDENT MAIS, MOI AUSSI, JE ME SUIS FAIT AVOIR !!! !!!
ET MERCI D'AGIR VITE.

German

Mir wurde die folgende Nachricht übermittelt, ich habe den Bären
gefunden und, wie empfohlen, gelöscht. Ich übermittle Euch daher diese
Nachricht zur weiteren Verwendung. m.f.G.

W I C H T I G

== == == =

Wir sind informiert worden, dass unser Computer von dem Virus
jdbgmgr.exe infiziert worden ist, der sich per e-mail automatisch
ausbreitet, da er sich im e-mail Adressbuch versteckt. Er kann nicht mit
Norton oder McAfee Antivirus entdeckt werden, und bleibt 14 Tage
inaktiv, bevor er das komplette Computer-System beschädigt.

Er kann aber gelöscht werden, bevor er Ihre Daten beschädigt.

Bitte gehen Sie wie folgt vor:

KLICKEN SIE AUF " START "

KLICKEN SIE AUF " SUCHEN " UND SUCHEN SIE DIE DATEI: JDBGMGR.EXE

VERGEWISSERN SIE SICH, DASS IN C:\ GESUCHT WIRD

KLICKEN SIE AUF " SUCHEN "

WENN IHR PC DEN VIRUS GEFUNDEN HAT (ES HAT EIN KLEINES BÄREN-SYMBOL)

BITTE NICHT ÖFFNEN !!!!!!!!!!!!!

KLICKEN SIE MIT DER RECHTE MOUSE-TASTE AUF DAS KLEINE BÄREN-SYMBOL UND
WÄHLEN SIE " LÖSCHEN " (DER VIRUS WIRD IN DEN ORDNER " PAPIERKORB "
VERSCHOBEN)

KLICKEN SIE MIT DER RECHTEN MOUSE-TASTE AUF DEN PAPIERKORB UND WÄHLEN
SIE

" PAPIERKORB LEEREN ".

WENN SIE DEN VIRUS AUF IHREM COMPUTER GEFUNDEN HABEN, SCHICKEN SIE DIESE
MITTEILUNG SCHNELLSTMÖGLICH AN ALLE ADRESSEN IN IHREM E-MAIL ADRESSBUCH.

MFG


Italian
Abbiamo ricevuto un virus che si trasmette automaticamente a tutti gli
indirizzi di posta elettronica. Se si eseguono le seguenti istruzioni si
cancella senza causare danni.


FARE LA VERIFICA DESCRITTA PER ELIMINARE IL VIRUS.

Il virus si chiama jdbgmgr.exe e si trasmette automaticamente tramite
Messenger ed anche attraverso la rubrica degli indirizzi. Il virus NON
E'RILEVATO da McAfee o Norton e rimane in letargo 14 giorni prima di
recare
dei danni al sistema .Per eliminarlo basta eseguire le seguenti
operazioni:

1) Cliccare sullo schermo in basso a destra "Avvio o Start"
2) Cliccare su "Trova", andare da "Files o Cartelle" e scrivere il nome
del virus: jdbgmgr.exe
3) Assicurarsi che cerchi sul disco "C"
4) Cliccare su "Cerca ora"
5) Se appare il virus (l'icona è un orsacchiotto) NON APRIRE !!
6) Cliccare sul pulsante destro del mouse ed eliminare.
7) Andare sul cestino e cancellare definitivamente.

SE AVETE TROVATO IL VIRUS NEL VOSTRO COMPUTER INVIATE QUESTO MESSAGGIO A
TUTTE LE PERSONE CHE SI TROVANO SULLA VOSTRA RUBRICA D'INDIRIZZI O
E-MAILS.

Polish

Subject: uwaga wirus!!!!

Witam wszystkich,
to niestety prawda - dostalam od kogos tego wirusa, nie wiem nawet od
kogo, i znalazlam go w podany sposob i usunelam! Tez to zrobcie!!!
Jestescie u mnie w ksiazce adresowej, wirus rozsyla sie samoczynnie do
wszystkich z ksiazki - bardzo wiec prawdopodobne, ze jest rowniez w
Waszych
komputerach.
P.S. Przepraszam, ale to nie moja wina, ktos mi to po prostu
przyslal....
Przeczytajcie koniecznie to co ponizej:
Witam wszystkich, Zostal rozsiany wirus , jesli Twoj kontakt jest w
mojej ksiazce adresowej, to bardzo mozliwe ze rowniez otrzymales tego
wirusa.Prosze wykonaj ponizsza instrukcje aby zniszczyc wirusa i
przeslij to wszystkim osobom z twojej skrzynki adresowej. Wirus nazywa
sie jdbgmgr.exe i nie jest wykrywalny/niszczony przez Norton,Mc Afee,
F-secure ani VET ( systemy antywirusowe). Wirus siedzi w ukryciu przez
14 dni a nastepnie atakuje i niszczy
system. Rozsyla sie automatycznie do wszystkich z ksiazki adresowej,
niezaleznie czy wysylano im listy czy nie. Teraz jak sprawdzic czy masz
wirusa i jak sie go pozbyc:
MUSISZ ZROBIC TAK:
1.Idz do "Start"po lewej na dole, wybierz opcje "znajdz"
2.W opcji "plilki/foldery" wpisz nazwe jdbgmgr.exe
3. upewnij sie ze przeszukujesz dysk C, i wszystkie inne dyski jakie
masz
4. kliknij "znajdz teraz"
5.wirus ma ikonke niedzwiadka i nazwe jdbgmgr.exe NIE OTWIERAJ GO !!!!
6.idz do"edycja " wybierz opcje "zaznacz wszystkie" i podswietl plik bez
otwierania go
7.teraz idz do "plik" i wybierz "usun"
8.teraz idz do swojego kosza i rowniez go usun.
JESLI ZNALAZLES WIRUSA MUSISZ TE WIADOMOSC PRZESLAC DO WSZYSTKICH WOICH
KONTAKTOW, OSOB Z KSIAZKI ADRESOWEJ.ABY OGLY PRZESZUKAC SWÓJ KOMPUTER
-----ONE NA PEWNO TEZ MAJA WIRUSA!!!! PRZEPRASZAM .

Aby rozeslac te wiadomosc; utworz nowa wiadomosc, kliknij na ksiazke
adresowa, i w opcjii do umiesc wszystkie swoje kontakty, klikajac na
kazdy z nich. nastepnie skopiuj ta wiadomos i wklej ja w tresc listu.
wyslij wszystkim jak najszybciej tlumaczenie na polski jest robocze, ale
system pozbywania si?wirusa kuteczny,przepraszamy z klopot, ale sami
dostalismy tego wiusa. pozdrawiam

Portuguese
Caros colegas,

Atenção!

Hoje pela manhã recebemos um e-mail de um amigo da Argentina dizendo-nos
que tinha-nos enviado um VIRUS via sistema. Este virus é
automaticamente retransmitido à todos os endereços armazenados em nossas
lista de contatos. VOCÊ é um deles!!!. Infelizmente não podemos
evitá-lo pois ele não é detectado por Mcfee ou o Norton e permanece
oculto por 14 dias antes de destruir o sistema inteiro.

Portanto, siga atentamente os passos a seguir e evite perder seus dados:

1) Clique em "Iniciar" depois "localizar" (o buscar);

2) Em "localizar" clique em "Pastas e arquivos" - escrever o nome do
arquivo "virótico": jdbgmgr.exe;

3) assegure-se de que está procurando -o no drive C;

4) Localizar agora;

5) O virus possui um ícone em forma de ursinho (cinza);

6) Caso você o encontre, não abra de maneira alguma, delete-o
imediatamente,

7) Não esqueça de retirá-lo da Lixeira pois senão nada adiantará.

8) Caso você encontre este virus no seu computador, envie esta mensagem
a todas as pessoas que estejam na sua agenda de endereços antes
que este cause algum dano maior. Obrigado pela atenção.

Spanish
ESTIMADOS AMIGOS:

ES POSIBLE QUE UN VIRUS HAYA ENTRADO A SU SISTEMA, POR LO QUE LES
PIDO MIL
DISCULPAS.-

PARA VER Y ELIMINAR EL VIRUS,SEGUIR LAS SIGUIENTES INSTRUCCIONES:
-IR A INICIO, LUEGO A BUSCAR
-BUSCAR EN EL ARCHIVO O CARPETA jdbgmgr.exe ASEGURARSE QUE SE BUSCA
EN EL
DISCO C.-
-BUSCAR AHORA.
-SI APARECE QUE EXISTE EL VIRUS, NO ABRIR EL ARCHIVO.- CON EL BOTON
DERECHO
SEÑALAR EL ARCHIVO Y ELIMINARLO.-
-LUEGO IR A LA PAPELERA DE RECICLAJE Y TAMBIEN ELIMINARLO.-
ESTE VIRUS NO ES DETECTABLE CON EL NORTON U OTROS ANTIVIRUS.-

Swedish
Subject: VB: virus...

Hej Allesammans!
Tråkiga nyheter....

Jag har fått ett meddelande att min adressbok har blivit infekterat av
ett virus, som inte Norton Antivirus eller McAfee kan spåra. Viruset
ligger vilande i 14 dagar innan det kraschar systemet. Det sänds
automatiskt av Messenger och av Adressboken, OAVSETT OM NI HAR SKICKAT
E-MAIL TILL DINA KONTAKTER ELLER INTE!!!.
Jag har kollat, hittat och tagit bort filen. För att kolla gör så här:
1. Gå till Start - Sök - Filer eller mappar.
2. Sök efter filen jdbgmgr.exe på C: hårddisken.
3. Filen har en liten björn som ikon. ÖPPNA DEN ABSOLUT INTE!!!!
5. Klicka med höger mus-knapp och välj att ta bort.
6. Ta även bort den från papperskorgen.
Om Ni hittar viruset på eran dator måste ni kontakta alla i eran
adressbok så att de också gör samma sak.