Free Republic
Browse · Search
News/Activism
Topics · Post Article

Skip to comments.

Worm and Virus Wars- the August Edition
various FR links & posts | 08-23-03 | The Heavy Equipment Guy

Posted on 08/23/2003 4:55:11 PM PDT by backhoe

 
http://www.freerepublic.com/focus/f-news/969301/posts
Beware of Hacker and Cracker Attacks!
Vanity ^ | 8/23/2002 | Myself
 
Go HERE and let ShieldsUp do a scan of your ports. It will determine if you are "in stealth mode" or vulnerable.


TOPICS: Extended News; News/Current Events
KEYWORDS: techindex; worm
Navigation: use the links below to view more comments.
first previous 1-2021-4041-6061-8081-84 next last
To: All
http://www.freerepublic.com/focus/f-news/970282/posts
Experts Say New Sobig Virus Could Strike Any Day
Yahoo! News ^ | August 25, 2K3 | Reuters
41 posted on 08/25/2003 4:54:50 PM PDT by backhoe
[ Post Reply | Private Reply | To 1 | View Replies]

To: backhoe
bump
42 posted on 08/25/2003 5:52:08 PM PDT by JamminJAY (This space for rent)
[ Post Reply | Private Reply | To 1 | View Replies]

To: backhoe
bttt and thanks
43 posted on 08/25/2003 5:54:58 PM PDT by freeangel (freeangel)
[ Post Reply | Private Reply | To 1 | View Replies]

To: backhoe
Tracking, and thanks.
44 posted on 08/26/2003 2:52:50 AM PDT by yhwhsman ("Never give in--never, never, never, never, in nothing great or small..." -Sir Winston Churchill)
[ Post Reply | Private Reply | To 1 | View Replies]

To: yhwhsman; freeangel
Thanks for the bumps^
45 posted on 08/26/2003 4:40:24 AM PDT by backhoe (Just an old Keyboard Cowboy, ridin' the trackball into the Sunset...)
[ Post Reply | Private Reply | To 44 | View Replies]

To: All
http://www.freerepublic.com/focus/f-news/970889/posts
Why computer virus writers are useful and we should thank them.
zone-h.org ^ | 08/25/2003 | Samuel D. Forrester
46 posted on 08/26/2003 3:38:27 PM PDT by backhoe
[ Post Reply | Private Reply | To 1 | View Replies]

To: All
SoBig.F Packs Few Design Surprises
      Posted by budwiesest to AppyPappy

47 posted on 08/27/2003 7:09:17 AM PDT by backhoe
[ Post Reply | Private Reply | To 1 | View Replies]

To: backhoe
BTTT & thanks
48 posted on 08/27/2003 7:23:03 AM PDT by orlop9
[ Post Reply | Private Reply | To 1 | View Replies]

To: orlop9
Thanks for looking!
49 posted on 08/27/2003 12:05:07 PM PDT by backhoe
[ Post Reply | Private Reply | To 48 | View Replies]

To: backhoe
http://www.freerepublic.com/focus/f-news/972462/posts
FBI TO ARREST TEEN IN INTERNET ATTACK
DrudgeReport ^
50 posted on 08/29/2003 3:05:17 AM PDT by backhoe (The 1990's will be forever known as "the Decade of Frauds" [ Clintons, dot-bombs, Oslo Accords...])
[ Post Reply | Private Reply | To 1 | View Replies]

To: All
http://www.freerepublic.com/focus/f-news/1067771/posts
Latest worm ( MyDoom ) has professional twist (Computer experts blame spammers)
AJC.com ^ | 1/28/04 | Bill Husted
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
Chronic W32.Swen Virus Attack - Anyone Else Getting It?
The Vanity Virus Times | 10/22/03 | Michael
 
 
 
 
 
 
 
 

51 posted on 01/30/2004 2:09:40 AM PST by backhoe (Virus authors should be flogged in public...)
[ Post Reply | Private Reply | To 1 | View Replies]

To: All
http://www.freerepublic.com/focus/f-news/1068428/posts
New Backdoor Worm Randex hitting
http://www.sarc.com/avcenter/venc/data/w32.randex.fc.html#removalinstructions ^ | 1-30-04 | self
52 posted on 01/30/2004 10:55:08 AM PST by backhoe
[ Post Reply | Private Reply | To 1 | View Replies]

To: All

http://www.freerepublic.com/focus/f-news/1066136/posts
Latest e-mail worm spreading fast
Associated Press via Sun Media ^ | January 27, 2004 | Matthew Fordahl
53 posted on 01/31/2004 1:54:27 AM PST by backhoe (Just an old Keyboard Cowboy, ridin' the TrackBall into the Sunset...)
[ Post Reply | Private Reply | To 52 | View Replies]

To: All
http://www.freerepublic.com/focus/f-news/1090364/posts
Virus Writers Wage Worm War
PC World ^ | Wednesday, March 03, 2004 | Paul Roberts

http://www.freerepublic.com/focus/news/1090024/posts?page=7#7
Virus writers trade insults as e-mail users suffer Some 20 variants spreading ....
MSNBC ^ | Updated: 3:31 p.m. ET March 03, 2004 | Bob Sullivan - Technology correspondent

http://www.freerepublic.com/focus/f-news/1089894/posts
Virus Alert - E-mail account disabling warning
Symantec ^ | March 3, 2004 | Nick Danger

54 posted on 03/04/2004 12:00:22 AM PST by backhoe (Just an old Keyboard Cowboy, ridin' the TrackBall into the Sunset...)
[ Post Reply | Private Reply | To 1 | View Replies]

To: All
To: Snowy; All
Has anyone else had problems with a mass emailing? My company yesterday had a bunch of emails (1000+ in 45 minutes, which is tons for us), bounce off our firewall. It was a level two virus, according to Symantec. Today, my husband's company had the same problem, but is a very short time, they had about 250,000 emails marked as spam hit their firewall. It can't be just us, can it?

This may not relate directly, but my normal spam/virus count is one or two a day- the last 2 days it has been dozens.

Some jackass keeps sending xxxjenniferthewildgirl.jpg.pif with virus attachments.

I will list below the most useful email I've gotten so far:


To recipients of emails with the subject line:  {Spam?} Re: {Spam?} RE: {Spam?} {Virus?} {Spam?} Check this out kid!!!

Okay, since all of you are sending ME stuff, I will send back to you some answers and cures.  So far I have received more than four dozen of your emails complaining about me and the others of you sending a virus.

Here is my analysis of what is happening and what you, each of you, can do about it.

First of all, do not send anything to cis-announce or cis-outgoing or any variation thereof.  Those might be their entire mailing list!  So let's not perpetuate this thing.  I am sending this email to all parties, including the firms named herein, and including an office in Homeland Security which is one of the senders to me!

It is possible that this particular virus is adding the word {Spam?} to its outgoing mail because I received from CIS their regular mailing with their regular subject line, but that word in brackets had been added at the beginning of the subject line.

Obviously, we are under attack from a virus, a Hungarian virus called Worm.Zafi.B.  Right now, this particular virus is the most "widespread email worm at the moment" and you can read the whole story which came out just about an hour ago: 
http://www.theage.com.au/articles/2004/06/15/1087244900422.html?oneclick=true. This is truly an international virus, as described here in the Virus Encyclopedia:  http://www.viruslist.com/eng/viruslist.html?id=1666973. Down toward the bottom you will find the text of the emails YOU got, along with the description of the attachment that was deleted (hopefully).  Note that I have received the original email with the attachment removed and replaced with text telling me what the virus is!  Here is that text:
This is a message from the MailScanner E-Mail Virus Protection Service
----------------------------------------------------------------------
The original e-mail attachment "jennifer the wild girl xxx07.jpg.pif"
was believed to be infected by a virus and has been replaced by this warning
message.
If you wish to receive a copy of the *infected* attachment, please
e-mail helpdesk and include the whole of this message
in your request. Alternatively, you can call them, with
the contents of this message to hand when you call.
At Sat Jun 12 17:19:29 2004 the virus scanner said:
   ClamAV: jennifer the wild girl xxx07.jpg.pif contains Worm.Zafi.B
   MailScanner: Shortcuts to MS-Dos programs are very dangerous in email (jennifer the wild girl xxx07.jpg.pif)
Note to Help Desk: Look on the MailScanner in /var/spool/MailScanner/quarantine/20040612 (message i5CLDxhq003158).
--
Postmaster
Mailscanner thanks transtec Computers for their support
Someone's computer is infected, and typically a virus will get into one person's computer, look around for email addresses, then send itself out to a whole bunch of the addresses it finds.

You cannot tell who really has the infected computer because the virus "spoofs" the sender's name, making it look like it is coming from someone else, NOT the person se computer is infected.  It will just pick at random one of those addresses that it found and use that as the "sender" and send itself to the other email addresses.  That is called "spoofing" which is quite commonly done by viruses.

An example:  Sharon's computer gets a virus which then sends itself to everyone in her address book but it looks like all those emails came from James!  Poor James doesn't even know this is happening until he starts getting those "bounced" emails saying that he is sending a virus.  He is innocent, does not have a virus, because all that is coming from Sharon's computer!  And Sharon has absolutely no clue that her computer is infected and doing all this.

Only by looking at the header of one of those spoofed emails very carefully can you get a hint of where it might be really coming from.  The following are two places where you can get a removal tool if you think you might be infected.

This is from http://vil.nai.com/vil/content/Print126242.htm
-- Update June 14th, 2004 03:01 PST --
The risk assessment of this threat has been raised to Medium due to increased prevalence.

If you think that you may be infected with this threat, and are unsure how to check your system, you may download the Stinger tool to scan your system and remove the virus if present.  This is not required for McAfee users as McAfee products are capable of detecting and removing the virus with the latest update. (see the removal instructions below for more information).

Note: Receiving an email alert stating that the virus came from your email address is not an indication that you are infected as the virus often forges the from address.
And this from http://www.f-secure.com/v-descs/zafi_b.shtml
F-Secure provides the special disinfection utility to eliminate Zafi.B worm infection. You can download this utility from our ftp site:

ftp://ftp.f-secure.com/anti-virus/tools/f-zafi.exe

ftp://ftp.f-secure.com/anti-virus/tools/f-zafi.zip
Disinfection instructions can be found here:

ftp://ftp.f-secure.com/anti-virus/tools/f-zafi.txt
I myself started getting these emails from "James Moore" on Saturday.  I have received several by now.  The header from one of the earlier ones is pasted below.  (It is NOT infected as it is a copy and paste rather than any kind of forwarding, which could perpetuate the virus.)

I have bolded some interesting lines.   The "return path" appears to be CIS.ORG.

A couple of other possibilities are these:  Numbers USA and The Social Contract are both clients of whetstonelogic.com, which appears in the header.  Note that wslogic.com is another name for whetstonelogic which specializes in "political intelligence tools".  Take a look at the header below.

You will see byromlaw.com which belongs to a law firm in Florida.  Did the emails originate there?  Or did they just go through their servers?  We don't know.  But in any case I sending all the these organizations a copy of this email.  Any one or all of the them might be infected and unknowingly sending out the virus to everyone else.

All of these organizations should check for viruses.  And so should you, the individuals that have received those emails from the "alleged" James Moore.

Here is the plan of action.  I am the webmaster for Terry Anderson and last fall I designed a page when we had another virus outbreak.  I called it "Got Virus?" and put up there the results of my research of what you can do to protect yourself and some free virus scans you can go to find out if you are infected.  Just finding those scan sites took a great deal of time, so all the work is already done -- all you have to do is run them on your own computers.  Everyone that receives this particular email should go to the following webpage and do your scans right away, and then at least once a week thereafter.  Bookmark the page and come back every week.  And update your Norton every day!  Including the special page that is updated more often than the "Live Update":  http://securityresponse.symantec.com/avcenter/download/pages/US-N95.html. I just ran all four scans and my computer is clean.

Also, make sure you have Norton Anti-virus and Zone Alarm (a free firewall).  The links are on the "Got Virus?" page.  There again, the link for Zone Alarm was hard to find on their website, so I saved you all that time by putting it there.

To summarize, it is imperative that all of these check for viruses and make sure that

        1.      CIS.org
        2.      Numbers USA
        3.      The Social Contract
        4.      Byrom, Miller & Coleman
        4.      Everyone else receiving this email

                        should immediately:

        A.      Get anti-virus if you don't have it.
        B.      Get Zone Alarm if you don't have it.
        C.      Set your "Scheduled Tasks" to update every day,
                        both Live Update and
                        http://securityresponse.symantec.com/avcenter/download/pages/US-N95.html.
        D.      Run all the scans on http://www.theterryandersonshow.com/Viruses.html
        E.      Run #D at least once a week.

These things need to be done immediately because this virus is proliferating rapidly!  While I wrote I received two dozen more of the spoofed emails!

Good luck!  If you have questions, please don't hesitate to contact me.  We are all in this together, regarding immigration as well as these virii.

Carol
webmaster4terry@dslextreme.com

10 posted on 06/15/2004 4:04:38 PM EDT by backhoe

55 posted on 06/15/2004 5:20:56 PM PDT by backhoe (Sleep tight, Ronnie... you reminded me of my Dad so much...)
[ Post Reply | Private Reply | To 1 | View Replies]

To: All
 More here:

 So, are you saying that the real fix is to install Linux and Mozilla? I would agree that this would be a much better solution to staying with microsoft windows.

That's where I'm headed... Firefox already on both home machines, and 3 MandrakeLinux CD's that I burned yesterday sit before me waiting to be installed.

I wasted days trying to get rid of a new hijacker and I'm tired of doing Microsoft's cleanups for them.

BTW, here's the best forum I found so far:

SWI Forums

56 posted on 06/30/2004 1:08:33 PM PDT by backhoe
[ Post Reply | Private Reply | To 55 | View Replies]

To: All
PestPatrol Shares Spyware Lessons ( Company will offer database of known... free.)
 Here's the best "concise collection of links" I have found so far:

How did I get infected in the first place?
Online Virus and Trojan Scanners
Panda Software . . . Trend Micro . . . Bitdefender . . . Sygate Trojan Scan . . . Trojan Scan
Tools for Fighting Spyware
Spybot S & D . . . Ad-aware . . . CWShredder . . . HijackThis . . . PeperFix
Tools for Prevention
SpywareBlaster . . . SpywareGuard . . . IE-Spyad . . . avast! Free Anti-Virus . . . AVG Free Anti-Virus
Zone Alarm Free Firewall . . . Kerio Personal Firewall

 ComputerWeekly: Security Statistics show Surprising Finds

 Microsoft Blames Hackers, Not Zero-Day Vulnerability, For Web Attack

 
 Removing Spyware
 
 Avoiding and preventing Virus infection
 
 Getting Rid of/Blocking Spyware - Share Your Tips ( 1 2 )

-Educate yourself here:
 MSN Spyware?
 
 
Opera is Spyware!? ^
 
 NewsMax installs Spyware ^
 
 Tenacious Spyware Problem (Vanity) ^
 
 computer questions: ethernet, spyware, viruses ^
 
 Programs: 'Spyware' Can Shatter Privacy, Trust  ^
 
 Dell Policy Forbids Spyware Removal Support ^
 
 Drudge Site Ripe with Computer Slowing Spyware ^
 
 Patriotism? No, just more pop-ups (Spyware alert!) ^
 
 'Spyware' would be tricky to outlaw, group says  ^
 
 Spyware cures may cause more harm than good ^
 
 Got to Drudge website: get hit with spyware ^
 
 Message To Spyware: Get Off Our Private Property ^
 
 
'Pop-up' firm seeks to block spyware act  ^
 
 Spyware slowing computer - ad aware fixed it (not a commercial) ^
 
 Heads Up! Someone is posting xupitor spyware link; Don't open it! ^
 
 Antispyware vendors come under fire (spyware alert from American Cnet News)  ^
 
 
Unlikely German Leads the War Against Spyware -- Spybot Seatch & Destroy Created by Anarchist ^
 
 
See you later, anti-Gators? (Gator forces sites NOT to call it spyware) ^
 
 
 Tech?:Did I get spyware from Google or somewhere else that affects my Google results? ^

57 posted on 07/02/2004 11:07:47 AM PDT by backhoe
[ Post Reply | Private Reply | To 56 | View Replies]

To: All

This found a file everything else had missed:


Visit http://www.ducky.atribune.org and download About:Buster. Save it to your desktop.

Has to restart in Safe Mode & use Explorer to get rid of the file, which had already cloned itself.


58 posted on 07/02/2004 1:18:05 PM PDT by backhoe
[ Post Reply | Private Reply | To 1 | View Replies]

To: All
 Freepers how do I get rid of this spyware crap that is on my computer?

59 posted on 07/03/2004 11:11:35 AM PDT by backhoe
[ Post Reply | Private Reply | To 1 | View Replies]

To: backhoe

bump


60 posted on 07/03/2004 11:20:04 AM PDT by VOA
[ Post Reply | Private Reply | To 1 | View Replies]


Navigation: use the links below to view more comments.
first previous 1-2021-4041-6061-8081-84 next last

Disclaimer: Opinions posted on Free Republic are those of the individual posters and do not necessarily represent the opinion of Free Republic or its management. All materials posted herein are protected by copyright law and the exemption for fair use of copyrighted works.

Free Republic
Browse · Search
News/Activism
Topics · Post Article

FreeRepublic, LLC, PO BOX 9771, FRESNO, CA 93794
FreeRepublic.com is powered by software copyright 2000-2008 John Robinson