Author Topic: Worm.SomeFool.P  (Read 1424 times)

0 Members and 1 Guest are viewing this topic.

Offline aldo_14

  • Gunnery Control
  • 213
does anyone know what this virus is, and more specifically how it's 'caught'?  I've been getting bounced back emails saying they contained this, but I've run a few AV scans without finding anything on my system.... so I'm trying to identify if I'm infected or if my mail address is being spoofed by the virus on another machine....

Unfortunately, I can't really find any good info by searching on google (and there seems to be nowt on the symantec website), so any advice is welcome (well, duh, seeing as I'm asking for it......).

Oh, and NB:  I'm not daft enough to open any attachments I don't send myself, so I can;t see how i could have caught it that way.... but without knowing the virus infection method, I can;t be sure.

EDIT: http://www.f-secure.com/v-descs/netsky_d.shtml might be it.... but feck knows i could have caught it, and I'm sure it would have been picked up on my last scan, as me AVG database is the newest....sigh.
« Last Edit: April 05, 2004, 05:30:53 am by 181 »

 

Offline WMCoolmon

  • Purveyor of space crack
  • 213
I hear it's a Trojan virus. I'm pretty sure it's been running around for a long time now, started by some guy in Italy.

The easiest way to tell if you have it is to check your USER.IQ file and look at the contents...if it contains a value such as "low" you probably have the virus.

The easiest fix is to close your DMAS port, then download and install the latest antivirus util from GNUB. :)
-C

 

Offline Sandwich

  • Got Screen?
  • 213
    • Skype
    • Steam
    • Twitter
    • Brainzipper
Dude. Wake up. :p

Faking a bounce-back email is one of the surest ways to get someone to open the email.

Either that, or more likely, your address was randomly generated and used in the spoofed "To:" field. Either way, you're likely not infected.
SERIOUSLY...! | {The Sandvich Bar} - Rhino-FS2 Tutorial | CapShip Turret Upgrade | The Complete FS2 Ship List | System Background Package

"...The quintessential quality of our age is that of dreams coming true. Just think of it. For centuries we have dreamt of flying; recently we made that come true: we have always hankered for speed; now we have speeds greater than we can stand: we wanted to speak to far parts of the Earth; we can: we wanted to explore the sea bottom; we have: and so  on, and so on: and, too, we wanted the power to smash our enemies utterly; we have it. If we had truly wanted peace, we should have had that as well. But true peace has never been one of the genuine dreams - we have got little further than preaching against war in order to appease our consciences. The truly wishful dreams, the many-minded dreams are now irresistible - they become facts." - 'The Outward Urge' by John Wyndham

"The very essence of tolerance rests on the fact that we have to be intolerant of intolerance. Stretching right back to Kant, through the Frankfurt School and up to today, liberalism means that we can do anything we like as long as we don't hurt others. This means that if we are tolerant of others' intolerance - especially when that intolerance is a call for genocide - then all we are doing is allowing that intolerance to flourish, and allowing the violence that will spring from that intolerance to continue unabated." - Bren Carlill

 

Offline Lonestar

  • Fred Zone Guru
  • 27
    • United Gamers Coalition
Put your computer in Safe Mode then run the scan, it will find more viruses that way.

  

Offline aldo_14

  • Gunnery Control
  • 213
Think I've tracked it down..... it's being bounced off a website who seem to have bought my name from a spam list.  They had a similar thing a month or so ago, when all the 'remove' replies were resent to eveyone on the mailing list with a spoofed 'to' field.

What i don;t know, is how they got my email - because it's my Uni one and AFAIK it's never been shown on a public forum, etc.

 

Offline Kazan

  • PCS2 Wizard
  • 212
  • Soul lives in the Mountains
    • http://alliance.sourceforge.net
UNIs like to sell their ugrads@*.edu and grads@*.edu lists -- when you agreed to use their system you agreed to this
PCS2 2.0.3 | POF CS2 wiki page | Important PCS2 Threads | PCS2 Mantis

"The Mountains are calling, and I must go" - John Muir

 

Offline aldo_14

  • Gunnery Control
  • 213
Quote
Originally posted by Kazan
UNIs like to sell their ugrads@*.edu and grads@*.edu lists -- when you agreed to use their system you agreed to this


I'm not sure that's legal in the Uk, tho.  I'm 99% sure Strathclyde doesn;t do it anyways - they're not even allowed to put our emails on departmental webpages because of the Data Protection Act (plus there's nothing in the CoU form regarding it).   I can only assume I must have put my email in my siggy when I first joined or summat, without thinking it would be picked up.

'tis not a major issue, anyways - I graduate in July, so I won't even have the account anymore.

 

Offline StratComm

  • The POFressor
  • 212
  • Cameron Crazy
    • http://www.geocities.com/cek_83/index.html
It really depends on the institution though.  I have never gotten spam on my school account, ever.  Then again, my friends down 15-501 get it all the time (though whether by selling of a list or their own lack of internet sense I do not know).  It's more likely been picked up from an aquaintence's address book or a mail list that you belong to, either by being on some insecure site or by a similar virus.  Any time your address has been spoofed from, your address is out.
who needs a signature? ;)
It's not much of an excuse for a website, but my stuff can be found here

"Holding the last thread on a page comes with an inherent danger, especially when you are edit-happy with your posts.  For you can easily continue editing in points without ever noticing that someone else could have refuted them." ~Me, on my posting behavior

Last edited by StratComm on 08-23-2027 at 08:34 PM

 

Offline Lonestar

  • Fred Zone Guru
  • 27
    • United Gamers Coalition
ALL YOUR ADDRESSES ARE BELONG TO US!

 

Offline karajorma

  • King Louie - Jungle VIP
  • Administrator
  • 214
    • Karajorma's Freespace FAQ
Did you ever send anything that might have been forwarded on?

Lots of people don't bother removing addresses when forwarding and if they eventually end up in the hands of a spammer it's easy to collect and add them to their lists.
Karajorma's Freespace FAQ. It's almost like asking me yourself.

[ Diaspora ] - [ Seeds Of Rebellion ] - [ Mind Games ]

 

Offline aldo_14

  • Gunnery Control
  • 213
Quote
Originally posted by karajorma
Did you ever send anything that might have been forwarded on?

Lots of people don't bother removing addresses when forwarding and if they eventually end up in the hands of a spammer it's easy to collect and add them to their lists.


Doubt it.... may have been something as stupid as putting my email on my old siggy at the VBB - especially as the email is to the old CS server (cs.strath) and not the one introduced in 3 years or so ago (cis.strath).

Odds are, it'll be something stupid and my fault :)

 

Offline WMCoolmon

  • Purveyor of space crack
  • 213
Err, you mean you weren't joking around in the first post? Sorry man, I thought it was a late April Fool's joke :o
-C

 

Offline StratComm

  • The POFressor
  • 212
  • Cameron Crazy
    • http://www.geocities.com/cek_83/index.html
Those pesky chain letters are monsterous for collecting e-mail addresses as well.  Even if you have no part in them, as long as one person in the list forwards it on all of the addresses are carried along with it.

As to the virus, it does seem to be a Netski variant.  Norton has a tool on their website that removes it quite painlessly.
who needs a signature? ;)
It's not much of an excuse for a website, but my stuff can be found here

"Holding the last thread on a page comes with an inherent danger, especially when you are edit-happy with your posts.  For you can easily continue editing in points without ever noticing that someone else could have refuted them." ~Me, on my posting behavior

Last edited by StratComm on 08-23-2027 at 08:34 PM

 

Offline Kazan

  • PCS2 Wizard
  • 212
  • Soul lives in the Mountains
    • http://alliance.sourceforge.net
he;s probably not infected
PCS2 2.0.3 | POF CS2 wiki page | Important PCS2 Threads | PCS2 Mantis

"The Mountains are calling, and I must go" - John Muir

 
Quote
Originally posted by StratComm
Those pesky chain letters are monsterous for collecting e-mail addresses as well.  Even if you have no part in them, as long as one person in the list forwards it on all of the addresses are carried along with it.

As to the virus, it does seem to be a Netski variant.  Norton has a tool on their website that removes it quite painlessly.


amen.

i always send people who send me chain letters a rather lengthy copy&paste about how this helps spammers and virus writers, and some people actually find the BCC field. oth, i get a lot of chain letter anyway.
just another newbie without any modding, FREDding or real programming experience

you haven't learned masochism until you've tried to read a Microsoft help file.  -- Goober5000
I've got 2 drug-addict syblings and one alcoholic whore. And I'm a ****ing sociopath --an0n
You cannot defeat Windows through strength alone. Only patience, a lot of good luck, and a sledgehammer will do the job. --StratComm

 

Offline aldo_14

  • Gunnery Control
  • 213
I'm not...i forgot the uni mailserver does it's own virus scan on the email, so if I did have one all my emails would be rejected and sys support would give me a bollocking.