Welcome to the GoFuckYourself.com - Adult Webmaster Forum forums.

You are currently viewing our boards as a guest which gives you limited access to view most discussions and access our other features. By joining our free community you will have access to post topics, communicate privately with other members (PM), respond to polls, upload content and access many other special features. Registration is fast, simple and absolutely free so please, join our community today!

If you have any problems with the registration process or your account login, please contact us.

Post New Thread Reply

Register GFY Rules Calendar Mark Forums Read
Go Back   GoFuckYourself.com - Adult Webmaster Forum > >
Discuss what's fucking going on, and which programs are best and worst. One-time "program" announcements from "established" webmasters are allowed.

 
Thread Tools
Old 01-28-2004, 03:22 PM   #1
Antxx
Confirmed User
 
Join Date: Dec 2003
Location: Qubec, Canada
Posts: 587
IWorm/doom virus problem- General interest

...is really taking a turn for the worst. Not only it did infect the home PC, but it does prevent you from getting to certain important sites to get rid of it. The last two days, i had to disinfect two PC and also to fix my own PC because of of the windows update, while i was infected went very wrong on me (Hopefully i made a restore point).

It is virtually impossible to do the automatic update for AVG. One of the computer i disinfected, had a 200+ contact list, so it's taskmon.exe was sending e-mail at a furious pace, making it hard to disinfect (I had to reset and caught it at startup). This thing is spreading at the speed of light. Hopefully MS will do something soon on the main net servers. This is wild! I also had a tentative of intrusion that my firewall detected coming from a software with the idoom sig. So it's not just an e-mail virus. Someone is trying to do something else with it. Nothing positive, i am sure...

Now the virus as changed the "unicode" message to a "server error". For those who liked to remove that crap:

http://vil.nai.com/vil/stinger/

or take AVG free edition with release 512
__________________
"Those who dream by day are cognizant of many things which escape those who only dream by night" -E A. Poe

http://www.playhon.com
http://www.living-glass.com
Antxx is offline   Share thread on Digg Share thread on Twitter Share thread on Reddit Share thread on Facebook Reply With Quote
Old 01-28-2004, 03:25 PM   #2
Antxx
Confirmed User
 
Join Date: Dec 2003
Location: Qubec, Canada
Posts: 587
French article:

http://www.branchez-vous.com/actu/04-01/08-137101.html

English:

http://news.com.com/2100-7355_3-5149...l?tag=nefd_top

http://news.com.com/2100-7349_3-5147...l?tag=nefd_pop

http://news.com.com/2100-7349-5148347.html?tag=nl
__________________
"Those who dream by day are cognizant of many things which escape those who only dream by night" -E A. Poe

http://www.playhon.com
http://www.living-glass.com
Antxx is offline   Share thread on Digg Share thread on Twitter Share thread on Reddit Share thread on Facebook Reply With Quote
Old 01-28-2004, 03:29 PM   #3
Shoplifter
Richest man in Babylon
 
Shoplifter's Avatar
 
Industry Role:
Join Date: Jan 2002
Location: Posts: 10,002
Posts: 5,742
This is why I read my email using pine on a unix box.

I think it has certainly been slowing down access for some sites and processors for the past day or so.
Shoplifter is online now   Share thread on Digg Share thread on Twitter Share thread on Reddit Share thread on Facebook Reply With Quote
Old 01-28-2004, 03:32 PM   #4
webair
Confirmed User
 
webair's Avatar
 
Industry Role:
Join Date: Feb 2002
Location: NYC, NY
Posts: 8,531
filtered out through our mail server...contact your host they should folllow suit...
webair is offline   Share thread on Digg Share thread on Twitter Share thread on Reddit Share thread on Facebook Reply With Quote
Old 01-28-2004, 03:35 PM   #5
Dirty F
Too lazy to set a custom title
 
Dirty F's Avatar
 
Industry Role:
Join Date: Jul 2001
Posts: 59,204
Quote:
Originally posted by Antxx
...is really taking a turn for the worst. Not only it did infect the home PC, but it does prevent you from getting to certain important sites to get rid of it. The last two days, i had to disinfect two PC and also to fix my own PC because of of the windows update, while i was infected went very wrong on me (Hopefully i made a restore point).

It is virtually impossible to do the automatic update for AVG. One of the computer i disinfected, had a 200+ contact list, so it's taskmon.exe was sending e-mail at a furious pace, making it hard to disinfect (I had to reset and caught it at startup). This thing is spreading at the speed of light. Hopefully MS will do something soon on the main net servers. This is wild! I also had a tentative of intrusion that my firewall detected coming from a software with the idoom sig. So it's not just an e-mail virus. Someone is trying to do something else with it. Nothing positive, i am sure...

Now the virus as changed the "unicode" message to a "server error". For those who liked to remove that crap:

http://vil.nai.com/vil/stinger/

or take AVG free edition with release 512
The solution is very simple.

Stop opening attachments!

The reason why this is spreading so fast because people will never learn not to open attachments.

Its not the virus writers who are so smart, its the people getting infected being so stupid.

And btw, why did you get infected? Opened an attachment?
Dirty F is offline   Share thread on Digg Share thread on Twitter Share thread on Reddit Share thread on Facebook Reply With Quote
Old 01-28-2004, 08:02 PM   #6
Antxx
Confirmed User
 
Join Date: Dec 2003
Location: Qubec, Canada
Posts: 587
Quote:
Originally posted by Battuss


The solution is very simple.

Stop opening attachments!

The reason why this is spreading so fast because people will never learn not to open attachments.

Its not the virus writers who are so smart, its the people getting infected being so stupid.

And btw, why did you get infected? Opened an attachment?
No, i didn't opened any attachement. I am not a newbie or average user, far from it (Computer technician). The virus is also spreading throught Kazaa with certain files (That i didn't downloaded). I did made two download with e-mule tho... If you want to know, the only explanation i have is that, i made an update with Microsoft update, and that's when i was infected. It screwed my windows for a while and once i got control over it, i immediately verified for virus and found it.

My firewall didn't see the virus during the update. Today i had a red alert intrusion coming from an "idoom" from my firewall. Since my computer is not infected anymore, my guest is that they also use that software for other pusposes then sending e-mail. I am still receiving that junk under the form of server error coming from mamkschools.org .

All i am saying, is that even MS don't know for now the extend of what that piece of shit do. For sure, it's an e-mail worm with an attachement. It also spraid through the automatic notice sended from antivirus software, by inserting itself into the e-mail. It also disrupt download from certain URL, during or before download. There also been report of PC intrusion like mine...

So check your PC. It doesn't take more than 15 minutes of your time to check your c:/windows folder....that gives a chance to big Cie to find solutions and possibly slow the growth of it.
__________________
"Those who dream by day are cognizant of many things which escape those who only dream by night" -E A. Poe

http://www.playhon.com
http://www.living-glass.com

Last edited by Antxx; 01-28-2004 at 08:08 PM..
Antxx is offline   Share thread on Digg Share thread on Twitter Share thread on Reddit Share thread on Facebook Reply With Quote
Post New Thread Reply
Go Back   GoFuckYourself.com - Adult Webmaster Forum > >

Bookmarks
Thread Tools



Advertising inquiries - marketing at gfy dot com

Contact Admin - Advertise - GFY Rules - Top

©2000-, AI Media Network Inc



Powered by vBulletin
Copyright © 2000- Jelsoft Enterprises Limited.