Re: Note on Swen from a newbie victim

From: Bit Twister (BitTwister_at_localhost.localdomain)
Date: 09/28/03

  • Next message: Walter Roberson: "Re: Note on Swen from a newbie victim"
    Date: Sun, 28 Sep 2003 12:46:57 GMT
    
    

    On 28 Sep 2003 04:51:08 -0700, Charles Packer wrote:
    >
    > You can't be serious...of course it matters.

    You had seemed to want to get back to using your temporary suspended
    email address. I was trying to show you that new users of usenet and
    new computer uses would become infected and those machines would send
    out the pay load to the email names in usenet, again and again.

    > So it's worth trying to keep this thread alive

    Your regulars will see your original question and reply. You do not
    have to "keep it alive"

    > until some of the regulars to this newsgroup can weigh in with something
    > more than ritual incantations.

    Think about it, the only way we would know how the virus acts is to get a
    copy of the firus code, not the virus, to be able to answer the question.

    The execption of course would to be set up a test rig, get it
    infected, put a firewall in front of it to block outbound email,
    emulate that the email was sent, wait until virus exausted all email
    addresses found in the news servers, reboot the box and watch it
    again. Then advance the date, boot the box, see if that effects it's
    operation.

    Mabye the virus is smart enough and remembers where it is installed.
    Next defrag would cause it to start over because it thinks it has been
    restored from backups.

    You can bet we will be seeing new viruses with the usenet email
    gleaming feature in the future.


  • Next message: Walter Roberson: "Re: Note on Swen from a newbie victim"

    Relevant Pages

    • Re: W32.Swen.A@mm virus HELP
      ... Use a program like Magic Mail Monitor to download the header and part of the ... from the email server, the virus infected messages. ... I did not post to usenet as I know. ...
      (microsoft.public.security.virus)
    • Re: $899
      ... shitty virus scanners like Macaffee do nothing to stop the carnage. ... reliable way of recovery after a real nasty malware infection. ... "Usenet Filters - Learn to shut yourself the fuck up!" ...
      (alt.2600)
    • Re: microsoft email virus
      ... If you post to UseNet with your TRUE, not a munged, email address then you have invited the ... Swen Internet worm to visit you. ... VIRUS DETECTED! ... | No attachments are in this category. ...
      (microsoft.public.security.virus)
    • Re: W32.Swen.A@mm virus HELP
      ... Listen jolielady I recieve this virus everyday about 20 times, ... I did not post to usenet as I know. ... >>harvests email addresses from UseNet News Groups. ...
      (microsoft.public.security.virus)
    • Re: Corrupt Updates: what to do?
      ... Tells people who really want to privately email me to use the "reply-to" ... Reminds people that on usenet they're normally supposed to reply back to ... address it's an overriding instruction to use it instead of the "from" ... "This message was sent without a virus, ...
      (alt.os.linux.redhat)