POV-Ray : Newsgroups : povray.binaries.images : Re: SORRY AGAIN! : Re: SORRY AGAIN! Server Time
5 Oct 2024 03:22:35 EDT (-0400)
  Re: SORRY AGAIN!  
From: Marc van den Dikkenberg
Date: 25 Jan 1999 22:10:06
Message: <36ad3185.2663431@news.povray.org>
>If you read this message: I've deleted the wsock32.dll and replaced it with the
>wsock32.ska file (renaming it of course). I hope this works.

It should take care of everything... I posted another message, describing
how to eliminate this virus from your system.

>Perhaps this explains why my post to a dutch newsgroup on the server of my ISP
>was rejected. I believe it has some huge filters/firewalls, whatever...
>Could it be it detected a corrupt WSOCK, or perhaps some sort of ID in the
>message? I'll give it a try...

I think that the 'new' winsock detects an e-mail message being send (or a
usenet posting) and before closing the socket, sends out a UUencoded
version of the virus itself. This shouldn't be too difficult to program...
And the problem is that the sender itself doesn't see it happening, it
would work with ANY mailclient, etc... Anyway, you've seen the results.

when my system was infected, I couldn't post to newsgroups at all: I simply
got a "500: What?" Error. Apparently the xs4all newsserver couldn't process
the message + attachment in the form winsock provided it to them...

Luckily.

>Anyways, I don't think it's fair to blame Rudy Velthuis and I hope this thing
>can be over soon.

He couldn't help it -- the winsock-thing totally bypasses your application,
it's invisible to the infected person, AND none of my virus-killers could
detect it...
-- 
Marc van den Dikkenberg
--
The PowerBasic Archives -- http://www.xs4all.nl/~excel/pb.html
All Basic Code Archives -- http://come.to/abcpackets


Post a reply to this message

Copyright 2003-2023 Persistence of Vision Raytracer Pty. Ltd.