POV-Ray : Newsgroups : povray.binaries.images : Re: SORRY AGAIN! Server Time
5 Oct 2024 05:13:31 EDT (-0400)
  Re: SORRY AGAIN! (Message 1 to 10 of 14)  
Goto Latest 10 Messages Next 4 Messages >>>
From: Remco de Korte
Subject: Re: SORRY AGAIN!
Date: 25 Jan 1999 08:31:01
Message: <36ABCFEF.848D917F@xs4all.nl>
Rudy Velthuis wrote:
> 
> Remco de Korte schrieb in Nachricht <36AB9A24.795DB0A0@xs4all.nl>...
> >Rudy Velthuis wrote:
> 
> >Yep, thanks, now I have it in my Windows directory. I scanned the happy-exe
> >before running it, but still it does this thing.
> 
> I warned everyone, not to run it, didn't I?
> 

Yes, but that was after I downloaded the EXE for the first time.
Am I the only one who ran it?
I think not, and I do think it's wise for everyone who did to check for the
SKA-file.

Vriendelijke groeten,

Remco


Post a reply to this message

From: Marc Schimmler
Subject: Re: SORRY AGAIN!
Date: 25 Jan 1999 08:37:14
Message: <36AC738A.579B4920@ica.uni-stuttgart.de>
Remco de Korte wrote:
> 
> Rudy Velthuis wrote:
> >
> > Remco de Korte schrieb in Nachricht <36AB9A24.795DB0A0@xs4all.nl>...
> > >Rudy Velthuis wrote:
> >
> > >Yep, thanks, now I have it in my Windows directory. I scanned the happy-exe
> > >before running it, but still it does this thing.
> >
> > I warned everyone, not to run it, didn't I?
> >
> 
> Yes, but that was after I downloaded the EXE for the first time.
> Am I the only one who ran it?
> I think not, and I do think it's wise for everyone who did to check for the
> SKA-file.
> 
> Vriendelijke groeten,
> 
> Remco

Has anyone informed the WEBMASTER by mail to remove this annoying
material from this thread? 

I don't think it is wise to leave it here for the Windows users!!!


Marc
-- 
Marc Schimmler


Post a reply to this message

From: Marc Schimmler
Subject: Re: SORRY AGAIN!
Date: 25 Jan 1999 09:46:52
Message: <36AC83DB.C6D589EE@ica.uni-stuttgart.de>
I mailed the newsadmin and asked him to remove the offending attachment!


Marc
-- 
Marc Schimmler


Post a reply to this message

From: Rudy Velthuis
Subject: Re: SORRY AGAIN!
Date: 25 Jan 1999 13:28:47
Message: <36acb7df.0@news.povray.org>
Marc Schimmler schrieb in Nachricht
<36AC83DB.C6D589EE@ica.uni-stuttgart.de>...
>I mailed the newsadmin and asked him to remove the offending attachment!
>
>
>Marc
>--
>Marc Schimmler

(Now I hope I'm not sending multiples again)

Dan Connely also did the same, so I suppose they're gone by now.

For everyone (esp.Remco): scan for everything which looks like: liste.dat,
ska.exe, ska.dll and happyXX.exe. The word "liste" makes me think this was a
German program.

Sorry again for the inconvenience this caused to everyone. I think I did the
wrong thing in the first place (sending all those infected messages, after I
found out there was an infection; I already sent one or two infected
messages without knowing, but I should have stopped there).

--
Rudy Velthuis


Post a reply to this message

From: Marc van den Dikkenberg
Subject: Re: SORRY AGAIN!
Date: 25 Jan 1999 15:51:01
Message: <36accf65.403256@news.povray.org>
On Mon, 25 Jan 1999 19:31:06 +0100, "Rudy Velthuis" <rve### [at] gmxnet>
wrote:

>
>Marc Schimmler schrieb in Nachricht
><36AC83DB.C6D589EE@ica.uni-stuttgart.de>...
>>I mailed the newsadmin and asked him to remove the offending attachment!
>>
>>
>>Marc
>>--
>>Marc Schimmler
>
>(Now I hope I'm not sending multiples again)
>
>Dan Connely also did the same, so I suppose they're gone by now.
>
>For everyone (esp.Remco): scan for everything which looks like: liste.dat,
>ska.exe, ska.dll and happyXX.exe. The word "liste" makes me think this was a
>German program.

HM... It definitely appears to be doing _something_ : I also found a file
called c:\win98\system\liste.ska, which contains the 4 e-mail addresses
where I most recently send something to...

I better warn them!

And something else caught my eye: All of a sudden wsock32.dll has a
datestamp of today, and there also is a file called wsock32.ska
Which I find rather _suspocious_... And considering that it seems to be
able to intercept e-mail addresses in Eudora, it looks like this
SKA-thingey has taken over Winsock, the control center of your internet
access... That means that it could also be capable of e-mailing those
intercepted e-mail addresses to whoever it feels like without you knowing
about it, should the programmer wanted to do so... (And given the fact that
they are harvesting those e-mail addresses, that wouldn't surprise me in
the least!)

A re-install of Win98 didn't change anything for me...

Could anyone who's also running Win98 please give me the system dates and
filesize of their wsock32.dll?

The wsock32.ska file is different from the wsock32.dll file, even though
the filesize is identical... wsock32.ska has a more normal datestamp, so it
might be a backup copy of the original .dll...

Thanks in advance!
-- 
Marc van den Dikkenberg
--
The PowerBasic Archives -- http://www.xs4all.nl/~excel/pb.html
All Basic Code Archives -- http://come.to/abcpackets


Post a reply to this message

From: Remco de Korte
Subject: Re: SORRY AGAIN!
Date: 25 Jan 1999 18:15:12
Message: <36ACF8B6.486A7246@xs4all.nl>
Marc van den Dikkenberg wrote:
> 
> On Mon, 25 Jan 1999 19:31:06 +0100, "Rudy Velthuis" <rve### [at] gmxnet>
> wrote:
> 
> >
> >Marc Schimmler schrieb in Nachricht
> ><36AC83DB.C6D589EE@ica.uni-stuttgart.de>...
> >>I mailed the newsadmin and asked him to remove the offending attachment!
> >>
> >>
> >>Marc
> >>--
> >>Marc Schimmler
> >
> >(Now I hope I'm not sending multiples again)
> >
> >Dan Connely also did the same, so I suppose they're gone by now.
> >
> >For everyone (esp.Remco): scan for everything which looks like: liste.dat,
> >ska.exe, ska.dll and happyXX.exe. The word "liste" makes me think this was a
> >German program.
> 
> HM... It definitely appears to be doing _something_ : I also found a file
> called c:\win98\system\liste.ska, which contains the 4 e-mail addresses
> where I most recently send something to...
> 
> I better warn them!
> 
> And something else caught my eye: All of a sudden wsock32.dll has a
> datestamp of today, and there also is a file called wsock32.ska
> Which I find rather _suspocious_... And considering that it seems to be
> able to intercept e-mail addresses in Eudora, it looks like this
> SKA-thingey has taken over Winsock, the control center of your internet
> access... That means that it could also be capable of e-mailing those
> intercepted e-mail addresses to whoever it feels like without you knowing
> about it, should the programmer wanted to do so... (And given the fact that
> they are harvesting those e-mail addresses, that wouldn't surprise me in
> the least!)
> 
> A re-install of Win98 didn't change anything for me...
> 
> Could anyone who's also running Win98 please give me the system dates and
> filesize of their wsock32.dll?
> 
> The wsock32.ska file is different from the wsock32.dll file, even though
> the filesize is identical... wsock32.ska has a more normal datestamp, so it
> might be a backup copy of the original .dll...
> 
> Thanks in advance!
> --
> Marc van den Dikkenberg
> --
> The PowerBasic Archives -- http://www.xs4all.nl/~excel/pb.html
> All Basic Code Archives -- http://come.to/abcpackets

If you read this message: I've deleted the wsock32.dll and replaced it with the
wsock32.ska file (renaming it of course). I hope this works.

Perhaps this explains why my post to a dutch newsgroup on the server of my ISP
was rejected. I believe it has some huge filters/firewalls, whatever...
Could it be it detected a corrupt WSOCK, or perhaps some sort of ID in the
message? I'll give it a try...

Anyways, I don't think it's fair to blame Rudy Velthuis and I hope this thing
can be over soon.

Regards,

Remco


Post a reply to this message

From: Ken
Subject: Re: SORRY AGAIN!
Date: 25 Jan 1999 18:54:37
Message: <36AD042E.50CADA12@pacbell.net>
Remco de Korte wrote:
> Anyways, I don't think it's fair to blame Rudy Velthuis and I hope this thing
> can be over soon.
> 
> Regards,
> 
> Remco

I don't blame Rudy. I was concerned for the safety of my system
but since I never activated the .exe it appears I have remained
unneffected by it.  Big sigh of relief !!!

It's over for me.

-- 
Ken Tyler

tyl### [at] pacbellnet


Post a reply to this message

From: Eric Freeman
Subject: Re: SORRY AGAIN!
Date: 25 Jan 1999 19:45:28
Message: <36ad1028.0@news.povray.org>
Remco de Korte wrote in message <36AB9A24.795DB0A0@xs4all.nl>...
>Yep, thanks, now I have it in my Windows directory. I scanned the happy-exe
>before running it, but still it does this thing.
>
>Remco

What virus scanner do you use???  I have McAfee VirsusScan 95 and for the
last six months I have been unable to update the virus list... it has an
auto-update feature that updates thru the net, but it just times out.
E-mails to the company get no response.  So much for eternal free upgrades.

Eric

--
"Truth derives its strength not so much from itself
as from the brilliant contrast it makes with what is
only apparently true." --- Emanual Lasker
--------------------------------
http://www.geocities.com/SiliconValley/Heights/2354/


Post a reply to this message

From: Spider
Subject: Re: SORRY AGAIN!
Date: 25 Jan 1999 20:36:38
Message: <36AD1B19.E6E0B585@bahnhof.se>
I get a "Good Times" feel over this... *sigh*

Well. i'm glad I dind't get this, I had enough with JDK 1.2 ...

(Anyone here runs JDK1.2 ??? I need HELP)

//Spider

Ken wrote:
> 
> Remco de Korte wrote:
> > Anyways, I don't think it's fair to blame Rudy Velthuis and I hope this thing
> > can be over soon.
> >
> > Regards,
> >
> > Remco
> 
> I don't blame Rudy. I was concerned for the safety of my system
> but since I never activated the .exe it appears I have remained
> unneffected by it.  Big sigh of relief !!!
> 
> It's over for me.
> 
> --
> Ken Tyler
> 
> tyl### [at] pacbellnet


Post a reply to this message

From: Marc van den Dikkenberg
Subject: Re: SORRY AGAIN!
Date: 25 Jan 1999 22:10:06
Message: <36ad3185.2663431@news.povray.org>
>If you read this message: I've deleted the wsock32.dll and replaced it with the
>wsock32.ska file (renaming it of course). I hope this works.

It should take care of everything... I posted another message, describing
how to eliminate this virus from your system.

>Perhaps this explains why my post to a dutch newsgroup on the server of my ISP
>was rejected. I believe it has some huge filters/firewalls, whatever...
>Could it be it detected a corrupt WSOCK, or perhaps some sort of ID in the
>message? I'll give it a try...

I think that the 'new' winsock detects an e-mail message being send (or a
usenet posting) and before closing the socket, sends out a UUencoded
version of the virus itself. This shouldn't be too difficult to program...
And the problem is that the sender itself doesn't see it happening, it
would work with ANY mailclient, etc... Anyway, you've seen the results.

when my system was infected, I couldn't post to newsgroups at all: I simply
got a "500: What?" Error. Apparently the xs4all newsserver couldn't process
the message + attachment in the form winsock provided it to them...

Luckily.

>Anyways, I don't think it's fair to blame Rudy Velthuis and I hope this thing
>can be over soon.

He couldn't help it -- the winsock-thing totally bypasses your application,
it's invisible to the infected person, AND none of my virus-killers could
detect it...
-- 
Marc van den Dikkenberg
--
The PowerBasic Archives -- http://www.xs4all.nl/~excel/pb.html
All Basic Code Archives -- http://come.to/abcpackets


Post a reply to this message

Goto Latest 10 Messages Next 4 Messages >>>

Copyright 2003-2023 Persistence of Vision Raytracer Pty. Ltd.