PDA

View Full Version : e-mail bomb virus thing from someone who plays jj2


Nimrod
Mar 6, 2004, 09:41 AM
someone in the jazz community, is infected with: W32.Beagle

How do I know this?

In my inbox i have 2 emails, both infected with W32.Beagle, and its 'suppose' to be from Newspaz and Fquist. I for one know that who it is from has been forged, but what it means is, someone who has me, fquist and newspaz in there address book, is infected.

Both emails had this receieived header:

Received: from SEAN-LIVINGROOM [68.163.58.61]


anyone fancy bringing some light onto the sitwation as to who that is? So we can get them sorted with some AV.... (although being on the internet without AV is plain stupid)

Newspaz
Mar 6, 2004, 01:20 PM
I don't think I know anyone who's name is Sean, or who's host is Verizon.

Link
Mar 6, 2004, 02:08 PM
It's JJ Tublear.

QuakeNet-#jj2trivia.log:Mar 05 20:12:27 --> [CC]Tublear (~timemaste@pool-68-163-58-61.phil.east.verizon.net) has joined #jj2trivia

Nimrod
Mar 6, 2004, 03:53 PM
Thanks Link :)

Tubz
Mar 15, 2004, 03:27 PM
EHH?!?!?! Virus, since when. Eh, I better do a scan. Thanks for noting me. Lol, now everyone knows about my network and IP and stuff, evilness to no static IP on DSL.
-------
Problem taken care of. Thanks for telling me, sorry for the trouble that this may have caused.

Trafton
Mar 16, 2004, 09:03 AM
For future reference, W32/Bagle and other common viruses can be removed using McAfee's free "Stinger" program, here:

http://vil.nai.com/vil/stinger/

I would recommend that you keep your antivirus program more up to date and not click on any executable attachment you are not expecting to receive, Tublear. It would also be a good idea to send a letter with information about this to everyone in your address book.

~ Traft

Tubz
Mar 16, 2004, 12:00 PM
Ehh, no one has complained. And furthermore, I didn't just click on anything I've had this for a while, I guess.

Trafton
Mar 16, 2004, 01:49 PM
Depending on whether this is Beagle.A or a newer version, it is likely that you have not had it for a while. You probably have recently received a notification that your account is being deactivated (email account) with a .ZIP file attached containing a .EXE file. This is the worm.

~ Traft