Computer Chess Club Archives


Search

Terms

Messages

Subject: Re: I Just Recieved An Infected E-Mail From Gambit Soft! W32.Badtrans.b@mm

Author: Jeroen van Dorp

Date: 08:43:35 11/30/01

Go up one level in this thread


>which makes me think they
>have harvested our email addresses from CCC.


As already stated a lot of times before, There are no "they". There is one: a
worm.
The worm needs *one* machine to be infected, connected to the Internet to spread
out. That is why they call it a *worm*: it makes a chain of infected PC's
becoming longer and longer.

You don't need a conspiracy, Osama Bin Laden or an attack to send a worm around.
There's one culprit, and that's the maker of the virus. There are a lot of
potential victims, the people online without sufficient virus protection.

The worm looks for email adresses a.o. in th Internet cache, i.e. the pages you
visited or visit now.
Thus these pages yield the email adresses, look at the source of the messages,
and you see all in there (look at all teh "mailto" tags):

<html><head><title>Subject: Re: I Just Recieved An Infected E-Mail From Gambit
Soft! W32.Badtrans.b@mm</title></head>
<body bgcolor="#FFFFFF">
<center><h1>Subject: Re: I Just Recieved An Infected E-Mail From Gambit Soft!
W32.Badtrans.b@mm</h1></center><hr><center>[&nbsp;<a
href="/forums/1/reply.shtml?message=199579%26board_id=1%26quote=n">Post&nbsp;Followup&nbsp;(without&nbsp;quoting)</a>&nbsp;]
[&nbsp;<a
href="/forums/1/reply.shtml?message=199579%26board_id=1%26quote=y">Post&nbsp;Followup&nbsp;(with&nbsp;quoting)</a>&nbsp;]
[&nbsp;<a
href="/ccc/resource/index.html">Computer&nbsp;Chess&nbsp;Resource&nbsp;Center</a>&nbsp;]
[&nbsp;<a href="/forums/1/index.shtml">Message&nbsp;Listing</a>&nbsp;]
</center><hr><p>
Posted by <a href="mailto:jrm@myrealbox.com">William Penn</a> (<a
href="../profile.shtml?jrm@myrealbox.com">Profile</a>) on November 29, 2001 at
12:24:32:<p>
In Reply to: <a href="message.shtml?199575">Re: I Just Recieved An Infected
E-Mail From Gambit Soft! W32.Badtrans.b@mm</a> posted by <a
href="mailto:nomad@easyfocus.com">Terry McCracken</a> on November 29, 2001 at
12:08:09:<p>
<pre>
On November 29, 2001 at 12:08:09, Terry McCracken wrote:

&#62;On November 29, 2001 at 12:00:05, Timothy J. Frohlick wrote:
&#62;
&#62;&#62;Terry,
&#62;&#62;
&#62;&#62;Most of these viruses are coming from the Netherlands and Germany.
Both have
&#62;&#62;very large Muslim populations.  You don't think that this is a form of
war do
&#62;&#62;you?
&#62;No...and since when did Muslims become dominant in the Netherlands and
&#62;Germany? I guess this is suppose to be funny?
&#62;&#62;
&#62;&#62;I got five Re; worm attacks from the Netherlands yesterday and one
today.
&#62;&#62;I hope that I am not sending out any shit myself.  I don't seem to be
infected.
&#62;&#62;
&#62;&#62;TIM
&#62;
&#62;If you send me infected e-mail I'll let you know.
&#62;&#62;
&#62;&#62;
&#62;&#62;On November 29, 2001 at 10:07:19, Terry McCracken wrote:
&#62;&#62;
&#62;&#62;&#62;Also in the subject header, it said Re; Brian McCarthy, I don't
know why?
&#62;&#62;&#62;He such a prick, I wouldn't put anything past him, sending
viruses whatever.
&#62;&#62;&#62;Or maybe he's just infected?
&#62;&#62;&#62;
&#62;&#62;&#62;I wrote Roland Troeger last night about why I have never heard
back or recieved
&#62;&#62;&#62;my winnings from them.
&#62;&#62;&#62;
&#62;&#62;&#62;I have sent him an e-mail and hope he can read it to rid himself
of this
&#62;&#62;&#62;worm/trojan.
&#62;&#62;&#62;
&#62;&#62;&#62;How to rid yourself of this virus, here's a link to Symantec.
&#62;&#62;&#62;
&#62;&#62;&#62;<a
href="http://www.symantec.com/avcenter/venc/data/w32.badtrans.b@mm.html">http://www.symantec.com/avcenter/venc/data/w32.badtrans.b@mm.html</a>
&#62;&#62;&#62;
&#62;&#62;&#62;
&#62;&#62;&#62;Terry McCracken

I've received the Badtrans worm from three domains so far: @xs4all.nl,
@t-online.de, and @online.no, which are I suppose in Netherlands, Germany, and
Norway (?, just guessing). All were sent to the mailbox used in my profile here
at CCC. I don't use that mailbox for anything else, which makes me think they
have harvested our email addresses from CCC.
WP


</pre>
<hr><nobr>
<ul></ul>
</nobr><p><hr><center>
[&nbsp;<a
href="/forums/1/reply.shtml?message=199579%26board_id=1%26quote=n">Post&nbsp;Followup&nbsp;(without&nbsp;quoting)</a>&nbsp;]
[&nbsp;<a
href="/forums/1/reply.shtml?message=199579%26board_id=1%26quote=y">Post&nbsp;Followup&nbsp;(with&nbsp;quoting)</a>&nbsp;]
[&nbsp;<a
href="/ccc/resource/index.html">Computer&nbsp;Chess&nbsp;Resource&nbsp;Center</a>&nbsp;]
[&nbsp;<a href="/forums/1/index.shtml">Message&nbsp;Listing</a>&nbsp;]
</center><hr>
<p align="center">

</p>
</body></html>


The level of *essential* knowlegde about dangers of people walking around the
internet is appaling.
That's no big deal, as there's always people around pointing each other to help.
But it becomes really annoying with stupid derogatory finger pointing by
paranoid individuals. Sorry. Wasn't directed especially at you, just in general.

J.



This page took 0 seconds to execute

Last modified: Thu, 15 Apr 21 08:11:13 -0700

Current Computer Chess Club Forums at Talkchess. This site by Sean Mintz.