OT: virus infections

"A. Craig West" <[email protected]> Fri, 9 Apr 2004 02:32:24 -0400 (EDT)
Newsgroups gmane.network.everybuddy.user
Message-ID <[email protected]>
On Fri, 9 Apr 2004, A. Craig West wrote:
> In case somebody is wondering, this message is one of those viruses I was
> mentioning in my previous email. It looks like it finally found the list
> address in the guys address book. I'm going to see what I can find out about
> these machines, and if I don't here from the people involved soon, I'll try
> to go through their ISP's to get ahold of them...

Okay, according to nmap, the Netherlands guy is running an Edimax Broadband
Router that last rebooted 30 days ago. If you are on this mailing list, in
the Netherlands, running a broadband router, and reading the list on a
windows box, you almost certainly have a virus, particularly if your IP
address is: 213.84.144.241. Go to http://housecall.trendmicro.com and get
your machine scanned, your machine is no longer in your control...

The other address (61.95.204.47) which appears to maybe be in India, is
running a windows box with a whole slew of open services, including a tomcat
server on port 8080. If this sounds like you, you are infected, and you are
sending out a HUGE amount of data over your conenction. Please fix it...

I would be more than happy to assist anybody with cleaning up their
computers, but make it soon, guys...

-- 
Craig West         Ph: (416) 666-1645	|  It's not a bug,
[email protected]              	|  It's a feature...