Re: [Paddlewise] Not from me, check your computers

From: <jfarrelly5_at_comcast.net>
Date: Wed, 02 Oct 2002 22:15:20 -0400
(I know I said this thread should die, I've gotten multiple copies of bugbear, from paddlewise subscribers and I'm trying to hunt them down.  Additionally Bugbear installs a password and credit card stealing trojan so you really do want to make sure you don't have it.  - Kirk)


I decided to follow Grant's advice.  My Zone Alarm firewall software had
been neutralized but left on.  In other words it had been left impotent.  It
was useless.  I had to reinstall it.  And my Norton antivirus claimed to
have caught the attachment.  A six pack if we ever meet Grant.  I have a
cable modem and was unprotected all day without knowing it.  Sneaky
bastards!

Jim et al


----- Original Message -----
From: "Grant Glazer" <grantglazer_at_clear.net.nz>
Subject: Re: [Paddlewise] Not from me, check your computers


> Again from McAfee's library on Bugbear:
> "The worm opens a port on the victim machine - port 36794 and searches for
> various running processes, stopping them if found. The list of processes
> includes many popular AV and personal firewall products."
>
> I can only encourage people to scan their system in SAFE MODE ( restart
> comp, keep pressing f8, select safe mode) as my scanner did not pick it up
> when running normal windows.
> Cheers
> Grant Glazer
> Who is now clean and cured.

***************************************************************************
PaddleWise Paddling Mailing List - Any opinions or suggestions expressed
here are solely those of the writer(s). You must assume the entire
responsibility for reliance upon them. All postings copyright the author.
Submissions:     PaddleWise_at_PaddleWise.net
Subscriptions:   PaddleWise-request_at_PaddleWise.net
Website:         http://www.paddlewise.net/
***************************************************************************
Received on Thu Oct 03 2002 - 07:27:19 PDT

This archive was generated by hypermail 2.4.0 : Thu Aug 21 2025 - 16:31:00 PDT