PaddleWise by thread

From: Grant Glazer <grantglazer_at_clear.net.nz>
subject: Re: [Paddlewise] Not from me, check your computers
Date: Wed, 02 Oct 2002 19:15:27 +1200
James and paddlewisers,

Firstly my sincere apologies IF the virus did originate from my computer.  I
was unknowingly effected by the Bugbear virus. But I am not sure that the
paddlewise infection started with me since I only started to receive "old"
emails this morning (Wednesday) .  James, yes your address was in my address
book, but Steves wasn't.  So I can only assume my address on another
computer was used to send to Steves. From the McAfee virus library info on
Bugbear  http://vil.nai.com/vil/content/v_99728.htm    "This worm emails
itself to addresses found on the local system."

The scary part is that I have McAfee virus scan running from the moment the
computer starts up until I close the comp down.  The program is on automatic
update and as of this morning had the most recent definitions (2 days old).
I also have the background system scan running.  It never picked it up. I
have a policy of additionally scanning my system once a week. This morning,
when I 1st knew there was a problem, I started the comp up in Safe Mode and
scanned.  That is when I discovered my system was infected.  McAfee has
stopped other viruses in the 6 months I have been using it so I know it is
setup correctly.  It just never picked it up during normal windows
operation.

Again from McAfee's library on Bugbear:
"The worm opens a port on the victim machine - port 36794 and searches for
various running processes, stopping them if found. The list of processes
includes many popular AV and personal firewall products."

I can only encourage people to scan their system in SAFE MODE ( restart
comp, keep pressing f8, select safe mode) as my scanner did not pick it up
when running normal windows.

As a sideline,  James, Please e-mail the sender personally if you receive a
virus alert.  It was a sickening feeling seeing your own name splashed on
paddlewise and associated with such a thing (espec. since I didn't know I
had a problem despite using a heavy duty "condom").  With these sorts of
viruses, the e-mail's received could come from anybodies computer with a
different header address, even looking at the e-mail properties you may not
be able to trace it.  By all means post a virus alert, but the list members
name doesn't need to be.  Approaching them back channel would be
appreciated.  It's kinda like a doctor shouting to the world that somebody
has a contagious disease before informing the patient.

If I am guilty of introducing the virus to paddlewisers, again you have my
apologies.


Cheers
Grant Glazer
Who is now clean and cured.

***************************************************************************
PaddleWise Paddling Mailing List - Any opinions or suggestions expressed
here are solely those of the writer(s). You must assume the entire
responsibility for reliance upon them. All postings copyright the author.
Submissions:     PaddleWise_at_PaddleWise.net
Subscriptions:   PaddleWise-request_at_PaddleWise.net
Website:         http://www.paddlewise.net/
***************************************************************************

This archive was generated by hypermail 2.4.0 : Thu Aug 21 2025 - 16:33:31 PDT