On Sun, Sep 21, 2003 at 08:25:25AM -0400, Timothy Luoma wrote: > This email address ([EMAIL PROTECTED]) started to receive the virus not > long after I used it to post to this freebsd-(questions|mobile). Since > the address was just created and has only been used for these two lists, > it seems a good guess that someone here is infected. > > I don't know if the headers would be useful in tracking down who it is > (may be more than one even) but here they are, FWIW.
It's an interesting virus. Seems to hit people roughly proportionate to their exposure on usenet / the web / IRC / mailing lists. Which is targetting exactly the sort of articulate, outspoken person who would be the most likely to publicise fixes and complain to ISPs... Anyhow, yes, it's quite likely there are several people on these lists who have been infected. Then there are the people who have access to a mail-to-news gateway carrying these lists, of which there are several archived on Google groups. And then there are people who have been hit through KaZaA or IRC or through a shared disk with an infected machine. If any one of those happens to have your e-mail address in a mailbox or similar file then you're going to get hit. See: http://www.sophos.com/virusinfo/analyses/w32gibef.html http://securityresponse.symantec.com/avcenter/venc/data/[EMAIL PROTECTED] (Although Symantec's estimate of the number of infections is laughable) Cheers, Matthew -- Dr Matthew J Seaman MA, D.Phil. 26 The Paddocks Savill Way PGP: http://www.infracaninophile.co.uk/pgpkey Marlow Tel: +44 1628 476614 Bucks., SL7 1TH UK
pgp00000.pgp
Description: PGP signature