Free Republic
Browse · Search
News/Activism
Topics · Post Article

Skip to comments.

Vanity: Is anyone else getting hit with "Netsky"?
4/30/04 | Redcloak

Posted on 04/30/2004 4:34:50 PM PDT by Redcloak

Is anyone else getting hit by emails infected with "Netsky"?

Over the past week, I've gotten about a dozen messages with the W32.Netsky.Q@mm worm. (Norton makes quick work of them, however.) A few have had return addresses from some of my customers' domains, but the worm can spoof the return address. Symantec's page on the worm is here.

I've gotten two thus far today and one automated response from a server where my email address had been spoofed. Is anybody else seeing this worm wiggling in their inbox?


TOPICS: Miscellaneous; Technical
KEYWORDS: netsky; virus; worm
Navigation: use the links below to view more comments.
first previous 1-2021-4041-46 next last
To: Oystir
I have been getting the microsoft "patch" thing from russia 2-3 times a day - driving me nuts as I get almost no spam.

That's probably intentional. The virus installs a backdoor on your machine, and the spammers then use it to send their crap. It's called a "spam zombie".

21 posted on 04/30/2004 5:35:28 PM PDT by tacticalogic (Controlled application of force is the sincerest form of communication.)
[ Post Reply | Private Reply | To 19 | View Replies]

To: Redcloak
I have had at least four hits today from this virus. McAFee is catching them, but it is an issue.
22 posted on 04/30/2004 5:35:58 PM PDT by devane617
[ Post Reply | Private Reply | To 1 | View Replies]

To: Redcloak
Another item that I am having tons of problems with is "Port Scans". My Firewall is logging the activity, but it is more than I can make reports on to the ISP(s). I have several hundred in the past two days alone.
23 posted on 04/30/2004 5:38:19 PM PDT by devane617
[ Post Reply | Private Reply | To 1 | View Replies]

To: mlbford2; Redcloak
Let me join mlbford2's statement. This is the first week I've not been hammered by a daily barrage of incoming infected emails.
24 posted on 04/30/2004 5:42:13 PM PDT by SandRat (Duty, Honor, Country. What else needs to be said?)
[ Post Reply | Private Reply | To 2 | View Replies]

To: Redcloak
We had a bunch of these coming from some charter.net customers. Charter finally took some of them offline. I haven't got a single one so far this week.

I run Linux, so I don't have to worry about 'em. But they clog up the inbox anyway, and I report every one of them.

25 posted on 04/30/2004 6:13:32 PM PDT by TechJunkYard
[ Post Reply | Private Reply | To 1 | View Replies]

To: tacticalogic
Use the IP Whois to find out who's network it's coming from. Works for regular spam, too, but if it traces back to China or one of the former Soviet republics (lots of them do), it's probably a waste of time to report it.

Ok! Thanks so much!

26 posted on 04/30/2004 6:31:18 PM PDT by SheLion (Curiosity killed the cat BUT satisfaction brought her back!!!)
[ Post Reply | Private Reply | To 18 | View Replies]

To: TechJunkYard
We had a bunch of these coming from some charter.net customers.

Same here. Adelphia.net seems to have a nest of 'em, too.

27 posted on 04/30/2004 6:38:04 PM PDT by tacticalogic (Controlled application of force is the sincerest form of communication.)
[ Post Reply | Private Reply | To 25 | View Replies]

To: R. Scott
Ditto, now if Cox would do something about the spam.
28 posted on 04/30/2004 6:41:13 PM PDT by razorback-bert
[ Post Reply | Private Reply | To 8 | View Replies]

To: Redcloak
I have had about a dozen of these over the last couple of weeks and I run Linux!!!

At least 6 were Netsky-p the rest I am not sure.
29 posted on 04/30/2004 6:47:10 PM PDT by amigatec (There are no significant bugs in our software... Maybe you're not using it properly.- Bill Gates)
[ Post Reply | Private Reply | To 1 | View Replies]

To: R. Scott
Dittos...Cox has started deleting them lately but I do some buying on eBay and I wonder how many of those dealers machines are trojans...
30 posted on 04/30/2004 6:49:55 PM PDT by tubebender (My wild oats have turned to shredded wheat...)
[ Post Reply | Private Reply | To 8 | View Replies]

Comment #31 Removed by Moderator

To: Redcloak
Norton does a great job on it. Be sure to update at least once a week.
32 posted on 04/30/2004 7:46:39 PM PDT by Cicero (Marcus Tullius)
[ Post Reply | Private Reply | To 1 | View Replies]

To: ilosetoo; Admin Moderator
what the heck was that?

My Nortron kicked in right away and said I was under virus attack!!!!!

33 posted on 04/30/2004 7:48:22 PM PDT by m87339 (If you could see what a drag it is to be you)
[ Post Reply | Private Reply | To 31 | View Replies]

To: tacticalogic
Thanks for providing this info. I've wondered about this awhile. Wonderful. It'll work for those Nigerian scam letters, too, yes? Wee!
34 posted on 04/30/2004 7:50:39 PM PDT by cgk
[ Post Reply | Private Reply | To 10 | View Replies]

To: Redcloak
I've never gotten a virus. What is usually in the subject line, or the headers? I guess I've been lucky.
35 posted on 04/30/2004 7:54:17 PM PDT by IamHD
[ Post Reply | Private Reply | To 1 | View Replies]

To: tacticalogic
Thanks for providing this info. I've wondered about this awhile. Wonderful. It'll work for those Nigerian scam letters, too, yes? Wee!
36 posted on 04/30/2004 7:55:41 PM PDT by cgk
[ Post Reply | Private Reply | To 10 | View Replies]

To: m87339
my AVG kicked it out. this guy is some kind of turd who posts screwed up links. put his name in 'search' author. that's all he does.
37 posted on 04/30/2004 9:13:37 PM PDT by mlbford2
[ Post Reply | Private Reply | To 33 | View Replies]

To: devane617
Same here. A lot of port scans and then spam follows. I gave up reporting them to the ISP because nothing happens as a result of the reports.
38 posted on 04/30/2004 9:19:00 PM PDT by arasina (So there.)
[ Post Reply | Private Reply | To 23 | View Replies]

To: ilosetoo; Admin Moderator
The link you provided is infected with a virus, according to my Anti-Virus Guard.
39 posted on 04/30/2004 9:27:26 PM PDT by arasina (So there.)
[ Post Reply | Private Reply | To 31 | View Replies]

To: IamHD
I hope that you have an anti-virus program. Luck has a way of running out.
40 posted on 05/01/2004 12:00:37 AM PDT by Redcloak (Have you hugged your tagline today?)
[ Post Reply | Private Reply | To 35 | View Replies]


Navigation: use the links below to view more comments.
first previous 1-2021-4041-46 next last

Disclaimer: Opinions posted on Free Republic are those of the individual posters and do not necessarily represent the opinion of Free Republic or its management. All materials posted herein are protected by copyright law and the exemption for fair use of copyrighted works.

Free Republic
Browse · Search
News/Activism
Topics · Post Article

FreeRepublic, LLC, PO BOX 9771, FRESNO, CA 93794
FreeRepublic.com is powered by software copyright 2000-2008 John Robinson