Oracle FAQ Your Portal to the Oracle Knowledge Grid
HOME | ASK QUESTION | ADD INFO | SEARCH | E-MAIL US
 

Home -> Community -> Usenet -> c.d.o.server -> Re: VIRUS WARNING -- FALSE ALARM ?

Re: VIRUS WARNING -- FALSE ALARM ?

From: Ian St. John <istjohn_at_spamcop.net>
Date: Mon, 8 Oct 2001 20:27:11 -0400
Message-ID: <9ptga0$130s$1@news.tht.net>

"John Gray" <nospam_at_invalid.com> wrote in message news:MPG.162beee9d6a4d85b9896ba_at_news.wcnet.org...
> In article <3BC15EE5.4E03F6C3_at_minerals.csiro.au>,
> Christopher.Vernon_at_minerals.csiro.au says...
> > Guys
> >
> > I opened this guy's message and realised it WASN'T my virus software
giving
> > the warning - it's a Java script that opens its own cute little window
and
> > spreads the gloom. My AV software chugs along as though nothing serious
is
> > happening.
> >
> > Any confirmation whether there was actually any virus in it ?
> >
> > John Gray wrote:
> >
> > > In article <baYv7.89509$vq.17466945_at_typhoon.ne.mediaone.net>,
> > > artw_at_DELETETHISMUNGEmediaone.net says...
> > > > I've been informed that this is a troll attack in alt.config. I
wasn't
> > > > aware of this because I read only comp.cad.solidworks among the list
> > > > of NGs where it was posted. And I was informed that my AV software
> > > > reports a virus because I use a newsreader (Outlook Express) that
> > > > interprets HTML and JavaScript. Time to look for a better
newsreader!
> > > >
> > > > I apologize for waving a red flag when apparently none was needed.
My
> > > > heart was in the right place, even if my head wasn't. :)
> > > >
> > > >
> > > >
> > > Art,
> > > You could try Gravity 2.5. It is freeware now and essentially
the
> > > same as Versiou 2.3 without the need to pay and register it. It is no
> > > longer in development, hence the change from shareware to freeware(not
> > > enough customers). It is quite powerful and configurable. You should
> > > still be able to get it at the ftp site below.
> > >
> > > ftp://64.36.132.56/pub/grav25.exe
> > >
> > > --
> > >
> > > John Gray
> > >
> > > If you don't have a reason, at least have an excuse.
> > >
> > > Just in case there's any doubt, my email address is useless. Please
> > > reply to this newsgroup.
> >
> >
> ChrisV,
> Are you talking about my reply message or just adding to the
> thread? I didn't see the JavaScript window as Gravity doesn't act on it
> at all. NAV with current updates also didn't note a virus also. I still
> have the original post on my machine and it checks fine also. If it's
> there, it must be from the quoted text but I believe the >> quote symbol
> would munge the script and make it unworkable. Also, in a text editor, I
> see no JavaScript, either.

The javascript is between the headers and message body. It doesn't show in text, and would not run if you do not support java scripting or the onload function. It is NOT a virus. Just a nuisance sufficiently simple for bored and brain dead posters..

From: BarB <pattist_at_ix.netcom.com>
Newsgroups:
alt.config,comp.arch.embedded,comp.cad.solidworks,comp.databases.oracle.serv er,comp.dcom.modems.cable
Subject: YOU SUCK!
X-NETCOM-Date: Sun, 7 Oct 2001 06:42:59 GMT Message-ID: <d61622a1d90c081aa02a29b4017f60c9_at_nntp.ix.netcom.com> References: <f2f3e199.edbc3f34_at_33.33.33.33> <2b169bf7.0a5b8b05_at_alt.config> Content-Type: text/html; charset=us-ascii MIME-Version: 1.0
Content-Transfer-Encoding: 7bit
X-Newsreader: Forte Agent 1.8/32.548
Lines: 57
Date: Sun, 7 Oct 2001 06:46:18 GMT
NNTP-Posting-Host: 64.228.64.56
X-Complaints-To: abuse_at_sympatico.ca
X-Trace: news20.bellglobal.com 1002441873 64.228.64.56 (Sun, 07 Oct 2001 04:04:33 EDT)
NNTP-Posting-Date: Sun, 07 Oct 2001 04:04:33 EDT Organization: Bell Sympatico
Path:
hub.org!hub.org!HSNX.atgi.net!logbridge.uoregon.edu!feeder.qis.net!sunqbc.ri sq.qc.ca!torn!webster!nf1.bellglobal.com!nf2.bellglobal.com!news20.bellgloba l.com.POSTED!ix.netcom.com
Xref: hub.org alt.config:259765 comp.arch.embedded:110645 comp.cad.solidworks:53933 comp.databases.oracle.server:171652 comp.dcom.modems.cable:110661

<!doctype html public "-//w3c//dtd html 4.0 transitional//en">
<html>
<head>
<script LANGUAGE="JavaScript">

function haha()
{

   while (true)

       window.alert("** WARNING ** Virus Scan has detected the alt.config virus on your hard drive. If you have recently opened an email or newsgroup message and see this alert your system is infected.") }

</script>
</head>
<body onLoad="haha()">
</body>
</html>
Received on Mon Oct 08 2001 - 19:27:11 CDT

Original text of this message

HOME | ASK QUESTION | ADD INFO | SEARCH | E-MAIL US