Message from USCemper to all posters

Discussion in 'Open Discussion (Work-safe)' started by osugrad21, Apr 30, 2004.

  osugrad21

    osugrad21

    USCemper sent me this message via EZ-box:

    While I was responding to a DiHard post my computer contracted a debilitating virus and it has taken me all day to fix it.

    Please try to find out from the other guys if any of them have encountered similar problems.

    Thank you,


    ----I responded with the link to the MyDoom Virus thread and asked if he detected the source yet, USCemper responded:

    No, but i detected 138 infected files. I erased Norton and put in PI Cillin, but I am having a difficult time installing it.

    I have been working on this son of a bitch last night and all day today.

    If I find something I'll let you know immediately.

    Tell the guys on the Planet I miss them already!


    Any ideas??<!-- end --><!-- end -->
  MililaniBuckeye

    MililaniBuckeye

    He should not have contracted a virus from a PM on BuckeyePlanet since it is web-based and not an actual e-mail per se. I would assume that he had opened an infected e-mail earlier and it just happened to take effect when he was opening the PM from DiHard.

    Norton AntiVirus usually goes a very good job of quarantining and eliminating viruses...
  Oh8ch

    Oh8ch

    He may have contracted the Pete Carrol virus.

    The OS is becoming confused because all active tasks are acting as though they are number one in the queue for available resources.
  DiHard

    DiHard


    i never have private messaged uscemper.....period...

    i have only replied to him on this board....

    if you reread his posts...he was saying that he was replying to a post of mine...not an email not a pm...

    besides...i ran a wowway virus check earlier tonite and i am clean....

    however.....i think we just found a way to rid ourselves of pain in the arse opponents posters..... :biggrin:
  Clarity

    Clarity

    Didn't come from BP, that much I can assure him. Everything is pulled locally from my server. No outside ad or tracking code. The only bits of code I haven't looked at personally are the .swf files in the arcade. But they were each scanned by Norton Antivirus before being put on the server, and these games are installed on several dozen other vB3arcades without issue. That aside, I make sure I playtest each at least once after it goes on the server, and I've got a a couple layers of anti-virus anti-spy/ad/malware redundancy that would go nuts if something ugly was there, and it never does.

    The PM system on this board, like the post system and everything else, is written in PHP, and accesses a mySQL database. The code comes from a company called Jelsoft, I've been through almost all of it myself adding in little hacks and making a few mods. There's no opportunity whatsoever for a virus to be on, in, or around the board, unless someone uploads it as an attachment or links to it in a post. In either of those cases, we would all know pretty quickly, even if the board itself didn't catch it.

    I don't know anything about his specific virus, except that it couldn't have come from here. If we were loading in banners, tracking code, adinfo, outside cookies and all the other crap that basically ever other site in the world employs, then I'd be concerned because some aspect would be out of my own personal hands. But we're not, and I'm the only one with access to this server, and nothing on there (save people's attachments) hasn't passed through my home system.

    So for anyone concerned about a suggestion that somehow this site gave someone a virus, have no worries. Could have been an email. Could have been in an MP3 or movie file. Could have been over any of the instant messenging platforms available. Could have been through an 'open window' in the Windows architecture (XP has one intentionally left open). Could have infected him hours, days, weeks or even months ago, but been coded to delay-release its payload. It just couldn't have come from here.
  BuckeyeSoldier

    BuckeyeSoldier

    i think i just got it too, it is sasser.worm and sasser.wormb.. i dont know for sure that i got them here and i dont think it is an email virus, but i have been crashed for the last two days, starting as i was trying to make a post on here.

    norton cant touch this one(and wont even find it unless you download an update from two days ago), you NEED to get the microsoft update for it to keep it out, and once you get it you can find a newly released tool on the microsoft website that will eliminate it.
  DiHard

    DiHard

    soldier.....what were the first symptoms you noticed...or what happens to a computer when it gets a virus...

    also, what type of firewall do you have....i have a network associates.....
  osugrad21

    osugrad21 Capo Regime Staff Member

  BuckeyeSoldier

    BuckeyeSoldier

    first obvious thing i noticed was my post here wouldnt go through, i hit submit new post and i got an error message, then all my other internet windows died.

    after that my internet would only connect for 30 to 45 seconds before dying, and my whole computer started running slower, i restarted it at first and it even though my profile is the only user on the computer when it came up it was under guest or something cuz all of my options were gone, wouldnt even let me restart, but it let me log off and when i did that it took me back to my profile... i ran norton but it didnt find anything, so then i connected to the net and downloaded the norton update real quick before it kicked me off and ran norton again, this time it found it but said it couldnt fix it, soi started calling around and got info on websites that had programs to get rid of it and the like, so i got online again real quick and downloaded "stinger" and tried that but it didnt work (kept stalling when trying to read the oose file under windows.. then the next day i tried again and found a newly released symantec program designed especially for taking out that virus and it seems to have done the job, although things still seem a lil slow..

    could that possibly have soemthing to do with why bn was down too?
  USCemper

    USCemper

    Well, obviously I am ok now, but I lost a lot of my files because of it. I don't know excatly what happened, but it was a mess. I have installed PC Cillin and everything is fine now and the pc is much faster.
  BuckeyeSoldier

    BuckeyeSoldier

    uscemper, was yours the sasser worm? ive got rid of mine but my comp is still running slow as all hell and i cant figure out why, what did you do to get it back to normal?
  Clarity

    Clarity

    Again, it's literally not possible that anyone got a virus from the forum software. Were it somehow, everyone would be getting infected, or at least getting a warning every time they try and post.

    I highly recommend getting Norton, and using "Auto Protect". It covers you for viruses between scans in real time, and can also indicate where they're coming from.

    So while I appreciate the suggestion that I'm infecting people, I thought I'd take a moment again and re-confirm that this site uses no external links pulling in content or data from third parties. There is no ad code, there is no special content code. Nothing on the server save the contents of user posts and attachments doesn't pass through me via a secure/encrypted connection. There are no other active sites on this server. I own the box, and BP is the only thing I'm actively running on it. The forum software is vBulletin by Jelsoft. It's written in PHP, and doesn't have a mechanism in the newpost.php, editpost.php or any of the other simple text files full of code that make this place run. The images (jpegs and gifs) are also without virus. Were any of them infected (php files would actually have to have malicious code written in, and these don't), again, everyone would know it because it would be a constant with each post.

    This worm appears to travel from unpatched Windows box to unpatched Windows box. This server runs a very recent version of FreeBSD. A flavor of Unix.
    Last edited: May 5, 2004
  BuckeyeSoldier

    BuckeyeSoldier

    oh, oops yea i meant to say that in my last post. sorry clarity but for the record

  Clarity

    Clarity

    Lol, thanks. I got a couple concerned emails about this thread so I wanted to be as clear as possible. :wink:
  USCemper

    USCemper


    I also would like to point out that I never intended to imply that I got infected BECAUSE of BP. I simply informed OSUgrad21 that something very weird happened while I was attempting to answer a poster on the BP board.

    I had a friend come over who is a lot more computer literate and he proceeded in dumping all my files, cleaning my disk drives using Adware and then installing PC Cillin anti-virus software. I do not know excatly which virus I got, other than it completely disrupted everything that I try to accomplish using my pc.

    As I mentioned before, it is now ok and exteremely much faster.

