Gentoo Forums
Gentoo Forums
Gentoo Forums
Quick Search: in
Virus?
View unanswered posts
View posts from last 24 hours

 
Reply to topic    Gentoo Forums Forum Index Off the Wall
View previous topic :: View next topic  
Author Message
mbirkett
n00b
n00b


Joined: 03 Sep 2002
Posts: 45
Location: Newcastle Upon Tyne

PostPosted: Thu Dec 19, 2002 4:18 pm    Post subject: Virus? Reply with quote

we seem to be getting hammered with a file called: x_mas_2002.exe, as e-mail attachements.

These are being rejected by out inflex scanner but does anyone know if this is a virus?

CHeers,

marc
_________________
I am Thybrush Greepwood, a mighty privet...
Back to top
View user's profile Send private message
Scandium
Retired Dev
Retired Dev


Joined: 22 Apr 2002
Posts: 340
Location: Germany

PostPosted: Thu Dec 19, 2002 7:34 pm    Post subject: Reply with quote

I'd say so for the following reasons:

1. it's .exe
2. you are "getting hammered"
3. the filename also sounds like a "christmas present" :)
Back to top
View user's profile Send private message
homerjay
n00b
n00b


Joined: 13 Oct 2002
Posts: 13
Location: Scotland

PostPosted: Thu Dec 19, 2002 7:50 pm    Post subject: Re: Virus? Reply with quote

mbirkett wrote:
we seem to be getting hammered with a file called: x_mas_2002.exe, as e-mail attachements.

These are being rejected by out inflex scanner but does anyone know if this is a virus?


Neither Google, Symantec nor McAfee know anything about this file. Do you have a sacrificial machine you can test it out on?
Back to top
View user's profile Send private message
mbirkett
n00b
n00b


Joined: 03 Sep 2002
Posts: 45
Location: Newcastle Upon Tyne

PostPosted: Mon Dec 23, 2002 8:12 am    Post subject: Reply with quote

no. i reckon i will just leave it for the mo.

but at least i know what it is.....
_________________
I am Thybrush Greepwood, a mighty privet...
Back to top
View user's profile Send private message
really
Guru
Guru


Joined: 27 Aug 2002
Posts: 430
Location: nowhere

PostPosted: Mon Dec 23, 2002 12:18 pm    Post subject: Reply with quote

its an .exe so probably a winshit executable. so why care?
_________________
NoManNoProblem

Get lost before you get shot.
Back to top
View user's profile Send private message
kraylus
l33t
l33t


Joined: 07 Jun 2002
Posts: 648
Location: ft.worth.tx

PostPosted: Mon Dec 23, 2002 3:18 pm    Post subject: Reply with quote

this looks like a job for wine! man... i always wanted to run a trojan/virus from windows in wine....

email it to me (pm me first) and ill do it when i get home.

ryan
_________________
I used gentoo BEFORE it was cool.
Back to top
View user's profile Send private message
pilla
Administrator
Administrator


Joined: 07 Aug 2002
Posts: 7209
Location: Pelotas, BR

PostPosted: Mon Dec 23, 2002 3:39 pm    Post subject: Reply with quote

Next post: I run a virus using wine and it screwed my Gentoo!!! :lol: You'd be the joke of the forum for quite some time...

kraylus wrote:
this looks like a job for wine! man... i always wanted to run a trojan/virus from windows in wine....

email it to me (pm me first) and ill do it when i get home.

ryan
Back to top
View user's profile Send private message
hook
Veteran
Veteran


Joined: 23 Oct 2002
Posts: 1398
Location: Ljubljana, Slovenia

PostPosted: Mon Dec 23, 2002 3:41 pm    Post subject: Reply with quote

that's a must see :lol: :D
_________________
tea+free software+law=hook

(deep inside i'm still a tux's little helper)
Back to top
View user's profile Send private message
perry
Tux's lil' helper
Tux's lil' helper


Joined: 18 Nov 2002
Posts: 142
Location: Cornfields of Indiana

PostPosted: Mon Dec 23, 2002 5:35 pm    Post subject: Reply with quote

kraylus wrote:
this looks like a job for wine! man... i always wanted to run a trojan/virus from windows in wine....

email it to me (pm me first) and ill do it when i get home.

ryan


Wine does run windows virii/trojans/worms/nastys .. In particular, the Klez.. This article was linked on Slashdot a couple months ago..
Back to top
View user's profile Send private message
really
Guru
Guru


Joined: 27 Aug 2002
Posts: 430
Location: nowhere

PostPosted: Mon Dec 23, 2002 7:27 pm    Post subject: Reply with quote

perry wrote:
kraylus wrote:
this looks like a job for wine! man... i always wanted to run a trojan/virus from windows in wine....

email it to me (pm me first) and ill do it when i get home.

ryan


Wine does run windows virii/trojans/worms/nastys .. In particular, the Klez.. This article was linked on Slashdot a couple months ago..
yyou all know that that article is not telling the trueth.
its FUD!!!
_________________
NoManNoProblem

Get lost before you get shot.
Back to top
View user's profile Send private message
kraylus
l33t
l33t


Joined: 07 Jun 2002
Posts: 648
Location: ft.worth.tx

PostPosted: Fri Dec 27, 2002 9:10 pm    Post subject: Reply with quote

yep, it's total bs. notice how this guy backs his story up every chance he gets.

in any case, i dont think running a trojan in wine would screw up a gentoo system.

Code:

killall -9 wine


and it's game-over for whichever trojan/virus/worm i ran. anyone got an exe file i can try?
_________________
I used gentoo BEFORE it was cool.
Back to top
View user's profile Send private message
delta407
Bodhisattva
Bodhisattva


Joined: 23 Apr 2002
Posts: 2876
Location: Chicago, IL

PostPosted: Sat Dec 28, 2002 3:14 am    Post subject: Reply with quote

VMware is perfect for this -- take a Windows installation, change the disk type to a non-persistent type (so it won't permanently alter anything), and run your virus. Attack it with debuggers, protocol analyzers, and Windows message spies -- then, when you've gathered all of the data you want, tell it to "Power Off", change your disk back, and nothing has changed. ;)
_________________
I don't believe in witty sigs.
Back to top
View user's profile Send private message
Display posts from previous:   
Reply to topic    Gentoo Forums Forum Index Off the Wall All times are GMT
Page 1 of 1

 
Jump to:  
You cannot post new topics in this forum
You cannot reply to topics in this forum
You cannot edit your posts in this forum
You cannot delete your posts in this forum
You cannot vote in polls in this forum