On Fri, 3 Oct 2003, Len Conrad wrote:

|->
|->
|->>The last 4 days we've seen something but I dont know what it is.
|->
|->have the infected machines run AV scanner and also SpyBot.

Yes after much hunting around its a proxy that gets installed on the
infected machines.

http://www.mail-archive.com/[EMAIL PROTECTED]/msg08569.html

I think this is what it is, or at least a variant.

|->They probably don't have their machines patched, are not running any kind 
|->of host firewall like ZoneAlarm or BlackIce, nor AV, and/or clicked on an 
|->executable.  boom

you have that right. Ive calmed down now and sat back, took a deep breath
and just let it roll off me...its Friday after all...

|->Apart from the spam problem, it's a very nasty place out there.

Those that Ive encountered so far dont have any AV or FW stuff in place.
As a temp measure Ive at least got them to turn on the XP FW, though not
sure how effective it is. But those that I have had cleaned up their
machines.

Over 10k messages in the queue on Tuesday all for aol.com then again today
over 8000 in the queue all to aol.com.

Takes a few minutes to clean them all out...but feel like I'm waging a
battle each time to stem the tide.

Thanks,
Keith


Reply via email to