[LUUG Publicity] Someone on the list has a virus

Andrew Findlay afindlay@ukuug.org
Sun, 14 Nov 2004 19:09:35 +0000


Someone on the LUUG-publicity list has a PC infected with the Bagle
virus. Starting last Wednesday it sent out at least four messages to
the list using a forged copy of my address. The messages were made
safe by the mailing-list system but were still passed on.

All I can tell from the messages is that the offending PC is connected
via a Blue Yonder cable service and is currently using the IP address
82.35.88.248

If you are a Blue Yonder customer with a Windows PC, please check your PC
and update your virus protection. This information from Sophos might help:

	http://www.sophos.com/support/disinfection/baglea.html

The Internet Storm Centre reports that the average survival time
for unpatched (presumably Windows) machines on the Internet is now
17 minutes. If you use Windows it is vital that you install patches
frequently and update your virus scanner definitions at least once
per day. Unix variants fare much better, but patching is still
necessary.

I am putting extra checks on the mailing list to block this sort of
virus-based nuisance in future.

Andrew
-- 
-----------------------------------------------------------------------
|                 From Andrew Findlay, Skills 1st Ltd                 |
| Consultant in large-scale systems, networks, and directory services |
|     http://www.skills-1st.co.uk/                +44 1628 782565     |
-----------------------------------------------------------------------