Jump to content

Information about virus that hit FPN


Admin

Recommended Posts

The following was sent to all members. If your profile does not have your current email address, please update it:

 

The email pretending to be from fpnadmin and instructing you to download a new JavaScript version and ignore any virus warning messages did not originate from fpnadmin. If you check the headers it will be clear that it didn't originate from FPN, but that it is a spoof.

 

If you did activate the link in that message, and you ignored the virus warnings, your computer will now be infected with a virus. This virus spreads itself via message boards as well. If you log in to a message board, like FPN, The board gets infected with it, and via FPN it can then be spread faster than only via email.

 

In order to get rid of this virus, please first get the latest virus updates, next scan your pc, and delete any viruses found.

 

Next, turn your computer off, completely. Wait 10 seconds and then restart your computer. The virus should be gone now.

 

Fortunately it is very easy to remove the virus from FPN itself.

 

However, since we won´t reach everybody in time before they log in to FPN, it is likely that the virus will get injected a few times again. If you do get virus messages from your scanner, do not ignore them, but log out from FPN.

 

We will attend to it as fast as possible, every time it reappears. In this case you can try occasionally to see if it has disappeared. Once everybody who has an infected computer has it cleaned, things should return to normal again.

 

Kind regards,

the FPN Admin Team

This account is unmanaged.
Please direct questions and comments to [email="fpnadmin@gmail.com"]FPN Admin email[/email], or directly to [url="http://www.fountainpennetwork.com/forum/index.php/user/17-wimg/"]admin Wim (wimg)[/url].
 
Thank you very much in advance.
 
Warm regards,
The FPN Admin Team

Link to comment
Share on other sites

  • Replies 25
  • Created
  • Last Reply

Top Posters In This Topic

  • Gerry

    2

  • Admin

    2

  • jd50ae

    2

  • Col

    2

Top Posters In This Topic

Thanks to the admin team for jumping on this problem and fixing it (at least fixing it the first time :D ) so quickly.

 

I appreciate all of your efforts!

 

kathy wc

We find rest in those we love, and we provide a resting place in ourselves for those who love us.--Bernard of Clairvaux

Link to comment
Share on other sites

Thank you FPN Admin folks. If we were paying you I would put you in for a bonus.

 

I saw the message late last evening, it did come as a popup but it appears my ZONE ALARM killed it before it did any harm.

Please visit my wife's website.

http://lh5.ggpht.com/_763_-2kMPOs/Sh8W3BRtwoI/AAAAAAAAARQ/WbGJ-Luhxb0/2009StoreLogoETSY.jpg

Link to comment
Share on other sites

Thank you FPN Admin folks. If we were paying you I would put you in for a bonus.

 

I saw the message late last evening, it did come as a popup but it appears my ZONE ALARM killed it before it did any harm.

If you really want to give us a bonus:

 

Donation Link

 

:D

This account is unmanaged.
Please direct questions and comments to [email="fpnadmin@gmail.com"]FPN Admin email[/email], or directly to [url="http://www.fountainpennetwork.com/forum/index.php/user/17-wimg/"]admin Wim (wimg)[/url].
 
Thank you very much in advance.
 
Warm regards,
The FPN Admin Team

Link to comment
Share on other sites

Thank you FPN Admin folks. If we were paying you I would put you in for a bonus.

 

I saw the message late last evening, it did come as a popup but it appears my ZONE ALARM killed it before it did any harm.

If you really want to give us a bonus:

 

Donation Link

 

:D

Done, wish it could be more. :D

Please visit my wife's website.

http://lh5.ggpht.com/_763_-2kMPOs/Sh8W3BRtwoI/AAAAAAAAARQ/WbGJ-Luhxb0/2009StoreLogoETSY.jpg

Link to comment
Share on other sites

Odd, I did not receive the suspicious email, and my email address on file is correct (I always receive email from other forumers, PM notification emails, etc.)

 

I even plumbed through the depths of my *shudder* spam folder, but I didn't see anything. Maybe gmail just rox my sox and deleted the mail before it even went into my spam folder. :)

happiness isn't caused

Link to comment
Share on other sites

Could be. I didn't get one either, and am glad I didn't. Another admin did.

 

There appears to be some randomness for whatever reason.

 

Regards,

 

Gerry

Link to comment
Share on other sites

The email pretending to be from fpnadmin and instructing you to download a new JavaScript version and ignore any virus warning messages did not originate from fpnadmin. If you check the headers it will be clear that it didn't originate from FPN, but that it is a spoof.

Hi Admins

 

Actually, I don't think it was spoofed - it was sent through your network. I'm reporting this only because it may help in dealing with problems like this in future. Here are the headers of the offending message (my email address and domain obscured):

 

----------

Return-Path: <nobody@host.refactored.com>

Received: from host.refactored.com (unknown97.36.157.204.defenderhosting.com [204.157.36.97])

by smtp.midair.net with ESMTP (Mailtraq/2.8.0.2048) id SMTP53BCDC63

for *@*; Fri, 09 Feb 2007 12:25:14 -0000

Received: from nobody by host.refactored.com with local (Exim 4.52)

id 1HFUlk-0008Tc-3M; Fri, 09 Feb 2007 05:22:24 -0700

To: fpnadmin@gmail.com

Subject: Fountainpennetwork administration ( From The Fountain Pen Network )

From: "The Fountain Pen Network" <fpnadmin@gmail.com>

X-Priority: 3

X-Mailer: IPB PHP Mailer

Message-Id: <E1HFUlk-0008Tc-3M@host.refactored.com>

Date: Fri, 09 Feb 2007 05:22:24 -0700

X-AntiAbuse: This header was added to track abuse, please include it with any abuse report

X-AntiAbuse: Primary Hostname - host.refactored.com

X-AntiAbuse: Original Domain - *

X-AntiAbuse: Originator/Caller UID/GID - [99 99] / [47 12]

X-AntiAbuse: Sender Address Domain - host.refactored.com

----------

 

And from your genuine message:

 

----------

Return-Path: <nobody@host.refactored.com>

Received: from host.refactored.com (unknown97.36.157.204.defenderhosting.com [204.157.36.97])

by smtp.midair.net with ESMTP (Mailtraq/2.8.0.2048) id SMTP53BEDC6B

for *@*; Fri, 09 Feb 2007 14:04:18 -0000

Received: from nobody by host.refactored.com with local (Exim 4.52)

id 1HFWK5-00034I-P7; Fri, 09 Feb 2007 07:01:57 -0700

To: fpnadmin@gmail.com

Subject: Urgent! Previous email from spoofed FPN address! ( From The Fountain Pen Network )

From: "The Fountain Pen Network" <fpnadmin@gmail.com>

X-Priority: 3

X-Mailer: IPB PHP Mailer

Message-Id: <E1HFWK5-00034I-P7@host.refactored.com>

Date: Fri, 09 Feb 2007 07:01:57 -0700

X-AntiAbuse: This header was added to track abuse, please include it with any abuse report

X-AntiAbuse: Primary Hostname - host.refactored.com

X-AntiAbuse: Original Domain - *

X-AntiAbuse: Originator/Caller UID/GID - [99 99] / [47 12]

X-AntiAbuse: Sender Address Domain - host.refactored.com

----------

 

As you can see, those headers clearly show an identical forward path. I run my own mail server here, and this extract from my server log is conclusive:

 

----------

00001000 00000000 09/02/2007 12:25:08 SMTP: (Accept) Receiving connection from 204.157.36.97

+ 0000001A host.refactored.com (204.157.36.97) [09/02/2007 12:25]

00000001 0000001A 09/02/2007 12:25:09 EHLO host.refactored.com ---> 250 smtp.midair.net

00000001 0000001A 09/02/2007 12:25:13 MAIL FROM:<nobody@host.refactored.com> ---> 250 receiving from nobody@host.refactored.com

00000001 0000001A 09/02/2007 12:25:13 RCPT TO:<*@*> ---> 250 will send to *@*

00000001 0000001A 09/02/2007 12:25:13 DATA ---> 354 send the message, terminate with "."

00000001 0000001A 09/02/2007 12:25:14 DATA ---> 250 received the message, thanks

00000080 00000000 09/02/2007 12:25:14 Routing (Inbound) SMTP53BCDC63 (0 locked, 0 queued)

00000080 00000000 09/02/2007 12:25:14 Router: (Depth 0) SMTP53BCDC64: "(nobody@host.refactored.com) Fountainpennetwork administration ( From The Fountain Pen Network )" from nobody@host.refactored.com for (2 rcpts) *@*,inbound

00000200 00010003 09/02/2007 12:25:14 nobody@host.refactored.com sent "Fountainpennetwork administration ( From The Fountain Pen Network )"

00000001 0000001A 09/02/2007 12:25:14 QUIT ---> 221 have a nice day (SMTP Closing)

00000001 0000001A 09/02/2007 12:25:14 SMTP Client Disconnected (204.157.36.97): Normal Transaction

----------

 

The HELO argument, MAIL FROM and RCPT TO may all be forged, but not I think your IP address.

 

Hope this helps, apologies for length.

Col

Link to comment
Share on other sites

Kudos for the swift response and for having the nerve to close the forum while it got sorted - would all forum admins 'net-wide had the sense!

 

...

 

Of course, being a Mac-man, I had no problems here :P :rolleyes: :D :lol:

 

/sorry :ph34r:

Mark Goody

 

I have a blog.

Link to comment
Share on other sites

As always, many thanks for a job well done (realizing it is an on-going one)!!!!

"But God demonstrates His own love toward us, in that while we were still sinners, Christ died for us." (Rom. 5:8, NKJV)
Link to comment
Share on other sites

I didn't get a spoof email, but my browser told me the website was trying to download something on my computer. As I didn't know what that would be and I didnt see the need to download anything I didn't allow the download. But I did get a virus warning from my anti virus software, and I deleted everything my anti virus told me to. So nothing bad happened here. :)

 

Thanks FPN Admin guys for the email. It explained why this website was acting so weird.

Maybe a tip for next time, mention a few admin names in the real email, that way we'll be even more sure that the email came from you guys.

 

Thanks again for handling this so well! :D

Link to comment
Share on other sites

We're thinking of all kinds of ideas, but certainly want to hear suggestions that you may have...

 

As a standard type of defense, it would be helpful if every member reading this would remember that Admin would never, never send instructions to download something to the members using the Admin bot. If you are ever in doubt - please always check the FPN site itself for information or news about anything we feel needs to be passed on. Don't click on any links ever. Just go to the site independently of the email, and see if there's something in the News.

 

If it's not there - the email must have been a phoney...

 

Regards,

 

Gerry

 

Ps - regarding similar headers... pretty much anything at all with regard to headers can be forged, and it's becoming rare that a real source of malicious email can be tracked down anymore...

Link to comment
Share on other sites

Odd, I did not receive the suspicious email, and my email address on file is correct (I always receive email from other forumers, PM notification emails, etc.)

Same here. I didn't get the e-mail either. But my virus protection did alert me that I had a virus. :o I screamed for my husband/resident-computer-doctor. This is what I do any time I have computer problems. He did whatever computer-doctors do to rectify the problem. So now my computer is squeaky clean - for the moment anyway. :)

 

Judybug

So many pens, so little time!

 

http://img244.imageshack.us/img244/5642/postcardde9.png

 

My Blog: Bywater Wisdom

Link to comment
Share on other sites

Odd, I did not receive the suspicious email, and my email address on file is correct (I always receive email from other forumers, PM notification emails, etc.)

Same here. I didn't get the e-mail either. But my virus protection did alert me that I had a virus. :o I screamed for my husband/resident-computer-doctor. This is what I do any time I have computer problems. He did whatever computer-doctors do to rectify the problem. So now my computer is squeaky clean - for the moment anyway. :)

 

Judybug

Judybug, do you have gmail as well?

 

I'm another one who didn't get anything, and I've got the gmail system tray alert deal going on--so I know that I've gotten every other notification and legitimate messages just fine.

Link to comment
Share on other sites

One question remains: whodunnit? :D

"There is hardly anything in the world that some man cannot make a little worse and sell a little cheaper and the people who consider price only are this man's lawful prey."

- John Ruskin (1819-1900)

 

Pelikan M800 Green (18C-750 OM), Pelikan 4001 Königsblau

Pelikan M200 "Citroenpers" (14C-585 M), Diamine Monaco Red

Pelikan M200 "Citroenpers" (14C-585 F), Diamine Prussian Blue

Link to comment
Share on other sites

I take it that one can't get the virus simply by logging on to FPN. One has to have received the bogus e-mail, and opened it. Yes? (I hope.)

 

P.S. I didn't receive the bogus e-mail.

Viseguy

Link to comment
Share on other sites

I take it that one can't get the virus simply by logging on to FPN. One has to have received the bogus e-mail, and opened it. Yes? (I hope.)

 

P.S. I didn't receive the bogus e-mail.

Sorry, not correct. Once one person opened that email and then opened FPN, thereby infecting it, the virus could be spread from simply signing into FPN.

 

The site has been clear since we re-opened it. We also have no idea what the virus does, nor how harmful it is.

 

My advice, don't surf without virus protection.

Link to comment
Share on other sites

Guest
This topic is now closed to further replies.


  • Most Contributions

    1. amberleadavis
      amberleadavis
      43844
    2. PAKMAN
      PAKMAN
      33553
    3. Ghost Plane
      Ghost Plane
      28220
    4. inkstainedruth
      inkstainedruth
      26724
    5. jar
      jar
      26101
  • Upcoming Events

  • Blog Comments

    • Shanghai Knife Dude
      I have the Sailor Naginata and some fancy blade nibs coming after 2022 by a number of new workshop from China.  With all my respect, IMHO, they are all (bleep) in doing chinese characters.  Go use a bush, or at least a bush pen. 
    • A Smug Dill
      It is the reason why I'm so keen on the idea of a personal library — of pens, nibs, inks, paper products, etc. — and spent so much money, as well as time and effort, to “build” it for myself (because I can't simply remember everything, especially as I'm getting older fast) and my wife, so that we can “know”; and, instead of just disposing of what displeased us, or even just not good enough to be “given the time of day” against competition from >500 other pens and >500 other inks for our at
    • adamselene
      Agreed.  And I think it’s good to be aware of this early on and think about at the point of buying rather than rationalizing a purchase..
    • A Smug Dill
      Alas, one cannot know “good” without some idea of “bad” against which to contrast; and, as one of my former bosses (back when I was in my twenties) used to say, “on the scale of good to bad…”, it's a spectrum, not a dichotomy. Whereas subjectively acceptable (or tolerable) and unacceptable may well be a dichotomy to someone, and finding whether the threshold or cusp between them lies takes experiencing many degrees of less-than-ideal, especially if the decision is somehow influenced by factors o
    • adamselene
      I got my first real fountain pen on my 60th birthday and many hundreds of pens later I’ve often thought of what I should’ve known in the beginning. I have many pens, the majority of which have some objectionable feature. If they are too delicate, or can’t be posted, or they are too precious to face losing , still they are users, but only in very limited environments..  I have a big disliking for pens that have the cap jump into the air and fly off. I object to Pens that dry out, or leave blobs o
  • Chatbox

    You don't have permission to chat.
    Load More
  • Files






×
×
  • Create New...