Friday, May 27, 2005

Planet Internet sends me w32.mydoom.bu@mm

Today the system at the farm was hit with a virus, sent by my Internet provider Planet!!! Two email were sent one from support@planet.nl and the other from admin@planet.nl both contained a variant of my doom. I have sent the message header to Planet it will be interesting to see what sort of explanation I get. No doubt it will be interesting. It was easy enough to work around rebooted the PC in safe mode and ran the update for Symantic. It could not find the liveupdate server it was then a fairly simple process to look into the hosts file and notice the fact that all the virus update services were being sent to the local loopback address (127.0.0.1). Removed the entries from the hosts file, then updated the virus check and ran it. It located and remove the w32.mydoom.bu@mm.

No comments: