John Corliss wrote:
>cnwyjn@test.org cross-posted a binary (probably some kind of malware):
i can't see a binary there John, only an incomplete post of one.
>> REMOVED
>
>Guy, don't reply to the original post to this thread. The troll who
>posted it has followed me here from the alt.comp.freeware newsgroup. He
>deliberately cross-posted his message into several disreputable and
>reputable newsgroups in a VERY lame attempt to trick me into replying a
>cross-posted reply into them so that he would be able to claim that I
>frequent the disreputable ones.
i can't see what other groups the original poster posted to
because the post is incomplete and won't open. how is it that you
can open the post to see what groups he posted to?
>The troll used a free throw-away usenet account with this company:
>
> http://www.hitnews.eu/english/
i just looked at that site and i can't see any free throw away
accounts. do you know something we don't?
>and I am going to file a complaint against him with them. He also uses
>Forte Agent so that he can obfuscate his header information, but when I
>send Hitnews a full copy of his message, they'll nail him down I'm sure.
the post was incomplete, how can you tell what newsreader the
poster used? how can agent obfuscate header information that other
news readers can't? and if other news readers can obfuscate headers
maybe the poster inserted agent to mislead you?
apart from that i agree you should send the headers from that
binary post to the website you mention for investigation. it'll be
interesting if you post their reply.
>Don't download the attachment that he appended to his message either. I
>could simply be a software cracker, but it also could be a Trojan,
>virus, rootkit or spyware of some kind.
it could be an invitation for dinner come to that.
>I sure wish the idiot who posted the troll would grow up and get a life.
lots of people need to grow up don't they John.
>Or better yet, lose the use of his computer for some reason.
that looks like one of your threats which you are notorious for making
are you going to beat the poster to a pulp with a baseball
bat John? go on you can tell us.
>(The idiot didn't write anything, just posted malware.)
>
>As it turns out, the attachment to the original post IS infected. From
>the alt.comp.freeware newsgroup:
>
>> BitDefender - Infected with: Generic.Malware.SI!YBdld.60322C31
>> Dr.Web - BackDoor.IRC.Sdbot.origin
odd that. i just looked at alt.comp.freeware and can't see any
mention of bit defender being infected. can you post a message-id to
where it is?
>DON'T DOWNLOAD THE ATTACHMENT!
right sir
..
..
..