"A Dream Is A Wish"

KCNET NEWSLETTER
12/28/03
TECHNICAL PAGE


VIRUS AND OTHER STINKY STUFF
TECHNICALLY SPEAKING
INTERESTING SITES
 


VIRUS AND OTHER STINKY STUFF
Two viruses to watch.
WORM_JUBON.A   From Trend Micro
WORM_JUBON.A is a memory-resident worm that propagates via the Web. It downloads a malicious file from a specific URL, which enables a mass-mailing routine. It runs on Windows 95, 98, ME, NT, 2000, and XP, and is currently spreading in-the-wild.
Upon execution, this worm runs one of its components, JAMES.EXE, in order to download another file, BOND.EXE, from one of two specific Web sites. It drops the downloaded file in the Windows system folder and sets its attributes to hidden. The component BOND.EXE is responsible for the mass-mailing routine.
Once download is successful, the file JAMES.EXE terminates. The component BOND.EXE remains in memory, listens to port 80, and establishes connection with two IP addresses. This worm also drops a file, JAMES.INI, in the Windows folder which contains vital information on JAMES.EXE.
The dropped BOND.EXE file sends an SMTP (Simple Mail Transfer Protocol) request to another set of IP addresses and attempts to send email messages to random users of the following domains:
    * hanmail.net
    * daum.net
From: Yaho <a9999999@yahoo.co.kr>
To:
    * <random user name>@hanmail.net
    * <random user name>@daum.net
Subject: <in Korean text>
Message Body:
an html that contains a link to a certain korean pornographic website:
http://38.118.128.181/check/yahogirl.htm
When the user clicks this link, this malware downloads the worm component, JAMES.EXE, to the Windows system folder. The attributes of this file are also set to hidden. This worm also creates a registry entry that allows it to automatically execute upon every Windows startup.

W32/Sober-C  From Sophos
W32/Sober-C is an internet worm which spreads via file sharing on peer-to-peer networks and by emailing itself to addresses found within files on the computer.
The email subject line and message text are randomly chosen from internal lists and will be in either English or German.
Example subject lines include:
ups, i've got your mail
Sorry, thats your mail
hi, its me
Thank You very very much
you are an idiot
why me?
I hate you
Preliminary investigation were started
Your IP was logged
You use illegal File Sharing ...
A Trojan horse is on your PC
a trojan is on your computer!
Anime, Pokemon, Manga, ...
Caution: To all gamers
Attention: To all gamers
Anmeldebestätigung
Bankverbindungs- Daten
Sie sind ein Raubkopierer
The following are examples of possible message texts:
"Sehr geehrter Kunde,
Vielen Dank für Ihre Anmeldung auf unserem Server.
Der Betrag von Euro 279,- wurde erfolgreich von Ihrem Konto abgebucht.
Ihnen stehen nun 1 Jahr lang mehr als 2300 sehr sehr heiße
Internet Seiten zur Verfügung.
Wir bedauern, das es im Vorfeld so lange gedauert hat,
unser Mail Dienst hatte diese Daten auf einen anderen E-Mail Empfänger
geschickt.
Da nun dieser Fehler behoben zu sein scheint, wünschen wir Ihnen
viel Spass mit unserem Angebot!
Die Seiten die Sie nun aufrufen können und die Zugangsdaten
befinden sich gesichert im Anhang."
"hi, I am from Austria and you'll don't believe me,
but a trojan horse in on your pc.
I've scanned the network-ports on the internet.
And I have found your pc.
Your pc is open on the internet for everybody!
Because the >filename<.exe trojan is running on your system.
Check this, open the task manager and try to stop that!
You'll see, you can't stop this trojan.
When you use win98/me you can't see the trojan!!
On my system was this trojan, too!
And I've found a tool to kill that bad thing.
I hope that I've helped you!"
The attachment filename is also randomly chosen from an internal list and can have an extension of EXE, SCR, PIF, COM, CMD or BAT. Examples include:
www.iq4you-german-test.com
www.freewantiv.com
www.free4manga.com
www.free4share4you.com
www.tagespolitik-umfragen.com
www.onlinegamerspro-worm.com
www.freegames4you-gzone.com
www.boards4all-terror432.com
www.anime4allfree.com
www.animepage43252.com
When first run, the worm copies itself to the Windows system folder as syshostx.exe and two other randomly selected filenames.
W32/Sober-C then creates the following registry entries:
HKLM\Software\Microsoft\Windows\CurrentVersion\Run\<random characters>
HKCU\Software\Microsoft\Windows\CurrentVersion\Run\<random characters>
that point to the two copies of the worm with randomly selected filenames to ensure it is run at system logon.
The following files are also created in the Windows system folder:
ms16taskwin.exe
savesyss.dll
Humgly.lkur
yfjq.yqwm
These files are not malicious and can simply be deleted.
W32/Sober-C copies itself to the My Shared Folder in the KaZaA folder replacing existing executables that have an extension of COM, EXE, SCR, BAT, CMD or PIF.
 

Have you updated your anti virus program lately?  If not, may I recommend that you do it today?

IF YOU SUSPECT THAT YOU HAVE A VIRUS OR IF YOU HAVE NOT SUCCESSFULLY SCANNED YOUR DRIVES FOR VIRUSES LATELY... THEN THE NEXT SUGGESTION IS FOR YOU.
Free Virus scan.
Trend Micro, more commonly referred to as Housecall, offers free virus scans and in most cases can fix damage down by a virus or worm that your computer may have contacted.  The program works well.  The first time one uses the free program it is necessary to download a small program. Trend Micro walks you through the process.   Then the virus scans are quite simple for each return.  You should disable any anti virus program that you have running.  If you do not have a virus program I recommend that you use this program first and then download one of the free programs listed above of install any anti virus program you have purchased.
Go to http://housecall.antivirus.com/ then choose the link   "Scan without registering".  Follow the directions.

Free Virus programs to download Quite a few KCnet members use these programs and like them.
Be careful if you download a virus program and you already have one installed on your computer.  You need to at least disable the program already installed.
http://www.grisoft.com/us/us_dwnl_free.php
Another good free program to take a look at is:
http://www.free-av.com/

10 Most Prevalent Viruses    Surveyed by Trend Micro US for December 12 - December 18.
   1. WORM_LOVGATE.G
   2. PE_VALLA.A
   3. WORM_SOBIG.F
   4. PE_FUNLOVE.4099
   5. PE_ELKERN.D
   6. WORM_KLEZ.H
   7. WORM_SWEN.A
   8. WORM_OPASERV.E
   9. WORM_NACHI.A
 10. WORM_LOVGATE.F

 
Tried and Untrue Viruses and Warning Letters of Impending Doom.
Believe it or not, the amount of harm done by sending false computer virus alarms and letters of impending doom to your thousand closest friends can be just as damaging as the alleged virus (if it even exists!);  if you remember the story of the boy who cried wolf, you understand why.
If you think you've got the scoop on the latest new devastating virus or latest doom warning, check it out at the Web sites below before taking it on yourself to alert the world.  If the virus is as terrible as you think it is, odds are the virus fighters already know about it and -- good news here!  -- your antivirus software provider probably knows about it too and already has an update for it.
Here are a few sites of many that can help you determine if an email is a hoax or real.
http://www.snopes.com/
http://www.urbanlegends.com/ulz/
http://hoaxbusters.ciac.org/HBHoaxIndex.html
http://vil.nai.com/VIL/hoaxes.asp
http://kumite.com/myths/
http://www.symantec.com/avcenter/hoax.html
http://www.scambusters.org/VirusHoaxes.html
http://www.sophos.com/virusinfo/hoaxes/
http://www.truthorfiction.com/


TECHNICALLY SPEAKING:
Sun: Microsoft forcing customers to upgrade  By Martin LaMonica  CNET News.com  December 22, 2003
Sun Microsystems' top software executive criticized Microsoft's decision to drop older software products that rely on Java software and offered a steep discount on Sun's own desktop software.
Sun: MS forcing customers to upgrade
Sun and Microsoft continue their spat over the Java virtual machine. Microsoft said that several products, including Windows 98, would be phased out because of a settlement reached with Sun regarding distribution of Windows products that use the JVM. Sun's Jonathan Schwartz said Microsoft's decision is a deliberate attempt to coerce customers to upgrade to newer software, and took issue with Microsoft's claim that Sun "forced its hand" to stop distributing older products. I also find Microsoft's claim difficult to believe.
READ FULL STORY  http://zdnet.com.com/2100-1104_2-5129793.html

Kim Komando offered the following info in here latest Newsletter.  -- Good Stuff (mike)
HOW MUCH HARD DRIVE CAN YOUR COMPUTER HOLD?
Have an old computer and want to know the maximum size hard drive the computer could use?  You're not alone.  I get this question a lot.
Hard drive capacity is determined by a few things: Windows and also, the basic input/output system (BIOS) on the motherboard.  An older computer probably uses Windows 98 or ME.  These use the FAT32 file system.  Early 98 machines had an 8 gigabyte limit; later versions of 98 and ME are restricted to 32GB.  If you still need a reason to upgrade to XP, here's one.
Windows 2000 and XP machines should be formatted with NTFS.  According to Ontrack, which makes hard drive management systems, these machines have no effective limitation.  They easily handle the largest hard drives.  So get the biggest one you can afford!

YOU CAN MIX DIFFERENT SPEEDS OF DDR MEMORY
New machines today almost all use DDR SDRAM (double data rate synchronous dynamic random access memory.  That's a mouthful!).
Some high-end computers use RDRAM, made under license to Rambus.  And older computers used SDRAM.
SDRAM runs as high as 133 MHz.  DDR SDRAM is an evolutionary development, and originally was rated at 266 MHz.  It is now rated up to 400 MHz.  DDR reads the data twice, whereas SDRAM reads it once.  If your computer is new, you almost certainly have DDR SDRAM.
Well, this listener has 256 megabytes of memory (DDR 2100) in his computer.  DDR 2100 RAM runs at 266 megahertz.  He wanted to know if he could add 256MB of DDR 3200 memory, which runs at 400MHz.
The answer is yes.  However, the new memory will run at the slower speed of 266MHz.  Since his computer is already running at that speed, he won't notice a slowdown.  But if the situation were reversed, and the original memory were the faster DDR 3200, he might well notice the change.

WHAT KIND OF RAM DOES YOUR PC USE?
Check your computer's manual.  It should have the specifications for memory.  The type and speed of the memory depends on the motherboard.
If you can't find the information there, check one of the memory sellers online.  They have memory listings for virtually any computer.
Crucial Technology   http://www.crucial.com
Kingston Technology   http://www.kingston.com
PNY Technologies   http://www.pny.com/configurator/

This one from From Worldstart
I have an A: drive and a C: drive. Why don’t I have a B: drive? Did the programmers at Microsoft skip kindergarten?
Ah, don’t fear, those MS programmers had a full education. The B: drive used to be (and still is I guess) reserved for a 5 1/4 inch floppy drive. You remember ‘em... They were the huge, bendy disks that didn’t hold much and were made of a kind of cardboard plasticy material.
Fortunately for us, they have gone the way of the 286, but their drive designation lives on – you know, just in case they make a comeback some day (maybe Elvis will bring them with him when he returns along with a handful of Beta video cassettes).
If you really must have a B: drive, you can always add a second 3.5 floppy drive to the mix. Now, I have no idea why you would actually want to do such a thing, but you can if you want.
Oh, and before you ask, no you normally can’t assign a CD, Zip, or hard drive with a “B” designation - unless you have a very cool BIOS that let’s you do that type of trick.

Dealing with Drop Down Menus  From Worldstart
Don't you get tired of scrolling through long drop down box lists? I know that I do. I'm gonna show you an easy way to get through them today. I'll illustrate how to do it with an example.
Let's say you're filling out an online registration form that asks for your country. If you live in Australia, you're all set since your country is towards the top. But what if you live here in the US? We have to scroll through tons of countries (many of which we've never heard of) to get to the entry for "United States."
Well, here's a quicker way. When you get to the box, click the first letter of the item you're hunting for. You'll find that items beginning with that letter start popping up in the drop box. So, when you get to the box, just hit the letter "U" until "United States" comes up.
Yeah! No more scrolling!

Converting tapes, records, etc   Worldstart Day!
We touched on this subject a couple of weeks ago in the Users Session on Wednesday.  The following will give the interested users some ideas and graphics showing connectors and boards.  Take a look it will become apparent.  The software mentioned is a product that Worldstart is promoting but there are dozens of software packages that will do the trick.
What do I need to put my old records and tapes onto the computer so I can make them into CDs?
First, you need a cable to connect your Stereo system to the computer.

The end going into the computer must be a "mini plug" (unless you have a really cool sound card with RCA jacks). This goes into the "line in" on the back of your computer. Usually this is the middle plug between the speaker output and the microphone mini plug jacks and might be colored light blue.

Depending on your setup and preference, the other end of the cable can either be two "RCA plugs" that go into the left and right Output on your stereo system/tape player...

...or the size plug that fits into your headphone jack (either another "mini plug" or a "phone plug").

You could even use a portable tape player with the cable running from the headphone jack to the line input of your computer (two mini plugs).

Once this is set up, you'll need good recording software. The Audio Cleaning Lab that Steve mentioned today is made especially for this and has all the tools you need.
That's it. Now you're ready to record and digitize your tapes and vinyl.
If you have a CD burner, you can burn them onto an audio CD-R that can be played on any CD player.


INTERESTING SITES:
Interesting facts about New Year Celebrations about the world:
http://www.geocities.com/Heartland/Plains/7214/newyear.htm
http://www.holidayorigins.com/html/new_years_day.html
http://www.theholidayspot.com/newyear/around-the-world.htm

BARNEY CAM IS BACK, SO IT MUST BE CHRISTMAS  It is not too late to tour this site.  It is good for all ages and politics are not in play.  There is just good viewing and a great learning experience.  Kids will especially love this one. (mike)
The White House has some interesting things on its site this holiday season.  Leading the list is a new version of Barney Cam.  Entitled Barney Cam II: Barney Reloaded, it chronicles the carefree attitude of President Bush's dog toward his duties.  There are also readings, tours and Christmas greetings:
http://www.whitehouse.gov/holiday/
 

Garrett Socling, KCnet member, frequent poster to the Community Forum, and a pretty savy computer operator has suggested this site.
This project was created to make a visual representation of a space that is very much one-dimensional, a metaphysical universe. The data represented and collected here serves a multitude of purposes: Modeling the Internet, analyzing wasted IP space, IP space distribution, detecting the result of natural disasters, weather, war, and esthetics/art. This project is free and represents a lot of donated time, please enjoy.  Here is a comment from slashdot.org:  "Yesterday morning Opte.org announced that they have successfully mapped the entire internet. They are currently compiling a LGL map for all to see. Currently they have a LGL map that has 'over 5 million edges and has an estimated 50 million hop count'. Also only took them 252.68 hours to complete."
http://www.opte.org
http://slashdot.org
Just thinking about it puts me into an awe trance.  Trying to understand the scope and content boggles me.  The graphic is a beaut though. It is worth the trip.  (mike)

Healing Herb Database  Find The Herb To Ease Your Ailment
Ever since the dawn of the ancient cultures, herbs have played an important role in healing. They still form the basis for scientific research into medical cures. And thanks to the work of progressive traditional medical doctors, alternative natural remedies have become increasing accepted by mainstream medicine. Even major HMO's have recognized the need for natural remedies and may cover alternative natural healing methods.
To help you learn more about widely accepted natural remedies and healing herbs, we've compiled a fully searchable database organized
http://futuregarden.com/knowledge_tree/growers_guides_healing_herbs.html

Doll Attic    This one from Amanda
This is the place to learn the history of the Barbie doll. "The idea of Barbie doll all started in 1959 when Ruth Handler, Barbie’s creator, noticed her daughter Barbara playing with paper dolls and imagining them in grown up roles such as college students, cheerleaders, and adults with careers."
If you take a walk in the History section you will learn all about Barbie's creation, growth, up until the 1968 or so to read more about it, you'll need to continue in the 1970's section. But in 1968 the first talking Barbie was created. The 70's has it's own section and covers all the way to this year because that is when Barbie picked up momentum. I found out some very interesting things about the doll in this section.
Then there is the facts section, here are the two facts I found most intriguing: "Right now about 120 new dresses and clothes are designed every year and more than 105 million yards of fabric has been used to create them." and this fact: "After stamp collecting Barbie collecting is the most popular hobby in America."
Enjoy!
http://www.dollattic.net/

ALL SEINFELD TV SCRIPTS!
This is a must look site for Seinfeld fans.  It is all here, scripts, schedules for current appearances, music, bios, etc.
So, Let's put on a show! Mom can sew the costumes, Dad can build the sets, I'll sell the tickets, we'll be Jerry, Elaine, George and Kramer --and sure! Fat Jimmy next door can play Neuman!
http://www.stanthecaddy.com/seinfeld-scripts.html

Powers of 10:  Jim Rockwell sent this suggestion.  It was an interesting link many months ago and deserves a rerun.  There are many new awesome photos also.
Florida State University, Tallahassee, Florida has put up a very interesting Java applet on their site.  It begins as a view of the Milky Way Galaxy viewed from a distance of 10 million light years and then zooms into towards Earth in powers of ten of distance.
10 million, to one million, to 100,000 light years and so on and then when it finally reaches a large Oak tree leaf.  But that is not all it zooms into the leaf until it reaches the level of the quarks viewed at 100 attometers.
This is a fantastic representation of how magnificent the Universe is and how vastly infinite it is both in the macroscopic and the microscopic level.
http://micro.magnet.fsu.edu/primer/java/scienceopticsu/powersof10/index

Time on your hands?
VIRTUAL BUBBLE-WRAP, FEED THE ADDICTION
http://fun.from.hell.pl/2003-11-24/bubblewrap.swf
WHAT'S BEHIND THE SMILEY FACE?
http://www.myshutter.com/flash/smiley-back.swf
 
 

HOME PAGE
KCNET NEWSLETTER
COMMENTARY AND CLASS 
SCHEDULE PAGE
MIKE'S COMMENTARY, SCHEDULE OF KCNET CLASSES,
NEWS & NOTES BY SUE FOUST
FUN PAGE
TRIVIA, QUOTES, 
CHUCKLES AND BELLY LAUGHS
KCNET SENIORCENTER.NET HOMEPAGE
NEWSLETTER ARCHIVES 2003, 2002, & 2001
KCNET NEWSLETTER MEMBER PAGES