Google Groups no longer supports new Usenet posts or subscriptions. Historical content remains viewable.
Dismiss

Ping: Pogo Stick aka Aardvark

3 views
Skip to first unread message

RonNNN

unread,
Jan 7, 2010, 7:15:06 PM1/7/10
to
When you gonna fix the damned stuttering mouse? Perhaps there's an "alt-s" keystroke in your "real" newsreader that you could use to send posts until you get that fixed?  

Aardvark

unread,
Jan 7, 2010, 7:42:17 PM1/7/10
to

LOL.

Funny you should ask right at this moment. It got so bad this evening that
not only was I double-posting, but every time I hit 'send' Pan (my
newsreader) would suddenly crash and disappear.

This particular session of Pan is being run from the CLI so that if it
crashes when I post, any errors that caused it will be echoed in the CLI.
Once I've sussed out why it's happening, I can begin to fix it.

I've narrowed down what causes this to one night a few weeks ago. I was on
the PC and my son was using the toaster in the kitchen. Whatever he did
caused the MCB which controls our downstairs power sockets in our domestic
electrical consumer unit to pop, killing everything plugged in downstairs
(we had the whole house rewired a couple of years ago and the new MCBs
will pop if you look at them funny sometimes- far too sensitive).

When I rebooted, Pan was kinda fucked up. I re-edited some of the config
files and got it running in some kind of semblance of normality, but I
know I missed something as things are still not quite right- strange
characters appear in funny places from time to time and such.

So, I'm hoping that this reply to you will double post and make Pan crash.
I trust you'll forgive me if it does, because you'll know I'm finally
doing something about it. Hopefully.

It's finally pissing me off enough to do something about it. :-)


--
Algy met a bear
The bear was bulgy
The bulge was Algy

Aardvark

unread,
Jan 7, 2010, 7:45:39 PM1/7/10
to
On Fri, 08 Jan 2010 00:42:17 +0000, Aardvark wrote:
>
> So, I'm hoping that this reply to you will double post and make Pan
> crash. I trust you'll forgive me if it does, because you'll know I'm
> finally doing something about it. Hopefully.
>
> It's finally pissing me off enough to do something about it. :-)

Guess what. The cussed thing didn't crash.

I'll just have to keep posting until it does.

RonNNN

unread,
Jan 8, 2010, 7:27:06 PM1/8/10
to
*Finally*! That's good news! And it seems that you've *finally* "wh00ped"
the problem. I didn't see one pogo-post from you today! wooohooo!


"Aardvark" <aard...@youllnever.know> wrote in message
news:hi5v19$cv2$1...@news.eternal-september.org...

~BD~

unread,
Jan 8, 2010, 7:38:35 PM1/8/10
to
On 09/01/2010 00:27, RonNNN wrote:
> *Finally*! That's good news! And it seems that you've *finally* "wh00ped"
> the problem. I didn't see one pogo-post from you today! wooohooo!

I'm not sure if you'd be interested, Ron but here's an extract from one
of my personal email messages:

> Thanks for the tip-off Rob,
> I recorded the 3 minute item and made it into a version that will
play on an
> iPod / iPhone
> or iTunes on a computer.
>
> File Name: RN-BBC.m4v
> Description:
> File Size: 33.8 Mb
> Download Link: http://uploading.com/files/get/m545a196/RN-BBC.m4v/
>
> If you have any trouble using Uploading.com services,
> please visit FAQ at http://uploading.com/faq/
>
> It is a bit slow to download depending on your connection, but well
worth the wait. Also you may have to dodge the adverts, but it is free.

The engine I have in my boat is rather 'special' - designed in 1930
.......... and still being manufactured today!

This is a short TV clip about the company and shows the engine off very
well!

If you look, let me know what you think! :)


--
Dave (Sometimes man stumbles over the truth ...... Sir Winston Churchill)

Aardvark

unread,
Jan 8, 2010, 7:47:16 PM1/8/10
to
On Fri, 08 Jan 2010 18:27:06 -0600, RonNNN wrote:
>
> "Aardvark" <aard...@youllnever.know> wrote in message
> news:hi5v19$cv2$1...@news.eternal-september.org...

>> It's finally pissing me off enough to do something about it. :-)


> *Finally*! That's good news! And it seems that you've *finally*
> "wh00ped" the problem. I didn't see one pogo-post from you today!
> wooohooo!
>

Surely you never doubted my ability to fix it! My *will* to fix it, maybe,
but definitely not my ability.

~BD~

unread,
Jan 8, 2010, 7:51:14 PM1/8/10
to
On 09/01/2010 00:38, ~BD~ wrote:
> The engine I have in my boat is rather 'special' - designed in 1930
> .......... and still being manufactured today!
>
> This is a short TV clip about the company and shows the engine off
> very well!
>
> If you look, let me know what you think! :)
>
>

I've also found the clip on the BBC site direct, but you may well not be
able to view sme in the USA.

http://news.bbc.co.uk/1/hi/england/8441919.stm

(Aardvark may just be mildly interested too! - that's why I interjected
here!)

Aardvark

unread,
Jan 8, 2010, 8:16:31 PM1/8/10
to
On Sat, 09 Jan 2010 00:51:14 +0000, ~BD~ wrote:

> On 09/01/2010 00:38, ~BD~ wrote:
>> The engine I have in my boat is rather 'special' - designed in 1930
>> .......... and still being manufactured today!
>>
>> This is a short TV clip about the company and shows the engine off very
>> well!
>>
>> If you look, let me know what you think! :)
>>
>>
>>
> I've also found the clip on the BBC site direct, but you may well not be
> able to view sme in the USA.
>
> http://news.bbc.co.uk/1/hi/england/8441919.stm
>
> (Aardvark may just be mildly interested too! - that's why I interjected
> here!)

Not just mildly.

Talking about mild, how's your weather?

< http://news.bbc.co.uk/1/hi/uk/8447262.stm?ls >

RonNNN

unread,
Jan 8, 2010, 8:42:42 PM1/8/10
to
I like the fact that the engine is still built using "cid's" instead of
"cc's"! [g] The engine sounds a lot like an old "John Deer" tractor... what
were those called? Popping Johnnies (or something like that)...

found a link

http://www.retiredtractors.com/Popper/index.htm

"~BD~" <Boate...@theobvious.hotmail.co.uk> wrote in message
news:UsadndOLENWfTtrW...@bt.com...

~BD~

unread,
Jan 9, 2010, 5:33:08 AM1/9/10
to
On 09/01/2010 01:42, RonNNN wrote:
> I like the fact that the engine is still built using "cid's" instead of
> "cc's"! [g] The engine sounds a lot like an old "John Deer" tractor... what
> were those called? Popping Johnnies (or something like that)...
>
> found a link
>
> http://www.retiredtractors.com/Popper/index.htm
>

Tractors were a boyhood love. Thanks for posting the link, Ron.

Were you able to watch the BBC site directly? I know the BBC were going
to change their stance.

**

If your phone can use an mp3 as a ring-tone, this is the sound of an
oily old dm2

http://uploading.com/files/e2b22fda/rn_ring_03.mp3/

~BD~

unread,
Jan 9, 2010, 5:39:00 AM1/9/10
to

You probably will find it hard to believe; although it's cold here, we
have 8/8 blue sky and sunshine!

And less than half an inch of snow ....... and that only in a few places
now!

If you email me, I'll send photos of my narrowboat at her base near
Coventry - ducks on the ice there too!
(remove - removetheobvious - from my address!)

RonNNN

unread,
Jan 9, 2010, 8:13:04 AM1/9/10
to
I don't use many sites that require me to register and/or give my email
address, such as "uploading.com"... I get enough spam as it is.

I was able to use the BBC link without a problem.

"~BD~" <Boate...@removetheobvious.hotmail.co.uk> wrote in message
news:QKGdnXDrzZ_4xtXW...@bt.com...

~BD~

unread,
Jan 9, 2010, 8:30:01 AM1/9/10
to
On 09/01/2010 13:13, RonNNN wrote:
> I don't use many sites that require me to register and/or give my email
> address, such as "uploading.com"... I get enough spam as it is.
>
> I was able to use the BBC link without a problem.
>

Hi Ron :)

Thanks for letting me know that you can now 'see' BBC items - I may feed
in a few more!

With regard to the "uploading.com" site I can tell you that the
initiator of the message is an IT
professional (and hopefully know what he's doing!) ....... and secondly,
one does *not* have to
'register' in order to utilise the service! <grin>

From personal experience there is an inbuilt time delay of, I think, 60
seconds
before items will download. I suspect it is to persuade people who use
the service often to subscribe
to their services! (this is quite a good idea methinks). Try it and see!

Btw, with regard to SPAM, is this your *real* email address?
nr...@charter.net

If it is, perhaps changing it to nr...@NOSPAM.charter.net or similar
would help matters. ;)

HTH

RonNNN

unread,
Jan 9, 2010, 8:35:12 AM1/9/10
to
Of course not.

"~BD~" <Boate...@removetheobvious.hotmail.co.uk> wrote in message

news:wbSdnfu0S7BHGdXW...@bt.com...

~BD~

unread,
Jan 9, 2010, 8:37:27 AM1/9/10
to
On 09/01/2010 13:35, RonNNN wrote:
> Of course not.
>

Please explain. How could *I* possibly know that?

RonNNN

unread,
Jan 9, 2010, 9:12:55 AM1/9/10
to
Do you know of anyone who uses their real email addy in usenet?

BTW, "uploading.com" tried to send me a present... Trojan.Script.255082
(Virus)

My security software took care of that for me. Perhaps you should scan your
computer for viruses.

"~BD~" <Boate...@removetheobvious.hotmail.co.uk> wrote in message

news:wbSdnfW0S7AKG9XW...@bt.com...

~BD~

unread,
Jan 9, 2010, 9:53:01 AM1/9/10
to
On 09/01/2010 14:12, RonNNN wrote:
> Do you know of anyone who uses their real email addy in usenet?
>
I know of no-one personally - I've made sure all my contacts know
better! ;)

However, if you visit any one of the thousands of Microsoft newsgroups,
almost every other poster is using a real addy!

I did too ..... when first I posted using Outlook Express to those
groups 4 years ago! Doh!

> BTW, "uploading.com" tried to send me a present... Trojan.Script.255082
> (Virus)
>

That's most interesting. I pasted your finding here
http://www.viruslist.com/ - it found nothing.

I tried here, too:
http://threatinfo.trendmicro.com/vinfo/default.asp?sect=SA Nothing of
that name found.

> My security software took care of that for me. Perhaps you should scan your
> computer for viruses.
>

What "security software" are you using, Ron?

Did you/can you send the 'rogue' item to http://www.virustotal.com/ or
http://virusscan.jotti.org/en or is it too late?

An independent check can be useful to rule out false positives.

****

You probably appreciate that I'm using an Apple iMac - with the most
current and up-to-date software.
OS X is (supposedly) virtually malware free, unlike Windows XP which I
think you are using.

I'd appreciate your further comments.

~BD~

unread,
Jan 9, 2010, 10:03:07 AM1/9/10
to

RonNNN

unread,
Jan 9, 2010, 10:37:31 AM1/9/10
to
Charter Security Suite 9.01

Viruses are automatically removed, all I see is what actions were taken.

From what I saw on the action log the infected file was named "pdffile.php"
and came from "statcntr.com".

"~BD~" <Boate...@removetheobvious.hotmail.co.uk> wrote in message

news:E9OdnbvK8rnQBdXW...@bt.com...

Aardvark

unread,
Jan 9, 2010, 11:27:28 AM1/9/10
to
On Sat, 09 Jan 2010 09:37:31 -0600, RonNNN wrote:
>
> "~BD~" <Boate...@removetheobvious.hotmail.co.uk> wrote in message
> news:E9OdnbvK8rnQBdXW...@bt.com...
>> What "security software" are you using, Ron?

> Charter Security Suite 9.01
>
> Viruses are automatically removed, all I see is what actions were taken.
>
> From what I saw on the action log the infected file was named
> "pdffile.php" and came from "statcntr.com".
>
>

Virus? That word rings a bell. What is it and what does it do?

RonNNN

unread,
Jan 9, 2010, 11:38:21 AM1/9/10
to
That's the first time since I've used F-Secure that I've seen a pop-up
showing a virus was caught and removed.

I have no idea what it might have done, had it not been caught by the
anti-virus software.

"Aardvark" <aard...@youllnever.know> wrote in message

news:hiaapg$phq$1...@news.eternal-september.org...

~BD~

unread,
Jan 9, 2010, 11:45:33 AM1/9/10
to
On 09/01/2010 15:37, RonNNN wrote:
> Charter Security Suite 9.01
>
> Viruses are automatically removed, all I see is what actions were taken.
>
> From what I saw on the action log the infected file was named "pdffile.php"
> and came from "statcntr.com".
>

Thanks Ron.

I've enquired on two 'security' groups but in the meantime found info
from Google.

I had *no* warnings from Safari (Apple's browser) on www.uploading.com
......

..... but I *did* get a warning when I attempted to go to
wxw.statcntr.com (obfuscated) ;)

Safe Browsing
Diagnostic page for statcntr.com

What is the current listing status for statcntr.com?
Site is listed as suspicious - visiting this web site may harm your
computer.

Part of this site was listed for suspicious activity 1 time(s) over the
past 90 days.

What happened when Google visited this site?
Of the 81 pages we tested on the site over the past 90 days, 0 page(s)
resulted in malicious software being downloaded and installed without
user consent. The last time Google visited this site was on 2010-01-08,
and the last time suspicious content was found on this site was on
2010-01-08.
Malicious software includes 39 trojan(s), 4 worm(s), 3 exploit(s).

This site was hosted on 1 network(s) including AS34305 (EUROACCESS).

Has this site acted as an intermediary resulting in further distribution
of malware?
Over the past 90 days, statcntr.com did not appear to function as an
intermediary for the infection of any sites.

Has this site hosted malware?
Yes, this site has hosted malicious software over the past 90 days. It
infected 32 domain(s), including dreamstoday.com/,
streamingepisode.com/, ddlspot.com/.

How did this happen?
In some cases, third parties can add malicious code to legitimate sites,
which would cause us to show the warning message.

**************

Are you absolutely sure (wink!) that *your* computer is clean?

If you have time, please do a scan with Malwarebytes (free, from here -
http://www.malwarebytes.org/)

It works best in 'normal' mode. Update the programme first and then do a
*full* scan.

I'll let you know what else I find out! :)

Aardvark

unread,
Jan 9, 2010, 11:46:21 AM1/9/10
to
On Sat, 09 Jan 2010 10:38:21 -0600, RonNNN wrote:
>
> "Aardvark" <aard...@youllnever.know> wrote in message
> news:hiaapg$phq$1...@news.eternal-september.org...
>> Virus? That word rings a bell. What is it and what does it do?

> That's the first time since I've used F-Secure that I've seen a pop-up


> showing a virus was caught and removed.
>

That indicates that your host/network is pretty securely configured and
your AV isearning its keep.

> I have no idea what it might have done, had it not been caught by the
> anti-virus software.

What ifs are pretty pointless, don't you think? Or was that you
figuratively wiping the nervous sweat from your brow while saying "Wow!
That was a close one!"?

I haven't had to use AV software for a few years. If I did somehow manage
to download some nasty that would even work on my system, it would take
quite a bit of work and a number of conscious decisions to make it do what
it was designed to do. Even then it mightn't even do that. :-)

RonNNN

unread,
Jan 9, 2010, 12:03:27 PM1/9/10
to
LOL! What do you mean? You just did get over the PoGo-Stick virus! [g]

"Aardvark" <aard...@youllnever.know> wrote in message

news:hiabst$9p1$2...@news.eternal-september.org...

Mike Easter

unread,
Jan 9, 2010, 5:50:20 PM1/9/10
to
~BD~ wrote:

> ..... but I *did* get a warning when I attempted to go to
> wxw.statcntr.com (obfuscated)

What exactly does statcntr have to do with RonNNN's accessing uploading.com?

I think the dots which need to be connected would be answers to the
question of what kind of configuration and behavior RonNNN performed to
enable/direct him to try to access and execute the malware from
somewhere else if it doesn't come from uploading.com.

He alleges that uploading.com tried to 'send' something, but in fact
uploading.com isn't associated with harboring malware and the webserver
for the Albanian IP 193.104.22.153 is what you are getting your positive
google tool response.

If I were RonNNN, I would want to be knowing what is wrong with my
system to be doing that.


--
Mike Easter

Mike Easter

unread,
Jan 9, 2010, 5:57:28 PM1/9/10
to
Mike Easter wrote:

> If I were RonNNN, I would want to be knowing what is wrong with my
> system to be doing that.

... because AV/antimalware is to be just one layer in the defense. The
normal state of affairs is that viruses and worms 'arise' in the wild
before any defense templates are created for them.

So, if RonnNN is configured in such a way that his AV ware has to go
into operation, there is something wrong with the way he is configured
-- his configuration is dangerous.

The proper configuration is for the AV ware to never have to do anything.


--
Mike Easter

RonNNN

unread,
Jan 9, 2010, 6:13:38 PM1/9/10
to
What I do know is that mal-ware was thwarted by my AV client. The why and
how are of no concern to me. What I do know is going to that site is what
caused my AV software to flag and eliminate the threat.

What's wrong with my system? Nothing as far as I can see. It worked just
like it should.

YMMV


"Mike Easter" <Mi...@ster.invalid> wrote in message
news:7qsfhd...@mid.individual.net...

Mike Easter

unread,
Jan 9, 2010, 6:26:25 PM1/9/10
to
RonNNN wrote:

> What's wrong with my system? Nothing as far as I can see.

Why should your system 'all by itself' decide to go off somewhere and
attempt to execute a malware?

A system/configuration which will do that will sometime manage to find a
malware which doesn't have an AV template written for it yet.

First a bunch of new malware is born/created. Next the AV dudes make
some new .dat files for some of it. Next you download the .dat
so that you can try to successfully defend yourself against some subset
of the malware, and meanwhile allow yourself to try to execute any new
malware you can find.

Someone else doesn't need any AV ware because they don't configure
themselves to be trying to execute malware. The person who doesn't have
any antimalware and doesn't ever need any is safer than the person who
has some antimalware and is configured to need it.

--
Mike Easter

~BD~

unread,
Jan 9, 2010, 6:37:35 PM1/9/10
to
On 09/01/2010 22:50, Mike Easter wrote:
> ~BD~ wrote:
>
>> ..... but I *did* get a warning when I attempted to go to
>> wxw.statcntr.com (obfuscated)
>
> What exactly does statcntr have to do with RonNNN's accessing
> uploading.com?

I truly have no idea.

> I think the dots which need to be connected would be answers to the
> question of what kind of configuration and behavior RonNNN performed
> to enable/direct him to try to access and execute the malware from
> somewhere else if it doesn't come from uploading.com.
>
> He alleges that uploading.com tried to 'send' something, but in fact
> uploading.com isn't associated with harboring malware and the
> webserver for the Albanian IP 193.104.22.153 is what you are getting
> your positive google tool response.
>
> If I were RonNNN, I would want to be knowing what is wrong with my
> system to be doing that.

No doubt he will heed our words.

I do thank you one again for your interest and advice, Mike.

At risk of "flogging a dead horse" may I remind you that Ron is a
'member' of Annexcafe. I may well have directed you here previously, but
others may not have read same. FYI I first 'met' P2U after installing
Kaspersky AV7 on a clean machine (fresh install) - on the Kaspersky
forums. Regrettably he became very ill and dropped out of posting, but
not before he had had a look-see at Annexcafe!

http://pqlr.org/bbs/viewtopic.php?f=21&t=940

RonNNN

unread,
Jan 9, 2010, 6:42:55 PM1/9/10
to
My point is that I don't claim to be a malware guru, and I *do* rely on my
software to protect my computer. It seems to be working. It's true that I
thought I could trust a link, provided by Dave, could be trusted, but I
found out otherwise. I don't blame him, but I'm glad my AV caught it before
it infecting my computer.

So... some of you Guru's don't need help adverting malware. Good for you!
I'm not in that group.


"Mike Easter" <Mi...@ster.invalid> wrote in message

news:7qshl2...@mid.individual.net...

RonNNN

unread,
Jan 9, 2010, 6:54:29 PM1/9/10
to
What the hell does that have to do with anything?


"~BD~" <Boate...@removetheobvious.hotmail.co.uk> wrote in message

news:ZqWdnVkTLpmijtTW...@bt.com...

Mike Easter

unread,
Jan 9, 2010, 6:59:35 PM1/9/10
to
RonNNN wrote:
> My point is that I don't claim to be a malware guru, and I *do* rely on my
> software to protect my computer.

I'm glad that your last line of defense held up, but my argument is that
you should question your first lines of defense.

You should wonder if your browser is a secure one and if it is
configured as securely as it should be.

> So... some of you Guru's don't need help adverting malware.

No I'm not trying to say you shouldn't have antimalware. I'm saying
that whenever it 'goes off' as you described, that generally means that
some other part of your defenses isn't right.

What is your browser? Some browsers are inherently less secure than
others; or conversely, some browsers are inherently more secure than
others -- and if you take a combination of an inherently insecure
browser (generally imbedded in an OS which has its own security
problems) and add to that an insecure configuration, you have an
invitation to -1- setoff your AV agent by the malware it sees and -2-
fail to setoff your AV agent by the malware it doesn't see.

All AV agents are able to detect only some fraction of the malware,
generally some large fraction, but definitely not all. Generally only
'pretty good'.


--
Mike Easter

RonNNN

unread,
Jan 9, 2010, 7:12:15 PM1/9/10
to
My guess, as far as my lack of defense, would be trusting links provided
from people in these usenet forums. However, I don't intend to be
imtimidated to the extent of not going there. I depend on my software to
catch the bad guys!


"Mike Easter" <Mi...@ster.invalid> wrote in message

news:7qsjj...@mid.individual.net...

~BD~

unread,
Jan 9, 2010, 7:45:20 PM1/9/10
to
On 09/01/2010 23:54, RonNNN wrote:
> What the hell does that have to do with anything?
>

Ron - in all honesty - I do not know! :(

Please pop back to the thread on Jenn's BB where I've added copies of
posts from P2U (Kaspersky)

I *do* know that something *is* amiss with the Annex operation. I just
...... *feel* it - Hinky, you say!

**

You could, yourself, ask *Roy C* exactly what it was that prompted him
to ban me from U2U. ;)

There was a follow-up post by Grybeard which said: ......

........ well, read it for yourself here:
http://pqlr.org/bbs/viewtopic.php?f=21&t=1379

Tinkerer joined the brief discussion thereafter until slapped down by Roy C.

Please do not hesitate to email me if there is anything more you'd like
to know.

Just remove 'removetheobvious' from my addy!

Time for my bed now! Back tomorrow. :)

~BD~

unread,
Jan 10, 2010, 5:26:43 PM1/10/10
to
On 09/01/2010 16:45, ~BD~ wrote:
>
> If you have time, please do a scan with Malwarebytes (free, from here
> - http://www.malwarebytes.org/)
>
> It works best in 'normal' mode. Update the programme first and then do
> a *full* scan.
>
> I'll let you know what else I find out! :)
>
Hi Ron

Quote:

January 7th, 2010, 05:54 AM

Trojan.Script.255082

I have F-Secure Charter Security Suite on my Windows Vista (Home)
computer. Two hours ago, it popped up and said that it detected
Trojan.Script.255082 but was unable to remove it. I found that it was in
my Temporary Internet Files so I deleted them. I don't know if I need to
do anything else.

I've been searching for trojan.script problems online but haven't been
able to find anything similar. I'm worried that it's something worse and
deleting the file won't get rid of it.

Ref:
http://www.cybertechhelp.com/forums/showthread.php?p=1148893#post1148893

*****

So, it seems you weren't alone! ;)

Have you run a scan of your machine with Malwarebytes? I strongly urge
you to do so if you haven't. It can do no harm and costs nothing but time.

Regardless, please confirm which browser you are currently using
(Internet Explorer 8 is the newest/best version - it is working just
fine on my wife's laptop with XP Home).

Better, though, to be using Firefox, Google Chrome or Opera rather than
the Microsoft product.

0 new messages