Forum: Poser - OFFICIAL


Subject: (OT)---W32/Polip virus??? layman explanation needed please........

bnetta opened this issue on Apr 30, 2006 · 38 posts


Angelshigh posted Tue, 02 May 2006 at 10:22 AM

Quote - "Risk Assessment     - Home Users: Low -  Corporate Users: Low  - Date Discovered: 4/25/2006 - Date Added: 4/25/2006 - Origin: N/A Length: N/A - Type: Virus SubType: P2P Worm DAT Required: 4748

**uses Gnutella protocol to spread through p2p clients like BearShare that implements this protocol."
**

**Very curious!!!, something strange is going on???
There's no way to a virus spread by P2P using Gnutella, eMule, BitTorrent!!!
You cannot send a virus or any file to a computer using P2Ps, the computer's user must request the file for downloading, it's not like emails that can be sent and received without your knowledge.
The only files that you download are those that you wanted,  this file can be infected, but never is downloaded if you haven't requested it.
Even if you download it and is infected, nothing happens, the file is stored only in the folders that you decided to share in the network,  but  nothing happens, downloading an infected file is not enough, you must execute it (run, open) to have your computer infected.
**

"From what I have been told I believe you have to be using a P2P programe and downloading pirated stuff in order to get this particular virus."
Another myth!, P2Ps are as a knife, with a knife you can kill someone or use it to eat, you decide how you use it.
There exist  a lot of  legal materials that you can use P2Ps, if you are the author and if want to do it, you can share your work with people usintg these networks and you needn't to have a site for this, your computer is just enough!

 

As I said above, and will say again, - I am not accusing anyone of anything  - just quoting from the link that original poster provided. It is obvious that using a P2P one has to request the file in order to download it - it is also obvious that without  opening that file you are not going to get "infected" - so it must then be equally obvious that requesting the file from a P2P means that you are eventually going to open the file - otherwise why bother?. And they sure ain't gonna tell you which files are infected.  I am equally sure that as you said, there are legal materials available - just as there are 99% more of the "pirated" variety.

Symantec says the following:

When W32.Polip is installed, it performs the following actions:

  1. Infects .scr and .exe files when they are opened or executed on the compromised computer.
  2. Hides its presence on the compromised computer by injecting its code into running processes.
  3. Attempts to spread by sharing infected files on the Gnutella file sharing network, even if the Gnutella software isn't installed on the compromised computer.
  4. Tries to lower security settings by deleting certain files relating to antivirus software.