WTF?

QuarterToThree Message Boards: Free for all: WTF?
Top of pagePrevious messageNext messageBottom of pageLink to this message  By Bruce_Geryk (Bruce) on Monday, July 23, 2001 - 09:15 pm:

For the past two or three days, I've been getting tons (1-2 per day) of emails with attached files, with some idiotic message like, "Hi, I've attached this file to get you advice!" or something. Has anyone else received anything similar? I assume it's the latest virus thing. Of course, I delete them on sight, but I'm curious as to what horrible things would happen if I ran the attached .bat file.


Top of pagePrevious messageNext messageBottom of pageLink to this message  By timelhajj on Monday, July 23, 2001 - 10:13 pm:

Yeah, sure sounds like you're being targeted by a virus. Next time you get one, drop the .bat file in a text editor and see what commands it intends to run.


Top of pagePrevious messageNext messageBottom of pageLink to this message  By Aszurom on Monday, July 23, 2001 - 10:26 pm:

OH YES. I'm getting these too.

so is Lumthemad... in fact he's traced it back to Funcom.


Top of pagePrevious messageNext messageBottom of pageLink to this message  By Bub (Bub) on Monday, July 23, 2001 - 11:33 pm:

I think anyone who has a website address is getting them Bruce. I'm getting them mainly through my two (old) Sharky addresses and also from Gamepen.

Blue had something up about it earlier. It seems to check clean on a virus sweep... but I'm not opening it. Interestingly I'm starting to get them in Spanish now.

-Andrew


Top of pagePrevious messageNext messageBottom of pageLink to this message  By David E. Hunt (Davidcpa) on Tuesday, July 24, 2001 - 12:36 am:

www.tomshardware.com has a news item on this virus. It comes in English and Spanish. It is supposed to be harmful. Definiately a do not open situation. See link:

Tom's news item

-DavidCPA


Top of pagePrevious messageNext messageBottom of pageLink to this message  By Jason_cross (Jason_cross) on Tuesday, July 24, 2001 - 02:31 am:

It's the latest worm. Pretty neat stuff, if TOTALLY annoying. I've gotten like 50 of these things.

It copies an executable to your system folder AND your recycle bin (since many virus scanners don't, by default, scan there...DUH). And it registers itself as the default to lauch executables with. So you run a program, and this worm will also launch.

It picks a .jpg, .zip, or .doc at random from your My Documents folder and mails it to people from your Address Book using it's own SMTP protocol.

Virus scanners can detect it (even the free web ones), but nobody's running it.

Over the weekend, it quickly jumped to the #1 most prolific virus in virutally every continent except Africa, where South Africans with the Love Bug virus totally dominate. Seriously.


Top of pagePrevious messageNext messageBottom of pageLink to this message  By Chet on Tuesday, July 24, 2001 - 01:56 pm:

Virus scanners can - but some like Norton's don't or at least didn't. When you get an email with an attachment from someone you are used to getting such emails from - its pretty easy to screw yourself. I did. I was running norton's and it did nothing. I cleaned my system by hand and now run AVP which always seems to update their profiles quicker.

I am surprised more admins aren't blocking this. At evilemail we scan for this now and just delete any email with the phrases in it. It is pretty trivial to do from a system admin standpoint. We already notified all our users so if someone was sending them an altert with the phrases in it - we have them covered.

Chet


Top of pagePrevious messageNext messageBottom of pageLink to this message  By Bub (Bub) on Tuesday, July 24, 2001 - 03:18 pm:

"Virus scanners can - but some like Norton's don't or at least didn't."

So, wait, I've gotten scores of these and I've never opened one. I delete them by hand. I've also come clean after several Norton virus checks. Am I clean? I even spot checked the System file like Jason mentions above.

-Andrew


Top of pagePrevious messageNext messageBottom of pageLink to this message  By Chet on Tuesday, July 24, 2001 - 04:55 pm:

http://www.centralcommand.com/ts/00D709001aet/antisircam.exe

Run it and it will tell you.


Top of pagePrevious messageNext messageBottom of pageLink to this message  By Aszurom on Tuesday, July 24, 2001 - 06:24 pm:

Thanks for the link, Chet.

Symantec's description of the bugger was pretty vague in that it didn't indicate if the thing triggered on viewing the email or only if you clicked an attachment. As a rule, only image or zipped attachments get clicked by me, hehe.

Now, if someone could figure out how to embed a virus in a .jpg... scary.


Top of pagePrevious messageNext messageBottom of pageLink to this message  By Rob Funk (Xaroc) on Tuesday, July 24, 2001 - 09:42 pm:

www.grisoft.com

AVG is free and picks it up. One of my wife's friends is infected and has been spamming her with these messages as well.


Top of pagePrevious messageNext messageBottom of pageLink to this message  By Chet on Wednesday, July 25, 2001 - 12:03 am:

The other thing to watch on this one. I have 3 windows machines at home. Once one got infected, it went out and infected the others. It does not seem to be able to infect NT machines.

Chet


Top of pagePrevious messageNext messageBottom of pageLink to this message  By Aszurom on Wednesday, July 25, 2001 - 05:00 am:

Somebody needs to write a virus that, once infected, causes the computer to randomly pop up a dialog box with the question mark icon on it that asks "Why does it hurt when I pee?"


Top of pagePrevious messageNext messageBottom of pageLink to this message  By Michael Murphy (Murph) on Wednesday, July 25, 2001 - 05:21 am:

Were you dropped on your head as a child?


Top of pagePrevious messageNext messageBottom of pageLink to this message  By Chet on Wednesday, July 25, 2001 - 11:13 am:

For the Amiga there was a virus that did nothing but flip your display upside down every so often. They named it the Australian virus. I thought that was slightly funny when I got it.

Chet


Add a Message


This is a public posting area. If you do not have an account, enter your full name into the "Username" box and leave the "Password" box empty. Your e-mail address is optional.
Username:  
Password:
E-mail:
Post as "Anonymous"