View Full Version : URGENT: Virus info
Chevy454
11-23-2002, 06:27 PM
Our main computer got hit by a virus this afternoon. If you get an email from us (Chevy454, sYc, yenko) with an attachment, then DO NOT OPEN. I have already gotten about 40+ emails bounced back from ISP's with fatal errors in the addresses (and a couple of "quarantine" notices), so that means a BUNCH got through. Be extra cautious, and when in doubt, email us and ask!
L78Impala
11-24-2002, 04:09 AM
Thanks for the heads up Rob.
Bill
SuperCars
11-29-2002, 01:39 PM
Something weird is going on. I've received emails from common car names, having no text and only an attachment. Names of IraceZ28, HP454, Marlin5 (are there 4 more of you out here Marlin?), and other car names I don't remember right now. As always, I deleted them. Possibly a hacker trying to get a guy to open an attachment on the premise it must be somone you know connected with cars.
Zedder
11-29-2002, 01:54 PM
Supercars, I'm getting the same messages. I believe the virus just takes names from the infected computer's email address book and sends out the messages.
bertfam
11-29-2002, 05:37 PM
Rob and everyone interested...
Rob, you may NOT actually have a virus on your system...
Virus's have become pretty sophisticated lately. For the last year or so there have been new "smart" virus's unleashed on the public. These "smart" virus's take addresses from your Microsoft Outlook Address Book (or equivilant) and sends itself to these people. But it also takes another random email address from your address book and uses this as the "from" address. This way the real computer can't be traced and the virus can run rampant!
For instance, let's say YOUR computer is virus free. However, a friend of yours DOES have the virus. He's also got your email address in his Address Book, along with several other's. When he connects to the internet, the virus sends itself out to several of the email address's in the Address Book and takes YOUR email address and places it in the "Senders" name. Any "bounced" emails will get returned to YOU and NOT your friend, who actually has the virus!! Pretty smart huh! Also, the virus has its own "engine" (or, way to send the mail), so your internet service provider has no way of blocking it from going. They CAN block it from getting to the recipient (virus protections programs like Norton, etc...) but when they send the notice that there was a virus in the email, it goes to YOU and NOT your friend!!
How to rectify this: Unfortunately, most of these new virus's can detect when your virus program starts a scan and "hides". When the scan is done and has found "no virus's" on your computer, it reappears and starts all over again. There ARE ways of getting rid of these virus's but it takes a lot of "manual" work and the person has to know that he has a virus in the first place! Most of the time he doesn't until it's too late.
If you need more info on these new "smart" virus's, you can go to Symantec (http://www.symantec.com) and get the latest...
Ed
Chevy454
11-29-2002, 06:54 PM
I had a "Klez" variant.
I have received two "bad" emails from syc
The sender shows up as sycyenko.net, and there is nonsense in the subject title.
but there is no subject or attachments? is this the virus? /ubbthreads/images/icons/confused.gif
bertfam
12-07-2002, 01:15 AM
If you get an email from a known friend that says "xxxxxxx has sent you a card", delete it ("xxxxxxx" is the friends name). It's the "friendgreeting" (?) virus and we got it today at work, and I got it this afternoon on my home computer. This is a real good one...
You get an email from someone you probably know stating that you have a card to be picked up. Considering this is the time of year for that kind of thing, I naturally clicked on the link. It then prompts you to download a file to make the card work. Again, suspecting nothing, I opened the file. THIS is where the virus resides. Once you download the file, you now have the virus.
So, if you get this, DON'T download the program. Also, if you get this from ME (bertfam or Bertrand), kill it...
Ed
MadMike
01-05-2003, 05:12 PM
Since I'm the "iracez28" mentioned above, I'll comment:
By now, you know the virus spoofs usernames. If you CAREFULLY view the headers on an infected email, you'll notice the "from" would be me (for example) and the actual sender (reply-to) address is the actual infected person. If you casually look at the email, it's "from me" because the virus attached my email address taken from the infected users address book and stuck it there. This is what makes this virus a major PITA.
Also, you can tell an email is a virus by the attachment and/or subjet.
I can assure you that I would never send anyone an email with a subject of
"Me love you long time - GI" along with an executable attachment. If you get anything like this - delete it.
Anything that can be run: exe, bat, com, scr, etc.... don't open that at all. Regardless of who it's from.
See: http://www.nastyz28.com/ubb/Forum1/HTML/000899.html
for more info.
My mother-in-law just got a new computer and she's already on these email joke passing around things. She sent me (my wife) "Christmascard.exe". I told her we deleted it without looking at it and gave her a pep-talk. I'm sure the thing was harmless and cute, but I don't need to find out the hard way.
vBulletin® v3.8.11, Copyright ©2000-2025, vBulletin Solutions Inc.