Beware New Virus

Kick Back and Relax in the Cheers! Forum. Thoughts on life or want advice or thoughts from other pca members. Or just plain "chill". Originator of da Babe threads.
Post Reply
blade
Posts: 9113
Joined: Wed Nov 22, 2000 1:56 am
Location: LV-426
Contact:

Beware New Virus

Post by blade »

Some dumb shit sent me a 4.18 meg file so I had to forward it to another free web email, since I can't receive large files on my dial up. I figured it was just another on cable who assumes everyone has cable.

But it's a virus. Others have received similar so you all need to be warned.

Here is the email:

Adam Cohen "acohen1@speakeasy.net"

Hi! How are you?

I send you this file in order to have your advice

See you later. Thanks

the attachement read: Clad20FULL.zip

here's the virus results using yahoo's online norton virus scan:

Virus W32.Sircam.Worm@mm found. File NOT cleaned.
This file contains a computer worm, a program that spreads very quickly over the Internet to many computers and can delete files, steal sensitive information, or render your machine unusable.

This attachment has a virus that may infect your computer. It cannot be cleaned.
We recommend that you DO NOT download this attachment.
User avatar
sbp
Posts: 3785
Joined: Wed Nov 22, 2000 2:36 am
Contact:

Post by sbp »

Instructions on how to remove this virus: http://www.symantec.com/avcenter/venc/d ... rm@mm.html


<A href="http://www.zdnet.com/zdnn/stories/news/ ... 23,00.html" target="_new' title=" 'Network-aware' virus on the loose"><b>'Network-aware' virus on the loose</b></a>

"A new virus that has the capability of attacking any machine attached to an infected network is on the loose.

Known as the Sircam.A virus, it is part of a new class of viruses dubbed "network-aware" for their ability to check for shared or mapped drives, and then spread themselves to other networked machines.

Anti-virus vendor Symantec Corp. said it had received more than 40 reports of infections from corporate customers as of 4:30 p.m. EDT Thursday.

The virus, first spotted on Wednesday, has already risen to the number three spot on Trend Micro Inc.'s list of the top 10 virus threats.

In addition to searching for other networked PCs, Sircam also sends copies of itself to every address in a user's Microsoft Outlook mailbox, a behavior that by now is all too familiar to network administrators. It arrives in a user's inbox with a random subject line and an attachment with the same name as the subject line, according to Trend Micro.

Officials at McAfee.com Inc., another anti-virus company, said they had also observed the Trojan hiding itself in the recycle bin on users' desktops, a place where most anti-virus software packages don't look during their scans.

The e-mail may also arrive in Spanish, and McAfee officials said they believe it originated in South America."
blade
Posts: 9113
Joined: Wed Nov 22, 2000 1:56 am
Location: LV-426
Contact:

Post by blade »

Just received another to a different email, that tells me this person is watching here. From the same name and email but this times it's a 2.66 meg file called Baldur2faq.doc.com

You don't open these files you'll have no problems. Just delete delete.
NascarFool
Posts: 3263
Joined: Thu Nov 23, 2000 1:21 pm

Post by NascarFool »

Originally posted by blade
Just delete delete. [/B]

Uhoh, it's the dreaded double delete. LOL
User avatar
FlyingPenguin
Flightless Bird
Posts: 32784
Joined: Wed Nov 22, 2000 11:13 am
Location: Central Florida
Contact:

Post by FlyingPenguin »

Just got my 1st one!
Christians warn us about the anti-christ for 2,000 years, and when he shows up, they buy a bible from him.

Image
JonasWorld
Genuine Member
Posts: 69
Joined: Mon Feb 05, 2001 8:44 pm
Location: Philly Suburbanite

Thanks for the warning!!!

Post by JonasWorld »

I just recieved the "I send you this file in order to have your advice" to my hot hotmail inbox. I recieved it from lisapsu @ home . com

I thought it was weird that the sender's adress has PSU in it since I go to Penn State however I don't recognize it from anyone I know. And it is not an oficial PSU adress.

Thanks again for the heads up. I probably wouldn't have opened without knowing the adress anyway but now I can warned my Dad.
AMD XP1800
Soyo SY-K7V Dragon+
VisionTek GeForce 4 TI4600
Onboard Audio
Onboard NIC
TDK 52X Burner
Aopen 16X DVD
512mb Crucial 2100
NEC MultiSync FE950+
Generic Aluminum Colored case with modded side fan
Slugbait
Golden Member
Posts: 1109
Joined: Thu Nov 23, 2000 11:48 am
Contact:

Post by Slugbait »

"I send you this file..." (present tense, should be past tense)
"...to have your advice" (incorrect use of a participle)

Oh, for Christ's sake, why can't people figure out that the most heinous virii are spread by email of which contains text that does not conform to standardized English? It's just as obvious as the bogus virus warning email that starts out in all caps, "Warning...don't open this email!"

Trust me...if the body of the mail reads as if it were translated from Japanese, and it's not from a moron you regularly receive mail from, just assume it's a virus or a trojan or a worm.
User avatar
Phjorg
Golden Member
Posts: 577
Joined: Fri Nov 24, 2000 11:24 am
Location: Edmonton

Post by Phjorg »

interesting... I've been using my hotmail for over 2 years now and using email for over 5 and today i just had my first email virus sent to me to my hotmail account! not only that, an hour later i got another one!!! Both from the same person, but different messages.. (never checked the attachments, but they both end in .com) crazy....
<FONT COLOR="#888888">I AM</FONT> Canadian!!
User avatar
Zyph
Golden Member
Posts: 1036
Joined: Tue Mar 27, 2001 6:50 pm
Location: Pittsburgh, PA, USA
Contact:

Post by Zyph »

Well, the part of the e-mail message that is not correct english is because it originally was in Spanish, so it's translated. (If you go to Norton/Symantec's webpage, it shows both the english and spanish versions....still wierd.)
User avatar
wvjohn
Posts: 9238
Joined: Wed Nov 22, 2000 7:09 am
Contact:

Post by wvjohn »

it's still going around - i got 3 this morning
<a href="http://www.heatware.com/eval.php?id=123" target="_blank" >Heatware</a>
JonasWorld
Genuine Member
Posts: 69
Joined: Mon Feb 05, 2001 8:44 pm
Location: Philly Suburbanite

That makes two!

Post by JonasWorld »

Chalk another one up for as well.
AMD XP1800
Soyo SY-K7V Dragon+
VisionTek GeForce 4 TI4600
Onboard Audio
Onboard NIC
TDK 52X Burner
Aopen 16X DVD
512mb Crucial 2100
NEC MultiSync FE950+
Generic Aluminum Colored case with modded side fan
User avatar
FlyingPenguin
Flightless Bird
Posts: 32784
Joined: Wed Nov 22, 2000 11:13 am
Location: Central Florida
Contact:

Post by FlyingPenguin »

I'm up to 20 - 5 from the same dude.
Christians warn us about the anti-christ for 2,000 years, and when he shows up, they buy a bible from him.

Image
Post Reply