Serious Virus warning!

Thread Tools
 
Search this Thread
 
Old Jul 25, 2001 | 12:33 PM
  #1  
Cowlady's Avatar
Thread Starter
|
Senior Member
Joined: Aug 2000
Posts: 336
Likes: 0
From: Buffalo, NY US
Serious Virus warning!

In the last 12 hours I have received the same infected email twice! The subject line was "LondonAirportAnnouncements" & it has a download too. I'd gotten a warning just a few hours before receiving the first virus so I didn't open it.
For more complete info, you can check www.mcafee.com or your own anti virus site. It's called the Sir32 or something like that.
For the record I did NOT receive it from anyone here or any other Ford site but I wanted to warn my friends (that would be YOU!) so you don't accidentally get infected. Good luck & be careful!
 
Reply
Old Jul 25, 2001 | 01:00 PM
  #2  
FleasF-150eatshondas's Avatar
Senior Member
Joined: Mar 2001
Posts: 742
Likes: 1
From: Kingsport, TN
Thanks cowlady!

-Flea
 
Reply
Old Jul 25, 2001 | 01:12 PM
  #3  
swampview's Avatar
Senior Member
Joined: Mar 2001
Posts: 351
Likes: 0
From: Hummelstown, PA
Talking

Many thanks Cowlady . . . !
 
Reply
Old Jul 25, 2001 | 01:21 PM
  #4  
Cowlady's Avatar
Thread Starter
|
Senior Member
Joined: Aug 2000
Posts: 336
Likes: 0
From: Buffalo, NY US
My pleasure!

I'm always happy to help out my friends! Glad I could pass this along in time!
Swampview - email me ok? I wanted to ask you about where you're from in PA. My address is Cowlady18@cs.com.
Talk to you soon & bye!
 
Reply
Old Jul 25, 2001 | 01:46 PM
  #5  
Dreamin's Avatar
Member
Joined: Jul 2001
Posts: 48
Likes: 0
From: NW Wisconsin
Thanks! I notified our administrator here at work so they could send out a warning for this.

There is always someone here who gets nailed by these viruses!
 
Reply
Old Jul 25, 2001 | 02:25 PM
  #6  
murfster's Avatar
Senior Member
Joined: Feb 2001
Posts: 249
Likes: 0
From: Henry County, GA
2 of 'em

There are actually 2 fairly nasty worm viruses going around: W32.Sircam.Worm@mm and CodeRed. We had one user get an email with the virus, but our corporate NAV edition, caught it, quarentined and deleted.

Excellent information at http://www.symantec.com on these 2 buggers.

...now onto a real threat...West Nile Virus being distributed by mosquitoes. We had a confirmed case in the metro Atlanta area (an infected bird). More info: http://www.accessatlanta.com/health/...tnile_faq.html
 
Reply
Old Jul 25, 2001 | 04:44 PM
  #7  
Dennis's Avatar
Senior Member
Joined: Feb 1999
Posts: 2,233
Likes: 0
Thank you for your diligence, Cowlady! You are a sweetheart for always thinking about us.

Just to let others know, I subscribed to McAfee.com's web based virus scan program several weeks ago -- VirusScan Online ActiveShield. Purchased and downloaded from the McAfee site.

So far, it's been working great. Since I have a dsl line and my computer is always on, I have it setup to update daily at a certain time. When I first sit at the computer, I force it to check for an update just to be sure there aren't any late updates.

It even automatically upgrades itself. All I have to do is tell it to reboot my computer and I have the latest version of the software.

I'm not sure if this is better or worse than the previously used Backweb updating.

BTW, the first time I bought it, the program was a bit flakey. The problems were cleared up after 2 or 3 program updates. The only thing wrong with this service is the support. Support really sucks unless you want to pay through the nose for it.
 
Reply

Trending Topics

Old Jul 25, 2001 | 06:10 PM
  #8  
Andthensometoo's Avatar
Senior Member
Joined: Jun 1999
Posts: 692
Likes: 0
From: Michigan Rocks and then some too!!!
On this page is a list of Free Virus Help sites
 
Reply
Old Jul 25, 2001 | 06:17 PM
  #9  
Don C's Avatar
Senior Member
Joined: Nov 1999
Posts: 1,751
Likes: 0
From: Waltham Ma.
Hi Cowlady
Thanks for the 411, what would we do around here with out you.

I did hear about it the other day, but you can't be to carefull.
 
Reply
Old Jul 25, 2001 | 07:40 PM
  #10  
lightningcrashz's Avatar
Senior Member
Joined: May 2000
Posts: 1,007
Likes: 0
From: liquid sunshine state (oregon)
yep its a nasty one

I read that one of the worm viruses took one of the mustang boards out of commission.Pretty scary stuff......a person just has to be carefull nowadays
 
Reply
Old Jul 26, 2001 | 08:06 PM
  #11  
Andthensometoo's Avatar
Senior Member
Joined: Jun 1999
Posts: 692
Likes: 0
From: Michigan Rocks and then some too!!!
Well don't I just feel special now?
I got one too, but my email proggy only displays everything in ascii so I had to read the codes to figure out which virus it was.
Mine (with IDying header removed) started out like:

Subject: MOM
date: Thu, 26 Jul 2001 17:30:26 -0700
MIME-Version: 1.0
X-MIMEOLE: Produced By Microsoft MimeOLE V5.50.4133.2400
X-Mailer: Microsoft Outlook Express 5.50.4133.2400
Content-Type: multipart/mixed; boundary="----749891FC_Outlook_Express_message_boundary"
Content-Disposition: Multipart message
Message-ID: <auto-000016529369@dc-mx04.cluster1.charter.net>
X-UIDL: 1DV!!!l~"!eh(!![Nh!!
Status: RO

------749891FC_Outlook_Express_message_boundary
Content-Type: text/plain; charset=ISO-8859-1
Content-Transfer-Encoding: quoted-printable
Content-Disposition: message text

Hi! How are you

I send you this file in order to have your advice

See you later Thanks

------749891FC_Outlook_Express_message_boundary
Content-Type: application/mixed; name=MOM.doc.lnk
Content-Transfer-Encoding: base64
Content-Disposition: attachment; filename=MOM.doc.lnk

TVpQAAIAAAAEAA8A//8AALgAAAAAAAAAQAAaAAAAAAAAAAAAAAAA
AAAAAAAAAAAAAAAAAAAAAAAAAAAAAAEAALoQAA4ftAnNIbgBTM 0h
kJBUaGlzIHByb2dyYW0gbXVzdCBiZSBydW4gdW5kZXIgV2luMz INC
iQ3AAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAA A
AAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAA A
AAAAAAAAAAAAAAAAAAAAAAAAAAAAA

and on and on for about 120 kb.
It appearently changes the subject when it sends itself out to everyone in a address book, but the file name will be the same as the subject name and it will say it is a ".doc.ink" making one think it is a document, but really it is a ".ink" file, an extension that you might not see unless you have windows configured to display all extensions.
Just another reason not to use outlook, like this poor guy did.
 
Reply
Old Jul 27, 2001 | 07:22 PM
  #12  
Cowlady's Avatar
Thread Starter
|
Senior Member
Joined: Aug 2000
Posts: 336
Likes: 0
From: Buffalo, NY US
Well, I got it again w/a new subject line!

As ATST said it is sending itself out OVER & OVER! I just posted a new warning about this. DON'T let me meet the moron who wrote this thing!
 
Reply
Old Jul 31, 2001 | 03:43 PM
  #13  
1depd's Avatar
Senior Member
20 Year Member
Joined: Apr 2001
Posts: 691
Likes: 1
From: Gulf Coast
Cowlady, I'd have to disagree. I want to meet them, that way they can die a slow painful death, or at least enjoy a little torture.
 
Reply
Old Sep 19, 2001 | 03:41 AM
  #14  
F150Europe's Avatar
Senior Member
Joined: Jul 1999
Posts: 558
Likes: 0
From: The Netherlands
Post New Virus

FYI

------------------------------------------------------------
** VIRUS ALERT - W32/Nimda@MM **
------------------------------------------------------------

McAfee.com has seen a large and growing number of systems
infected with the W32/Nimda@MM. This is a HIGH RISK virus
that is spread via email. W32/Nimda@MM also spreads via open
shares, the Microsoft Web Folder Transversal vulnerability
(also used by W32/CodeBlue), and a Microsoft content-type
spoofing vulnerability.

The email attachment name VARIES and may use the icon for an
Internet Explorer HTML document.

It will also attempt to spread itself as follows:

- The email messages created by the worm include content
that allows the worm to execute the attachment even if
the user does not open it.
- It modifies HTML documents, so that when this infected
window is accessed (locally or remotely), the machine
viewing the page is then infected.

Once infected, your system is used to seek out others to
infect over the Web.
 
Reply
Old Sep 19, 2001 | 08:01 AM
  #15  
Andthensometoo's Avatar
Senior Member
Joined: Jun 1999
Posts: 692
Likes: 0
From: Michigan Rocks and then some too!!!
- The email messages created by the worm include content that allows the worm to execute the attachment even if
the user does not open it.
- It modifies HTML documents, so that when this infected
window is accessed (locally or remotely), the machine
viewing the page is then infected.
That is exactly why I don't use outlook and use JBmail instead which makes me impossible to infect via email.
I also have "File sharing" and "windows scripting host" disabled, and "Show all extensions" enabled.
 
Reply




All times are GMT -4. The time now is 09:05 AM.