Search the archive:
YaBB - Yet another Bulletin Board
 
   
 
Page Index Toggle Pages: 1
Send Topic Print
VIRUS ALERT (Read 803 times)
May 19th, 2003 at 6:15am

Blade   Offline
Colonel
Annapolis, MD

Gender: male
Posts: 2477
*****
 
Just recieved this email from "support@microsoft.com" subject "Screensaver". The body reads "All information is in the attached file." The attached file is named "approved.pif" at 53.6kb. Don't know about you guys but Microsoft doesn't send mail this way, and there is no hint of whats inside. My thinking is  DON'T OPEN IT! If anyone wants to check it here's the senders IP 80.230.125.224, and this is the server it was sent from mxng00.kundenserver.de. I don't think Microsoft support is in Denmark, do you?  Roll Eyes
 

...&&&&Dell 4550&&P4 2.53Ghz &&512MB DDR SDRAM&&GeForceFX 5900 129MB&&60GB HD @ 7200RPM &&PROUD TO BE AN AMERICAN
IP Logged
 
Reply #1 - May 19th, 2003 at 7:05am

WebbPA   Ex Member
I Like Flight Simulation!

*
 
I just got this in my mail this morning.  It looks awfully suspicious.  Safer is better - going back to delete it now.
 
IP Logged
 
Reply #2 - May 19th, 2003 at 7:22am

Craig.   Offline
Colonel
Birmingham

Gender: male
Posts: 18590
*****
 
thanks for the heads up
i'll make sure to keep an eye out for it.
on a side note dont your mail programs have virus checkers? i know both MSN and Yahoo have them i dont know about others though
 
IP Logged
 
Reply #3 - May 19th, 2003 at 7:56am

Maccers   Offline
Colonel
Goodbye old friend
NEWI Campus, Wrexham. UK

Gender: male
Posts: 1872
*****
 
In 99.9% of cases, its common sence that detects the viruses in your inbox.
I've never had an e-mail that was a virus and didn't know about before checking with Mcafee. Smiley
 

...&&Athlon XP 1800+, 1GB RAM, Asus V9560 FX 5600 256Mb, 40Gb HDD
IP Logged
 
Reply #4 - May 19th, 2003 at 9:48am

Craig.   Offline
Colonel
Birmingham

Gender: male
Posts: 18590
*****
 
well just recieved this one myself through yahoo, and used their virus scanner to check it and it is definatly a virus
 
IP Logged
 
Reply #5 - May 19th, 2003 at 10:56am

BFMF   Offline
Colonel
Pacific Northwest

Gender: male
Posts: 19820
*****
 
Just got an email supposedly from 'Support@microsoft.com' subject 'Re:Movie'.

interestingly enough, Norton did not pick it up. I probably better update it.

Anyhow, microsoft support never sends an e-mail to you with an attachment, let alone an e-mail without a tracking number.

flipin' morons....
 
IP Logged
 
Reply #6 - May 19th, 2003 at 2:17pm

katana_1000   Offline
Colonel
a_blesk
patomac,MD

Gender: male
Posts: 1803
*****
 
thnx 4 telling me.havent gotten that email yet but ill keep a look out.
 

......&&and yet i cant say it in the chat room:P&&&&http://airliners.net/random.inc&&&&;
IP Logged
 
Reply #7 - May 19th, 2003 at 4:08pm

SilverFox441   Offline
Colonel
Now What?
Mississauga, Ontario, Canada

Gender: male
Posts: 1467
*****
 
I've got at least 7 versions of this so far...and they have all been deleted. Wink
 

Steve (Silver Fox) Daly
&&
IP Logged
 
Reply #8 - May 19th, 2003 at 4:31pm
RollerBall   Ex Member

 
???

As I tell my support clients endlessly.

If you receive ANY email with an attachment that is one of the following file types it is an active program and should be DELETED IMMEDIATELY as it is almost certainly a virus.

.scr
.pif
.exe
.bat

The way these thing work is they plonk the prog somewhere in your Windows\System folder and place a 'Run' or 'RunOnce' entry in your registry.

Nothing happens immediately but when you reboot, the prog runs and the damage starts.

.scr is the file type for a screen saver -  but I'm pretty sure you'd get your screen savers from somewhere reputable and not just from somoeone you don't know off the Net!

SO BEWARE!!

PS Unless you've been getting regular updates for your McAfee or any other virus software your are using for that matter - like every week at most, your protection is ZILCH


BTW - this one has been doing the rounds for many weeks if not months now.
 
IP Logged
 
Reply #9 - May 19th, 2003 at 5:06pm

BFMF   Offline
Colonel
Pacific Northwest

Gender: male
Posts: 19820
*****
 
I just got 4 more e-mails!

The subject's were: "Re: My details", "Re: My application", "Your details", "Re: Approved (Ref: 3394-65467)"

I guess that proves my 'tracking number' theory wrong, even though what I got was obviously a fake one.

Even though this has been around for a while, something is causing it to be distributed more all of a sudden
 
IP Logged
 
Reply #10 - May 19th, 2003 at 5:54pm

BFMF   Offline
Colonel
Pacific Northwest

Gender: male
Posts: 19820
*****
 
I just scanned one of the e-mails and the virus is 'W32.Sobig.B@mm'.

"W32.Sobig.B@mm is a mass-mailing worm that sends itself to all the email addresses that it finds in the files with different extensions"

You can read about it here: http://securityresponse.symantec.com/avcenter/venc/data/w32.sobig.b@mm.html

 
IP Logged
 
Reply #11 - May 20th, 2003 at 6:05am

Blade   Offline
Colonel
Annapolis, MD

Gender: male
Posts: 2477
*****
 
My McAffee didn't pick it up either when I recieved it, but then I scaned it directly and it picked it up.
 

...&&&&Dell 4550&&P4 2.53Ghz &&512MB DDR SDRAM&&GeForceFX 5900 129MB&&60GB HD @ 7200RPM &&PROUD TO BE AN AMERICAN
IP Logged
 
Reply #12 - May 20th, 2003 at 7:22am

pete   Offline
Admin
'That would be a network
issue'
Cloud Cuckoo Land

Posts: 8500
*****
 
I'm getting dozens of them daily - but all picked up on the mail server by norton.

'.de' is Germany - not Denmark Smiley & yes MS have a lot of German based support services - like they do in most countries so that wouldn't be unusual.

The main thing as always - get a good anti virus! If you are running one & it's updated & doesn't pick this virus up - scrap it ! You've been had.
 

Think Global. It's the world we live in.
IP Logged
 
Reply #13 - May 20th, 2003 at 9:57am

Ivan   Offline
Colonel
No, I'm NOT Russian, I
only like Russian aircraft
The netherlands

Gender: male
Posts: 6058
*****
 
That's the price you pay for having a publicised e-mail adress...

and even if it isn't public, most family computers only get a virus scanner when at least one infection has had sevre results, leading to widespread havoc with every remailing virus
 

Russian planes: IL-76 (all standard length ones),  Tu-154 and Il-62, Tu-134 and An-24RV&&&&AI flightplans and repaints can be found here
IP Logged
 
Reply #14 - May 21st, 2003 at 12:43pm

Paul2k12   Offline
Colonel
^Powers My Comp^
Newcastle, United Kingdom

Gender: male
Posts: 195
*****
 
Thanks Everybody


I just had a look in my inbox and I had an e-mail from them with "my password"

Deleted it and just to say thanks for letting me know before hand!!

Paul2k10
 

...&&&&
IP Logged
 
Page Index Toggle Pages: 1
Send Topic Print