Search the archive:
YaBB - Yet another Bulletin Board
 
   
 
Pages: 1 
Send Topic Print
VERY IMPORTANT - VIRUS ALERT (Read 1506 times)
Aug 20th, 2003 at 4:51am
RollerBall   Ex Member

 
Here we go again.

My website is currently under attack from yet another low-life piece of sh*t by dozens of virus containing emails.

I am sure I'm not alone but as the emails contain the (forged) identities of many well and less well known names in FS it looks as though the FS community is being targetted.

SO BE WARNED ESPECIALLY IF YOU HAVE A WEBSITE OF YOUR OWN.

The idiot behind it is not very clever and is using a simple attachment method. It's easy to spot and look for the following giveaways.

- Any subject line that starts Re: Re:
- Any attachment that contains a file ending in {xyz}.bat
- Any attachment ending in {xyz}.pif
- Any attachment ending in {xyz}.scr
- Any attachment ending in {xyz).exe

(where {xyz} is a file name)

In any case you should NEVER open any such attachment even when they come from someone you APPEAR to know.

The emails have subjects like

Re: Thank you
Re: Your details
Re: Approved
Re: That Movie  and so on

ANYWAY, YOU HAVE BEEN WARNED Angry

Roger
 
IP Logged
 
Reply #1 - Aug 20th, 2003 at 4:56am

Craig.   Offline
Colonel
Birmingham

Gender: male
Posts: 18590
*****
 
yep already dealing with this one. total now upto 100 recieved.
 
IP Logged
 
Reply #2 - Aug 20th, 2003 at 5:30am

Paz   Offline
Colonel
USA

Gender: male
Posts: 1922
*****
 
  I've got about 15 of them now.
 

&&Still no linked images allowed around here Paz! Naughty...&&
IP Logged
 
Reply #3 - Aug 20th, 2003 at 6:10am

ozzy72   Offline
Global Moderator
Pretty scary huh?
Madsville

Gender: male
Posts: 37122
*****
 
I've got none! Nobody loves me Cry
 

...
There are two types of aeroplane, Spitfires and everything else that wishes it was a Spitfire!
IP Logged
 
Reply #4 - Aug 20th, 2003 at 6:19am

Professor Brensec   Offline
Colonel
Can't you give me a couple
more inches, Adam?
SYDNEY - AUSTRALIA

Gender: male
Posts: 2955
*****
 
I've been getting a number of emails with 'attachments'. I have no idea what any of them are or were, but I'm sure some must have been 'virus's.

Not on a webpage but just in my personal email.

It'll do them no good with me. I never, ever open an email that has an attachment, unless I have specifically asked for it from someone I know to be ok, and even then, I'm very careful.

I have had alot of the 'You've just been approved' ones.

Just as a point of interest, I'll be posting a business webpage shortly, where people will be emailing an order form to me. It will be through my Web host who has a SSL facility for me to use. Can someone attach or somehow 'infect' my order form with something and then send it to me so that it will look like any other form that is returned to me? If so what can I do to guard against this?

P.S. Is there any penalty if one of the morons happens to be caught. Does anyone know of a case where a 'Virus spreader' has been caught?.....What happened?
Does he still have balls...........or in the case of a woman......does she still have a ****.   Grin Wink
 

...&&...&&http://www.ra.online-plus.biz&&&&&&I cried because I had no shoes - until I saw a man who had no feet.&&&&Dell Dimension 8100 - Intel P4 1.7 Gb - 512 RD Ram - nVidia GeForce 128 mb FX5200.
IP Logged
 
Reply #5 - Aug 20th, 2003 at 7:16am
RollerBall   Ex Member

 
Quote:
I have had alot of the 'You've just been approved' ones.


Chance is these were virus-containing. There would be no need to attach anything to a genuine email confirming approval for something you had genuinely applied for

Quote:
Can someone attach or somehow 'infect' my order form with something and then send it to me so that it will look like any other form that is returned to me? If so what can I do to guard against this?


They can't infect your form because the contents of that will be generated by your software using something like Sendmail or Blat. Also, as they don't know what the output of your form looks like, they can't easily create a copy. But in any case, you know that your form doesn't have an attachment, so you'd be alerted anyway. So don't worry too much!

Quote:
Is there any penalty if one of the morons happens to be caught. Does anyone know of a case where a 'Virus spreader' has been caught?.....What happened?


The so-called Love Bug perpetrator was located at enormous effort in the Phillipines I think. He was a computer student and did receive a prison term I'm glad to say.

In view of the cost of his little effort to the World commercial and IT system I think he should have got 30 years as a deterrent to others, frankly, but it was a lot less than that.

PS

Just noticed the pic. If you need further info, send Teryl over for an in-depth one-2-one discussion about viruses, the Internet and the World Wide Web Wink

 
IP Logged
 
Reply #6 - Aug 20th, 2003 at 7:24am

deadnight   Offline
Colonel
Georgia, USA

Gender: male
Posts: 166
*****
 
I had a virus yesterday, it first succeded in disableing my norton, then it somehow took over my hotmail email. Probably through msn messenger. It was automatically sending out virused emails at random to people. I kept on getting returned emails about every 3 minutes saying the email couldn't be sent because hotmail virus scanner detected a virus on it. Hopefully none of them got through their virus scanner. It took me about 7 hours to clean the virus. Everytime I got Norton up and running it was disabled again. Then it said I had to re-install it. Gave me quite a headache.
 

ASUS P4C800 Deluxe &&Geforce FX5900 Ultra(256 MB)&&1 gig DDR PC3200 RAM&&Pentium 4, 3.0 GHZ, 800 mhz FSB&&Coolermaster 550 watt power supply&&----------------------------&&<-3dmark03 =
6535
->
IP Logged
 
Reply #7 - Aug 20th, 2003 at 7:34am

Romulus111VADT   Offline
Colonel

Gender: male
Posts: 5521
*****
 
I got hit with 23 to date. They should take these A$$holes out and shoot them live via the internet. Start off with the legs and work your way around...make them suffer for all the misery they've caused and the fact you need a full 2 gigs of darn hard drive just to hold the programs to protect your system from their warped sense of reality. Angry
 

"I have a place where dreams are born, And time is never planned. It’s not on any chart, You must find it with your heart."

Albert Einstein - "Two things are infinite: the universe and human stupidity; and I'm not sure about the universe."

Martin Luther King Jr. - “Nothing in the world is more dangerous than a sincere ignorance and conscientious stupidity.”

Johann Wolfgang von Goethe - “There is nothing worse than aggressive stupidity.”

Mark Twain - “Never argue with stupid people, they will drag you down to their level and then beat you with experience.”
IP Logged
 
Reply #8 - Aug 20th, 2003 at 7:37am

Craig.   Offline
Colonel
Birmingham

Gender: male
Posts: 18590
*****
 
well the only good news on this is it expires in two weeks or sept 10th
 
IP Logged
 
Reply #9 - Aug 20th, 2003 at 8:12am

Scottler   Offline
Colonel
Albany, New York USA

Gender: male
Posts: 5989
*****
 
I logged in this morning to find 115 emails, all seeming to be from FS related sites.  Some of the bigger ones were:

FSInflight.com
FSNavigator
Simflight

There may or may not have been a Simviation, I didn't keep them long enough to make a mental list.  lol

Many said "You're Approved", some others said "Your details" or "My Details".

Seems odd that they'd all be FS related...
 

Great edit, Bob.&&&&&&Google it. &&&&www.google.com
IP Logged
 
Reply #10 - Aug 20th, 2003 at 8:46am

Biggles   Offline
Colonel

Gender: male
Posts: 404
*****
 
Today I was hit with about 150 of them for the first time. It took me ages just to get through all the virus reports from Norton.
Just wondering, does viewing the message actually do any harm or do you have to open the attachments???

One last question, can Firewalls protect your computer from this type of bombardment???  ???
Biggles
 
IP Logged
 
Reply #11 - Aug 20th, 2003 at 8:48am

Mr. Bones   Offline
Colonel

Posts: 4304
*****
 
thanks for letting us know...but i haven't had any of them...lucky me!  Wink
 

Raw power...the J-58.&&...&&&&My Anet collection.&&
IP Logged
 
Reply #12 - Aug 20th, 2003 at 9:10am

Professor Brensec   Offline
Colonel
Can't you give me a couple
more inches, Adam?
SYDNEY - AUSTRALIA

Gender: male
Posts: 2955
*****
 
I don't know anything about these things or the protection methods, but they have a firewall at the office I work at occasionally. They had the Internet 'offline' last week, because they said the firewall was down for some reason.

So the firewall apparently does give a degree of protection otherwise they wouldn't have taken the Internet offline.

Personally, I thought that if you had the most up to date Norton, you would be safe (the program would catch it and warn you) except for the most recent virus's that weren't included in the latest updates.
Is this a fair assumption?  Grin Grin Wink
 

...&&...&&http://www.ra.online-plus.biz&&&&&&I cried because I had no shoes - until I saw a man who had no feet.&&&&Dell Dimension 8100 - Intel P4 1.7 Gb - 512 RD Ram - nVidia GeForce 128 mb FX5200.
IP Logged
 
Reply #13 - Aug 20th, 2003 at 9:10am

Craig.   Offline
Colonel
Birmingham

Gender: male
Posts: 18590
*****
 
opening the email shouldnt do any harm but its best just to delete them to avoid any slight possibility of infection. the firewall cant stop this kind of thing if you open the attachment i believe.
whats really starting to annoy me is the fact i could be missing important emails because these things are filling up my inbox and bouncing back any legit emails to the sender due to a full inbox.
i seriously hope they catch the person who did this and hang him from a high beam by his testicles using fishing wire
 
IP Logged
 
Reply #14 - Aug 20th, 2003 at 9:11am

Scottler   Offline
Colonel
Albany, New York USA

Gender: male
Posts: 5989
*****
 
Apparently the problem goes beyond the FS world...

http://news.yahoo.com/fc?tmpl=fc&cid=34&in=tech&cat=computer_viruses_and_worms
 

Great edit, Bob.&&&&&&Google it. &&&&www.google.com
IP Logged
 
Reply #15 - Aug 20th, 2003 at 9:12am

Craig.   Offline
Colonel
Birmingham

Gender: male
Posts: 18590
*****
 
hi bren i believe the firewall is used to stop people putting these things directly onto your computer. like that other virus recently which got into windows through the hole. with a firewall it stopped the virus and stopped it from working. and in general its used to stop outside lines gaining control of your computer
 
IP Logged
 
Reply #16 - Aug 20th, 2003 at 9:29am

Daz   Offline
Colonel
in the morning im making
WAFFLES!
Leeds, UK

Gender: male
Posts: 1171
*****
 
love to see them get past norton antivirus 2003 i have full faith in that program and it monitors emails and file downlaods aswell
 

AMD athlon XP2800+ @2.34ghz&&Epox 8RDA3G 400 fsb, 8x AGP&&1024MB DDR400 PC3200&&XFX 256MB FX5950 Ultra (oc 525/1.04)&&40 gig maxtor 7200rpm&&80 gig seagate baracuda 7200rpm&&
IP Logged
 
Reply #17 - Aug 20th, 2003 at 9:51am

loomex   Offline
Colonel
My 1969 Ludwig "pre-Bohnam"
with extra stuff
FAA Ident KITH

Gender: male
Posts: 1853
*****
 
this virus is taking email addresses from other places and using them. Example:
simviation has my email address...the virus finds it, uses it to send to some one else. I have gotten emails from places that say that I sent them a virus which I didnt
My email is web based (yahoo)
 

Windows 7 Home Premium (x64) ,2.70 gigahertz AMD Phenom II X6 1045T(6-core), two HD (1TB and 500GB), 8gb RAM, ATI Radeon HD 5570,
IP Logged
 
Reply #18 - Aug 20th, 2003 at 9:51am
RollerBall   Ex Member

 
No, firewalls don't stop viruses. They are there to stop hackers getting direct access to your network (or PC) while it's connected direct to the Internet - very common now that people have DSL, Broadband and stuff via cable, PST line, satellite.

So a firewall won't protect you from a virus. Neither will a virus prog if it's not being regularly updated - like every 1-2 days!!

I got nearly 6 days work from a client who was running a well-known corporate AV prog (in the UK) and was hit twice in succession a few days apart by 2 separate viruses. The supplier said that it was bad luck because the viruses had hit before the scheduled updates had been issued!

Don't forget that AV progs are not 'catch-alls' - they are virus specific. It's no good relying on the McAfee virus scan prog that came free with your version of Windoes 4 years ago - it's now worse than useless because it gives you a false sense of security.

If you need a PROPER free AV prog note the following.

Go to www.grisoft.com

Download their FREE single user prog. It works - REALLY WELL to professional standard - and you get FREE updates. Stuff Norton!
 
IP Logged
 
Reply #19 - Aug 20th, 2003 at 9:53am

deadnight   Offline
Colonel
Georgia, USA

Gender: male
Posts: 166
*****
 
Quote:
love to see them get past norton antivirus 2003 i have full faith in that program and it monitors emails and file downlaods aswell



I have that same program.. A virus I had which I told about earlier in this thread disabled it completly. I had to reinstall it about 10 times before I could get it to clean out the virus. took an entire day almost.
 

ASUS P4C800 Deluxe &&Geforce FX5900 Ultra(256 MB)&&1 gig DDR PC3200 RAM&&Pentium 4, 3.0 GHZ, 800 mhz FSB&&Coolermaster 550 watt power supply&&----------------------------&&<-3dmark03 =
6535
->
IP Logged
 
Reply #20 - Aug 20th, 2003 at 9:57am
RollerBall   Ex Member

 
It's common for viruses to be progd to attack AV software now.

The best form of defence is USE YOUR EYES AND COMMONSENSE

Most common viruses come in via email attachments. In my opening post I told how to avoid opening attachments that will put a virus on your system
 
IP Logged
 
Reply #21 - Aug 20th, 2003 at 10:00am

Scottler   Offline
Colonel
Albany, New York USA

Gender: male
Posts: 5989
*****
 
Another good tip, which I can't even believe people still need to be told, is this:

NEVER, under any circumstances, open an email attachment if you're not sure what it is.  (And never open it if it's an .exe file even if you DO know!)

Unfortunately, you can't rely on the "as long as you know the sender" rule anymore, as today's problem has illustrated.

The best thing to do is this.  If you get an attachment from someone you know, ask them what it is before you open it. 

This won't stop EVERYTHING, but it will stop some of the viruses from spreading.

Common sense.  Nothing is really as safe as we'd like to think it is when it comes to the internet...
 

Great edit, Bob.&&&&&&Google it. &&&&www.google.com
IP Logged
 
Reply #22 - Aug 20th, 2003 at 10:31am

Lethal.Ambition   Offline
Colonel
They call me John.
Florida

Gender: male
Posts: 1563
*****
 
My virus DATS are one day old. Apparently no updates yet. No matter, I don't open attachments unless I asked for them...the firewall does help if the trojan wants to connect to the internet and youdon;t even know what the program is. I once got a pictures EXE from a friend. It was supposed to extract the pictures with the exe, kind of what winzip does, and my firewall goes nuts telling me it wants to connect to the internet. As you may know, I blocked it forever!!!!!!!Mua ha ha ha!

Grin Grin Grin Grin Grin
 

Oderint Dum Metuant - Let them hate as long as they fear.&&Proud member of the =XE= Xtreme Eagles&&Oderint Dum Metuant&&
IP Logged
 
Reply #23 - Aug 20th, 2003 at 10:38am

Ivan   Offline
Colonel
No, I'm NOT Russian, I
only like Russian aircraft
The netherlands

Gender: male
Posts: 6058
*****
 
Wensday(sp) McAfee update day

They have W32.Sobig and W32.Nahi on respectively high and medium alert status
 

Russian planes: IL-76 (all standard length ones),  Tu-154 and Il-62, Tu-134 and An-24RV&&&&AI flightplans and repaints can be found here
IP Logged
 
Reply #24 - Aug 20th, 2003 at 10:48am

Lethal.Ambition   Offline
Colonel
They call me John.
Florida

Gender: male
Posts: 1563
*****
 
God you have got to be joking me!!.....

I have like 10 e-mails. One from SimMarket....and a link to download some sort of receipt....except the file ends in .php It is called ticket create.php....OMG Like I got something from simMarket....and the others saying that my e-mail was not sent to download the attacthement for original mail. Funny thing is it said an e-mail I sent to someone with Earthlink, and no one I know is with Earthlink..........I am not complaining, but how stupid could these people be? I mean..come on!

Oh oh, and another one from Frank from Gateway!!! OMG I am luaghing so damn hard.

Quote:
Please be aware that a response is required within 1 day(s) to prevent your messages from being automatically deleted.


I will rush right over to your link sending me to some other site....NOT

And this one which caught my eye:

Quote:
your computer is sending me the w32.sobig.f virus repeatedly


Anyone in these here forums, do not download any of my attachments because they are simply not mine. Thanks.
 

Oderint Dum Metuant - Let them hate as long as they fear.&&Proud member of the =XE= Xtreme Eagles&&Oderint Dum Metuant&&
IP Logged
 
Reply #25 - Aug 20th, 2003 at 10:57am

Lethal.Ambition   Offline
Colonel
They call me John.
Florida

Gender: male
Posts: 1563
*****
 
And I did just downloaded the latest DAT files. And the installer says I already have the latest. So I am safe

PS: I am still laughing
 

Oderint Dum Metuant - Let them hate as long as they fear.&&Proud member of the =XE= Xtreme Eagles&&Oderint Dum Metuant&&
IP Logged
 
Reply #26 - Aug 20th, 2003 at 11:16am
RollerBall   Ex Member

 
Angry

Be nice if we could find who's behind it and send some of the Boys from Simviation round to his place for a chat.......


BTW - do you need virus detectors where the sun doesn't shine?

(another quaint British expression!)
 
IP Logged
 
Reply #27 - Aug 20th, 2003 at 12:04pm

DanielF   Offline
Colonel
Virigina, USA

Gender: male
Posts: 507
*****
 
I've recieved over 100 of these since yesterday.  Undecided  I'm getting about 1 every 5 minutes.  And like everyone else, I'm getting a lot from FS sites; flightsim.com, flight1.com, simmarket.com, simflight.com.  Luckily nothing from simviation yet.

Quote:
as long as you know the sender rule...

Maybe a good rule is that you know the sender and you know exactly what and when he or she is sending it.


Would deleting my addresses in my address book help prevent this from spreading?
 

...&&FS Evolution&&&&DanielF
IP Logged
 
Reply #28 - Aug 20th, 2003 at 12:07pm

Blade   Offline
Colonel
Annapolis, MD

Gender: male
Posts: 2477
*****
 
Well now that I've seen this I'm happy my Dad's company is based here at home, our LAN has some of the best civilian antivirus software in the world, but still he's already received 7 Sobig.F emails this morning.  Angry
 

...&&&&Dell 4550&&P4 2.53Ghz &&512MB DDR SDRAM&&GeForceFX 5900 129MB&&60GB HD @ 7200RPM &&PROUD TO BE AN AMERICAN
IP Logged
 
Reply #29 - Aug 20th, 2003 at 12:10pm

Scottler   Offline
Colonel
Albany, New York USA

Gender: male
Posts: 5989
*****
 
Quote:
Maybe a good rule is that you know the sender and you know exactly what and when he or she is sending it.


This is what happens when you only quote someone partially.

What I said was:

Quote:
Unfortunately, you can't rely on the "as long as you know the sender" rule anymore, as today's problem has illustrated.


I then went on to say:

Quote:
The best thing to do is this.  If you get an attachment from someone you know, ask them what it is before you open it.



It's pretty much just getting redundant now.  lol


 

Great edit, Bob.&&&&&&Google it. &&&&www.google.com
IP Logged
 
Reply #30 - Aug 20th, 2003 at 12:19pm

deadnight   Offline
Colonel
Georgia, USA

Gender: male
Posts: 166
*****
 
The wierd thing about the virus I got is that I don't know how I got it. I've never had one before and I know all the rules and safety procedures to protect against getting one. The entire day yesterday my email was empty.  I have a really strong firewall so I dont think anybody could have hacked into my computer and dumped it. About 10 minutes before norton detected a virus I had downloaded about 50 files from project ai. I doubt any of that would have been infected though.

Im at a loss as to how I got it.
 

ASUS P4C800 Deluxe &&Geforce FX5900 Ultra(256 MB)&&1 gig DDR PC3200 RAM&&Pentium 4, 3.0 GHZ, 800 mhz FSB&&Coolermaster 550 watt power supply&&----------------------------&&<-3dmark03 =
6535
->
IP Logged
 
Reply #31 - Aug 20th, 2003 at 12:26pm

DanielF   Offline
Colonel
Virigina, USA

Gender: male
Posts: 507
*****
 
Quote:
This is what happens when you only quote someone partially.


Sorry, I didn't really mean that to be a quote from you.  It was supposed to be a general quote that anyone could have said, just to bring up the subject. (notice it doesn't say your name and date there Wink)  And as for what you went on to say, I just misunderstood it.  Embarrassed lol sry
 

...&&FS Evolution&&&&DanielF
IP Logged
 
Reply #32 - Aug 20th, 2003 at 12:48pm

Scottler   Offline
Colonel
Albany, New York USA

Gender: male
Posts: 5989
*****
 
lol it's cool Daniel...it was said with a comic tone.  Unfortunately, in text a lot of meaning is lost just in the person's tone and inflections...

No worries dude... Grin
 

Great edit, Bob.&&&&&&Google it. &&&&www.google.com
IP Logged
 
Reply #33 - Aug 20th, 2003 at 2:21pm

BFMF   Offline
Colonel
Pacific Northwest

Gender: male
Posts: 19820
*****
 
This is Pi$$ing me off! Angry Angry

Opened up my e-mail to find 150 new messages, all infected with that damn virus

Andrew Angry
 
IP Logged
 
Reply #34 - Aug 20th, 2003 at 2:32pm

WebbPA   Ex Member
I Like Flight Simulation!

*
 
Last night I was convinced I had it.  Now I'm convinced I never did have it.

I got about 100 emails last night and who knows how many this morning - I had to just empty the entire inbox.

I ran every scan/fix/search possible and couldn't find anything, so there was nothing to fix.  About 4 hours ago all the emails stopped.

Get one of the fixes and if it says you aren't infected you probably aren't.  You're just getting mail from people who are.

 
IP Logged
 
Reply #35 - Aug 20th, 2003 at 4:28pm

DanielF   Offline
Colonel
Virigina, USA

Gender: male
Posts: 507
*****
 
I haven't recieved one since about 11 this morning.  Maybe it came to an early end?  Grin
 

...&&FS Evolution&&&&DanielF
IP Logged
 
Reply #36 - Aug 20th, 2003 at 4:32pm

Craig.   Offline
Colonel
Birmingham

Gender: male
Posts: 18590
*****
 
someone def must have found a way to slow it down or stop it thank god
 
IP Logged
 
Reply #37 - Aug 20th, 2003 at 4:38pm

Iroquois   Offline
Colonel
Happy Halloween
Ontario Canada

Gender: male
Posts: 3244
*****
 
I haven't see this yet but I'm taking my Email down from the web to stop it. I programed Outlook to delete any such messages from the server before they get to me.

Something really needs to be done about these people. I think it's really sad that the only thing they have to do in their pathetic lives is to destroy other peoples hard earned property. Let me think about this, well the normal prison term is about 2 years less a day for vandalism. Now multiply that by about 50,000 charges, that's 100,000 years of prison. I think that's an apropriate sentance.  Grin
Imagine the little nerd creating these viruses being sodomized by his cell mate, a 300lb gay guy named Buba for the rest of his life.  Shocked
 

I only pretend to know what I'm talking about. Heck, that's what lawyers, car mechanics, and IT professionals do everyday. Wink&&The Rig: &&AMD Athlon XP2000+ Palomino, ECS K7S5A 3.1, 1GB PC2700 DDR, Geforce FX5200 128mb, SB Live Platinum, 16xDVD, 16x10x40x CDRW, 40/60gb 7200rpm HDD, 325w Power, Windows XP Home SP1, Directx 9.0c with 66.81 Beta gfx drivers
IP Logged
 
Reply #38 - Aug 20th, 2003 at 5:00pm
RollerBall   Ex Member

 
Yeah, looks as though the worst of the 'virus storm' is over. How dya do?

I'm pretty sure 1 or 2 of us will have ben affected but hopefully most will have got off pretty much scott free.

Talking about dealing with these pathetic sh*ts, maybe they'll do that themselves.

Everyone (if they have any sense at all) has got some kind of AV software now - if not why not, it's free (see my earlier post). And most of us just laughed when we saw what was happening.

So perhaps that's it. There ain't no NEW viruses coming along (as far as I know) - they're just variations on tired old themes. So pretty soon there will just be no point in wasting your time doing it.

Maybe I'm wrong and there always will be enough of these little jerks around (you know the kind - like to break up bus stop shelters and kick litter bins across the road) but only time will tell.

But let's hope if the 'authorities' are able to get their hands on a few of them the punishment WILL fit the crime.

BTW

Here's something else you might want to try. I'm using a free prog called Frontgate. It's really an anti-spam prog that works in the background and 'learns' what to put thru to you and what to delete from your ISP's server even before it gets to you.

I've got it working in 'visible' mode while it's learning my preferences so I could see all of these virus containing emails ON MY ISP's SERVER and delete them even before they got to me.

Take a look at it!
 
IP Logged
 
Reply #39 - Aug 20th, 2003 at 5:05pm

Craig.   Offline
Colonel
Birmingham

Gender: male
Posts: 18590
*****
 
i'll have to check it out thanks for the info. as for this virus i received 245 emails in total with it, never opened one as its sensible practise like so many have said not to download anything from people you dont know.
i just wish i had a chance to go face to face with some of these creators. they would know what hit em thats for sure.
 
IP Logged
 
Reply #40 - Aug 20th, 2003 at 5:16pm

Deputy   Offline
Colonel
Hillsboro, Oregon

Gender: male
Posts: 2090
*****
 
Guys, keep it cool. There are about 1,000 people working on this case. Several F.B.I. Computer Crime agents work on these cases. It is a felony, which means a minimum sentance of one year, and, the person who is found guilty by a court, well, they can kiss about 50 years away. Don't get too upset.

Also, beware, there are MANY more "subjects" that are infected.

Some of them are as follows (As reported to the Sheriff's Office)

Thank You
Your Application
Your Requested Material
Your New Account
Your Account Details
Stop Junk Mail - Free
Nortan Anti-Virus - Free Updates (Spelling is wrong, should be Norton)
Your Account Summary
Your Results
Free Viagra

 

Bad boys, bad boys, whatcha gonna do? Whatcha gonna do when I come for you?&&&&Iustita Omnibus&&Justice for All&&&&Women are: attractive, single, mentally stable. Pick two.&&... &&Yes, we drive on the right-hand-side of the road. Yes, I parked on the left-hand-side of the road. Yes, I blocked traffic for a picture. &&&&&&
IP Logged
 
Reply #41 - Aug 20th, 2003 at 5:19pm

Craig.   Offline
Colonel
Birmingham

Gender: male
Posts: 18590
*****
 
had all those aswell, even received some from members email accounts,
although thats some good news brad
 
IP Logged
 
Reply #42 - Aug 20th, 2003 at 6:23pm

Iroquois   Offline
Colonel
Happy Halloween
Ontario Canada

Gender: male
Posts: 3244
*****
 
Great list Scupapro, I'll program these new ones into Outlook too.

We should compile a list like that for people and stick it up top in the Software forum.
 

I only pretend to know what I'm talking about. Heck, that's what lawyers, car mechanics, and IT professionals do everyday. Wink&&The Rig: &&AMD Athlon XP2000+ Palomino, ECS K7S5A 3.1, 1GB PC2700 DDR, Geforce FX5200 128mb, SB Live Platinum, 16xDVD, 16x10x40x CDRW, 40/60gb 7200rpm HDD, 325w Power, Windows XP Home SP1, Directx 9.0c with 66.81 Beta gfx drivers
IP Logged
 
Reply #43 - Aug 20th, 2003 at 6:58pm

wolf8218   Offline
Colonel
No Escape.... Consider
Yourself Screwed
Houston, Texas

Gender: male
Posts: 784
*****
 
i git about 30 of them
 

Life Is a Design Flaw.......&&...&&(cool)&&... (cool too)&&...
IP Logged
 
Reply #44 - Aug 20th, 2003 at 9:05pm

DanielF   Offline
Colonel
Virigina, USA

Gender: male
Posts: 507
*****
 
But what happens if you sign up for something and they send you your password by email with the subject title, "Your New Account"?   Wink
 

...&&FS Evolution&&&&DanielF
IP Logged
 
Reply #45 - Aug 20th, 2003 at 10:48pm

BFMF   Offline
Colonel
Pacific Northwest

Gender: male
Posts: 19820
*****
 
What I want to know is why I got some of these e-mails from senders supposedly as FSTipster, library@avsim, francois, WebPA, BMan, Y2Craigie, Webmaster@simviation.com, even some FSgateway addresses.

Are these people really infected with this virus and have me in their address books, or is virus just a personal attack against our hobby?
 
IP Logged
 
Reply #46 - Aug 20th, 2003 at 11:24pm

geezer   Offline
Colonel
Raleigh, NC

Posts: 30
*****
 
This is the SoBig virus guys in case you already don't know. It spoofs addresses on the infected computers and sends out junk to overload the Internet.

There is no personal attack. It is just that some computers that are not protected have been used as middle men to broadcast these e-mails to lists of addresses that reside on them. In most cases, the users don't even realize what is going on with their machines. It comes mostly from users that either don't have av on their machines or don't keep their pattern files up to date.

You can read about the viruses and worms we have been contending with over the last few days here:

http://www.trendmicro.com/vinfo/

Keep your av pattern files up to date and use a good firewall. If you are one of these guys I have heard about who doesn't have av installed because "it slows my connection down" or "I don't have time" or "I can't afford it" then you are probably the person who is enabling these virus cretins to do their business. No virus distributor is going to be the one to mount the attack. All they do is scan for ports on on-line machines, when they find an open one they go in and plant their bugs. If the bug is discovered by an av program it is gone. If not, it does its work when it is scheduled to or when it is contacted to do so by the main distributor.

If you keep your av pattern files up to date and use real time scan when you are on line, you will not have any trouble.

If you "run bare" you are either going to get infected, you are now infected, or you are going to infect someone else.

 

Imagine...
IP Logged
 
Reply #47 - Aug 21st, 2003 at 1:19am

Professor Brensec   Offline
Colonel
Can't you give me a couple
more inches, Adam?
SYDNEY - AUSTRALIA

Gender: male
Posts: 2955
*****
 
Quote:
I've recieved over 100 of these since yesterday.  Undecided  I'm getting about 1 every 5 minutes.  And like everyone else, I'm getting a lot from FS sites; flightsim.com, flight1.com, simmarket.com, simflight.com.  Luckily nothing from simviation yet.

Would deleting my addresses in my address book help prevent this from spreading?


I'm not a 'member' at any other Sim sight other than Simviation.
So, I imagine the few that I have got (the 'you've been approved' ones) have probably come through another source.
I'm not getting heaps of them though, just the occasional one or two, but they're pretty regular.

Since the Mrs got an email from a friend that had that 'worm' thing that accessed your address book, we no longer maintain an address book, except for the 'paper one'.................lol (fortunately there were only a few names in it and she was able to warn everyone before they opened it.

We got McAfee as part of a Windows package and I've never been able to 'enable' the 'email scan' facility. So I've found the whole thing pretty useless.
I'd like to get Norton 2003. They have that at work and it checks everything. Everytime you open even your own programs it comes up and says it's scanning for virus's etc.
I am however in the process of downloading the 'trial version' of the one recommended by Rollerball. It's 8+ Mb, so it's taking a while.
If it's good, I'll keep it for a while and see how it goes.  Grin Grin

Thanks for the advice all.  Wink
 

...&&...&&http://www.ra.online-plus.biz&&&&&&I cried because I had no shoes - until I saw a man who had no feet.&&&&Dell Dimension 8100 - Intel P4 1.7 Gb - 512 RD Ram - nVidia GeForce 128 mb FX5200.
IP Logged
 
Reply #48 - Aug 21st, 2003 at 12:23pm

Deputy   Offline
Colonel
Hillsboro, Oregon

Gender: male
Posts: 2090
*****
 
Some good news - There has been a break in the case, somebody found an I.P. address. Keep it quiet, but I will keep you all  informed.

 

Bad boys, bad boys, whatcha gonna do? Whatcha gonna do when I come for you?&&&&Iustita Omnibus&&Justice for All&&&&Women are: attractive, single, mentally stable. Pick two.&&... &&Yes, we drive on the right-hand-side of the road. Yes, I parked on the left-hand-side of the road. Yes, I blocked traffic for a picture. &&&&&&
IP Logged
 
Reply #49 - Aug 21st, 2003 at 4:22pm

DanielF   Offline
Colonel
Virigina, USA

Gender: male
Posts: 507
*****
 
It was quiet for me for a long time, but I got another one today at 2:20.  Tongue  But just one is a lot better than 100.  Grin
 

...&&FS Evolution&&&&DanielF
IP Logged
 
Reply #50 - Aug 21st, 2003 at 6:43pm

Lethal.Ambition   Offline
Colonel
They call me John.
Florida

Gender: male
Posts: 1563
*****
 
I have the McAfee Virus-scan and it comes with HAWK, a component that monitors what is being sent through my outlook.....if it notices that e-mail is being sent to more 25 percent of my contacts ( I set the percentage ) and the whole thing freeze until I set to send it or not. I love it.  I sent 4 attachments to a friend once and it alerted me
 

Oderint Dum Metuant - Let them hate as long as they fear.&&Proud member of the =XE= Xtreme Eagles&&Oderint Dum Metuant&&
IP Logged
 
Reply #51 - Aug 21st, 2003 at 11:29pm

Chuck58   Offline
Lieutenant Colonel
I love YaBB 1G - SP1!

Posts: 9
*****
 
I opened my emal and found 127 of the things in it. As of right now, 9:29pm, I've gotten only 3 today. Fortunately my av (ETrust) caught every one of them.

It's an interesting but apparently relatively harmless thing, more a nuisance than anything. There are far, far worse worms, trojans, and viruses out there.

If anybody is on the Internet these days without a good antivirus and firewall, they're really tempting fate. I use ETrust av (2 scan engines) and LooknStop firewall. Both are rated highly at Wilders.org, a security forum and sometimes I wonder if those are enough.
 
IP Logged
 
Reply #52 - Aug 22nd, 2003 at 5:09am

Professor Brensec   Offline
Colonel
Can't you give me a couple
more inches, Adam?
SYDNEY - AUSTRALIA

Gender: male
Posts: 2955
*****
 
I keep getting one every day that seems suspicious to me. It comes with an attachment.

The sender is 'Got StudentLoan?' and the subject field is 'ReduceYourPayments'.

As I said, I never do anything but delete everything I'm not perfectly sure I ask for. (Anyone who mants me badly enough, that I would want to talk to, has my phone number!!

I must admit that I did not run McAfee all the time, only when I was on the Net. The reason was that many of my programs (especially CFS2), were very slow and I needed as much Ram as I could muster. I have downloaded the AVG program suggested by RollerBall, and it seems to be more comprehensive and easier to understand than McAfee, which came with my Windows Millenium OP.
As of today, I have solved the long standing problem of the Compaq Pressario RAM strip.  I now have 384 MB of RAM. So I can run AV all the time now.

(P.S. For anyone interested, I have posted in the 'Hardware' forum under 'Finally, some Compaq RAM'.
I have included the explainatuion as to why all the chips I tried never worked, and why the one I have now, does.)   Grin Grin Wink
« Last Edit: Aug 23rd, 2003 at 12:41am by Professor Brensec »  

...&&...&&http://www.ra.online-plus.biz&&&&&&I cried because I had no shoes - until I saw a man who had no feet.&&&&Dell Dimension 8100 - Intel P4 1.7 Gb - 512 RD Ram - nVidia GeForce 128 mb FX5200.
IP Logged
 
Reply #53 - Aug 22nd, 2003 at 1:28pm

Fozzer   Offline
Colonel
An elderly FS 2004 addict!
Hereford. England. EGBS.

Posts: 24861
*****
 
Having had the virus W32KLEZ in the past, and remembering all the trouble it caused to all the addressees in my address book, I now keep my address book empty, and all the addresses are hand written in a paper note-book.
The only affect is that I have to write-out the full address each time I post mail, but at least it stops the circulation of the virus to others if I should I receive it.
At the moment my system is clear. I have the latest Norton up-dates, and also have Zone Alarm running.
I think that I read on the Microsoft site that the virus does not affect Windows '98 users, only XP, NT, and 2000 users.
I run Windows '98 SE... Grin...!

Cheers all... 8)...!
Paul.
(England).

P.S.  It's interesting to note that my Norton up-dates go into warp-drive every time I log-on now... Shocked...!
 

Dell Dimension 5000 BTX Tower. Win7 Home Edition, 32 Bit. Intel Pentium 4, dual 2.8 GHz. 2.5GB RAM, nVidia GF 9500GT 1GB. SATA 500GB + 80GB. Philips 17" LCD Monitor. Micronet ADSL Modem only. Saitek Cyborg Evo Force. FS 2004 + FSX. Briggs and Stratton Petrol Lawn Mower...Motor Bikes. Gas Cooker... and lots of musical instruments!.... ...!
Yamaha MO6,MM6,DX7,DX11,DX21,DX100,MK100,EMT10,PSR400,PSS780,Roland GW-8L v2,TR505,Casio MT-205,Korg CX3v2 dual manual,+ Leslie 760,M-Audio Prokeys88,KeyRig,Cubase,Keyfax4,Guitars,Orchestral,Baroque,Renaissance,Medieval Instruments.
IP Logged
 
Reply #54 - Aug 23rd, 2003 at 12:47am

Professor Brensec   Offline
Colonel
Can't you give me a couple
more inches, Adam?
SYDNEY - AUSTRALIA

Gender: male
Posts: 2955
*****
 
Hey Foz,

I do the same, I don't keep anything in the address book. But to save time and trouble, I keep a Notepad Doc. with all the names and addresses in 'MY Documents'.
It's in Alphabetical order, so all I have to do is copy and paste from that. It saves having to individually type out each addressee, and possibly 'misprinting' and having it returned 'no such addressee'.

Try that. There's no way a Virus will find a Notepad Doc that has nothing to do with the email system, and then recognise the characters as 'email addresses'. Is there?   Grin Grin Wink
 

...&&...&&http://www.ra.online-plus.biz&&&&&&I cried because I had no shoes - until I saw a man who had no feet.&&&&Dell Dimension 8100 - Intel P4 1.7 Gb - 512 RD Ram - nVidia GeForce 128 mb FX5200.
IP Logged
 
Reply #55 - Aug 23rd, 2003 at 4:19am

Fozzer   Offline
Colonel
An elderly FS 2004 addict!
Hereford. England. EGBS.

Posts: 24861
*****
 
Quote:
Hey Foz,

I do the same, I don't keep anything in the address book. But to save time and trouble, I keep a Notepad Doc. with all the names and addresses in 'MY Documents'.
It's in Alphabetical order, so all I have to do is copy and paste from that. It saves having to individually type out each addressee, and possibly 'misprinting' and having it returned 'no such addressee'.

Try that. There's no way a Virus will find a Notepad Doc that has nothing to do with the email system, and then recognise the characters as 'email addresses'. Is there?   Grin Grin Wink


Hi Bren...!
I had considered that long ago... Wink...!
...but...
according to Sod's Law, anything you put on your computer will disappear in a puff of smoke the next time your computer crashes.... Cry...!
...so...
no alternative to the good-old pen and paper... Grin
just like the olden days... 8)...!

...I also keep all my log-in names and password details, payware key details, etc, in a paper note book in front of me for the same reason....VERY IMPORTANT.. Shocked...!

If my 'puter goes tits-up I still have all my important "stuff" in my little black book... Grin...!
(Can't rely on the old memory any more..).... Cry...LOL...!

Cheers mate... Grin...!
Paul.
(England).

P.S. thinking about it some more, a good alternative is to keep important details on a seperate floppy disk...
I have all the service schedules for my bike on floppy disk, 'cos I dont want to loose them... 8)...!
 

Dell Dimension 5000 BTX Tower. Win7 Home Edition, 32 Bit. Intel Pentium 4, dual 2.8 GHz. 2.5GB RAM, nVidia GF 9500GT 1GB. SATA 500GB + 80GB. Philips 17" LCD Monitor. Micronet ADSL Modem only. Saitek Cyborg Evo Force. FS 2004 + FSX. Briggs and Stratton Petrol Lawn Mower...Motor Bikes. Gas Cooker... and lots of musical instruments!.... ...!
Yamaha MO6,MM6,DX7,DX11,DX21,DX100,MK100,EMT10,PSR400,PSS780,Roland GW-8L v2,TR505,Casio MT-205,Korg CX3v2 dual manual,+ Leslie 760,M-Audio Prokeys88,KeyRig,Cubase,Keyfax4,Guitars,Orchestral,Baroque,Renaissance,Medieval Instruments.
IP Logged
 
Reply #56 - Aug 23rd, 2003 at 5:47am

Professor Brensec   Offline
Colonel
Can't you give me a couple
more inches, Adam?
SYDNEY - AUSTRALIA

Gender: male
Posts: 2955
*****
 
You got in with the floppy bit just as I was planning to send this suggestion:

Why not back up the Notepad info on a floppy like I do.

That way it's handy and retrievable if you PC dies.  Grin Wink

Copying and pasting is certainly less trouble than punching the info in everytime. No room for errors either.  Grin Grin Wink
 

...&&...&&http://www.ra.online-plus.biz&&&&&&I cried because I had no shoes - until I saw a man who had no feet.&&&&Dell Dimension 8100 - Intel P4 1.7 Gb - 512 RD Ram - nVidia GeForce 128 mb FX5200.
IP Logged
 
Reply #57 - Aug 24th, 2003 at 11:45pm

loomex   Offline
Colonel
My 1969 Ludwig "pre-Bohnam"
with extra stuff
FAA Ident KITH

Gender: male
Posts: 1853
*****
 
I have gotten over 200 in the past three days. I finaily got one from the simV site today
 

Windows 7 Home Premium (x64) ,2.70 gigahertz AMD Phenom II X6 1045T(6-core), two HD (1TB and 500GB), 8gb RAM, ATI Radeon HD 5570,
IP Logged
 
Reply #58 - Aug 25th, 2003 at 9:28am

Scottler   Offline
Colonel
Albany, New York USA

Gender: male
Posts: 5989
*****
 
Just a reminder to everyone, even though I've mentioned it earlier in the thread...

The Sobig virus is programmed to self-destruct on September 10th.

Hang in there guys...
 

Great edit, Bob.&&&&&&Google it. &&&&www.google.com
IP Logged
 
Pages: 1 
Send Topic Print