Results 1 to 16 of 16

Thread: Virus Alert

  1. #1

    Thread Starter
    Former Admin/Moderator MartinLiss's Avatar
    Join Date
    Sep 1999
    Location
    San Jose, CA
    Posts
    33,431

    Virus Alert

    The text below is from my company's internal web site. I'm posting here because I think that those of us who try to provide help might think that the email was legitimate.

    There is a new mass mailer virus, W32/SirCam@MM, which should be regarded as high risk. The relevant email message can be identified by:
    * The "Subject" of this virus varies.
    * The body of the message also varies and may include:
    Hi! How are you?
    and I send you this file in order to have your advice
    or I hope you can help me with this file that I send
    or I hope you like the file that I send you
    or This is the file with the information that you ask for
    and See you later. Thanks.
    * Alternatively the body of the message may be received in Spanish
    and may include: Hola como estas?
    and Te mando este archivo para que me des tu punto de vista
    or Espero me puedas ayudar con el archivo que te mando
    or Espero te guste este archivo que te mando
    or Este es el archivo con la informacion que me pediste
    and Nos vemos pronto, gracias.

  2. #2
    Monday Morning Lunatic parksie's Avatar
    Join Date
    Mar 2000
    Location
    Mashin' on the motorway
    Posts
    8,169
    I was caught by this one, although the sender's mail server cleaned it up so I missed the virus. Is it another VBS worm?
    I refuse to tie my hands behind my back and hear somebody say "Bend Over, Boy, Because You Have It Coming To You".
    -- Linus Torvalds

  3. #3

  4. #4
    The Devil crptcblade's Avatar
    Join Date
    Aug 2000
    Location
    Quetzalshacatenango
    Posts
    9,091
    I got 3 today. It is a PIF file, and if you float the mouse over the file icon in WinME it says "This file executes text based command-line ..." so I guess it is like a compiled batch file.
    Laugh, and the world laughs with you. Cry, and you just water down your vodka.


    Take credit, not responsibility

  5. #5
    Fanatic Member Kaverin's Avatar
    Join Date
    Oct 2000
    Posts
    930
    I've not seen that particular one (or heard of it), but I have gotten a few emails from people asking VB questions, which strikes me as odd. It's never happened before. They're legit as far as I can tell though, but most of them definitely don't speak English as their first language. I just ignore most of them because I can't even make sense of them .
    I'm baaaack...
    VB5 Professional Edition, VC++ 6
    Using a 1 gHz Thunderbird, 256 mb RAM, 40 gb HD system with Win98se

    I feel special because I finally figured out how to loop midis: Post link
    I'm a fanatic too

  6. #6
    Matthew Gates
    Guest
    I keep getting sent this *****. People keep sending me files with..well, here's one I received today. I didn't even bother opening it, as it has "com" as an extension.


    From :
    "John Lovelace"<[email protected]>

    To :
    [email protected]

    Subject :
    SciProj6

    Date :
    Sun, 22 Jul 2001 21:06:46 -0400

    Attachment : SciProj6.doc.com (207k)



    Hi! How are you?

    I send you this file in order to have your advice

    See you later. Thanks

    Also got sent it the other day, but the user's Firewall said it had deleted it. Weird thing is, when I sent the person an email (cursing them off), the email address didn't exist.

  7. #7
    Monday Morning Lunatic parksie's Avatar
    Join Date
    Mar 2000
    Location
    Mashin' on the motorway
    Posts
    8,169
    I got one from John Lovelace as well

    Firstly, ZoneAlarm wrapped the attachment in a .zlo wrapper to save it being accidentally executed, then AVG decided it was a virus (I bow down to automatic updates ) and locked it away.
    I refuse to tie my hands behind my back and hear somebody say "Bend Over, Boy, Because You Have It Coming To You".
    -- Linus Torvalds

  8. #8
    Fanatic Member Kaverin's Avatar
    Join Date
    Oct 2000
    Posts
    930
    I'm getting this feeling it's a luser from in here . Probably some punk kid heh heh. But that's the conclusion I reach knowing that it's hitting people in here, and all we have in common is that we are in here, and our emails are easily available. But it could be random. That's how this kind of junk works isn't it? As long as something blocks it, I'm happy.
    I'm baaaack...
    VB5 Professional Edition, VC++ 6
    Using a 1 gHz Thunderbird, 256 mb RAM, 40 gb HD system with Win98se

    I feel special because I finally figured out how to loop midis: Post link
    I'm a fanatic too

  9. #9
    Retired VBF Adm1nistrator plenderj's Avatar
    Join Date
    Jan 2001
    Location
    Dublin, Ireland
    Posts
    10,359
    I have dealt with this virus a number of times over the past few days.

    One receives an email from someone you know, with an attachment. So, because you know the person you open the attachment.
    This will execute the virus ; which would not be caught by the latest virus DAT files at the time of release of the virus.
    It will also show you the personal/private/confidential document you were sent.

    The virus will replace your rundll.exe and rundll32.exe files with hidden viral copies. It will also put a hidden scam32.exe file into your c:\windows\system directory.
    It will also put a hidden sirc32.exe into the \recycled\ folder.

    The virus will then try to infect other systems through windows sharing over the network. It will append a line like this :
    @win \recycled\sirc32.exe
    to the autoexec.bat file of any systems it can.

    The virus will also make 2 important registry changes.
    hkey_local_machine\software\windows\currentversion\runservices. It will add an item called "Driver32" here which runs the \windows\system\scam32.exe file.
    It will also edit hkey_classes_root\exefile\shell\open\command, and change "%1" %* (or something like that) to \recycled\sirc32.exe ....
    This means that everytime you want to run a program, it runs the virus instead.

    So far I've received minutes from directors mettings, plans, quotations.... all this other stuff I should not have received through email.

    Its a nasty bugger, but very easy to remove.
    Microsoft MVP : Visual Developer - Visual Basic [2004-2005]

  10. #10
    PowerPoster MidgetsBro's Avatar
    Join Date
    Oct 2000
    Location
    Apparently, Internet.com
    Posts
    3,125
    I was checking my email and watching TechTV at the same time... When Leo, on The Screen Savers started talking about the virus, I got the email. It was a rather strange coincidence. I knew not to open it, so I just deleted it. It wouldn't really matter to me since I have nothing in my addressbook, and my computer has nothing of good use on it. It's about time for a reformat... maybe after vacation
    <removed by admin>

  11. #11
    Fanatic Member Kaverin's Avatar
    Join Date
    Oct 2000
    Posts
    930
    I remember seeing something on there about this too MidgetsBro. We recently got digital cable, so I watch TechTV all the time.

    I don't know the lamer that sent this though. None of my friends even send me emails, much less try to give me attachments heh heh. We always talk over IM or face to face. I'm on the lookout now though.
    I'm baaaack...
    VB5 Professional Edition, VC++ 6
    Using a 1 gHz Thunderbird, 256 mb RAM, 40 gb HD system with Win98se

    I feel special because I finally figured out how to loop midis: Post link
    I'm a fanatic too

  12. #12
    PowerPoster MidgetsBro's Avatar
    Join Date
    Oct 2000
    Location
    Apparently, Internet.com
    Posts
    3,125
    TechTV kicks ass, but my parents hate it! They say that it won't help them learn anything, then (if it's my mom) turn it on the Lifetime Movie Network (ugh! 2 hour soap operas!). Or if it's my dad, here comes the golf channel (24 hours of old guys in funny pants whacking balls with clubs ).

    Well looky here! 800 posts! Never thought I'd see the day
    <removed by admin>

  13. #13
    Fanatic Member InvisibleDuncan's Avatar
    Join Date
    May 2001
    Location
    Eating jam.
    Posts
    819
    Apparently this one sends itself to people it selects from your address book, with an attachment that it chooses from the C:\My Documents directory. For some reason it's designed so that it doesn't always do this, though.
    Indecisiveness is the key to flexibility.

    www.mangojacks.com

  14. #14
    Addicted Member Eric_B's Avatar
    Join Date
    May 2001
    Location
    home sweet home
    Posts
    130
    i think i caught the virus. my AV alerted me, but it couldn't quarantine or delete the file becoz it was d/l in progress. Anyway, i accidently executed the file.
    Can someone tell me how to remove it?

    Thanx in advance

  15. #15
    Retired VBF Adm1nistrator plenderj's Avatar
    Join Date
    Jan 2001
    Location
    Dublin, Ireland
    Posts
    10,359
    Microsoft MVP : Visual Developer - Visual Basic [2004-2005]

  16. #16
    Fanatic Member
    Join Date
    Aug 2000
    Posts
    736
    More info is here too :Virus Info

Posting Permissions

  • You may not post new threads
  • You may not post replies
  • You may not post attachments
  • You may not edit your posts
  •  



Click Here to Expand Forum to Full Width