|
Author
|
Topic: This was not an obvious virus at all... nope. No sir. Not at all.
|
Clme cake fiend
|
posted 07-19-2001 20:09
quote: Originally quoted by someone who thought "Lets click here!":
X-Apparently-To: clme3748@yahoo.com Received: from orval.pccon.net (EHLO orval.sprint.ca) (209.5.194.98) by mta544.mail.yahoo.com with SMTP; 19 Jul 2001 12:56:15 -0700 (PDT) Received: from ruckstuhl ([149.99.74.181]) by orval.sprint.ca (InterMail vM.5.01.01.04 201-252-108-20000901) with SMTP id <20010719200609.LADT25655.orval.sprint.ca@ruckstuhl> for ; Thu, 19 Jul 2001 16:06:09 -0400 From: "The Ruckstuhls" To: clme3748@yahoo.com Subject: 036 date: Thu, 19 Jul 2001 16:06:38 -0700 X-Mailer: Microsoft Outlook Express 5.50.4133.2400 To: clme3748@yahoo.com Subject: 036 Content-Type: text/plain; charset=ISO-8859-1 Content-Disposition: message text
Hi! How are you? I send you this file in order to have your advice See you later. Thanks
Attachment: 036.DOC.com
I would like to thank the ruckstuhls, whoever they are, for deeming me fit to send this lovely file. It really brightened up my day. I hope they can read this when they're computer finally comes back online  http://www.symantec.com/avcenter/venc/data/w32.sircam.worm@mm.html This one is really a nasty one too. For once it isn't reliant on loopholes in outlook, it actually scans your registry for your email address book and then searches any HTML documents stored on your drive for stored email addresses. Then there's a 1 in 20 chance your computer will lose all files, and a good chance it will fill up your hard drive with random script garbage. Never NEVER open an email executable without wearing asbestos gloves, putting it into quarantine, and then shooting yourself in the head, just to be safe. So to all of you out there: Keep on clicking! And keep on shooting! -Chris IP: Logged |
Jimbo 1 dr3w j00 4 p1ggy!
|
posted 07-19-2001 20:44
Some retarded chick at my company sent out a mass-forward of one of those stupid "My son-in-law works for MIC0RSOFT!!11!1 and he asid theirs' a new VIRUS!!!11" mails to the ENTIRE DAMN COMPANY (1200 people or so) and got roundly lambasted for it.God, I love working at a company where OTHER people both recognize virus hoax forwards and flambe people for passing them on.  IP: Logged |
Clme cake fiend
|
posted 07-20-2001 16:41
quote: Originally quoted by yet another person that didnt' question a double extension:
From: "ahensley" To: clme3748@yahoo.com Subject: lindacover date: Fri, 20 Jul 2001 18:34:06 -0500 X-Mailer: Microsoft Outlook Express Hi! How are you? I send you this file in order to have your advice See you later. Thanks
Attached File: lindacover.doc.pif
Thanks to ahensley, and especially to Linda, whoever you are! -Chris IP: Logged |
Jimbo 1 dr3w j00 4 p1ggy!
|
posted 07-20-2001 17:57
Apparently, an awful lot of retards have you in their address book, Clem.IP: Logged |
eod TREAT MERIGHT!
|
posted 07-20-2001 18:01
Our email virus scanner has turned away 20 emails with the SirCam attachment.IP: Logged |
Clme cake fiend
|
posted 07-21-2001 07:59
As much as I'd like to believe that a bunch of random people I dont know have me in their address books, I'm more apt to believe that the virus is scanning html documents and sending to people's email addresses found there. I beleive that several other penIsites have had emails from the same people.This is actually an interesting virus for once. It picks random documents to send to people, and is actually done well. Why it sends a double extension, I still dont know. This one would be much more effective if it didn't have a double extension and the words were spelled correctly (and grammatically) in the message. -Chris [This message has been edited by Clme (edited 07-21-2001).] IP: Logged |
zippy Member with a member bigger than the member with a member
|
posted 07-21-2001 08:49
this worm hasnt hit me yet, but i'm waiting with baited breath. i'm hoping to get something personal attached, likemenaked.jpg from sexychick@hotmail.com or something. this could be the first fun and exciting virus ever. it's like opening a box of crackerjacks and wondering what your secret surprise is. you can them even trade it with your friends by sending them the email. hoorah IP: Logged |
Jimbo 1 dr3w j00 4 p1ggy!
|
posted 07-22-2001 21:28
Yay! I got a copy too!Mine was "handsignals.doc.pif", from "Blued Market." IP: Logged |
BaldGhoti Member with a member
|
posted 07-23-2001 05:43
I've gotten about twenty or thirty such emails. Then again, I'm not private about my email addy.
------------------ Reverend Rob IP: Logged |
Jimbo 1 dr3w j00 4 p1ggy!
|
posted 07-23-2001 11:08
I wonder if I can open the document in Word directly, thus bypassing the worm executable appended to it?Be interesting to see just what is getting sent to you randomly from some poor loser's hard drive - like what Zippy was talking about with the somehottie@isp.com menaked.jpg thing.  IP: Logged |
zippy Member with a member bigger than the member with a member
|
posted 07-23-2001 14:15
i wonder how the worm gets added to a real data file? i mean, what would happen if you just removed the second extenstion and tried to open the file as if it were a real jpeg or .doc?IP: Logged |
Jimbo 1 dr3w j00 4 p1ggy!
|
posted 07-23-2001 15:31
I tried that - you get garbage; unfortunately (for Microsoft Word files at least) adding the worm into the file breaks the Word format enough that Word can't really recognize it properly.In the case of Word files you can see what's going on just by opening it up in Wordpad or something though - the raw text will be visible towards the end of the file. IP: Logged |
Jimbo 1 dr3w j00 4 p1ggy!
|
posted 07-23-2001 15:34
Oh yeah - and DO NOT DO NOT DO NOT change the extension and double-click - just right-click the damn thing and select "Open With". Doubleclicking is ESPECIALLY dangerous for the files that get renamed to *.pif, because you CANNOT rename away the .pif extension under Windows - Windows assumes anything that's a .pif really is a shortcut to an MS-DOS file, and therefore won't allow you access to the filetype.You can rename .pif files under DOS if you want to go that route, but you're much better off just never, ever, EVER double-clicking a file you know damn well's been infected with a worm anyway.  IP: Logged |
Nereus unregistered
|
posted 07-29-2001 18:14
What if the file isn't plain-text? I got my very first SirCam (and probably my only, I dunno who would have me in an HTML file on their computer or in their address book that is ALSO dumb enough to get virused), but it is a ZIP file. I already tried viewing it in wordpad just in case, but of course nothing.Any way to strip out the virus and find out what some poor sap sent me? Thanx guys. -Nereus (avid reader, novice poster) IP: Logged |
Jimbo 1 dr3w j00 4 p1ggy!
|
posted 07-29-2001 19:24
Have you tried to find out what happens if you right click and select open with Winzip? Winzip's "repair" option may fix it for you, who knows  IP: Logged |
BIG I.T. Guy! unregistered
|
posted 01-12-2002 00:07
If I could find you little fuckers I'd sue you!IP: Logged |
xclusive069 drooling cretin
|
posted 01-12-2002 01:36
haha whover sent it doesnt even know how to spell ASHLEY right:::smakcshaead::: IP: Logged |
Dave Almighty lord of relevant links
|
posted 01-12-2002 04:38
There was info on how to strip the host file of the virus on a slashdot article (in the comments, actually,) not too long ago. I don't remember all of it but in essense it boiled down to: -hex edit the last 174 bytes of the file (the virus) -view file------------------ "I steal teeth from kittens to make necklaces for Satan." IP: Logged |
doomy304 member with a hymen I stole Mon's goat
|
posted 01-12-2002 07:48
I would like to know who the hell went around last night randomly jolting back to life threads that were LONG dead.IP: Logged |
FaRaN Member with a member bigger than the member with a member
|
posted 01-12-2002 08:07
You can investigate by looking at the postdates.next! IP: Logged |
FaRaN Member with a member bigger than the member with a member
|
posted 01-12-2002 08:08
As I see now, it is an unregistered person. Consider my last post as non-existendIP: Logged |