work=affiliates&rating=r">




UBBFriend: Email This Page to Someone!
  PenIs Forum
  General Discussion
   This was not an obvious virus at all... nope. No sir. Not at all.

Post New Topic  Post A Reply
profile | register | preferences | faq | search

next newest topic | next oldest topic
Author Topic:   This was not an obvious virus at all... nope. No sir. Not at all.
Clme
cake fiend
posted 07-19-2001 20:09     Click Here to See the Profile for Clme   Click Here to Email Clme     Edit/Delete Message Reply w/Quote
quote:
Originally quoted by someone who thought "Lets click here!":

X-Apparently-To: clme3748@yahoo.com Received: from orval.pccon.net (EHLO orval.sprint.ca) (209.5.194.98)
by mta544.mail.yahoo.com with SMTP; 19 Jul 2001 12:56:15 -0700 (PDT)
Received: from ruckstuhl ([149.99.74.181]) by orval.sprint.ca
(InterMail vM.5.01.01.04 201-252-108-20000901) with SMTP
id <20010719200609.LADT25655.orval.sprint.ca@ruckstuhl>
for ; Thu, 19 Jul 2001 16:06:09 -0400
From: "The Ruckstuhls"
To: clme3748@yahoo.com
Subject: 036
date: Thu, 19 Jul 2001 16:06:38 -0700

X-Mailer: Microsoft Outlook Express 5.50.4133.2400

To: clme3748@yahoo.com
Subject: 036


Content-Type: text/plain; charset=ISO-8859-1
Content-Disposition: message text


Hi! How are you?

I send you this file in order to have your advice

See you later. Thanks

Attachment:
036.DOC.com


I would like to thank the ruckstuhls, whoever they are, for deeming me fit to send this lovely file. It really brightened up my day. I hope they can read this when they're computer finally comes back online
http://www.symantec.com/avcenter/venc/data/w32.sircam.worm@mm.html

This one is really a nasty one too. For once it isn't reliant on loopholes in outlook, it actually scans your registry for your email address book and then searches any HTML documents stored on your drive for stored email addresses.

Then there's a 1 in 20 chance your computer will lose all files, and a good chance it will fill up your hard drive with random script garbage.

Never NEVER open an email executable without wearing asbestos gloves, putting it into quarantine, and then shooting yourself in the head, just to be safe.

So to all of you out there: Keep on clicking! And keep on shooting!

-Chris

IP: Logged

Jimbo
1 dr3w j00 4 p1ggy!

posted 07-19-2001 20:44     Click Here to See the Profile for Jimbo   Click Here to Email Jimbo     Edit/Delete Message Reply w/Quote
Some retarded chick at my company sent out a mass-forward of one of those stupid "My son-in-law works for MIC0RSOFT!!11!1 and he asid theirs' a new VIRUS!!!11" mails to the ENTIRE DAMN COMPANY (1200 people or so) and got roundly lambasted for it.

God, I love working at a company where OTHER people both recognize virus hoax forwards and flambe people for passing them on.

IP: Logged

Clme
cake fiend
posted 07-20-2001 16:41     Click Here to See the Profile for Clme   Click Here to Email Clme     Edit/Delete Message Reply w/Quote
quote:
Originally quoted by yet another person that didnt' question a double extension:

From: "ahensley"
To: clme3748@yahoo.com
Subject: lindacover
date: Fri, 20 Jul 2001 18:34:06 -0500
X-Mailer: Microsoft Outlook Express


Hi! How are you?

I send you this file in order to have your advice

See you later. Thanks

Attached File:
lindacover.doc.pif


Thanks to ahensley, and especially to Linda, whoever you are!

-Chris

IP: Logged

Jimbo
1 dr3w j00 4 p1ggy!

posted 07-20-2001 17:57     Click Here to See the Profile for Jimbo   Click Here to Email Jimbo     Edit/Delete Message Reply w/Quote
Apparently, an awful lot of retards have you in their address book, Clem.

IP: Logged

eod
TREAT MERIGHT!
posted 07-20-2001 18:01     Click Here to See the Profile for eod   Click Here to Email eod     Edit/Delete Message Reply w/Quote
Our email virus scanner has turned away 20 emails with the SirCam attachment.

IP: Logged

Clme
cake fiend
posted 07-21-2001 07:59     Click Here to See the Profile for Clme   Click Here to Email Clme     Edit/Delete Message Reply w/Quote
As much as I'd like to believe that a bunch of random people I dont know have me in their address books, I'm more apt to believe that the virus is scanning html documents and sending to people's email addresses found there. I beleive that several other penIsites have had emails from the same people.

This is actually an interesting virus for once. It picks random documents to send to people, and is actually done well.

Why it sends a double extension, I still dont know. This one would be much more effective if it didn't have a double extension and the words were spelled correctly (and grammatically) in the message.

-Chris

[This message has been edited by Clme (edited 07-21-2001).]

IP: Logged

zippy
Member with a member bigger than the member with a member
posted 07-21-2001 08:49     Click Here to See the Profile for zippy   Click Here to Email zippy     Edit/Delete Message Reply w/Quote
this worm hasnt hit me yet, but i'm waiting with baited breath. i'm hoping to get something personal attached, like

menaked.jpg from sexychick@hotmail.com or something. this could be the first fun and exciting virus ever. it's like opening a box of crackerjacks and wondering what your secret surprise is. you can them even trade it with your friends by sending them the email. hoorah

IP: Logged

Jimbo
1 dr3w j00 4 p1ggy!

posted 07-22-2001 21:28     Click Here to See the Profile for Jimbo   Click Here to Email Jimbo     Edit/Delete Message Reply w/Quote
Yay! I got a copy too!

Mine was "handsignals.doc.pif", from "Blued Market."

IP: Logged

BaldGhoti
Member with a member
posted 07-23-2001 05:43     Click Here to See the Profile for BaldGhoti   Click Here to Email BaldGhoti     Edit/Delete Message Reply w/Quote
I've gotten about twenty or thirty such emails. Then again, I'm not private about my email addy.

------------------
Reverend Rob

IP: Logged

Jimbo
1 dr3w j00 4 p1ggy!

posted 07-23-2001 11:08     Click Here to See the Profile for Jimbo   Click Here to Email Jimbo     Edit/Delete Message Reply w/Quote
I wonder if I can open the document in Word directly, thus bypassing the worm executable appended to it?

Be interesting to see just what is getting sent to you randomly from some poor loser's hard drive - like what Zippy was talking about with the somehottie@isp.com menaked.jpg thing.

IP: Logged

zippy
Member with a member bigger than the member with a member
posted 07-23-2001 14:15     Click Here to See the Profile for zippy   Click Here to Email zippy     Edit/Delete Message Reply w/Quote
i wonder how the worm gets added to a real data file? i mean, what would happen if you just removed the second extenstion and tried to open the file as if it were a real jpeg or .doc?

IP: Logged

Jimbo
1 dr3w j00 4 p1ggy!

posted 07-23-2001 15:31     Click Here to See the Profile for Jimbo   Click Here to Email Jimbo     Edit/Delete Message Reply w/Quote
I tried that - you get garbage; unfortunately (for Microsoft Word files at least) adding the worm into the file breaks the Word format enough that Word can't really recognize it properly.

In the case of Word files you can see what's going on just by opening it up in Wordpad or something though - the raw text will be visible towards the end of the file.

IP: Logged

Jimbo
1 dr3w j00 4 p1ggy!

posted 07-23-2001 15:34     Click Here to See the Profile for Jimbo   Click Here to Email Jimbo     Edit/Delete Message Reply w/Quote
Oh yeah - and DO NOT DO NOT DO NOT change the extension and double-click - just right-click the damn thing and select "Open With". Doubleclicking is ESPECIALLY dangerous for the files that get renamed to *.pif, because you CANNOT rename away the .pif extension under Windows - Windows assumes anything that's a .pif really is a shortcut to an MS-DOS file, and therefore won't allow you access to the filetype.

You can rename .pif files under DOS if you want to go that route, but you're much better off just never, ever, EVER double-clicking a file you know damn well's been infected with a worm anyway.

IP: Logged

Nereus
unregistered
posted 07-29-2001 18:14           Edit/Delete Message Reply w/Quote
What if the file isn't plain-text? I got my very first SirCam (and probably my only, I dunno who would have me in an HTML file on their computer or in their address book that is ALSO dumb enough to get virused), but it is a ZIP file. I already tried viewing it in wordpad just in case, but of course nothing.

Any way to strip out the virus and find out what some poor sap sent me?

Thanx guys.

-Nereus (avid reader, novice poster)

IP: Logged

Jimbo
1 dr3w j00 4 p1ggy!

posted 07-29-2001 19:24     Click Here to See the Profile for Jimbo   Click Here to Email Jimbo     Edit/Delete Message Reply w/Quote
Have you tried to find out what happens if you right click and select open with Winzip? Winzip's "repair" option may fix it for you, who knows

IP: Logged

BIG I.T. Guy!
unregistered
posted 01-12-2002 00:07           Edit/Delete Message Reply w/Quote
If I could find you little fuckers I'd sue you!

IP: Logged

xclusive069
drooling cretin
posted 01-12-2002 01:36     Click Here to See the Profile for xclusive069   Click Here to Email xclusive069     Edit/Delete Message Reply w/Quote
haha whover sent it doesnt even know how to spell ASHLEY right

:::smakcshaead:::

IP: Logged

Dave
Almighty lord of relevant links
posted 01-12-2002 04:38     Click Here to See the Profile for Dave     Edit/Delete Message Reply w/Quote
There was info on how to strip the host file of the virus on a slashdot article (in the comments, actually,) not too long ago. I don't remember all of it but in essense it boiled down to:
-hex edit the last 174 bytes of the file (the virus)
-view file

------------------
"I steal teeth from kittens to make necklaces for Satan."

IP: Logged

doomy304
member with a hymen
I stole Mon's goat
posted 01-12-2002 07:48     Click Here to See the Profile for doomy304   Click Here to Email doomy304     Edit/Delete Message Reply w/Quote
I would like to know who the hell went around last night randomly jolting back to life threads that were LONG dead.

IP: Logged

FaRaN
Member with a member bigger than the member with a member
posted 01-12-2002 08:07     Click Here to See the Profile for FaRaN   Click Here to Email FaRaN     Edit/Delete Message Reply w/Quote
You can investigate by looking at the postdates.

next!

IP: Logged

FaRaN
Member with a member bigger than the member with a member
posted 01-12-2002 08:08     Click Here to See the Profile for FaRaN   Click Here to Email FaRaN     Edit/Delete Message Reply w/Quote
As I see now, it is an unregistered person. Consider my last post as non-existend

IP: Logged

All times are PT (US)

next newest topic | next oldest topic

Administrative Options: Close Topic | Archive/Move | Delete Topic
Post New Topic  Post A Reply
Hop to:

Contact Us | Penismightier.com

Look out for the mexican. He knows where you hide your cake.

Powered by: Ultimate Bulletin Board, Version 5.44
© Infopop Corporation (formerly Madrona Park, Inc.), 1998 - 1999.



work=affiliates&rating=r">