Virus disguised as MS Email

If it doesn't fit .. It fits here .. - -

Virus disguised as MS Email

Postby btbrossard » Fri Sep 19, 2003 10:07 am

I received a good number of the following e-mails today:

Image

All were infected by a virus.

The e-mail is obviously not from Microsoft.
Last edited by btbrossard on Fri Sep 19, 2003 10:07 am, edited 1 time in total.
Image
User avatar
btbrossard
Ground hog
Ground hog
 
Posts: 22
Joined: Fri Aug 15, 2003 10:58 am
Location: KMKE

Re: Virus disguised as MS Email

Postby Scottler » Fri Sep 19, 2003 10:11 am

Which virus is it infected with?
Great edit, Bob.


Google it.

www.google.com
Scottler
Lieutenant Colonel
Lieutenant Colonel
 
Posts: 5011
Joined: Mon Jun 16, 2003 10:40 am
Location: Albany, New York USA

Re: Virus disguised as MS Email

Postby btbrossard » Fri Sep 19, 2003 10:14 am

These are the log entries from Norton:

Source: gydemn.exe
Description: The email attachment gydemn.exe is infected with the Worm.Automat.AHB virus.


Source: q778299.exe
Description: The email attachment q778299.exe is infected with the Worm.Automat.AHB virus.


Source: cebdzhs.exe
Description: The email attachment cebdzhs.exe is infected with the Worm.Automat.AHB virus.


Source: Q384939.exe
Description: The email attachment Q384939.exe is infected with the Worm.Automat.AHB virus.

Source: install.exe
Description: The email attachment install.exe is infected with the Worm.Automat.AHB virus.

/Benjamin
Image
User avatar
btbrossard
Ground hog
Ground hog
 
Posts: 22
Joined: Fri Aug 15, 2003 10:58 am
Location: KMKE

Re: Virus disguised as MS Email

Postby Iroquois » Fri Sep 19, 2003 10:14 am

I got this, exept it was from my internet provider. This isn't a hoax, believe me. It's infected with the Blaster worm and another worm type virus that changes serial numbers, making it impossible to log onto Windows.
[center]I only pretend to know what I'm talking about. Heck, that's what lawyers, car mechanics, and IT professionals do everyday. ;)
The Rig:
AMD Athlon XP2000+ Palomino, ECS K7S5A 3.1, 1GB PC2700 DDR, Geforce FX5200 128mb, SB Live P
User avatar
Iroquois
Major
Major
 
Posts: 2704
Joined: Sat Nov 16, 2002 10:03 pm
Location: Ontario Canada

Re: Virus disguised as MS Email

Postby Hagar » Fri Sep 19, 2003 11:16 am

I've seen plenty of these some time ago. It appears they're doing the rounds again. At first sight they appear to be a genuine warning from M$. The message actually refers to a genuine security update. The links are also genuine but the attachment contains the virus. Delete it immediately.

M$ would never send out updates as an e-mail attachment. For the real thing, check the Windows Updates site regularly. Fortunately, it seems your anti-virus software dealt with it. ;)
Image

Founder & Sole Member - Grumpy's Over the Hill Club for Veteran Virtual Aviators
Member of the Fox Four Group
My Google Photos albums
My Flickr albums
User avatar
Hagar
Colonel
Colonel
 
Posts: 30862
Joined: Wed Jun 19, 2002 7:15 am
Location: Costa Geriatrica

Re: Virus disguised as MS Email

Postby Birdie2112 » Fri Sep 19, 2003 12:38 pm

I work in Internet Security, and deal with these things on a regular basis.

Hagar, your exactly right;
Microsoft will NEVER send out updates as patches, right now they use windows update for that, but that will soon be replaced as well.

In addition, that text is not the normal write up, but thats another story...

BOTTOM LINE:
NEVER DOWNLOAD ATTACHMENTS FROM E-MAIL, EVEN IF THEY LOOK LEGIT AND/OR APPEAR TO BE FROM MICROSOFT/SOMEONE YOU KNOW
User avatar
Birdie2112
2nd Lieutenant
2nd Lieutenant
 
Posts: 68
Joined: Thu Jan 30, 2003 5:20 pm

Re: Virus disguised as MS Email

Postby Birdie2112 » Fri Sep 19, 2003 12:51 pm

i just found this:

http://insight.zdnet.co.uk/0,39020415,39116512,00.htm

give you a bit more info about it
User avatar
Birdie2112
2nd Lieutenant
2nd Lieutenant
 
Posts: 68
Joined: Thu Jan 30, 2003 5:20 pm

Re: Virus disguised as MS Email

Postby Scottler » Fri Sep 19, 2003 1:01 pm

Megastever you're my megahero.  LOL
Great edit, Bob.


Google it.

www.google.com
Scottler
Lieutenant Colonel
Lieutenant Colonel
 
Posts: 5011
Joined: Mon Jun 16, 2003 10:40 am
Location: Albany, New York USA

Re: Virus disguised as MS Email

Postby Birdie2112 » Fri Sep 19, 2003 1:37 pm

oh i am. i am.  :-* :-*
User avatar
Birdie2112
2nd Lieutenant
2nd Lieutenant
 
Posts: 68
Joined: Thu Jan 30, 2003 5:20 pm

Re: Virus disguised as MS Email

Postby Scottler » Fri Sep 19, 2003 10:23 pm

Great edit, Bob.


Google it.

www.google.com
Scottler
Lieutenant Colonel
Lieutenant Colonel
 
Posts: 5011
Joined: Mon Jun 16, 2003 10:40 am
Location: Albany, New York USA

Re: Virus disguised as MS Email

Postby Cherokee_6 » Fri Sep 19, 2003 10:27 pm

Thanks for all the heads up guys!
P4 2.6 Ghz w/ 800Mhz FSB & HT Technology, XP Home, 512MB Dual Channel DDR SDRAM at 333 Mhz, 128MB GeForce FX 5200 Video Card, 80GB Ultra ATA/100 HD, Sound Blaster Live! 5.1 w/ Dolby Digital Sound Card.
User avatar
Cherokee_6
Major
Major
 
Posts: 1087
Joined: Fri Jan 10, 2003 1:06 pm
Location: Calgary, Alberta, Canada

Re: Virus disguised as MS Email

Postby BFMF » Fri Sep 19, 2003 10:35 pm

I've seen this over and over again.

just remember, don't ever open up an attachment unless your expecting it.

Always follow this rule ;)
BFMF
Colonel
Colonel
 
Posts: 16266
Joined: Mon Feb 25, 2002 6:06 pm
Location: Pacific Northwest

Re: Virus disguised as MS Email

Postby Cherokee_6 » Fri Sep 19, 2003 10:47 pm

I've seen this over and over again.

just remember, don't ever open up an attachment unless your expecting it.

Always follow this rule ;)

Try to tell my wife that! ::) ::)
P4 2.6 Ghz w/ 800Mhz FSB & HT Technology, XP Home, 512MB Dual Channel DDR SDRAM at 333 Mhz, 128MB GeForce FX 5200 Video Card, 80GB Ultra ATA/100 HD, Sound Blaster Live! 5.1 w/ Dolby Digital Sound Card.
User avatar
Cherokee_6
Major
Major
 
Posts: 1087
Joined: Fri Jan 10, 2003 1:06 pm
Location: Calgary, Alberta, Canada

Re: Virus disguised as MS Email

Postby BFMF » Fri Sep 19, 2003 10:57 pm

lol

My mom once got woried about this and asked me about it.

My response was, "mom, you don't know enough to even run an attachment" ;D ;D

and she really wouldn't know either ;)
BFMF
Colonel
Colonel
 
Posts: 16266
Joined: Mon Feb 25, 2002 6:06 pm
Location: Pacific Northwest

Re: Virus disguised as MS Email

Postby btbrossard » Fri Sep 19, 2003 11:18 pm

just remember, don't ever open up an attachment unless your expecting it


Some e-mail programs will attempt to run the attactchment without user intervention.

For example, the web mail service I use on my server (OpenMail, I belive) ran the attatchment on a computer at work without any prompting.

Also, a good portion of people will try to open anything that gets sent to them via e-mail.

I'm sick of getting this crap.  10 messages at 142K each over dial up makes a slow e-mail experience  ;) .

/Benjamin
Image
User avatar
btbrossard
Ground hog
Ground hog
 
Posts: 22
Joined: Fri Aug 15, 2003 10:58 am
Location: KMKE

Next

Return to General Discussion

Who is online

Users browsing this forum: No registered users and 308 guests