Page 1 of 2

Virus disguised as MS Email

PostPosted: Fri Sep 19, 2003 10:07 am
by btbrossard
I received a good number of the following e-mails today:

Image

All were infected by a virus.

The e-mail is obviously not from Microsoft.

Re: Virus disguised as MS Email

PostPosted: Fri Sep 19, 2003 10:11 am
by Scottler
Which virus is it infected with?

Re: Virus disguised as MS Email

PostPosted: Fri Sep 19, 2003 10:14 am
by btbrossard
These are the log entries from Norton:

Source: gydemn.exe
Description: The email attachment gydemn.exe is infected with the Worm.Automat.AHB virus.


Source: q778299.exe
Description: The email attachment q778299.exe is infected with the Worm.Automat.AHB virus.


Source: cebdzhs.exe
Description: The email attachment cebdzhs.exe is infected with the Worm.Automat.AHB virus.


Source: Q384939.exe
Description: The email attachment Q384939.exe is infected with the Worm.Automat.AHB virus.

Source: install.exe
Description: The email attachment install.exe is infected with the Worm.Automat.AHB virus.

/Benjamin

Re: Virus disguised as MS Email

PostPosted: Fri Sep 19, 2003 10:14 am
by Iroquois
I got this, exept it was from my internet provider. This isn't a hoax, believe me. It's infected with the Blaster worm and another worm type virus that changes serial numbers, making it impossible to log onto Windows.

Re: Virus disguised as MS Email

PostPosted: Fri Sep 19, 2003 11:16 am
by Hagar
I've seen plenty of these some time ago. It appears they're doing the rounds again. At first sight they appear to be a genuine warning from M$. The message actually refers to a genuine security update. The links are also genuine but the attachment contains the virus. Delete it immediately.

M$ would never send out updates as an e-mail attachment. For the real thing, check the Windows Updates site regularly. Fortunately, it seems your anti-virus software dealt with it. ;)

Re: Virus disguised as MS Email

PostPosted: Fri Sep 19, 2003 12:38 pm
by Birdie2112
I work in Internet Security, and deal with these things on a regular basis.

Hagar, your exactly right;
Microsoft will NEVER send out updates as patches, right now they use windows update for that, but that will soon be replaced as well.

In addition, that text is not the normal write up, but thats another story...

BOTTOM LINE:
NEVER DOWNLOAD ATTACHMENTS FROM E-MAIL, EVEN IF THEY LOOK LEGIT AND/OR APPEAR TO BE FROM MICROSOFT/SOMEONE YOU KNOW

Re: Virus disguised as MS Email

PostPosted: Fri Sep 19, 2003 12:51 pm
by Birdie2112
i just found this:

http://insight.zdnet.co.uk/0,39020415,39116512,00.htm

give you a bit more info about it

Re: Virus disguised as MS Email

PostPosted: Fri Sep 19, 2003 1:01 pm
by Scottler
Megastever you're my megahero.  LOL

Re: Virus disguised as MS Email

PostPosted: Fri Sep 19, 2003 1:37 pm
by Birdie2112
oh i am. i am.  :-* :-*

Re: Virus disguised as MS Email

PostPosted: Fri Sep 19, 2003 10:23 pm
by Scottler

Re: Virus disguised as MS Email

PostPosted: Fri Sep 19, 2003 10:27 pm
by Cherokee_6
Thanks for all the heads up guys!

Re: Virus disguised as MS Email

PostPosted: Fri Sep 19, 2003 10:35 pm
by BFMF
I've seen this over and over again.

just remember, don't ever open up an attachment unless your expecting it.

Always follow this rule ;)

Re: Virus disguised as MS Email

PostPosted: Fri Sep 19, 2003 10:47 pm
by Cherokee_6
I've seen this over and over again.

just remember, don't ever open up an attachment unless your expecting it.

Always follow this rule ;)

Try to tell my wife that! ::) ::)

Re: Virus disguised as MS Email

PostPosted: Fri Sep 19, 2003 10:57 pm
by BFMF
lol

My mom once got woried about this and asked me about it.

My response was, "mom, you don't know enough to even run an attachment" ;D ;D

and she really wouldn't know either ;)

Re: Virus disguised as MS Email

PostPosted: Fri Sep 19, 2003 11:18 pm
by btbrossard
just remember, don't ever open up an attachment unless your expecting it


Some e-mail programs will attempt to run the attactchment without user intervention.

For example, the web mail service I use on my server (OpenMail, I belive) ran the attatchment on a computer at work without any prompting.

Also, a good portion of people will try to open anything that gets sent to them via e-mail.

I'm sick of getting this crap.  10 messages at 142K each over dial up makes a slow e-mail experience  ;) .

/Benjamin