EMAIL VIRUS alert

Wednesday, July 18, 2001 by Dangeruss | Discussion: WinCustomize Talk

If you've received email from me with the message:

Hi! How are you?
I send you this file in order to have your advice
See you later Thanks

DO NOT OPEN THE ATTACHMENT(s)

I've been infected with an email virus that's mailed all of my skinning contacts. Opening the attachment will infect your Outlook as well.

Norton is not finding any virii, so I can't acertain how malicious this is.
First Previous Page 1 of 3 Next Last
Transmutate
Reply #1 Wednesday, July 18, 2001 1:46 AM
The email attachment has put a file named "SirC32.exe" into my c:\recycled folder. It keeps trying to access the internet whenever i'm connected.....i have a firewall, that's how I know!

If I look at the directory from explorer it says that it's empty?...if I look at the directory from dos it says it's empty?....if i look at the directory from my virus checker i can see it but there's no delete function in the program.....if i try to move the file from within dos (even though i can't see it) i get the cannot move - permission denied error...

...can someone tell me how to delete this file?...please
ess-vid
Reply #2 Wednesday, July 18, 2001 2:09 AM
Uh... you do realise that message has "HELLO I AM A VIRUS ARE YOU A SUCKER?" written all over it, right? Shame you got infected, but you're not a newb, Russ, so you should have seen that one coming.

PS: Norton is butt. Try AVP (it seems popular amongst some techies that use virus software).
Buzz_Hog
Reply #3 Wednesday, July 18, 2001 2:20 AM
ess-vid,

Russ must get about 100 e-mails a day asking for his advice. Russ is a good guy in this community and would help anyone here. Can you not expect him to open an e-mail and do what he did?

All it takes is one click on a file... anyone could have done it...
treetog
Reply #4 Wednesday, July 18, 2001 2:26 AM
Russ, I got it here from you, my Norton didn't detect it either, i tried to open, because I was familiared with the file's name, but I couldn't open.
Untill now, nothing wrong...let's see later. =/
JcRabbit
Reply #5 Wednesday, July 18, 2001 2:28 AM
c:\recycled? How about clearing your trash can then?
Alexandrie
Reply #6 Wednesday, July 18, 2001 2:43 AM
I got 4 emails with same msg and one was from Russ.

I did not open the file.

damn this is not funny
ess-vid
Reply #7 Wednesday, July 18, 2001 2:47 AM
Well aware of the circumstances, Buzz. I'm not really -condemning- him for what he did, just pointing out that he really needs to be more observant and/or practice better policies for email handling. For example, any email that I get from an unknown person, or someone known to use html email (evil stuff, that) is checked pure ascii (outlook express users: do this by right clicking the mail, select properties, go to the details tab, and click "Message Source"... you get all of the headers, and the body plus any attachments in pure ascii) before it is opened normally, then if there's any attachments, only those from known sources are checked, and no executable filetypes are checked, regardless of sender. It takes marginally longer, yes, but it's worth the effort to keep one's system clean and stable.

Don't get me wrong, even though I did giggle a bit when I read this (I mean, it -is- pretty much a big red "I AM A VIRUS" sign... the "look it's porn" emails are not the only hallmark of carrier emails, after all), I do feel bad for the guy (I may be an ass, but I'm not a jerk =P )... but he's always struck me as someone at least a little knowledgable in system maintenence, in which case he really should have spotted that.
JcRabbit
Reply #8 Wednesday, July 18, 2001 3:09 AM
Well, I can't find any information on this virus whatsoever. Must be brand new?

Anyway, I never run attachments either. I can't afford the 'luxury' of having my production machine infected. I also always scan downloads for viruses, even if they come from known sources.
Jafo
Reply #9 Wednesday, July 18, 2001 3:25 AM
I think I have helped Trans with his...
I got the email, but have an intelligent Virus proggy which intercepted it and deleted it for me...if anyone wants it...its in my quarantine directory...
Jafo
Reply #10 Wednesday, July 18, 2001 4:08 AM
Trans is still having trouble....looks like it is a feisty little critter...
Transmutate
Reply #11 Wednesday, July 18, 2001 4:21 AM
i've deleted the file in question (and the file that seems to respawn it) but now all my .exe want to open with sirc32.exe instead of rundll32.exe (i think that's right, yeah?) and there's no way of changing it (the edit button is greyed out) ???

hmmmmm......why did i look at that email from Russ (i'm REALLY not blaming you russ, it was my own fault!!!!)

...the saga continues

craeonics
Reply #12 Wednesday, July 18, 2001 4:38 AM
This is why Outlook is dubbed Lookout by most of my friends and we all use better stuff. OKay okay, I'm not helping. Guess the thing to do is boot from your bootflop and sort things out, right?
BoXXi
Reply #13 Wednesday, July 18, 2001 5:33 AM
Russ, what I would like to know is, why was I in your list of contacts? I've never had any contact with you in any shape or form, yet I'm in your e-mail address book! Hmmmmm.........
Dangeruss
Reply #14 Wednesday, July 18, 2001 6:45 AM
Boxxi-
I'm getting returns and mail failures from addresses that are not in my address book. This seems to also scan the internet cache looking for email links that have been cached and hits them too.
retiredmaster
Reply #15 Wednesday, July 18, 2001 6:52 AM
I received it, but fortunately deleted it without opening the attachment. I guessed that Russ's english could do better than "I send you this file in order to have your advice".
paxx
Reply #16 Wednesday, July 18, 2001 6:56 AM
Russ, and eveybody, Norton detects it, but make sure you have just updated your file definitions. Norton tells me it's the W32.Sircam.Worm@mm virus.
Read what Norton says about it: http://www.symantec.com/avcenter/venc/data/[email protected]
paxx
Reply #17 Wednesday, July 18, 2001 6:58 AM
The name of the virus was interpreted as an email address by the script in the messageboard...
OK the name of the virus is W32.Sircam.Worm @ mm (without the spaces.)
paxx
Reply #18 Wednesday, July 18, 2001 6:59 AM
Heck and the link too isn't right... Here it is again:
http://www.symantec.com/avcenter/venc/data/w32.sircam.worm @ mm.html (without the spaces before and after the at sign)
paxx
Reply #19 Wednesday, July 18, 2001 7:01 AM
Grrrr!! Here it is again without the http stuff:
www.symantec.com/avcenter/venc/data/w32.sircam.worm @ mm.html (again, remove the spaces before and after the at sign)
Jafo
Reply #20 Wednesday, July 18, 2001 7:02 AM
OK, Paxx...I'm off to check that out....I'm still trying to help Trans....he's in a bit of a mess....my virus proggy doesn't care what the virus is, and doesn't know....just reacts to the threat and kills it....no signature is needed, just the 'activity'....clever but ignorant at the same time, so, although it can catch it, it hasn't a clue what it is....

Please login to comment and/or vote for this skin.

Welcome Guest! Please take the time to register with us.
There are many great features available to you once you register, including:

  • Richer content, access to many features that are disabled for guests like commenting on the forums and downloading skins.
  • Access to a great community, with a massive database of many, many areas of interest.
  • Access to contests & subscription offers like exclusive emails.
  • It's simple, and FREE!



web-wc01