EMAIL VIRUS alert
Wednesday, July 18, 2001 by Dangeruss | Discussion: WinCustomize Talk
Hi! How are you?
I send you this file in order to have your advice
See you later Thanks
DO NOT OPEN THE ATTACHMENT(s)
I've been infected with an email virus that's mailed all of my skinning contacts. Opening the attachment will infect your Outlook as well.
Norton is not finding any virii, so I can't acertain how malicious this is.
Reply #22 Wednesday, July 18, 2001 9:41 AM
...all that has happened for me is that every time i open an .exe file (eg- a program) it tries to access the internet???....i should add that this only happens when you are connected to the net.
I have blocked it's access to the net from here, so hopefully when more information is known about this i'll be able to get rid of it safely :/
Reply #23 Wednesday, July 18, 2001 9:44 AM
Reply #25 Wednesday, July 18, 2001 9:47 AM
...what i mean there is i've blocked it with a firewall from (only) my computer

...carry-on ppl

Reply #26 Wednesday, July 18, 2001 10:26 AM
Pseudo_ez.zip,com and sunken_hvd.zip.com ...I got two....

Reply #27 Wednesday, July 18, 2001 10:30 AM

Reply #28 Wednesday, July 18, 2001 10:33 AM

Reply #30 Wednesday, July 18, 2001 11:36 AM
Reply #31 Wednesday, July 18, 2001 11:48 AM
I got an email from Dangeruss, who is a friend of mine that I correspond with regularly, with an attachment that says "Liquid2" which is a skin he and I collaborated on that recently got 100,000 downloads here. So I thought he was sending me an update on it. I clicked on it.
I heard my hard drive thrashing so I opened up the task list and killed "SirC32.exe" which was using a lot of CPU at the time.
It was right before I went to bed so I turned off my computer. I'm not sure what it did yet (it's my home machine).
And no ess-vid, I don't think it was obvious it was a virus. Getting a skin you worked on with someone in email from them asking an opinion on it is pretty clever.
Anyway, does anyone know specifically what this virus does? I.e. does it delete data or just try to send out email or what? My home machine is off right now and it's behind a firewall anyway but I would still like to know what it does.
Reply #32 Wednesday, July 18, 2001 12:07 PM
W32.Sircam.Worm@mm
Discovered on: July 17, 2001
Last Updated on: July 17, 2001 at 10:57:39 PM PST
W32.Sircam.Worm@mm was discovered on July 17, 2001. It contains its own SMTP engine in order to propagate itself simlarly to the W32.Magistr.Worm. SARC has received several submissions of this worm from corporate customers. The worm is still being analyzed more in depth and this page will be updated as new information becomes available. SARC will be posting new virus definitions around 3 AM (Pacific) on July 18th.
The worm will arrive in an email with the following content:
The "Subject" of the email will be random and will be the same as the filename of the attachment in the email.
The "Body" of the message will be semi-random but will alway contain one of the following two types (either English or Spanish) as first sentence of the message and last sentence.
Spanish Version:
TOP LINE: Hola como estas ?
LAST LINE: Nos vemos pronto, gracias.
English Version:
TOP LINE: Hi! How are you?
LAST LINE: See you later. Thanks
In between these two sentences may contain some of the following text.
Spanish Version:
Te mando este archivo para que me des tu punto de vista
Espero me puedas ayudar con el archivo que te mando
Espero te guste este archivo que te mando
Este es el archivo con la informacion que me pediste
English Version:
I send you this file in order to have your advice
I hope you can help me with this file that I send
I hope you like the file that I send you
This is the file with the information that you ask for
The filenames under which this threat have been submitted so far are:
SirC32.exe
Tech Specs and Financials.doc.com
More information will be posted as soon as it becomes available. Definitions will be available via LiveUpdate later this evening.
Also Known As: W32/SirCam@mm, Backdoor.SirCam
Category: Worm
Virus Definitions: July 17, 2001
Damage:
Payload:
Large scale e-mailing: The worm embed random documents from the infected PC to itself
Releases confidential info: It will export random document with in the body of the worm
Distribution:
Subject of email: Filename of attachment
Reply #33 Wednesday, July 18, 2001 12:13 PM
Reply #34 Wednesday, July 18, 2001 12:58 PM
1) Tech13_ns (wich is one of MY files)
2) Liquid 2
3) PDS 00013
Since yesterday I couldn't detect any problem here.
Reply #35 Wednesday, July 18, 2001 3:27 PM
Finding file names and changing it's own name to camoflauge itself... Sending out it's little destructive children..
pretty intense...
Reply #36 Thursday, July 19, 2001 9:06 AM
Of course I never open anything from someone that I don't know but at least I was extra suspicious due to reading this here.
Mine came from a domain CANTV.NET which, oddly enough, shows the REGISTRAR as TUCOWS.COM but shows the registrant as:
CANTV Servicios
Av. Francisco de Miranda, Centro Lido
Torre E, Piso 9, Oficina. 91-E
Caracas, Miranda 1060
VE
Since it was originally registered on 9-28-96 but modified 7-18-2001 (yesterday), I have to wonder what's going on here.
Odd thing is there is NO IP address available for this domain!
Reply #37 Thursday, July 19, 2001 9:14 AM
Here's the deal: This virus propagates itself in a very sneaky way. It modifies the registry and attaches itself to any .exe command, so whenever you execute a .exe it runs the virus too. This virus sends mail with a random attachment from any .xls,.exe.zip or .doc file on your HD. It contains it's own STMP protocol, so it acts as it's own mail app. It seeks out your address book AND any cached internet files looking for addresses. This means that if you participate in any forums (Devart - WC - others) it gleans addresses from all the participants on those cached pages that contain those user profiles!!! That's why I was sending messages to parties I had never corressponded with.
This caused me a lot of problems because I'm active in several other forums. In particular, a very popular mountain bike forum where I was just lurking for a while. So the virus sent dozens of mails to the participants of this forum, who thought I was spamming the group. I got home to find that I'd been mail bombed by the members of this forum, and reported to my ISP as a Spammer.
I managed to eliminate the virus from my home PC with the help of Norton Anti Virus and several Registry edits. Visit Nortons page for more details on eliminating this virus if you suspect you have it. The catch is - you have to edit the Registry by renaming regedit.exe to regedit.com, since every .exe respawns the virus. Sneaky bastards.
The really crap part is the payload that is deployed on October 16th. It will likely delete the contents of c:\ or regenerate a text file in the recycle bin until all available disk space is consumed.
Reply #38 Thursday, July 19, 2001 9:45 AM
Russ...this is the proggy which I have, which caught/intercepted the virus without my input....it does not need a signature to detect....relying on suspicious activity, rather than a signature. So for it has caught every virus in the wild, macro, worm, and otherwise.
Give it a look, and check out the main Proggy as well...

Please login to comment and/or vote for this skin.
Welcome Guest! Please take the time to register with us.
There are many great features available to you once you register, including:
- Richer content, access to many features that are disabled for guests like commenting on the forums and downloading skins.
- Access to a great community, with a massive database of many, many areas of interest.
- Access to contests & subscription offers like exclusive emails.
- It's simple, and FREE!








Reply #21 Wednesday, July 18, 2001 7:16 AM