|
|
|
|
#1 |
|
Nothing to say...
Join Date: Sep 2000
Location: UK
Posts: 23,020
|
Is it just me, or is there a new virus/spam campaign doing the rounds at the minute?
I've been bombarded with the following e-mail god knows how many times over the last two days.... "Hi! How are you? I send you this file in order to have your advice See you later. Thanks " Followed by some hokey .bat file attachment, had them in English, Spanish and Italian so far. And yes they are all going to a mail box that is used in skins only , I don't mind so much, being web mail based, but it's making reading the real hate mail just that bit harder ![]() Just thought I'd warn you guys
|
|
|
|
|
|
#3 |
|
Candyass
(Major Dude) |
yeppers...
I get it about 2 a day...the bat file is really a shortcut zip with an exe in it. (A Setup.exe)
Regarding what it is...who knows...I won't run anything like that (because, I'm not that stupid). Anyways, yeah...it is for my skin accounts... |
|
|
|
|
|
#5 |
|
Major Dude
|
havent seen any
![]() "when you are with me i'm free, i'm careless, i believe" |
|
|
|
|
|
#6 | |
|
Nothing to say...
Join Date: Sep 2000
Location: UK
Posts: 23,020
|
Re: yeppers...
Quote:
|
|
|
|
|
|
|
#7 | |
|
Skin Wizard
(Forum King) |
Re: Re: yeppers...
Quote:
And at first you thought you became popular ![]() don't be a thief of your own life.... : DEXYD - Digitally EXpressing Your Dreams |
|
|
|
|
|
|
#8 |
|
Forum King
|
I've gotten 2 of those.
When I executed the attachments my puter locked up, and it's been acting weird ever since ( )
|
|
|
|
|
|
#10 | |
|
Forum King
|
Quote:
I only do that when my cpu is at too high a temperature...so I won't have to change my name to compburner
|
|
|
|
|
|
|
#11 |
|
Senior Member
Join Date: May 2001
Location: Hamilton, Scotland
Posts: 281
|
I had one in Spanish. Deleted it straight away (extension was .doc.bat ...well sussed). First really malicious one I've had from my known skins address but not the first weird foreign language one. That goes to the one with a blank message and an attachment in Hebrew!
Support your local team |
|
|
|
|
|
#12 |
|
Eat, skin, sleep. Repeat.
(Major Dude) |
My comp never get's too hot. For two reasons.
1. It has no sides .2. It has a turbo charged fridge/fan stuck up it's ass. (Just a big ass fan with coolant. Not really that special.)I have this 'cos my computer's a Frankomputer. It's a mishmash of my past 4 computers. I think I've got 3 hardrives. But all together only 12 gig. |
|
|
|
|
|
#13 |
|
Senior Member
Join Date: May 2001
Location: Hamilton, Scotland
Posts: 281
|
You need to experiment more Dr Lucid. My dad's PC has 17 gig and my wee iMac has 30.
Still I suppose it's hard to get parts in Transylvania. Credit for putting it together though - memory upgrades are the extent of my maintenance prowess.
Support your local team |
|
|
|
|
|
#14 |
|
Eat, skin, sleep. Repeat.
(Major Dude) |
I'm currently in the process of bringing it up to date.
I'm gonna bit by bit update it. So far: 1. Bithcin' graphics tablet. ( ![]() ![]() ![]() )2. £3000 worth of graphics software. Planned for the next week or so: 1. Memory, shitloads. 2. Processor, fast, much. 3. Speakers, small, good, many. More and more over time, 'til it is bitchin' once more. |
|
|
|
|
|
#15 |
|
Forum King
|
I just got another 2
|
|
|
|
|
|
#16 |
|
Major Dude
Join Date: Dec 2000
Location: Kiss my ass.
Posts: 1,809
|
Just had one from a "Carlos Sosa" fall on me? Whatz up?
|
|
|
|
|
|
#17 |
|
Nothing to say...
Join Date: Sep 2000
Location: UK
Posts: 23,020
|
Heh, it's been a busy old night, I wake to find another 10 of the fuckers arrived in my mailbox over night
![]() I'm putting a block on my mailbox for file attachements for the time being, enuff is enuff, so if anyone has MikroSkins, funny ha ha jokes, naked pictures of their girlfriends to send me hit the mail button down there first and I'll send you an alternative box to use
|
|
|
|
|
|
#18 |
|
Skin Wizard
(Forum King) |
current system specs:
near future upgrades:
don't be a thief of your own life.... : DEXYD - Digitally EXpressing Your Dreams |
|
|
|
|
|
#19 |
|
Canis Sapiens
(Reviewer) |
I didn't get nothing today like that, but everyone seems to love sending me Hybris's,today's virus is in French
.
My latest pack (old): http://www.winamp.com/plugins/details.php?id=134260 My latest skin: A Skin ? v1.0: http://www.winamp.com/skins/details.php?id=135874 |
|
|
|
|
|
#20 |
|
Candyass
(Major Dude) |
NOTICE
These are actually worm applications...Essentially, somebody trying to get to your system using the wscript.exe host. I found in one of them a doc file that was intended to be opened by Word. However, I long ago disabled wscript.exe. I do not know exactly what this stupidity is doing but, I do believe there was a delete command executed in the code base. Where/what it deletes I do not know...I would say if it looks funny better delete.!!!
|
|
|
|
|
|
#21 |
|
Major Dude
Join Date: Mar 2001
Location: UK
Posts: 619
|
I got four of these this morning, in various languages. For more info about it go to the symantic website.
http://www.symantec.com/avcenter/ven...m.worm@mm.html Winamp 5 updates Spilt_Milk |
|
|
|
|
|
#22 |
|
Senior Member
Join Date: Dec 2000
Posts: 259
|
I got 4 of them
delete, delete, delete, delete.. Buuuu Byeeeeee lol |
|
|
|
|
|
#23 |
|
Nothing to say...
Join Date: Sep 2000
Location: UK
Posts: 23,020
|
CP ym gnihtyna od t'ndid ti tub ,elif eht denepo I
|
|
|
|
|
|
#24 |
|
Eat, skin, sleep. Repeat.
(Major Dude) |
Hehe. Nice one Mr Jones.
I don't get any spam, ever. Thanks to super duper AI span deleter!
|
|
|
|
|
|
#25 |
|
total eclipsed
(Major Dude) Join Date: Apr 2001
Posts: 1,488
|
same here - got around 10 of those in several different languages and from several different sources - also with different attachments (either doc, exe or bat)
only to my skin address Mr Jones, be aware that a irc bot does no harm to your local machine (at least for the moment) but is used for remote access while you're online (e.g. for spoofing or looging accounts in your name and with your ip address) - you should install a good firewall to check if the attachment was really harmless. Also, look at this article http://grc.com/dos/grcdos.htm ![]() the Southern Pinwheel Project A conversation with our universe googlism note of the week: cyana is going to be the last thing you ever see |
|
|
|
|
|
#26 | |
|
Senior Member
Join Date: Jan 2001
Location: the elizabethan era.
Posts: 446
|
Virus Info
Ran across this news item on LotsOf Skins.com, figured it was worth mentioning here.
Quote:
|
|
|
|
|
|
|
#27 |
|
Nothing to say...
Join Date: Sep 2000
Location: UK
Posts: 23,020
|
Funny I don't know any of the names that I have had this virus from so far, that is unless it's picking random names from an address book and firing out mails to them and then them onto me, in which case one of you lot in here subscribes to donkeyporn.com
![]() C'mon own up who is it
|
|
|
|
|
|
#28 |
|
Major Dude
Join Date: Dec 2000
Location: Kiss my ass.
Posts: 1,809
|
I never receive any type of virus by e-mail. Now look at this, I come back to the forum, and the deluge begins. Nah. Don't need the system problems. This little 'puter thing is my bread and butter. :: poof ::
|
|
|
|
|
|
#29 |
|
Candyass
(Major Dude) |
okay ...
You guys that have opened these files with their various attachments are sending these files out to all your contacts and it will get worse with time. I suggest using a really good virus program to get rid of them. Just because, you think it isn't do anything to your system does not mean that it is isn't. I tracked some more info on one of the 'attachments' that I got and it sends data to a ftp server using port 21. Also, note that this is silent movement (meaning its not going to just login.) By my understanding it seems to be sending login account information and password combo's of web entered input boxes.
Also, it seems a derivitive of this also may remove files from the system using a deltree /y command for a given directory. Its seems that this is not only random but will happen without user intervention given time activation. I would suggest going to mcaffee online and getting cleaned asap. (they provide their server for free for 30 days). ie online web virus clean. |
|
|
|
|
|
#32 |
|
Major Dude
|
Based on a recent topic (check the list, I forget which one), I don't think you people who format once a month have too much to worry about
![]() Note to simon on another thread: Just to save space (since I know you'll be coming back here likely), too bad I don't download (based on that same previously mentioned thread) but I would if I did
If anyone can find any of the skins I made please email them to Forevever@aol.com I can't remember all the names but specifically hunting for Lascivious, and DEVOUR (compilation with Jax) and any in the Impulse series which had 6 total. Auriferous, Gilt, Impulse, Nadir, and 2 others I can't remember but you dig. |
|
|
|
|
|
#33 |
|
Candyass
(Major Dude) |
basically this is the way it should look...
An obscure message from an uknown...
With a File Attachment... Usually containing two files. One Misnamed as one of the following or similar. - .doc.bat - .xls.lnk - .exe.bat etc etc. and Another attachment that is a txt file. This is a randomly generated macro txt file that will be used to 'fire' the macro virus. Anyways...there you go...and yeah probably Simond. |
|
|
|
|
|
#34 | |
|
Skin Wizard
(Forum King) |
Quote:
what was the topic?
don't be a thief of your own life.... : DEXYD - Digitally EXpressing Your Dreams |
|
|
|
|
|
|
#35 |
|
Major Dude
|
Sorry Simon, I didn't mean to lose you.
The topic I was referring to about reformating hard drives and I don't download is a misspelled curious (I think its closed now). The second, we were talking about Garet's skin and you said I could download it before it was published, but I don't download (as previously mentioned) Dig? |
|
|
|
|
|
#36 |
|
Forum King
|
Just got another shitload of those emails *sigh*
|
|
|
|
|
|
#37 |
|
Candyass
(Major Dude) |
yep,
Just got 3...its a really bad way of trying to move a virus through. Poorly written as well. Someone gonna get smacked for this....
|
|
|
|
|
|
#38 |
|
Nothing to say...
Join Date: Sep 2000
Location: UK
Posts: 23,020
|
I had 4 while "on the job" with my girl earlier
, damd cell phone,must remember to turn it off
|
|
|
|
|
|
#39 |
|
Eat, skin, sleep. Repeat.
(Major Dude) |
Haha. I just got two. That's quite pathetically stupid actually
.It didn't come with the file tho. 'cos my little email reader deleted it for me !I could do better than that .
|
|
|
|
|
|
#40 |
|
Candyass
(Major Dude) |
quickie
If you ctrl-alt-del and find winword.exe in your task this the possibility of the virus already having infected your system is 100%.
To take measures against this activity do the following: remember however, that preview in outloook express and outlook 97+ will no longer work. Rename the file located in c:\windows (wscript.exe) to hscript.exe. This will prohibit the passing along of the virus. |
|
|
|
![]() |
|
|||||||
| Thread Tools | Search this Thread |
| Display Modes | |
|
|