Some kind of new friggin' virus using emails from websites...

Discussions about anything Computer Hardware Related. Overclocking, underclocking and talk about the latest or even the oldest technology. PCA Reviews feedback
Post Reply
User avatar
FlyingPenguin
Flightless Bird
Posts: 33162
Joined: Wed Nov 22, 2000 11:13 am
Location: Central Florida
Contact:

Some kind of new friggin' virus using emails from websites...

Post by FlyingPenguin »

I just checked my mail and I've got 140 bounced emails that contain viruses. Return addresses are all from websites I've designed.

Looks like there's a new virus that culls emails from websites that's doing mass mailings this week.

Joy.

I was already in the process of replacing emails on websites with contact forms before this started because spammers also do this, but I've NEVER seen anything like this.

------
EDIT
------

Yup new one, just came out. Here's the poop: http://securityresponse1.symantec.com/s ... .f@mm.html

I'm up to 200 emails now, most sent to my old webmaster email that's still posted on some websites.
---
“The Government of Spain will not applaud those who set the world on fire just because they show up with a bucket.” - Prime Minister of Spain, Pedro Sánchez

Image
User avatar
Hipnotic_Tranz
Almighty Member
Posts: 3750
Joined: Wed Nov 22, 2000 6:35 am
Location: Indpls, IN
Contact:

Post by Hipnotic_Tranz »

The worm de-activates on September 10, 2003. The last day on which the worm will spread is September 9, 2003.
Atleast they were nice about it :p
[align=center]<img src=http://i54.tinypic.com/j9tydf.gif>
<i>
My get up and go
must have got up and went.
</i>[/align]
User avatar
FlyingPenguin
Flightless Bird
Posts: 33162
Joined: Wed Nov 22, 2000 11:13 am
Location: Central Florida
Contact:

Post by FlyingPenguin »

400+ emails and counting today.

Fortunately all the ones with the virus contain the same message so I've got a mail rule setup to delete them, but I'm also getting a LOT of bounces and autonotification of infected attachments from situations where the virus used my email as the return address.

It's also a hassle if I want to check my mail online when I'm away from home (as I often do during the day at client's offices).

Fucking annoying. :mad
---
“The Government of Spain will not applaud those who set the world on fire just because they show up with a bucket.” - Prime Minister of Spain, Pedro Sánchez

Image
User avatar
Pugsley
Posts: 7512
Joined: Mon Aug 19, 2002 11:54 pm
Location: NW Indiana
Contact:

Post by Pugsley »

so other then waste bandwith... what does it do?
[align=center]A self-aware artificial intelligence would suffer from a divide by zero error if it were programmed to be Amish[/align]
User avatar
Hipnotic_Tranz
Almighty Member
Posts: 3750
Joined: Wed Nov 22, 2000 6:35 am
Location: Indpls, IN
Contact:

Post by Hipnotic_Tranz »

<li>Attempts to download the DCOM RPC patch from Microsoft's Windows Update Web site, install it, and then reboot the computer.
<li>Checks for active machines to infect by sending an ICMP echo request, or PING, which will result in increased ICMP traffic.
<li>Attempts to remove W32.Blaster.Worm.

http://securityresponse.symantec.com/av ... .worm.html
It fixes your PC :lol
[align=center]<img src=http://i54.tinypic.com/j9tydf.gif>
<i>
My get up and go
must have got up and went.
</i>[/align]
User avatar
DocSilly
Posts: 1558
Joined: Wed Nov 22, 2000 8:24 am
Location: Germany
Contact:

Post by DocSilly »

Hipnotic_Tranz:

You mixed up the viruses this time ... that isn't the Welchia worm you're quoting from, that is the Sobig.F email virus.

FP already posted the correct URL to a detailed description of this new virus.
User avatar
Hipnotic_Tranz
Almighty Member
Posts: 3750
Joined: Wed Nov 22, 2000 6:35 am
Location: Indpls, IN
Contact:

Post by Hipnotic_Tranz »

Oh I know....I found this other "virus" somewhere else which after a short read seems to remove another virus....thought it was humorous so I posted it :o
[align=center]<img src=http://i54.tinypic.com/j9tydf.gif>
<i>
My get up and go
must have got up and went.
</i>[/align]
User avatar
DocSilly
Posts: 1558
Joined: Wed Nov 22, 2000 8:24 am
Location: Germany
Contact:

Post by DocSilly »

Ah, I see ;)
User avatar
sbp
Posts: 3785
Joined: Wed Nov 22, 2000 2:36 am
Contact:

Post by sbp »

Thank goodness for MailWasher
Post Reply