The Oregonian's Bill Monroe!

Go Back   www.ifish.net > Ifish Archives > Ifish 2001 archives

Reply
 
Thread Tools Display Modes
Old 07-30-2001, 06:45 PM   #1
Jennie@ifish
AdminiMom
 
Jennie@ifish's Avatar
 
Join Date: Apr 2000
Location: North Coast
Posts: 97,970
Default W32.Sircam.Worm@mm

I know, I know, no virus warnings on ifish.
However, this is a very fast moving hassle virus, and I want everyone here to take care of their computer.
The sircam virus spread is huge.
I have gotten perhaps 40 copies of it, from various e mails.
It is NOT a malicious virus, meaning the people sending it do not even know they are sending it.
Please read this

If you don't read that, know that if you get any e mails, with this wording, or similar:

Subject: The subject of the email will be random, and will be the same as the file name of the email attachment.
Attachment: The attachment is a file taken from the sender's computer and will have the extension .bat, .com, .lnk or .pif added to it.
Message: The message body will be semi-random, but will always contain one of the following two lines (either English or Spanish) as the first and last sentences of the message.

Spanish Version:
First line: Hola como estas ?
Last line: Nos vemos pronto, gracias.

English Version:
First line: Hi! How are you?
Last line: See you later. Thanks

Between these two sentences, some of the following text may appear:

Spanish Version:
Te mando este archivo para que me des tu punto de vista
Espero me puedas ayudar con el archivo que te mando
Espero te guste este archivo que te mando
Este es el archivo con la informaci=n que me pediste

English Version:
I send you this file in order to have your advice
I hope you can help me with this file that I send
I hope you like the file that I sendo you
This is the file with the information that you ask for

-----

There is a fix on the link above, and you should run it, if you have opened anything suspicious like this.
I have NEVER opened any of these files, yet I ran the fix, and it found files infected.
It resides/hides in your recycle bin which is not always scanned with your virus checker.
Your virus definitions NEED to be updated, as this virus was just created on July 17th.
The trigger date is October 16th.
DO NOT be upset with someone for sending this to you. Please do inform them of their problem calmly and tell them how to fix it. It will be appreciated.

I'm sorry to write two unrelated topics in one day, but hey, I care about the people here, and your computers!
Be careful out there, and even if you KNOW someone that sends the attachment, don't open it unless you were expecting it, or if you write and ask them if they MEANT to send an attachment.
Viruses cannot spread by magic. It's like a gun. It won't hurt you if you simply pick it up and look at it, but if you pick it up and shoot it, you are vulnerable.

Just curious, anyone out there get it lately?

Jen
__________________
The goal in Life's Journey is not to arrive at the grave safely in a well preserved body, but rather to skid in sideways, totally worn out, shouting "whooo hoooo (!) what a ride!"
Jennie@ifish is offline   Reply With Quote
Old 07-30-2001, 08:01 PM   #2
Steve
Steelhead
 
Join Date: Jul 2000
Location: Tidewater, OR U.S.A.
Posts: 297
Default Re: W32.Sircam.Worm@mm

I intercepted a worm virus tonight, Had See you later as the last line from someone named Jason Altman, actually there was ten messages with his name attatched, ran it by Norton anti-virus and was shocked by how fast it rejected....Steve....this is a worse virus than the one I had to take penicillian for...
Steve is offline   Reply With Quote
Old 07-30-2001, 08:42 PM   #3
smilesforu
Tuna!
 
Join Date: May 2000
Location: Port Angeles
Posts: 1,147
Default Re: W32.Sircam.Worm@mm

Jen I too have recieved a lot of these emails 4 or 5 a day. It looks like some of the emails I have gotten were from mailing lists which is really bad since they have huge databases sending this thing out.

I will scan my system to see if I have anything I missed. I haven't opened any either...better safe than sorry.
__________________
Marty M
Steelheader.net
smilesforu is offline   Reply With Quote
Old 07-30-2001, 11:59 PM   #4
poshie
Steelhead
 
Join Date: Apr 2001
Location: OREGON
Posts: 241
Default Re: W32.Sircam.Worm@mm

That virus comes from the following email...Jackie Presley sub: Presley construction.
ALSO..
lewmiller.. no subject but same message.
And a series of letters for an ID.
I also got messed up last Thursday with the code red worm...I was down from Thursday til Monday thru USQwest. It trashed my Cisco (read CNN). Couldn't even get them on the phone from late Thursday evening until Saturday. They tried to reconfigure my Cisco 675 and even knocked the phone service..DSL didn't get restored until Monday afternoon and every password had to be reentered.. USWest suggested not turning on computor Tuesday. The 11:00 news said it should hit Portland around 5:00 p.m.
[img]images/icons/frown.gif[/img] [img]images/icons/frown.gif[/img]
poshie is offline   Reply With Quote
Old 07-31-2001, 12:00 AM   #5
poshie
Steelhead
 
Join Date: Apr 2001
Location: OREGON
Posts: 241
Default Re: W32.Sircam.Worm@mm

THAT IS 5:00 p.m. Tuesday
poshie is offline   Reply With Quote
Reply

Thread Tools
Display Modes

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is On
HTML code is Off

Cast to



All times are GMT -8. The time now is 06:11 AM.

Terms of Service
Page generated in 0.06664 seconds with 10 queries