Skip to comments.
Two level 3 virus/worms in two days [Netsky.B]
Symantec Security Response website ^
| 2/18/2004
Posted on 02/18/2004 11:18:16 AM PST by FourPeas
The email has the following characteristics:
From: (Spoofed)
Subject: (One of the following)
hi
hello
read it immediately
something for you
warning
information
stolen
fake
unknown
Message: (One of the following)
anything ok?
what does it mean?
ok
i'm waiting
read the details.
here is the document.
read it immediately!
my hero
[here
is that true?
is that your name?
is that your account?
i wait for a reply!
is that from you?
you are a bad writer
I have your password!
something about you!
kill the writer of this document!
i hope it is not true!
your name is wrong
i found this document about you
yes, really?
that is bad
here it is
see you
greetings
stuff about you?
something is going wrong!
information about you
about me
from the chatter
here, the serials
here, the introduction
here, the cheats
that's funny
do you?
reply
take it easy
why?
thats wrong
misc
you earn money
you feel the same
you try to steal
you are bad
something is going wrong
something is fool
Attachment Name: (One of the following)
document
msg
doc
talk
message
creditcard
details
attachment
me
stuff
posting
textfile
concert
information
note
bill
swimmingpool
product
topseller
ps
shower
aboutyou
nomoney
found
story
mails
website
friend
jokes
location
final
release
dinner
ranking
object
mail2
part2
disco
party
misc
Attachment Extension 1: (May include one of the following)
.txt
.rtf
.doc
.htm
Attachment Extension 2: (One of the following)
.exe
.scr
.com
.pif
(Excerpt) Read more at sarc.com ...
TOPICS: Business/Economy; Crime/Corruption; Culture/Society; News/Current Events
KEYWORDS: computer; tech; virus; worm
Gotta love it when they come in bunches.
1
posted on
02/18/2004 11:18:17 AM PST
by
FourPeas
To: FourPeas
Nope. Don't love it one bit.
Vote Death penalty for virus-creators!
I'm half-kidding... I think...
To: FourPeas
We barely got our mail server blocked before these started pouring in.
3
posted on
02/18/2004 11:20:44 AM PST
by
eyespysomething
(There is no threat. The Communists are not about to take over our McDonald hamburger stands. JFK '71)
To: Teacher317
Mr. FourPeas works in IT Security. A level three (or four) often means he won't be home tonight. It also means his "super-high priority" project that MUST be finished by this Friday is going to slip because he has to spend time distributing new virus definitions, so he probably won't be home tomorrow night or the night after that, either. Ugh.
Gotta love it when they come in bunches.
4
posted on
02/18/2004 11:24:01 AM PST
by
FourPeas
To: eyespysomething
How do you block a mail server?
I use earthlink, btw.
5
posted on
02/18/2004 11:30:25 AM PST
by
EggsAckley
({...................troll patrol........on duty...................})
To: FourPeas
At least one of them removes other viruses,
6
posted on
02/18/2004 11:32:45 AM PST
by
AppyPappy
(If You're Not A Part Of The Solution, There's Good Money To Be Made In Prolonging The Problem.)
To: EggsAckley
This was at work and the network guy did it. Sorry I wasn't clear.
If you use an internet based email it usually does a good job of blocking the viruses. We don't use Outlook Express at home, we check all our email over the internet.
Of course there are drawbacks, such as file size causes attachments to sometimes be discarded as being too big or suspect, but I have a secondary account I can use if needed.
7
posted on
02/18/2004 11:33:52 AM PST
by
eyespysomething
(There is no threat. The Communists are not about to take over our McDonald hamburger stands. JFK '71)
To: eyespysomething
Earthlink has "spamblocker" which offers a list of suspected spam. Most of it IS spam and is easily deleted. On a rare occasion there is a legitimate email which I can safely retrieve.
I don't open ANY attachments anymore.
8
posted on
02/18/2004 11:41:32 AM PST
by
EggsAckley
({...................troll patrol........on duty...................})
To: FourPeas
Gotta love it when they come in bunches.
Since I use qmail at home I've made up a lot of "dash extension" email addresses. So I have "lelio" for normal email, "lelio-dns" for DNS related issues, "lelio-qmail" for the qmail mailing list, etc.
What kills me is when I get 3 spams to all three addresses at the same time. Its obvious that they have a list of email addresses from mailing lists and just did an alphabetical sort on them.
I'm amazed that an "intellegent spammer" (is there one?) hasn't written up a program to narrow cast spam to people based on where they get the email address from. Granted a lot of spammers just buy the email address with no context and a lot of it is for penis extenders -- which I doubt there's a fan club site about.
9
posted on
02/18/2004 11:47:58 AM PST
by
lelio
To: AppyPappy
I forgot about the Welchia version that made it to level three. Make that three level three virus/worms in the past two days.
10
posted on
02/18/2004 11:54:44 AM PST
by
FourPeas
To: EggsAckley
I call and ask people if they meant to send me an attachment usually.
I was very happy with earthlink when I used to use it. We use our cable company now for cable DSL.
11
posted on
02/18/2004 11:56:04 AM PST
by
eyespysomething
(There is no threat. The Communists are not about to take over our McDonald hamburger stands. JFK '71)
To: AppyPappy
Ooops. My mistake. Welchia.B went level three on the 13th IIRC, not in the past two days.
12
posted on
02/18/2004 12:01:03 PM PST
by
FourPeas
To: Teacher317
Vote Death penalty for virus-creators! I'd be in favor of making them subject to civil liabilities. I can see them as defendants in a class action suit where the plaintiff is every one attacked by their worm or virus!
To: FourPeas
Now at Level 4. It's going to be a long night.
14
posted on
02/18/2004 1:21:19 PM PST
by
FourPeas
To: FourPeas
I just got whacked today.
Finally got around it for a NAV fix.
Hackers should euneched w/o anesthesia!
15
posted on
02/25/2004 1:38:46 PM PST
by
JimVT
To: EggsAckley
I set up Outlook to take all incoming mail with attachments and put them into a separate folder.
Then, I can turn off the "preview pane" and check the properties of said email, and determine "friend/foe" without without even viewing them.
16
posted on
02/25/2004 1:43:21 PM PST
by
Johnny Gage
(God Bless our Firefighters, our Police, our EMS responders, and most of all, our Veterans)
To: Johnny Gage
It's been said before, but also turn OFF any settings that
allow for Network Access when displaying complex HTML
17
posted on
02/25/2004 1:55:54 PM PST
by
bwteim
(Begin With The End In Mind)
To: JimVT
This is not hackers..
18
posted on
02/25/2004 2:00:03 PM PST
by
N3WBI3
Disclaimer:
Opinions posted on Free Republic are those of the individual
posters and do not necessarily represent the opinion of Free Republic or its
management. All materials posted herein are protected by copyright law and the
exemption for fair use of copyrighted works.
FreeRepublic.com is powered by software copyright 2000-2008 John Robinson