Free Republic
Browse · Search
News/Activism
Topics · Post Article

Skip to comments.

Deadly New Virus Being Spread by E-Mail
Computer Associates ^ | 4/13/2002 | Staff

Posted on 04/13/2002 8:02:40 AM PDT by ex-Texan

Deadly New Virus Being Spread by E-Mail

Win32/myLife.J.Worm

This is an e-mail worm which spreads using Microsoft Outlook.

Subject: sexyy Screen Saver

Body: hi look to the screen saver it's very funny bye

Attachment: USA.scr

When run, the worm immediately displays a small picture in a window with the title "SHARON", similar to Win32.MyLife.G.

Meanwhile, it copies itself to the system directory as "USA.scr" and "sh.scr" and adds the following registry value so it will be run each time Windows starts:

HKCU\Software\Microsoft\Windows\CurrentVersion\Run\scr="%System%\sh.scr"

The worm spreads in a similar way to other Win32.Mylife variants. It sends itself out using Microsoft Outlook to all addresses in the Outlook address book and the Microsoft Messenger contact list.

It also sends an email message to a hardcoded address with the

Subject: funny Screen Saver

Body: hi all, look to the 3D screen saver it's very funny bye

Attachment: sh.scr

The eTrust InoculateIT signature updates listed below contain detection and system cure for Win32/MyLife.J.

To cure an infected system, all files being detected as Win32/MyLife.J must be deleted. This can either be done manually or by setting eTrust InoculateIT to delete infected files.


TOPICS: Announcements; Crime/Corruption; Culture/Society; Technical
KEYWORDS: newtrojanorworm; newvirus
Navigation: use the links below to view more comments.
first 1-2021-35 next last

1 posted on 04/13/2002 8:02:40 AM PDT by ex-Texan
[ Post Reply | Private Reply | View Replies]

To: ex-Texan
This is a good rule to remember:

Never open an unsolicited attachment with any of the following file types:
.EXE, .COM, .BAT, .PIF, .LNK, .VBS, .VBE, .REG, .CMD, or .SCR

Following this rule will eliminate the risk of virtually all email-borne worms.

2 posted on 04/13/2002 8:11:33 AM PDT by MikeJ
[ Post Reply | Private Reply | To 1 | View Replies]

To: ex-Texan
Sharon and USA. I wonder who invented this virus?
3 posted on 04/13/2002 8:13:06 AM PDT by I still care
[ Post Reply | Private Reply | To 1 | View Replies]

To: MikeJ
Never open an unsolicited attachment with any of the following file types: .EXE, .COM, .BAT, .PIF, .LNK, .VBS, .VBE, .REG, .CMD, or .SCR

Additionally, I would suggest ensuring that file extensions are set to display (so a file FOO.TXT.EXE doesn't simply appear as FOO.TXT), and would recommend using Wordpad to open .doc files (it usually produces okay-looking results, but can't run any imbedded macros).

4 posted on 04/13/2002 8:32:04 AM PDT by supercat
[ Post Reply | Private Reply | To 2 | View Replies]

To: ex-Texan
Can anyone point me to a Windows forum that might be able to help me?

I have got a font glitch that appeared this week that has me stumped.

Also, when I try to log onto raginbull.com, I get an internal server error, even though I can log on through Netscape. (I've dumped my temp files and cookies.)

5 posted on 04/13/2002 9:20:41 AM PDT by Nephi
[ Post Reply | Private Reply | To 1 | View Replies]

To: Nephi
'raginbull' is now:

http://ragingbull.lycos.com/cgi-bin/static.cgi/a=index.txt&d=mainpages

I have no answers about a Windows forum but you might try searching around at www.msn.com ...

6 posted on 04/13/2002 9:29:26 AM PDT by ex-Texan
[ Post Reply | Private Reply | To 5 | View Replies]

To: Nephi
Point your newsreader to MS's support newsgroups and try the appropriate group over there. It's chock full of support goodness ;)

Their NNTP server is msnews.microsoft.com, and if you don't have an NNTP reader, I think they're also carried by Google, IIRC.

7 posted on 04/13/2002 9:42:34 AM PDT by general_re
[ Post Reply | Private Reply | To 5 | View Replies]

Comment #8 Removed by Moderator

Turn off Windows scripting, don't use Outlook. Tell your granny.
9 posted on 04/13/2002 9:58:11 AM PDT by D-fendr
[ Post Reply | Private Reply | To 8 | View Replies]

To: D-fendr
How does one turn off Windows scripting? Please advise. I'm with ya on the Outlook thing - it's a target for hackers looking to "get even" with Bill Gates :-).
10 posted on 04/13/2002 10:00:27 AM PDT by NotJustAnotherPrettyFace
[ Post Reply | Private Reply | To 9 | View Replies]

To: toddhisattva
LOL - you're probably right.
11 posted on 04/13/2002 10:01:00 AM PDT by NotJustAnotherPrettyFace
[ Post Reply | Private Reply | To 8 | View Replies]

To: NotJustAnotherPrettyFace
How to turn off Windows Scripting
12 posted on 04/13/2002 10:06:23 AM PDT by D-fendr
[ Post Reply | Private Reply | To 10 | View Replies]

To: ex-Texan
This is an e-mail worm which spreads using Microsoft Outlook...

It sends itself out using Microsoft Outlook to all addresses in the Outlook address book and the Microsoft Messenger contact list.

So what else is new? Perhaps someday there will be a class action lawsuit against Mr. Gates & Co. for the bajillions of dollars and hours of productivity lost because of their unbelievably insecure software.

In the meantime, a couple of solutions to this problem:
1. Don't use Microsoft Outlook or Microsoft Outlook Express. There are plenty of other excellent email programs out there and most are free.
2. If you MUST use Outlook, make sure you have anti-virus software installed. Update your virus definitions on a regular (ie weekly) basis. Get and install a copy of ZoneAlarm, a personal firewall. It's free and excellent.

Actually, everyone should be running anti-virus and firewall software. If they were, the spread of viruses would be nill. And ZoneAlarm will prevent the various 'phone-home' software applications from communicating with their mothership.

13 posted on 04/13/2002 11:38:55 AM PDT by upchuck
[ Post Reply | Private Reply | To 1 | View Replies]

To: Nephi
"I have got a font glitch that appeared this week that has me stumped. "

Is it one where everything looks ok, then just "dissolves" into giberish? I had that problem a few years ago. I cured it with a little gem from Microsoft called "Tweak UI"

Go find it and grab it. It adds an icon to your control panel with lots of nice little things it will let you do. One of the added features is "Rebuild Fonts".

14 posted on 04/13/2002 12:04:34 PM PDT by Bill Rice
[ Post Reply | Private Reply | To 5 | View Replies]

To: Bill Rice
Thanks for your help.

Oh and, as for my glitch, it affects only portions of the fonts on certain web pages and even when using Windows Explorer. For instance, when I open My Documents, the "My Documents" which is displayed with sky background appears to be an extreme "data" type font. This same font appears only on portions of some web pages - my Ameritrade account for instance.

15 posted on 04/13/2002 1:30:34 PM PDT by Nephi
[ Post Reply | Private Reply | To 14 | View Replies]

Comment #16 Removed by Moderator

To: Conservative_Dr.Pepper_Drinker
Thousands perhaps but all the fatalities are 'puters ...
17 posted on 04/13/2002 10:14:54 PM PDT by ex-Texan
[ Post Reply | Private Reply | To 16 | View Replies]

Comment #18 Removed by Moderator

To: matamoros
I've made it clear to all my friends that I never open attachments. If the message doesn't come up on my screen I don't see it because I refuse to open them. Besides what makes anyone think I would ever open an e-mail with sexy in the title?
19 posted on 04/14/2002 10:35:51 AM PDT by WVNan
[ Post Reply | Private Reply | To 18 | View Replies]

To: MikeJ
Even better, DON'T USE OUTLOOK!
20 posted on 04/14/2002 5:37:33 PM PDT by JAWs
[ Post Reply | Private Reply | To 2 | View Replies]


Navigation: use the links below to view more comments.
first 1-2021-35 next last

Disclaimer: Opinions posted on Free Republic are those of the individual posters and do not necessarily represent the opinion of Free Republic or its management. All materials posted herein are protected by copyright law and the exemption for fair use of copyrighted works.

Free Republic
Browse · Search
News/Activism
Topics · Post Article

FreeRepublic, LLC, PO BOX 9771, FRESNO, CA 93794
FreeRepublic.com is powered by software copyright 2000-2008 John Robinson