Free Republic
Browse · Search
News/Activism
Topics · Post Article

Skip to comments.

E-mail Virus Wreaking Havoc Worldwide
Talon News ^ | June 17, 2004 | By Jimmy Moore

Posted on 06/17/2004 7:00:09 AM PDT by MountainPatriot

click here to read article


Navigation: use the links below to view more comments.
first previous 1-2021-4041-6061-8081-94 next last
To: MountainPatriot; All
Here's an email with the best advice, info, & links so far:


To recipients of emails with the subject line:  {Spam?} Re: {Spam?} RE: {Spam?} {Virus?} {Spam?} Check this out kid!!!

Okay, since all of you are sending ME stuff, I will send back to you some answers and cures.  So far I have received more than four dozen of your emails complaining about me and the others of you sending a virus.

Here is my analysis of what is happening and what you, each of you, can do about it.

First of all, do not send anything to cis-announce or cis-outgoing or any variation thereof.  Those might be their entire mailing list!  So let's not perpetuate this thing.  I am sending this email to all parties, including the firms named herein, and including an office in Homeland Security which is one of the senders to me!

It is possible that this particular virus is adding the word {Spam?} to its outgoing mail because I received from CIS their regular mailing with their regular subject line, but that word in brackets had been added at the beginning of the subject line.

Obviously, we are under attack from a virus, a Hungarian virus called Worm.Zafi.B.  Right now, this particular virus is the most "widespread email worm at the moment" and you can read the whole story which came out just about an hour ago: 
http://www.theage.com.au/articles/2004/06/15/1087244900422.html?oneclick=true. This is truly an international virus, as described here in the Virus Encyclopedia:  http://www.viruslist.com/eng/viruslist.html?id=1666973. Down toward the bottom you will find the text of the emails YOU got, along with the description of the attachment that was deleted (hopefully).  Note that I have received the original email with the attachment removed and replaced with text telling me what the virus is!  Here is that text:
This is a message from the MailScanner E-Mail Virus Protection Service
----------------------------------------------------------------------
The original e-mail attachment "jennifer the wild girl xxx07.jpg.pif"
was believed to be infected by a virus and has been replaced by this warning
message.
If you wish to receive a copy of the *infected* attachment, please
e-mail helpdesk and include the whole of this message
in your request. Alternatively, you can call them, with
the contents of this message to hand when you call.
At Sat Jun 12 17:19:29 2004 the virus scanner said:
   ClamAV: jennifer the wild girl xxx07.jpg.pif contains Worm.Zafi.B
   MailScanner: Shortcuts to MS-Dos programs are very dangerous in email (jennifer the wild girl xxx07.jpg.pif)
Note to Help Desk: Look on the MailScanner in /var/spool/MailScanner/quarantine/20040612 (message i5CLDxhq003158).
--
Postmaster
Mailscanner thanks transtec Computers for their support
Someone's computer is infected, and typically a virus will get into one person's computer, look around for email addresses, then send itself out to a whole bunch of the addresses it finds.

You cannot tell who really has the infected computer because the virus "spoofs" the sender's name, making it look like it is coming from someone else, NOT the person se computer is infected.  It will just pick at random one of those addresses that it found and use that as the "sender" and send itself to the other email addresses.  That is called "spoofing" which is quite commonly done by viruses.

An example:  Sharon's computer gets a virus which then sends itself to everyone in her address book but it looks like all those emails came from James!  Poor James doesn't even know this is happening until he starts getting those "bounced" emails saying that he is sending a virus.  He is innocent, does not have a virus, because all that is coming from Sharon's computer!  And Sharon has absolutely no clue that her computer is infected and doing all this.

Only by looking at the header of one of those spoofed emails very carefully can you get a hint of where it might be really coming from.  The following are two places where you can get a removal tool if you think you might be infected.

This is from http://vil.nai.com/vil/content/Print126242.htm
-- Update June 14th, 2004 03:01 PST --
The risk assessment of this threat has been raised to Medium due to increased prevalence.

If you think that you may be infected with this threat, and are unsure how to check your system, you may download the Stinger tool to scan your system and remove the virus if present.  This is not required for McAfee users as McAfee products are capable of detecting and removing the virus with the latest update. (see the removal instructions below for more information).

Note: Receiving an email alert stating that the virus came from your email address is not an indication that you are infected as the virus often forges the from address.
And this from http://www.f-secure.com/v-descs/zafi_b.shtml
F-Secure provides the special disinfection utility to eliminate Zafi.B worm infection. You can download this utility from our ftp site:

ftp://ftp.f-secure.com/anti-virus/tools/f-zafi.exe

ftp://ftp.f-secure.com/anti-virus/tools/f-zafi.zip
Disinfection instructions can be found here:

ftp://ftp.f-secure.com/anti-virus/tools/f-zafi.txt
I myself started getting these emails from "James Moore" on Saturday.  I have received several by now.  The header from one of the earlier ones is pasted below.  (It is NOT infected as it is a copy and paste rather than any kind of forwarding, which could perpetuate the virus.)

I have bolded some interesting lines.   The "return path" appears to be CIS.ORG.

A couple of other possibilities are these:  Numbers USA and The Social Contract are both clients of whetstonelogic.com, which appears in the header.  Note that wslogic.com is another name for whetstonelogic which specializes in "political intelligence tools".  Take a look at the header below.

You will see byromlaw.com which belongs to a law firm in Florida.  Did the emails originate there?  Or did they just go through their servers?  We don't know.  But in any case I sending all the these organizations a copy of this email.  Any one or all of the them might be infected and unknowingly sending out the virus to everyone else.

All of these organizations should check for viruses.  And so should you, the individuals that have received those emails from the "alleged" James Moore.

Here is the plan of action.  I am the webmaster for Terry Anderson and last fall I designed a page when we had another virus outbreak.  I called it "Got Virus?" and put up there the results of my research of what you can do to protect yourself and some free virus scans you can go to find out if you are infected.  Just finding those scan sites took a great deal of time, so all the work is already done -- all you have to do is run them on your own computers.  Everyone that receives this particular email should go to the following webpage and do your scans right away, and then at least once a week thereafter.  Bookmark the page and come back every week.  And update your Norton every day!  Including the special page that is updated more often than the "Live Update":  http://securityresponse.symantec.com/avcenter/download/pages/US-N95.html. I just ran all four scans and my computer is clean.

Also, make sure you have Norton Anti-virus and Zone Alarm (a free firewall).  The links are on the "Got Virus?" page.  There again, the link for Zone Alarm was hard to find on their website, so I saved you all that time by putting it there.

To summarize, it is imperative that all of these check for viruses and make sure that

        1.      CIS.org
        2.      Numbers USA
        3.      The Social Contract
        4.      Byrom, Miller & Coleman
        4.      Everyone else receiving this email

                        should immediately:

        A.      Get anti-virus if you don't have it.
        B.      Get Zone Alarm if you don't have it.
        C.      Set your "Scheduled Tasks" to update every day,
                        both Live Update and
                        http://securityresponse.symantec.com/avcenter/download/pages/US-N95.html.
        D.      Run all the scans on http://www.theterryandersonshow.com/Viruses.html
        E.      Run #D at least once a week.

These things need to be done immediately because this virus is proliferating rapidly!  While I wrote I received two dozen more of the spoofed emails!

Good luck!  If you have questions, please don't hesitate to contact me.  We are all in this together, regarding immigration as well as these virii.

Carol
webmaster4terry@dslextreme.com

41 posted on 06/17/2004 8:56:05 AM PDT by backhoe (-30-)
[ Post Reply | Private Reply | To 1 | View Replies]

To: JoJo Gunn
You're coming across as an Enabler.

Just who do you think I am enabling. The person who does nothing wrong and accidently opens up a virus? Ok. I accept that.

You, on the other hand, are making excuses for and enabling the criminal. I like my position much better.

42 posted on 06/17/2004 9:04:19 AM PDT by raybbr (My 1.4 cents - It used to be 2 cents, but after taxes - you get the idea.)
[ Post Reply | Private Reply | To 35 | View Replies]

To: MountainPatriot
For the afflicted, HERE is a removal tool.

I dunno - I'd find an email whose subject line read "SPAM! XXX Nekkid Ladies!! Click on this attachment and trust us!!!" to be pretty tempting, myself. I mean, it's not like pornographers and virus authors are bad people or anything...

43 posted on 06/17/2004 9:10:47 AM PDT by Billthedrill
[ Post Reply | Private Reply | To 1 | View Replies]

To: MountainPatriot

Bump to save for later


44 posted on 06/17/2004 9:11:12 AM PDT by Cuttnhorse (John Kerry, Unfit to be Commander in Chief)
[ Post Reply | Private Reply | To 1 | View Replies]

To: hummingbird
Forget all your favorites.......go into the address line and type in Yahoo.com

I did the same thing for google.com bypassing my favorites and the google on my desktop.

I am the original techno-dope but have struggled lately with all kinds of virus attacks and spyware attacks and people out of the kindess of their hearts have helped me so I am hoping this helps you. Good luck.

45 posted on 06/17/2004 9:11:17 AM PDT by OldFriend (LOSERS quit when they are tired/WINNERS quit when they have won)
[ Post Reply | Private Reply | To 39 | View Replies]

To: MountainPatriot
Why is it considered news that Nancy Pelosi, the White House, and God above (for all I know) RECEIVED an e-mail virus?

I receive a couple virus-laden e-mails a week. My AV scrubs them. I have yet to issue a press release about the event.
46 posted on 06/17/2004 9:12:30 AM PDT by Xenalyte (This dog bite me.)
[ Post Reply | Private Reply | To 1 | View Replies]

To: raybbr
Xena's Mom is 62 (and thank God she's not on FR). She is an AOL user and as such, is by definition largely clueless.

Yet she has never gotten a virus, because she never clicks on anything that says "Jennifer the wild girl" or similar.

Avoiding viruses is easy, if you're not stupid or into porn.
47 posted on 06/17/2004 9:14:56 AM PDT by Xenalyte (This dog bite me.)
[ Post Reply | Private Reply | To 10 | View Replies]

To: maridee; 2banana; BipolarBob; MountainPatriot; raybbr
Sheesh, y'all calm the hell down.

MP was bringing an article to our notice, and commenting that his server gets many a hit from the virus. He never said he'd opened anything - clearly, MP is not one of the stupid.

2B made a comment that, while obvious, needs to be made occasionally: if you're dumb enough to click on a random attachment, you deserve the hell you're about to get. He didn't call MP stupid.

Now unwad those panties.
48 posted on 06/17/2004 9:17:03 AM PDT by Xenalyte (This dog bite me.)
[ Post Reply | Private Reply | To 18 | View Replies]

To: kayak
That's a good idea!

I've had to call Mom on more than one occasion and tell her that she'll shortly be receiving something safe to open from me.
49 posted on 06/17/2004 9:17:36 AM PDT by Xenalyte (This dog bite me.)
[ Post Reply | Private Reply | To 24 | View Replies]

To: MountainPatriot
I feel doubly neglected by this worm. First off, I haven't received a copy of it yet. Secondly, since I'm using Linux, I don't get to play along with all of the Windows users.

Yes, I'm being sarcastic!

50 posted on 06/17/2004 9:17:58 AM PDT by Redcloak (My tagline was abducted by aliens and replaced with this exact duplicate.)
[ Post Reply | Private Reply | To 1 | View Replies]

To: raybbr
Yes, try to protect yourself but when you get attacked you blame the poor schlub who's computer go wrecked?

"Trying to protect yourself" from viruses by opening a picture sent by someone you don't know is the equivalent of trying to protect yourself from herpes by dating Bill Clinton.
51 posted on 06/17/2004 9:18:57 AM PDT by Xenalyte (This dog bite me.)
[ Post Reply | Private Reply | To 30 | View Replies]

To: LibKill

When will the morons learn? If you get something prurient yet interesting at work, send it home for later perusal.


52 posted on 06/17/2004 9:20:18 AM PDT by Xenalyte (This dog bite me.)
[ Post Reply | Private Reply | To 40 | View Replies]

To: OldFriend
Thanks for the tip, OldFriend...I like "techno-dope!" Sounds like t-shirt-making time!

Obsessively, I check Windows Update every day & scan but it has been a while since there were any updates for my computer. Maybe even Windows Update is broken....
53 posted on 06/17/2004 9:22:37 AM PDT by hummingbird ("If it wasn't for the insomnia, I could have gotten some sleep!")
[ Post Reply | Private Reply | To 45 | View Replies]

To: raybbr
Accidentally???

Let me put it in plainer terms. Considering how addresses are forged, you'd dismiss someone as not being "savvy" if it was so bereft of common sense as to "accidentally" click on something so blatantly sexual supposedly received from it's own Momma?

Forgive me. "Enabler" was the wrong word.

54 posted on 06/17/2004 9:22:42 AM PDT by JoJo Gunn (Intellectuals exist only if you believe they do. ©)
[ Post Reply | Private Reply | To 42 | View Replies]

To: hummingbird
I had a similar problem, except every time I'd search from MSN, Google, or Yahoo, a results window would pop up trying to get me to buy something, and the second results page was what you'd think the first results page would have been.

After wrangling with it for several months, I finally said the hell with it and completely wiped my drive.

I can help you with that, if you'd like - FReepmail me.
55 posted on 06/17/2004 9:23:37 AM PDT by Xenalyte (This dog bite me.)
[ Post Reply | Private Reply | To 39 | View Replies]

To: hummingbird
I did tech support in a former life, and it was odd . . . I knew everything about everything in the office, but when I got home my IT knowledge left my head. I'd holler at Xena's Guy to come see why my PC was beeping and wouldn't come on, and he'd yell back to check the UPS because we had a power surge, which I already knew because all the VCRs were blinking.

I used to call myself a techno-tard, but I was taken up by some offended people who have relatives riding the short bus.
56 posted on 06/17/2004 9:25:35 AM PDT by Xenalyte (This dog bite me.)
[ Post Reply | Private Reply | To 53 | View Replies]

To: hummingbird
I have Windows 98 and am convinced I've been abandoned by Microsoft! I check for updates every few days, run Ad Aware every other day and use my Trend Micro virus scan every three or four days......in addition to the weekly pre scheduled scan.

And I cry a lot too!!! LOL......

57 posted on 06/17/2004 9:29:25 AM PDT by OldFriend (LOSERS quit when they are tired/WINNERS quit when they have won)
[ Post Reply | Private Reply | To 53 | View Replies]

To: OldFriend

You haven't been abandoned.

XP is now the target of choice for the hackers nowadays, partly because it's the latest, and partly because it's a feather in a hacker's cap to force Gates and crew to issue updates for their supposedly beter, safer, more secure Big Brother Operating System.

They're sorta leaving us 9x users behind, and that's fine with me. There's still a lot of life left with '98 and ME.


58 posted on 06/17/2004 9:38:39 AM PDT by JoJo Gunn (Intellectuals exist only if you believe they do. ©)
[ Post Reply | Private Reply | To 57 | View Replies]

To: Xenalyte

Sheesh, y'all calm the hell down.
Now unwad those panties.

Consider panties unwadded.


59 posted on 06/17/2004 9:42:23 AM PDT by BipolarBob (Yes I backed over the vampire, but I swear I didn't see it in my rearview mirror.)
[ Post Reply | Private Reply | To 48 | View Replies]

To: Xenalyte
Avoiding viruses is easy, if you're not stupid or into porn.

Agreed. At least for the e-mail type viruses, you'd think everyone would know the drill by now.

Although I get the giggles thinking how CNN, NBC, CBS, ABC, AP, Wash Post, NY Times, etc. could be ground to a halt if they were sent a virus with an attachment "proofbushresponsibleforabughraib.jpg.pif". Those thumb-sucking libs couldn't possibly resist that!

60 posted on 06/17/2004 9:42:50 AM PDT by Tall_Texan (Ronald Reagan - Greatest President of the 20th Century.)
[ Post Reply | Private Reply | To 47 | View Replies]


Navigation: use the links below to view more comments.
first previous 1-2021-4041-6061-8081-94 next last

Disclaimer: Opinions posted on Free Republic are those of the individual posters and do not necessarily represent the opinion of Free Republic or its management. All materials posted herein are protected by copyright law and the exemption for fair use of copyrighted works.

Free Republic
Browse · Search
News/Activism
Topics · Post Article

FreeRepublic, LLC, PO BOX 9771, FRESNO, CA 93794
FreeRepublic.com is powered by software copyright 2000-2008 John Robinson