![]() |
![]() |
![]() |
![]() |
![]() |
![]() ![]() ![]() ![]() ![]()
|
Author | Topic: HUSHMAIL USERS READ THIS! | ||
Elite Bodybuilder ![]() ![]() ![]() Posts: 1344 |
I got a virus in my hushmail account from thie email addy: [email protected]. Thankfully I have virus shield and it detected it before I opened the attachment. Just for you guys that don't have virusshield, beware and don't open anything that has to do with snow white in the subject. ------------------ ![]() ![]() ![]() ![]() | ||
Elite Bodybuilder ![]() ![]() ![]() Posts: 869 |
good looking out Blackhaus, Thanx!!! ![]() ![]() ![]() ![]() | ||
Elite Bodybuilder ![]() ![]() ![]() Posts: 1058 |
Damn, I got the same thing, but thankfully didn't open it. ![]() ![]() ![]() ![]() | ||
Moderator ![]() ![]() ![]() ![]() Posts: 6009 |
If you want to see something really sketchy, then go and visit www.sexyfun.net !! [This message has been edited by 2Thick (edited January 11, 2001).] ![]() ![]() ![]() ![]() | ||
Elite Bodybuilder ![]() ![]() ![]() Posts: 823 |
Thanks Blackhaus. ![]() ![]() ![]() ![]() | ||
Elite Bodybuilder ![]() ![]() ![]() Posts: 1344 |
I just wanna keep this at the top...its not only limited to hushmail users...anyone could have gotten this since its a worm file...heres the info on it... Name: W32/Hybris-C Sophos has received several reports of this worm from the wild. Sophos researchers have released an updated IDE file which detects a minor mutation of the virus. It consists of a base part and a collection of upgradeable components. The components are stored within the worm body encrypted with 128-bit strong cryptography. When run, the worm infects WSOCK32.DLL. Whenever an email is sent, the worm attempts to send a copy of itself as an attachment to a separate message to the same recipient. Any other behaviour exhibited by the worm is entirely dependent on the set of installed components. The effects of components known to Sophos at the time of writing are described below. The text of the email message is determined by one of the installed components, and hence can be changed by the upgrading mechanism detailed below. Consequently the message can have any subject, any message text and any filename for the attached file. A common component of the worm checks the language settings of the computer it has infected, and selects a message accordingly from: English Subject: Message text:
Subject: Message text: Portuguese Subject: Message text: Spanish Subject: Message text: The methods for upgrading the worm can also be changed as they are also upgradable components. At the time of writing, two have been seen. One of the upgrading techniques attempts to download the encrypted components from a website which is presumably operated by the worm author. This website has since been disabled. However, this component could be upgraded to have a different web address. The other method involves posting its current plug-ins to the usenet newsgroup alt.comp.virus, and upgrading them from other posts by other infections of the worm. These are again in the encrypted form, and have a header with a four character identifier and a four character version number, in order for the worm to know which plug-ins to install. Another component of the worm searches the PC for .ZIP and .RAR archive files. When it find one, it searches inside it for a .EXE file, which it renames to .EX$, and then adds a copy of itself to the archive using the original filename. There is a payload component, which on the 24th of September of any year (which very ironically, is my BIRTHDAY!!!!!!!!), or at 1 minute to the hour at any day in the year 2001, displays a large animated spiral in the middle of the screen which is difficult to close.
[This message has been edited by blackhaus1 (edited January 11, 2001).] ![]() ![]() ![]() ![]() | ||
Guru ![]() ![]() ![]() ![]() ![]() Posts: 2291 |
Blackhaus1...What kind of sites have you been visiting? Sexyfun? ![]() ![]() ![]() | ||
Amateur Bodybuilder ![]() ![]() Posts: 152 |
Yeah, I got the same email on my hotmail addy. ![]() ![]() ![]() ![]() | ||
Elite Bodybuilder ![]() ![]() ![]() Posts: 1344 |
If u went to the site you'd realize its a worm virus that is spread thru address books. I didn't visit any dirty sites thank you very much. ------------------ ![]() ![]() ![]() ![]() | ||
Guru ![]() ![]() ![]() ![]() ![]() Posts: 2291 |
quote:
I'm in the IT field, so I know (all too well) how those viruses are spread. ![]() ![]() ![]() | ||
Elite Bodybuilder ![]() ![]() ![]() Posts: 1344 |
just bumpin it up ------------------ ![]() ![]() ![]() ![]() | ||
Novice ![]() Posts: 2 |
Did anyone find out how to detect it if you may have opened something like this? I think I may have gotten a mail like that a month ago. I wonder if I have it......... ![]() ![]() ![]() |
All times are ET (US) | |
![]() |
Powered by Infopop www.infopop.com © 2000
Ultimate Bulletin Board 5.45c