Notices
ScoobyNet General General Subaru Discussion

Homepage virus

Thread Tools
 
Search this Thread
 
Old May 9, 2001 | 09:57 PM
  #1  
MrData's Avatar
MrData
Thread Starter
Scooby Regular
 
Joined: Jan 2001
Posts: 342
Likes: 0
Angry

OK guys. The regular virus alerts that we see all the time p!ss me off, but I know first hand this one is for real.

Today we received a very similar virus to the LoveBug. Needless to say, we now know our exchange server is capable of sending 578 e-mails in 30 seconds.

The message arrives with homepage as the subject heading.

The text within the message simply says check out my cool homepage ;O).

The attached file was homepage.HTML.vbs

The curious turkeys at work actually clicked and hey presto - floods of e-mails.

Keep a close eye on this one. You're bound to get it.

The message originated from someone at the following domain
Reply
Old May 9, 2001 | 10:11 PM
  #2  
Puff The Magic Wagon!'s Avatar
Puff The Magic Wagon!
Moderator
25 Year Member
iTrader: (2)
 
Joined: May 2000
Posts: 16,980
Likes: 15
From: From far, far away...
Talking

Yup - we got this today too

Fortunately, spied, seen, apprehended and removed automatically by AV software Got paged as well

Had pleasure in deleting permanently later



Had another similar strain/different name as well today - I'm going to get the pager turned of, it's bugging me
Reply
Old May 9, 2001 | 10:18 PM
  #3  
MrData's Avatar
MrData
Thread Starter
Scooby Regular
 
Joined: Jan 2001
Posts: 342
Likes: 0
Wink

Puff.

Two questions......

a) Have you got that front spoiler yet

b) Do you recall who the virus came from?

Cheers
Data
Reply
Old May 9, 2001 | 10:26 PM
  #4  
Puff The Magic Wagon!'s Avatar
Puff The Magic Wagon!
Moderator
25 Year Member
iTrader: (2)
 
Joined: May 2000
Posts: 16,980
Likes: 15
From: From far, far away...
Talking

1) It's on it's way

2) Not at the moment as I am at home, on the beer & I deleted it hours ago! 1 virus definately came from an address with koolart in it, but I think that one was entitled "sales".
Reply
Old May 9, 2001 | 10:32 PM
  #5  
ChrisB's Avatar
ChrisB
Moderator
 
Joined: Dec 1998
Posts: 23,573
Likes: 0
From: Staffs
Thumbs up

<BLOCKQUOTE><font size="1" face="Verdana, Arial">quote:<HR>The message originated from someone at the following domain
Reply
Old May 9, 2001 | 10:39 PM
  #6  
MrData's Avatar
MrData
Thread Starter
Scooby Regular
 
Joined: Jan 2001
Posts: 342
Likes: 0
Wink

Puff.

What software are you running?

Ta
Kurt
Reply
Old May 9, 2001 | 10:49 PM
  #7  
Puff The Magic Wagon!'s Avatar
Puff The Magic Wagon!
Moderator
25 Year Member
iTrader: (2)
 
Joined: May 2000
Posts: 16,980
Likes: 15
From: From far, far away...
Talking

Dr Solomans or whatever it is nowadays - NAI Anti-Virus Suite - 2 year deal.

I have it polling constantly (well often ) for dat updates (leased line) & it integrates nicely with all aspects of our set-up

Added to this is my own draconian hold over the network & what users can/cannot do

Going to bed now, but drop me an email if you want a call about it...
Reply
Old May 9, 2001 | 10:50 PM
  #8  
Puff The Magic Wagon!'s Avatar
Puff The Magic Wagon!
Moderator
25 Year Member
iTrader: (2)
 
Joined: May 2000
Posts: 16,980
Likes: 15
From: From far, far away...
Talking

PS - My company doesn't sell AV software - we're a courier company
Reply
Old May 9, 2001 | 10:51 PM
  #9  
ChrisB's Avatar
ChrisB
Moderator
 
Joined: Dec 1998
Posts: 23,573
Likes: 0
From: Staffs
Cool

<BLOCKQUOTE><font size="1" face="Verdana, Arial">quote:<HR>Added to this is my own draconian hold over the network & what users can/cannot do <HR></BLOCKQUOTE>

Puff, you need to change your name to Puff the B O F H!

Reply
Old May 10, 2001 | 12:22 AM
  #10  
Toby C's Avatar
Toby C
Scooby Regular
 
Joined: Nov 1999
Posts: 108
Likes: 0
From: Cambridgeshire
Post

We've just had it. So guess what I've been doing all morning.

And I've found out our server can send 600 e-mails........Not bad for a little Dell.

Also Symantec have got downloads for this Virus.
Reply
Old May 10, 2001 | 07:19 AM
  #11  
philc's Avatar
philc
Scooby Regular
 
Joined: Mar 2001
Posts: 767
Likes: 0
From: NZ
Post

trapped 4 hits from this virus this a.m. on our gateway server.

thanx once again to MailMarshal (plug, plug), for saving the day -
Reply
Old May 10, 2001 | 07:54 AM
  #12  
Dave T-S's Avatar
Dave T-S
Scooby Regular
 
Joined: Aug 2000
Posts: 8,897
Likes: 4
From: Newmarket Suffolk
Wink

<BLOCKQUOTE><font size="1" face="Verdana, Arial">quote:<HR>Originally posted by Puff The Magic Wagon!:
<B>PS - My company doesn't sell AV software - we're a courier company [/quote]

But for a price, you'll deliver it......

Reply
Old May 10, 2001 | 04:48 PM
  #13  
JackClark's Avatar
JackClark
Scooby Senior
25 Year Member
Liked
Loved
Community Favorite
 
Joined: Dec 2000
Posts: 20,896
Likes: 53
From: Overdosed on LCD
Post

I do have shares in the company!

Glad to hear that our Generic detection worked for some of you, expect to see it in action again at a later date.

Some advice for all, block .vbs files at the gateway.
Reply
Old May 10, 2001 | 09:59 PM
  #14  
SiCotty's Avatar
SiCotty
Scooby Regular
 
Joined: Jan 2001
Posts: 442
Likes: 0
Post

You might also want to have a look at
Reply
Old May 10, 2001 | 10:13 PM
  #15  
47 NAT's Avatar
47 NAT
Scooby Regular
 
Joined: Dec 2000
Posts: 1,708
Likes: 0
From: In a village in Hants
Post

We had at work today some 161 messages with it attached, but luckily it never got through!!

Nath
Reply
Old May 10, 2001 | 10:26 PM
  #16  
Puff The Magic Wagon!'s Avatar
Puff The Magic Wagon!
Moderator
25 Year Member
iTrader: (2)
 
Joined: May 2000
Posts: 16,980
Likes: 15
From: From far, far away...
Talking

<BLOCKQUOTE><font size="1" face="Verdana, Arial">quote:<HR>Originally posted by Dave T-S:
<B> But for a price, you'll deliver it......

[/quote]

& a very competitive price too

Reply
Old May 10, 2001 | 11:31 PM
  #17  
johnfelstead's Avatar
johnfelstead
Scooby Regular
25 Year Member
 
Joined: Oct 1999
Posts: 11,440
Likes: 54
Thumbs up

thanks for the warning, i just got this in my hotmail account, it went straight in the bin!
Reply
Related Topics
Thread
Thread Starter
Forum
Replies
Last Post
Hanslow
Member's Gallery
5
Jul 8, 2001 12:37 PM
Hanslow
Member's Gallery
10
Jun 17, 2001 06:59 PM
a2jcy
ScoobyNet General
3
May 30, 2001 12:38 PM
Big RS Dave
ScoobyNet General
5
Apr 14, 2001 08:12 PM




All times are GMT +1. The time now is 08:51 PM.