Medical Forum / Diseases and Disorders / Lupus / September 2003
OT: Help! Multiple Virus Attacks!
|
|
Thread rating:  |
Mair - 20 Sep 2003 15:51 GMT Hi, I downloaded Norton 2003 Antivirus Suite last weekend. In the past three days I have started getting smacked with dozens of infected letters. A lot of them are that "Microsoft Security...." stuff, and some of them are erroneous "returned mail."
Can one of you "computer smarties" tell me what's happening, and how I can stop it? I got 22 letters this morning that were simply virus carriers. And it is all the same virus Worm. AB thingy. The virus protection is great, but it makes me stop and verify each of these letters that comes in, which takes a lot of time. Why am I suddenly getting these now? Is it something in the Security System that the virus is detecting? Maybe it is a former creditor trying to make my life miserable?
Thanks in Advance
Mair
--
stingo2@earthlink.net http://radio.weblogs.com/0114986/
BJ - 20 Sep 2003 15:56 GMT Not a clue here Mary. I have been getting them too. All I know to do is delete them right away. Must be someone without a life. BJ-Sk. Canada
> Hi, > I downloaded Norton 2003 Antivirus Suite last weekend. In the past three [quoted text clipped - 19 lines] > stingo2@earthlink.net > http://radio.weblogs.com/0114986/ Melanie Angel - 20 Sep 2003 16:11 GMT I had 552 yesterday an now my outlook is trying to download another 113 and like you I have to verify it each time so cant just leave the pc running on its own to download them all :0(
There is something about it on symantec which I believe is www.symantec.com
Lots of love Mel xxx
> Not a clue here Mary. I have been getting them too. All I know to do is > delete them right away. Must be someone without a life. [quoted text clipped - 25 lines] > > stingo2@earthlink.net > > http://radio.weblogs.com/0114986/ Marg Watson - 20 Sep 2003 18:08 GMT Me too!
I have to watch it as I don't get much space with the webtv & each takes up 6% to 7%
I went to a webtv help group & one lady thought she was getting spammed from an eBay buyer out of Hades, so she called MSN & they verified the virus & are aware of the problem. They apparently are working on it.
Maggie
Wende - 21 Sep 2003 15:36 GMT Mary, we have been gettingthem too along with the other crap, so you are not alone. ((((((((MAIR& PIGMET))))))) Wende
> Not a clue here Mary. I have been getting them too. All I know to do is > delete them right away. Must be someone without a life. [quoted text clipped - 25 lines] > > stingo2@earthlink.net > > http://radio.weblogs.com/0114986/ J - 21 Sep 2003 16:27 GMT You too BJ? I thought it was only people, like me, who'd posted to newsgroups, when not spam-proofed. they take forever to download on dial-up eh? (here anyway) J
> Not a clue here Mary. I have been getting them too. All I know to do is > delete them right away. Must be someone without a life. Andy - 21 Sep 2003 19:31 GMT In article <3F6DC37F.C86BD5A1@execulink.com>, J <FakeE@invalid.invalid> wrote
>You too BJ? >I thought it was only people, like me, who'd posted to newsgroups, when not >spam-proofed. Apparently names are taken from (a) newsgroups (b) hard disks on infected machines (including but not limited to Microsoft address books on them). The record so far is 35 minutes from posting with a newly invented name to it receiving a spam. There is a story that names including "spam" or "delete" are immune - eg it would attack andy@ but ignore andy.spam@ - but this is not an established fact.
>they take forever to download on dial-up eh? (here anyway) here also... 1 hour 45 minutes this morning...
One irritating point is that aol are filtering out the worm, so the Ferrous Fuckwit's latest posting will not send him the 123,456 copies he deserves.
 Signature Andy [Chair, N E Lupus Group] See http://www.kitzbuhel.demon.co.uk/lupus for more!
Robert Musicant - 21 Sep 2003 21:55 GMT > You too BJ? > I thought it was only people, like me, who'd posted to newsgroups, when not > spam-proofed. > they take forever to download on dial-up eh? (here anyway) > J J, I think most of the major internet service providers offer a webview of mail waiting for you on their server before it is downloaded to your computer. Using Eathlink, for example, I check in to https://webmail.atl.earthlink.net/ , sign in, and get to look at the headings of all the messges waiting, and delete all the obvious messages of this type. My problem, therefore, is not that I have all this getting onto my computer, but that a few hours' worth of these messages pouring in takes up all the 10 MB of space allocated to me on the ISP's mail server.
Bob
Melanie Angel - 22 Sep 2003 08:47 GMT Hi Bob,
I have the same problem here. I have to go to tiscali and open up my email there delete all the ones I dont want then let outlook grab the rest but like you I only have 10mb of space (not like AOL which this person is on) so all my genuine emails are either getting bounced or que'd until later :0(
Lots of love Mel xxxx
> > You too BJ? > > I thought it was only people, like me, who'd posted to newsgroups, when [quoted text clipped - 14 lines] > > Bob Bob Musicant - 22 Sep 2003 13:05 GMT > Hi Bob, > [quoted text clipped - 5 lines] > Lots of love > Mel Mel, What does AOL have? Bob
J - 23 Sep 2003 11:10 GMT > I think most of the major internet service providers offer a webview of mail > waiting for you on their server before it is downloaded to your computer. [quoted text clipped - 4 lines] > my computer, but that a few hours' worth of these messages pouring in takes > up all the 10 MB of space allocated to me on the ISP's mail server. Hello Bob and all who are following this thread. I opted to get rid of my real e-mail address and create a new one and thereby (temporarily at least) lose them. J
Bob Musicant - 24 Sep 2003 23:16 GMT > > I think most of the major internet service providers offer a webview of mail > > waiting for you on their server before it is downloaded to your computer. [quoted text clipped - 7 lines] > Hello Bob and all who are following this thread. > I opted to get rid of my real e-mail address <snip>
So I see : )
J - 25 Sep 2003 01:08 GMT > > Hello Bob and all who are following this thread. > > I opted to get rid of my real e-mail address > <snip> > > So I see : ) How? I've been spam-proofed for quite a while. I changed my real e-mail address to another real e-mail address. J
Bob Musicant - 26 Sep 2003 00:58 GMT > > > Hello Bob and all who are following this thread. > > > I opted to get rid of my real e-mail address [quoted text clipped - 5 lines] > I changed my real e-mail address to another real e-mail address. > J J - I was referring to the address I see at the top of this message.
Bob
Paula Love - 20 Sep 2003 18:35 GMT ~Hi, ~I downloaded Norton 2003 Antivirus Suite last weekend. In the past three ~days I have started getting smacked with dozens of infected letters. A lot ~of them are that "Microsoft Security...." stuff, and some of them are ~erroneous "returned mail."
i get 8-10 ofthose a day, yes it is a virus no im not sure how to fix it, since im on a mac i have all the .EXE files going to the trash, hopefully someone else can help here......
~I got 22 letters this morning that were simply virus carriers. And it is ~all the same virus Worm. AB thingy. The virus protection is great, but it ~makes me stop and verify each of these letters that comes in, which takes a ~lot of time. Why am I suddenly getting these now? Is it something in the ~Security System that the virus is detecting? Maybe it is a former creditor ~trying to make my life miserable? ~ ~Thanks in Advance ~ ~Mair ~ ~-- ~ ~stingo2@earthlink.net ~http://radio.weblogs.com/0114986/
 Signature Paula from AL.
Sharon - 21 Sep 2003 03:35 GMT > ~Hi, > ~I downloaded Norton 2003 Antivirus Suite last weekend. In the past three [quoted text clipped - 16 lines] > ~ > ~Mair <snip>
It's the new worm going around unfortunately. Hotmail isn't filtering them out, but yahoo is. I'm getting about 20 or more a day in my Hotmail box, which makes me go over my email quota. Hopefully nothing bounced if someone tried to email me there when the box was over quota!
The subject headings so far seem to be MS patches and email failure delivery. Just don't open them, delete them and hopefully the ISP's should start blocking them soon.
-Sharon
 Signature "Don't make me come down there..." -God
Sherry - 21 Sep 2003 04:06 GMT Another thing that you can do if you are using Outlook or Outlook Express 6. Go to the Tools/ slide down to options (click)/ security (click)/ then check the box that says do not allow attachments to be saved or opened that could potentially be a virus. Then click apply and then ok.
Unfortunately it is possible that it will keep you from opening something that you know is safe and you want to open. In this case you will have to follow above steps and uncheck the box. Then return and change it back.
Sherry
> > ~Hi, > > ~I downloaded Norton 2003 Antivirus Suite last weekend. In the past three [quoted text clipped - 28 lines] > > -Sharon Candi Bowen - 25 Sep 2003 22:05 GMT Unfortunately, if you have a Mac & use Outlook Express, you HAVE to open the messages in order to delete them. If you click once, it opens the file - too late; you're infected even before you can hit delete. And you have to click once to highlight it, to delete it. This one seems to be able to cross platforms since everyone is having the same problem. Most worms are created for Windows users & the only worm I've come across for Mac is called Mac.Simpsons@mm, yet this new one's doing the same thing for everyone, & Norton AntiVirus says I don't have it so it's probably pretty new & they don't have the RX to get rid of it yet. I'm sure the inventors of this worm/virus are having a heyday right now. Hopefully, it'll be resolved soon.
Candi ----------
>> ~Hi, >> ~I downloaded Norton 2003 Antivirus Suite last weekend. In the past three [quoted text clipped - 28 lines] > >-Sharon Sherry - 25 Sep 2003 22:45 GMT Candi, If you use outlook express to read your mail on your mac or any other computer you can close the prieview pane and then you can delete messages without them opening.
you can right click on the toolbar and then click on customize...add prieview pane to the toolbar and you are set. I always have the preview pane option set so that I can delete any mail that I do not want to read and it won't open. then I use the prieview pane icon on my toolbar and then view the messages that I want to read. After done I close the preview pane again.
Andy might be able to tell you if there is another way to do this. It can be a pane but it sure helps you delete mail and not get stuck with it opening be it a virus or the "porn" or other unsolicted junk we sometimes get.
Hope that helps.
Hugs, Sherry
> Unfortunately, if you have a Mac & use Outlook Express, you HAVE to open the > messages in order to delete them. If you click once, it opens the file - too [quoted text clipped - 42 lines] > > > >-Sharon Sherry - 26 Sep 2003 00:15 GMT Oops I forgot the important part.
To disable the preview pane in Outlook Express:
Select View | Layout... from the menu in Outlook Express. Make sure Show preview pane is not checked. Click OK. You can also click Apply to put the new settings into effect without closing the configuration dialog.
Sherry
> Candi, > If you use outlook express to read your mail on your mac or any other [quoted text clipped - 76 lines] > > > > > >-Sharon Andy - 26 Sep 2003 17:42 GMT >Candi, >If you use outlook express to read your mail on your mac or any other [quoted text clipped - 12 lines] >opening be it a virus or the "porn" or other unsolicted junk we sometimes >get. I neither use nor have Outlook (express or slow), but everywhere I read that with "modern" viruses, opening a message in the preview pane which contains a virus will activate the virus, and the only safe thing to do with the preview pane is turn it off!
I don't know how to delete messages unread in O/OE - can someone out there help?
 Signature Andy [Chair, N E Lupus Group] See http://www.kitzbuhel.demon.co.uk/lupus for more!
Candi Bowen - 26 Sep 2003 22:46 GMT Thanks but right click on a Mac mouse isn't the same as right click with a Windows-based mouse. My right click OPENS; doesn't bring up any dialog box. I have to use a Mac because I'm a graphic designer, but things are different when you navigate between the 2 platforms. Are you aware that Windows was created to emulate the Macintosh environment, since it's so user friendly, back when when DOS predominated? Changed some things, but Mac was the 1st in menu driven applications. Do you do design? If you do, you have to realize that the advertising industry is still predominantly Mac based,in part, because of the very expensive output devices that the service bureaus have purchased, which are still Mac based. Yeah Fiery Rips work to a cedrtain extent, but in a perfect world, we'll all be on the same page, but it hasn't happened yet. It's coming close tho. I know service bureau owners who get hives when they get Windows files because they just don't translate well, especially text.
Unfortunately, my version of Outlook Express doesn't look like most of yours. I wish it did.
Candi
----------
>>Candi, >>If you use outlook express to read your mail on your mac or any other [quoted text clipped - 20 lines] >I don't know how to delete messages unread in O/OE - can someone out >there help? kcat - 20 Sep 2003 22:31 GMT >Hi, >I downloaded Norton 2003 Antivirus Suite last weekend. In the past three [quoted text clipped - 4 lines] >Can one of you "computer smarties" tell me what's happening, and how I can >stop it? You can't stop it - but with NAV you should be able to find the radio button or checkbox that says not to ask you if you want it deleted but to go ahead and delete it. that way it happens behind the scenes.
I have 69 of the **** things in this account but Newsguy is so bogged down by them that i can't clear them all.
grr..
Wesley - 21 Sep 2003 03:38 GMT Me too! Is someone attacking members of this group?
> >Hi, > >I downloaded Norton 2003 Antivirus Suite last weekend. In the past three [quoted text clipped - 13 lines] > > grr.. J - 21 Sep 2003 09:58 GMT It's everywhere/one Wes, it's mail bombing attacks combined with viruses, Trojans and worms. J
> Me too! Is someone attacking members of this group? Robert Musicant - 20 Sep 2003 22:50 GMT > Hi, > I downloaded Norton 2003 Antivirus Suite last weekend. In the past three > days I have started getting smacked with dozens of infected letters. A lot > of them are that "Microsoft Security...." stuff, and some of them are > erroneous "returned mail." Mair, It's just coincidence that you installed the Antivirus and you started getting these messages. It hit on Thursday, I think. When it installs itself on someone's computer, it sends copies of itself to everyone in that person's address book, and the process starts again. I'm getting hundreds of these a day, and I don't know what to do about it. Bob
Shelagh - 21 Sep 2003 00:01 GMT Yup... it happened here too... tons of them daily.... soooo annoying!! -----Shelagh "Robert Musicant" <musicant@mindspring.com> wrote in message
> Mair, > It's just coincidence that you installed the Antivirus and you started [quoted text clipped - 3 lines] > of these a day, and I don't know what to do about it. > Bob Sharon - 21 Sep 2003 03:43 GMT >>Hi, >>I downloaded Norton 2003 Antivirus Suite last weekend. In the past three [quoted text clipped - 12 lines] > of these a day, and I don't know what to do about it. > Bob Someone on another ng speculated that spammers have downloaded the worm and now the worm is sending out to all their vicims on the spam list.
-Sharon
 Signature "Don't make me come down there..." -God
RhondaM - 21 Sep 2003 01:25 GMT getting them here too since yesterday
> Hi, > I downloaded Norton 2003 Antivirus Suite last weekend. In the past three [quoted text clipped - 19 lines] > stingo2@earthlink.net > http://radio.weblogs.com/0114986/ Andy - 21 Sep 2003 12:13 GMT >Hi, >I downloaded Norton 2003 Antivirus Suite last weekend. In the past three [quoted text clipped - 10 lines] >Security System that the virus is detecting? Maybe it is a former creditor >trying to make my life miserable? It's the SWEN worm. There seem to be two types of email: one with an about-150kb attachment, and one that looks like a bounce message. As I type, I am downloading about 350 of them - luckily I have a BIG mail spool...
Usual rules apply:
1 DO NOT OPEN an attachment unless you are sure who it's from *and* you are expecting it
2 If you use Outlook, disable the Preview pane
3 Don't bother bouncing them - the address is probably forged
4 Remember that Microsoft do not distribute patches by email
5 And unless you work in a large office you don't have a "local administrator" so kill his patches also.
6 If you find who created the worm, sauté his genitals.
One possible way of stopping it is if you can limit the size of messages you will accept - that depends on your programs and on your ISP, and would also kill photos of relatives etc. But for many people, who receive text-only messages, killing say "everything over 15kb" will help.
 Signature Andy [Chair, N E Lupus Group] See http://www.kitzbuhel.demon.co.uk/lupus for more!
kcat - 21 Sep 2003 17:09 GMT keeping these intact:
>Usual rules apply: > [quoted text clipped - 11 lines] > >6 If you find who created the worm, sauté his genitals. LOL! A new twist on Mountain Oysters eh? :) k
Marg Watson - 21 Sep 2003 18:17 GMT How come you're getting them J? How'd they find your box with all those invalid email addys you use? That's just scarey.
They didn't get through to my Yahoo either, nor did they make it into any of my other user names at webtv. <shhhh!>
Maggie
bruce - 21 Sep 2003 19:22 GMT > They didn't get through to my Yahoo either, nor did they make it into > any of my other user names at webtv. <shhhh!> > Maggie Hi Maggie :))
Well I must be the one without a life. "I heard that Janers !!" My only mail is through hotmail ,they charck then my norton on my pc check. Norton is auto updating neer every day now so there must be a mess out there. I only let in the family here and a few I subscride to. All else is blocked. Bruce On. " circled wagons make for a smaller train , but more secure:)) "
Marg Watson - 21 Sep 2003 22:13 GMT Bruce wrote:
Well I must be the one without a life.
-------------------- Awww! I'm so sorry. I will kindly forward you some, Bruce. : ) I'll even do that blind cc thing, just for you. --------------------
Maggie : )
Sherry - 21 Sep 2003 19:41 GMT Maggie, The unfortunate thing is when we forward something that has been forwarded to us and do not remove the address of who it came from and who they sent it to then everypnes e-mail addy is circulating around the world. The best thing is to edit it before forwarding and send it to blind carbon copies if sending to lots of people. Keeps the e-mail address more private and harder for the spammers to retrieve.
I read something on one of the antivirus things that said people using Webtv should make sure thatthey have a firewall as well as an antivirus program.
Yahoo is also filtering my e-mail and only the ones I want are making it to my outlook so I have not been flooded with the virus e-mails.
Sherry
> How come you're getting them J? How'd they find your box with all those > invalid email addys you use? That's just scarey. [quoted text clipped - 3 lines] > > Maggie Andy - 21 Sep 2003 21:50 GMT >Maggie, >The unfortunate thing is when we forward something that has been forwarded [quoted text clipped - 3 lines] >sending to lots of people. Keeps the e-mail address more private and harder >for the spammers to retrieve. This is true for emails - however this beastie seems to be grabbing names from newsgroups like this. For these you cannot delete the where-from info, otherwise your PC doesn't know what you have replied to, which makes conversation difficult.
One idea is to invent a name used only for newsgroup postings, and reject all email to it. You need to provide a way for people to email you (eg stated in text in your sig*) unless you decide not to allow any emailed follow-ups to news postings.
eg: "send emailed replies to mary23 at phoenix dot net"
 Signature Andy [Chair, N E Lupus Group] See http://www.kitzbuhel.demon.co.uk/lupus for more!
kcat - 21 Sep 2003 23:21 GMT >This is true for emails - however this beastie seems to be grabbing >names from newsgroups like this. yup. it's only my newsgroup addies and my old ghg addy that are getting bombed with this stuff. sbc is filtering perfectly. I don't understand why newsguy can't - they've always filtered most everything else.
Andy - 22 Sep 2003 08:57 GMT >>This is true for emails - however this beastie seems to be grabbing >>names from newsgroups like this. [quoted text clipped - 3 lines] >understand why newsguy can't - they've always filtered most everything >else. Apparently this worm is not consistent, so there isn't an easy test for it. Eg, I find its messages vary from 144 to 156Kb, and the contents vary slightly.
 Signature Andy [Chair, N E Lupus Group] See http://www.kitzbuhel.demon.co.uk/lupus for more!
Marg Watson - 21 Sep 2003 22:00 GMT Sherry Wrote:
The best thing is to edit it before forwarding and send it to blind carbon copies if sending to lots of people. -----------------------
I have a cousin that does that & another cousin that sends it with 400 other address. I don't understand it. I rarely forward stuff & if I do, I always cc&p it, but I don't do the blind thing. Gonna learn how though. Thanks!
I read something on one of the antivirus things that said people using Webtv should make sure that they have a firewall as well as an antivirus program. -------------------------
I don't think this is possible unless they provide it in an update. We can't download anything & there's no software. Hmmm? We also cannot be affected by viruses, but I don't open spam as I fear they may still be able to access my addy book & infect others.
Fortunately this worm we are all getting had the header of the MSN patch at first & I deleted it, unopened, as I felt it was quite ignorant of MSN to send it to a webtv'er & then when they kept showing up, I checked a webtv ng & saw what they were.
I don't know, but I'm willing to go dibs on a plane ticket to send this butthead to Andy, if they find him.
Maggie : )
Andy - 22 Sep 2003 08:58 GMT [
>I don't know, but I'm willing to go dibs on a plane ticket to send this >butthead to Andy, if they find him. I'll start warming up the oil now.
 Signature Andy [Chair, N E Lupus Group] See http://www.kitzbuhel.demon.co.uk/lupus for more!
J - 21 Sep 2003 20:00 GMT > How come you're getting them J? How'd they find your box with all those > invalid email addys you use? That's just scarey. I wasn't spamproofing until recently.
> They didn't get through to my Yahoo either me either, which made me think it's coming from newsgroup posts. or e-mail lists. (which I try very hard to ask ppl to take me off or blind-copy (don't show the e-mail addy's of everyone they're sending to). Bev's very good about that. I can't seem to train relatives or off-group friends about that though, so I quit replying to them, if they don't get it after several times explaining.
> , nor did they make it into > any of my other user names at webtv. <shhhh!> Ah...the benefits of webtv eh? Lucky you :-) Hugs J
Marg Watson - 21 Sep 2003 22:08 GMT I wasn't spamproofing until recently. ----------------
Ahhhh! I see. Thank goodness! I was thinking about wrapping my webtv unit in heavy duty foil. : )
which made me think it's coming from newsgroup posts. or e-mail lists. -----------------
Both, I think. My brother has been getting them & he doesn't post at ng's, but he gets those same 'cousin' emails, that I do---with 400 names attached.
Maggie
Candi Bowen - 24 Sep 2003 01:14 GMT I'm getting over 100 a day & am trying to figure it out; I have a Macintosh & am supposed to be immune to most worms, but not viruses.
Camdo ----------
>Hi, >I downloaded Norton 2003 Antivirus Suite last weekend. In the past three [quoted text clipped - 19 lines] >stingo2@earthlink.net >http://radio.weblogs.com/0114986/ Andy - 24 Sep 2003 11:05 GMT >I'm getting over 100 a day & am trying to figure it out; I have a Macintosh >& am supposed to be immune to most worms, but not viruses. Having a Mac doesn't stoop you being sent the messages, it only denies them the opportunity to do their thing.
 Signature Andy [Chair, N E Lupus Group] See http://www.kitzbuhel.demon.co.uk/lupus for more!
Candi Bowen - 24 Sep 2003 16:24 GMT It's still VERY annoying. The only worm a Mac is susceptible to is called Mac.Simpsons@mm, & apparently we've contracted it.
Candi ----------
>>I'm getting over 100 a day & am trying to figure it out; I have a Macintosh >>& am supposed to be immune to most worms, but not viruses. >> >Having a Mac doesn't stoop you being sent the messages, it only denies >them the opportunity to do their thing. Bob Musicant - 25 Sep 2003 03:11 GMT Candi,
If you are talking about the multiple messages that appear to be (but are not) coming from Microsoft, it is not you who has the worm. The worm infrects PCs, and then starts sending these out to all the addresses in that PC's address book. It is irrelevant whether you have a Mac or a PC. It is a little like being sneezed on by someone who has a virus.
Bob
> It's still VERY annoying. The only worm a Mac is susceptible to is called > Mac.Simpsons@mm, & apparently we've contracted it. [quoted text clipped - 7 lines] > >Having a Mac doesn't stoop you being sent the messages, it only denies > >them the opportunity to do their thing.
|
|
|