PDA

View Full Version : Virus or Worm?



Xyvol
05-03-2002, 03:11 AM
I recived an suspicious e-mail the other night though Outlook Express. It was from a address that I knew, but it wasn't something that I had in my book, or anywhere for that matter. It was a friend's bussiness address, except that it had a _ in front. I checked with that person, and they told me they did not have my address. The message area was completely blank. But when it's opened, or previewed, a windows box pops up. I don't know if it's a copy file box or a download box because it's only there for a fraction of a second, then dissapears. I checked for viruses, found none. So if this thing is a worm, what's it do? Anybody know?

Saffith
05-03-2002, 03:44 AM
Not a lot of information there...
I'd guess that window that pops up is the program itself running. There's a bit of a major security issue than a lot of worms take advantage of. Incorrect MIME headers will make it run programs automatically. (Technically, that bug is in certain versions of IE, but I think it'll work the same in Outlook.)
I'm afraid I don't know enough about viruses and such to be of any real help. But try here: http://vil.nai.com/vil/default.asp.

Menokh
05-03-2002, 03:50 AM
My advice to you is to find a scanner for worms.
I'm not sure where to find one though.
But as Saffith said, it's most likely some program that the email tried to run.

I would also suggest using a different POP3 client than Outlook. Outlook and Outlook Express are known to have far too many security holes to be worth risking it.

inori
05-03-2002, 04:01 AM
There seem to be a lot of worms running around lately ... my university has anti-virus/worm software running automatically on my inbox, and I get notices whenever something's caught by the software. I've been getting a lot of notices recently.

The Silent Assassin
05-03-2002, 04:02 AM
It's the Klez E worm. It's been going around recently.

Menokh
05-03-2002, 04:03 AM
I just love the emails I get that are around 5-15k, but have no subject(or mayber a 're:'), and have no text inside and have a .vbs or .com or .exe file as the attachment.
Yeah, like I'm actually going to download one of those.

The Silent Assassin
05-03-2002, 04:09 AM
THis one is clever...it says it is from people you know...but I can tell it isn't because it doesn't have a "date" associated with the file.

Xyvol
05-03-2002, 05:39 AM
This mail doesn't have an attachment. But it's the file download window that pops up, I can sometimes make out the earth on one side and the folder on the other. I'm gonna search the net for that Klez E worm TSA mentioned. Any names for a anti-worm program I can get?

The Silent Assassin
05-03-2002, 05:41 AM
Go to Norton's page, they have a thing you can download and run to clear it out.