Virus warning (no hoax) (Community)

Virus warning (no hoax) // Community

1  |  

ananas

Mar 16, 2001, 12:27am
This is a multi-part message in MIME format.
--------------814394042356A71EA2F76D02
Content-Type: text/plain; charset=us-ascii
Content-Transfer-Encoding: 7bit

Today I received 2 EMails from hahaha at sexyfun.net , both containing
TROJ_HYBRIS.B

The originator was definitely c.provan at ntlworld.com - he must be user of
ActiveWorlds or another AW based universe, as he asked me about the
AwStart installation. In the mail header of the two virus mails I could
see that both mails were sent from the same SMTP host as the two mails
he sent with his own account - and at about the same time.


I already informed abuse at ntlworld.com
--------------814394042356A71EA2F76D02
Content-Type: text/x-vcard; charset=us-ascii;
name="vha.vcf"
Content-Transfer-Encoding: 7bit
Content-Description: Card for Volker Hatzenberger
Content-Disposition: attachment;
filename="vha.vcf"

begin:vcard
n:Hatzenberger;Volker
x-mozilla-html:FALSE
url:oct31.de
adr:;;Bornheimer Strasse 15;Bonn;;53111;Germany
version:2.1
email;internet:vha at oct31.de
end:vcard

--------------814394042356A71EA2F76D02--

eep

Mar 16, 2001, 3:46am
Um, so what? New viruses appear every DAY, Ananas. Simply scan them for virii before executing them and you shouldn't have any problems.

Incidentally, that trojan attacks Microslop Outlook Express users (as usual) and automatically forwards itself to every user in the address book and every email address it ever comes across. It's VERY annoying; I've received at least 20 spams in the past month or so because of it.

[View Quote] > Today I received 2 EMails from hahaha at sexyfun.net , both containing
> TROJ_HYBRIS.B
>
> The originator was definitely c.provan at ntlworld.com - he must be user of
> ActiveWorlds or another AW based universe, as he asked me about the
> AwStart installation. In the mail header of the two virus mails I could
> see that both mails were sent from the same SMTP host as the two mails
> he sent with his own account - and at about the same time.
>
> I already informed abuse at ntlworld.com

ananas

Mar 16, 2001, 4:00am
This is a multi-part message in MIME format.
--------------3B64969B14ABFCB3F87C23C8
Content-Type: text/plain; charset=us-ascii
Content-Transfer-Encoding: 7bit

ok, thanks - I will warn the sender than :)

[View Quote] begin:vcard
n:Hatzenberger;Volker
x-mozilla-html:FALSE
url:oct31.de
adr:;;Bornheimer Strasse 15;Bonn;;53111;Germany
version:2.1
email;internet:vha at oct31.de
end:vcard

--------------3B64969B14ABFCB3F87C23C8--

xero

Mar 16, 2001, 5:52am
Thats an old virus, and if you go to sexyfun.net its a site that tells you
how to get rid of the virus and how they bought the domain to help people
get rid of the virus, lol..
[View Quote]

ananas

Mar 16, 2001, 11:59pm
This is a multi-part message in MIME format.
--------------12E854A55F9936317473CB03
Content-Type: text/plain; charset=us-ascii
Content-Transfer-Encoding: 7bit

It might be old but it seems to spread across AW at the moment. It
didn't infect my PC, I never have scripting enabled and never open
attachements before checking - but I think in this case it's better to
issue the warning.

[View Quote] begin:vcard
n:Hatzenberger;Volker
x-mozilla-html:FALSE
url:oct31.de
adr:;;Bornheimer Strasse 15;Bonn;;53111;Germany
version:2.1
email;internet:vha at oct31.de
end:vcard

--------------12E854A55F9936317473CB03--

datedman

Mar 17, 2001, 2:19pm
Anyone who hasn't gotten 5 copies of that by now is either a net newbie or a
statistical anomaly. :)

[View Quote] > It might be old but it seems to spread across AW at the moment. It
> didn't infect my PC, I never have scripting enabled and never open
> attachements before checking - but I think in this case it's better to
> issue the warning.
>
[View Quote]

wing

Mar 17, 2001, 5:06pm
As far as I know I haven't gotten that virus yet. And I sure aint a newbie.
Now a statistical anomaly is pretty likely concidering I get 9 copies of
happy99.exe every damned day and never anything else and have never been
infected by a legit virus. That I know of anyway. I should run a scan and
see if anything turns up :)
[View Quote]

datedman

Mar 17, 2001, 6:49pm
Hehe yeah yer anomalous! I see at least a couple a week of the dwarf4you come
through my antivirus gateway. Funny I hardly ever see happy99 tho... I suppose
we could trade some of our surplus virii. :)


[View Quote] > As far as I know I haven't gotten that virus yet. And I sure aint a newbie.
> Now a statistical anomaly is pretty likely concidering I get 9 copies of
> happy99.exe every damned day and never anything else and have never been
> infected by a legit virus. That I know of anyway. I should run a scan and
> see if anything turns up :)
[View Quote]

1  |  
Awportals.com is a privately held community resource website dedicated to Active Worlds.
Copyright (c) Mark Randall 2006 - 2024. All Rights Reserved.
Awportals.com   ·   ProLibraries Live   ·   Twitter   ·   LinkedIn