VIRUS WARNING!
#1
Senior Member
Thread Starter
Join Date: Apr 2002
Location: Collierville,
TN
Posts: 2,749
Likes: 0
Received 0 Likes
on
0 Posts
VIRUS WARNING!
I have no idea how/why but I received several emails today with the title "gyrator3.mpeg.scr" that have a virus attached!! Fortunately, uncle Norton shot 'em down for me and I didn't get the virus.
Since the filename is the same as the movie I uploaded months ago onto the design contest link at Bipe Flyer's site, I assume it's some pervert out there in cyberspace that somehow pinched the filename and doesn't like me. That's OK, I just hope none of you guys gets it!
I assure you, I have nothing to do with it whatsoever. I wouldn't even know how to get my hands on a virus, much less send it to someone!
Since the filename is the same as the movie I uploaded months ago onto the design contest link at Bipe Flyer's site, I assume it's some pervert out there in cyberspace that somehow pinched the filename and doesn't like me. That's OK, I just hope none of you guys gets it!
I assure you, I have nothing to do with it whatsoever. I wouldn't even know how to get my hands on a virus, much less send it to someone!
#2
Senior Member
Join Date: Oct 2002
Location: Creedmoor ,
NC
Posts: 977
Likes: 0
Received 0 Likes
on
0 Posts
RE: VIRUS WARNING!
are you sure dickey???i've noticed that you and the norvelites,are like the hatfield's&mcCoy's...getting rid of some norvelites is part of your master plan for total cox domination...
that was the PM i got yesturday...
just joking around,
john
that was the PM i got yesturday...
just joking around,
john
#3
RE: VIRUS WARNING!
I just received the same email and of course my system blocked it. Based on the email account I received it on and the body of the message it looks like it is specifically targeted at us smallsters.
Here is the message that accompanied with the attachment I received.
__________________________________________________ ___________
Dear Andy,
My .010 always ran reliably on Cox red Can fuel. I found that the prop
intended for .020s worked well on the.010 and gave me an added ability to
match the engine to whatever airplane I was trying to fly. Try it yourself.
George
Here is the message that accompanied with the attachment I received.
__________________________________________________ ___________
Dear Andy,
My .010 always ran reliably on Cox red Can fuel. I found that the prop
intended for .020s worked well on the.010 and gave me an added ability to
match the engine to whatever airplane I was trying to fly. Try it yourself.
George
#4
Senior Member
Join Date: Oct 2002
Location: Creedmoor ,
NC
Posts: 977
Likes: 0
Received 0 Likes
on
0 Posts
RE: VIRUS WARNING!
i just deleted all my e-mails...this is scary...i got the worm like a month ago...i don't want to go though that agian...
no joke this time...
john
no joke this time...
john
#5
Senior Member
Thread Starter
Join Date: Apr 2002
Location: Collierville,
TN
Posts: 2,749
Likes: 0
Received 0 Likes
on
0 Posts
RE: VIRUS WARNING!
Yup, no joke with this stuff. It's too scary for words.
Andrew, I over-reacted and instantly deleted the emails so I have no idea what the contents were.
Are you most often referred to as "Andy" or do you think the original message was sent to Andy Woitowicz? Geez, I hope whoever's doing this isn't a pi$$ed off Norvelite! All of my ramblings about Norvels are absolutely done tongue-in-cheek....surely everybody knows that?? I'd hate to think somebody's so bent over that stuff to try to ruin someone's equipment. This is SUPPOSED to be a fun forum.
Please, everybody STAY AWAY FROM THE ATTACHMENT "gyrator3.mpg.scr" and I guess if they were capable of sending that, they will send others with similar filenames. Please be cautious and GET A VIRUS PROGRAM!
Andrew, I over-reacted and instantly deleted the emails so I have no idea what the contents were.
Are you most often referred to as "Andy" or do you think the original message was sent to Andy Woitowicz? Geez, I hope whoever's doing this isn't a pi$$ed off Norvelite! All of my ramblings about Norvels are absolutely done tongue-in-cheek....surely everybody knows that?? I'd hate to think somebody's so bent over that stuff to try to ruin someone's equipment. This is SUPPOSED to be a fun forum.
Please, everybody STAY AWAY FROM THE ATTACHMENT "gyrator3.mpg.scr" and I guess if they were capable of sending that, they will send others with similar filenames. Please be cautious and GET A VIRUS PROGRAM!
#7
RE: VIRUS WARNING!
I am most often referred to as Andrew. The message didn't even get to my virus scanner as my system blocks ".scr" files from being accessd via email.
The header of the email is forged. It looks lie a joe job to me as apposed to a random attack.
The header of the email is forged. It looks lie a joe job to me as apposed to a random attack.
#8
Join Date: Oct 2002
Location: Chilliwack, BC, CANADA
Posts: 12,425
Likes: 0
Received 22 Likes
on
19 Posts
RE: VIRUS WARNING!
Guys, I was assuming that this was a virus being passed on by someone's infected machine without their knowledge. But if it's a malicious attack as it appears to be then please use your virus checker to quarantine the message and it's attachment. PM me and I'll pass the occurances onto Marc and the other big wigs for some serious attention.
They'll probably want you to do something that passes it onto them in a safe manner for further study.
If this IS an attack of any sort with intent you can bet your bippy that the user will be banned for life under any IP.
They'll probably want you to do something that passes it onto them in a safe manner for further study.
If this IS an attack of any sort with intent you can bet your bippy that the user will be banned for life under any IP.
#9
Senior Member
My Feedback: (3)
Join Date: Nov 2002
Location: Durham, NC
Posts: 506
Likes: 0
Received 0 Likes
on
0 Posts
RE: VIRUS WARNING!
yup. I got it too. My Norton didn't catch it, I saw it late last night and luckily came here before I checked my email again.
For what it's worth, I am also on the 049Collectors yahoo list and about a week and a half ago there were two emails sent out to the list that had viruses. Both sent from suspicious "microsoft" address and both contained different strains of the same virus.
My Norton got those so I was safe, but still, they were sent specifically to Cox lovers...
..now this, wonder who/ or what it is...
I'm just glad that everyone is ok here....
timothy
For what it's worth, I am also on the 049Collectors yahoo list and about a week and a half ago there were two emails sent out to the list that had viruses. Both sent from suspicious "microsoft" address and both contained different strains of the same virus.
My Norton got those so I was safe, but still, they were sent specifically to Cox lovers...
..now this, wonder who/ or what it is...
I'm just glad that everyone is ok here....
timothy
#10
Senior Member
Join Date: Oct 2002
Location: Creedmoor ,
NC
Posts: 977
Likes: 0
Received 0 Likes
on
0 Posts
RE: VIRUS WARNING!
guys you have to know,I WAS JOKEING IN POST 2...please don't take offence to what i said...
what do you think this virus will do to a puter???if it's like the worm,it will screw up everything...
john
what do you think this virus will do to a puter???if it's like the worm,it will screw up everything...
john
#11
Senior Member
Thread Starter
Join Date: Apr 2002
Location: Collierville,
TN
Posts: 2,749
Likes: 0
Received 0 Likes
on
0 Posts
RE: VIRUS WARNING!
UPDATE: I'm still getting emails with the "gyrator3.mpg.scr" virus attached but today a new wrinkle appeared. Now it's "gyrator3.mpeg.pif" and it slipped through Norton. It comes from various well-known "S.M.A.L.L.sters" which disturbs me. Please keep your eyes open and DON'T OPEN ANY ATTACHMENTS WITH THAT NAME!
#12
Senior Member
My Feedback: (5)
Join Date: Mar 2002
Location: LITTLE ROCK,
AR
Posts: 940
Likes: 0
Received 0 Likes
on
0 Posts
RE: VIRUS WARNING!
DICKEY.....I'm a NORVELITE as you know.....I hope it's not one of us!!! I'll whoop a yellow dog 'norvelite' who tries some sneaky mess like that!!!!! CAN'T WE ALL JUST GET ALONG????? :-0
I hate to say this, but I have not gotten this e-mail yet. I wonder if it's just using the e-mail list of the people who opened it? Let's hope so.
Anyway, Long live Cox and Norvel. Now go fly something.
I hate to say this, but I have not gotten this e-mail yet. I wonder if it's just using the e-mail list of the people who opened it? Let's hope so.
Anyway, Long live Cox and Norvel. Now go fly something.
#13
Senior Member
Join Date: Jul 2003
Location: Hilo,
HI
Posts: 179
Likes: 0
Received 0 Likes
on
0 Posts
RE: VIRUS WARNING!
Dickeybird,
Be sure to contact the people you are getting the virus from as they may have a Trojan or Worm running on their systems and not know it.........
Bill Sindel
P.S. using the reply function would not be nice.
Be sure to contact the people you are getting the virus from as they may have a Trojan or Worm running on their systems and not know it.........
Bill Sindel
P.S. using the reply function would not be nice.
#15
Senior Member
Thread Starter
Join Date: Apr 2002
Location: Collierville,
TN
Posts: 2,749
Likes: 0
Received 0 Likes
on
0 Posts
RE: VIRUS WARNING!
ORIGINAL: bsindel
Be sure to contact the people you are getting the virus from as they may have a Trojan or Worm running on their systems and not know it.
Be sure to contact the people you are getting the virus from as they may have a Trojan or Worm running on their systems and not know it.
To: <[email protected]>
Subject: Returned mail: Service unavailable
Date: Wednesday, October 22, 2003 7:04 AM
#16
Senior Member
Join Date: Jul 2003
Location: Hilo,
HI
Posts: 179
Likes: 0
Received 0 Likes
on
0 Posts
RE: VIRUS WARNING!
That sounds like the headers are forged. Can those same folks be contacted via their regular email address? Oh well, it sure looks like someone out there is being a real pill. Thus far I have not seen one of these emails, so I guess that the attack is coming from some other direction than RCU.
If you know someone who is a real computer guru, get them to look at the forged header on the email. They may be able to identify the server or Internet provider where the messages are originating. If you can ID the IP you might be able to find out who the PITA is.
Bill Sindel
Edit:
Oh yeah, contact your internet service provider, they may be able to help identify this BOZO.
If you know someone who is a real computer guru, get them to look at the forged header on the email. They may be able to identify the server or Internet provider where the messages are originating. If you can ID the IP you might be able to find out who the PITA is.
Bill Sindel
Edit:
Oh yeah, contact your internet service provider, they may be able to help identify this BOZO.
#17
RE: VIRUS WARNING!
This has just reared its ugly head again. I received "Gyrator3.mpeg.pif". The return address is forged to look like a SMALLnet posting with the title "Sub 08 10-23-01" and the message body is a portion of the first paragraph of the SMALLnet post 395RR08.
#18
RE: VIRUS WARNING!
In all likelihood, the source of the email is unaware they're sending infected email. The double extension is very characteristic of many of the email virii -- typically, the virus will harvest both TO: and FROM: addresses out of the infected machine's address book and may insert into the subject and body portions of messages with a .DOC or .TXT found in the My Documents folder or other system folders of the originating computer.
While some of these virii do have malicious payloads, the majority are resenders -- unfortunately, we have to treat each as potentially harmful. I regularly receive notification that one of my emails has been picked up by a scanning server and returned to me as infected. Actually, the email was sent by another computer using my harvested address as the email source.
The originating computer is often hard to track because the virus uses its own SMTP engine and is capable of falsifying the headers before transmission. The best weapon is a good anti-virus routine that has up-to-date data files.
Over 60% of our incoming traffic is rejected by our packet shaper as either infected or as a port scan -- while the internet gives us this forum, it also brings a lot of aggrevation.[:@]
While some of these virii do have malicious payloads, the majority are resenders -- unfortunately, we have to treat each as potentially harmful. I regularly receive notification that one of my emails has been picked up by a scanning server and returned to me as infected. Actually, the email was sent by another computer using my harvested address as the email source.
The originating computer is often hard to track because the virus uses its own SMTP engine and is capable of falsifying the headers before transmission. The best weapon is a good anti-virus routine that has up-to-date data files.
Over 60% of our incoming traffic is rejected by our packet shaper as either infected or as a port scan -- while the internet gives us this forum, it also brings a lot of aggrevation.[:@]
#19
Senior Member
Thread Starter
Join Date: Apr 2002
Location: Collierville,
TN
Posts: 2,749
Likes: 0
Received 0 Likes
on
0 Posts
RE: VIRUS WARNING!
Thanks Andrew & Andrew....I'd TOTALLY forgotten this thread and would have tried to open any email with "Gyrator" in the title! (Poor little 'gyro never hurt anyone!)
#20
RE: VIRUS WARNING!
The odd thing is that the email, payload and recipients are all modelling related and nobody's virus scanner has identified it as a specific virus.
#21
Banned
Join Date: Mar 2003
Location: Tokoroa, , NEW ZEALAND
Posts: 3,848
Likes: 0
Received 0 Likes
on
0 Posts
RE: VIRUS WARNING!
Remember the golden rule -- *NEVER* open any unsolicited attachments, even if they appear to be valid files from people you know.
If you get an inexpected attachment by email from a friend, don't open it until you've emailed them to confirm that they actually did send it and that it's safe to open.
Following this simple rule can reduce the chances of getting infected to virtually zero percent.
If you get an inexpected attachment by email from a friend, don't open it until you've emailed them to confirm that they actually did send it and that it's safe to open.
Following this simple rule can reduce the chances of getting infected to virtually zero percent.
#22
My Feedback: (3)
Join Date: Nov 2002
Location: Russell, PA
Posts: 805
Likes: 0
Received 0 Likes
on
0 Posts
RE: VIRUS WARNING!
Email can be rid of bad stuff, I have used Benign for some time. Check out the site link below, its free to try and it works.
http://www.firetrust.com/products/benign/
This should help stop the threat from email trouble for all ..
. Also, all virus scan software is not the same. Do some checking on what you use to see how effective others say it works..
Remby
http://www.firetrust.com/products/benign/
This should help stop the threat from email trouble for all ..
. Also, all virus scan software is not the same. Do some checking on what you use to see how effective others say it works..
Remby