Community
Search
Notices
The Clubhouse If it doesn't fit in any other category and is about general RC stuff then post it here at the Clubhouse.

Virus Caution

Thread Tools
 
Search this Thread
 
Old 10-13-2003 | 10:03 PM
  #1  
Thread Starter
 
Joined: Oct 2002
Posts: 232
Likes: 0
Received 0 Likes on 0 Posts
From: Hazel Green, AL
Default Virus Caution

I received an email with the W32 Bugbear.b@mm virus attached this evening. It was from "R/C Groups Discussion Group Mailer, and the subject was "Reply to Post "What Did You Get For Fathers Day". The infection was in the attachment "address book.mdb.scr" and the size of the attachment was 70.5KB.

The reason that I am posting this is that the email and the message in the body looked identical to the R/C Universe emails that you receive when there is a reply to a thread or post that you are watching. Also, this is the only forum I belong to, so chances are it is from some low life who has read or reads RCU.

My Norton Antivirus picked it up immediately, but if you have another antivirus or none at all be sure to check your email attachments carefully. Keep your eyes open so that this gutless scum doesn't infect your computer.[>:]

Happy Flying
Old 10-14-2003 | 07:25 AM
  #2  
*Crash*Johnson*'s Avatar
Senior Member
My Feedback: (7)
 
Joined: Apr 2003
Posts: 1,089
Likes: 0
Received 0 Likes on 0 Posts
From: Here, NJ
Default RE: Virus Caution

ORIGINAL: gfinan

Keep your eyes open so that this gutless scum doesn't infect your computer.[>:]

Happy Flying
Your warning is appreciated, yet is a little harsh. Viruses are tricky little buggers, and I SERIOUSLY doubt someone would get a virus and send it out on purpose. When a computer gets infected, it can use any email that was received, and mimic it and blast it out to any email address it can find in it's address book (or elsewhere for that matter).

Whoever is sending it out probably has no idea he / she is even infected.

now if they are doing it on purpose, then I can understand the gutless scum comment....
Old 10-14-2003 | 07:27 AM
  #3  
Grumpy Monkey's Avatar
My Feedback: (7)
 
Joined: Feb 2002
Posts: 448
Likes: 0
Received 0 Likes on 0 Posts
From: Bridgewater, NJ
Default RE: Virus Caution

Gfinan,
Obviously, you need to do a little research before posting in a harsh maneer about RCU readers. It looks to me like a mailing worm. People get these in their email and if they dont have antivirus software, it attaches to their address book without them even knowing it. Most are a Medium Risk mass-mailing worm. This comes from the Mcafee site
"Sometimes posing as a Microsoft Security Update, this worm is intended to spread via the following methods:
Mailing itself to recipients extracted from the victim's machine. It mails itself from your machine and you dont even know it.
Copying itself over network shares (mapped drives)
Sharing itself over the KaZaa P2P network (Notorious for this)
Sending itself via IRC
The worm terminates processes relevant to various security and anti-virus products. Additionally, the worm contains its own SMTP engine to create outgoing messages to harvested email addresses from the victim's machine.
Various outgoing messages are created, with multiple subject lines and attachment names. Some make use of an Internet Explorer vulnerability to ensure the worm attachment is run upon viewing the email. When the worm is run on the victim's machine, a series of fraudulent message boxes are displayed. The worm installs itself (using a random filename) into %WinDir%, for example: C:\WINDOWS\ZNFUL.EXE."
So you see, someone has a virus and probably doesnt even know it. So its a good thing you have AV software. Consider yourself informed.
Old 10-14-2003 | 11:42 AM
  #4  
Thread Starter
 
Joined: Oct 2002
Posts: 232
Likes: 0
Received 0 Likes on 0 Posts
From: Hazel Green, AL
Default RE: Virus Caution

My post may seem a little harsh, and I appoligize for that. I am well aware of how worms, etc propagate on a persons system. The worm came in the attachment to an email and has the same properties as the worm has had since it was discovered some time ago. All the sender did was attach the original worm to the email that was sent out.

The problem I have, however, is that I have never heard of a worm that can create a message body to appear as though it came from a legitimate web site without manipulation from the originator of the message. I am aware that worms spoof email addresses, headers, etc all the time, but this one was designed to appear as though it came from RCU (I reinerate that I said appear). The email was close enough to an original one from RCU that I probably would have opened it! My only intention of this post was to warn the readers of this issue and nothing else. Also, I am not saying that the sender of the email was the originator of the worm. All I am trying to get across is to be aware.

Below is the message and header. As you can see the header is definitely bogus. But I will let you guys fight about the meaning of the rest. Next time I won't say a thing...

X-Symantec-TimeoutProtection: 0
X-Symantec-TimeoutProtection: 1
X-Symantec-TimeoutProtection: 2
Return-Path: <[email protected]>
Received: from excellerant.com ([209.61.186.122]) by lakemtai10.cox.net
(InterMail vM.5.01.06.05 201-253-122-130-105-20030824) with SMTP
id <20031014002959.EYDC16416.lakemtai10.cox.net@ex cellerant.com>
for <[email protected]>; Mon, 13 Oct 2003 20:29:59 -0400
Received: (qmail 10670 invoked from network); 14 Oct 2003 00:12:05 -0000
Received: from cs666968-227.satx.rr.com (HELO Cruz) (66.69.68.227)
by jaden.net with SMTP; 14 Oct 2003 00:12:05 -0000
From: "R/C Groups Discussion Mailer" <[email protected]>
Subject: Reply to post 'What Did YOU Get For Father's Day?'
MIME-Version: 1.0
Content-Type: multipart/mixed; boundary="----------C78NMREM465WDW"
Message-Id: <20031014002959.EYDC16416.lakemtai10.cox.net@ex cellerant.com>
Date: Mon, 13 Oct 2003 20:30:00 -0400

------------C78NMREM465WDW
Content-Type: text/plain; charset=us-ascii
Content-Transfer-Encoding: 7bit

Hello cruzomatic,

Dale Case has just replied to a thread you have subscribed to entitled - What Did YOU Get For Father's Day? - in the Open Discussion forum of R/C Groups Discussion.

This thread is located at:
http://www.rcgroups.com/forums/showt...........edited

There may be other replies also, but you will not receive any more notifi

------------C78NMREM465WDW--
Old 10-14-2003 | 12:03 PM
  #5  
WORNBOOTS's Avatar
My Feedback: (33)
 
Joined: Aug 2002
Posts: 1,147
Likes: 0
Received 0 Likes on 0 Posts
From: Texas, TX
Default RE: Virus Caution

RC Groups is not RCU, two differant sites'

But when I got hit last year with a worm, it was an attachment from a site that was rc related, and also appeared to have been a result of a posting as well.

Norton/Internet security 2003 has worked great ever since, it MS that has been an issue lately, and My ISP's upgrade.
Old 10-14-2003 | 12:09 PM
  #6  
Thread Starter
 
Joined: Oct 2002
Posts: 232
Likes: 0
Received 0 Likes on 0 Posts
From: Hazel Green, AL
Default RE: Virus Caution

Please reread all the post. I NEVER said it was RCU. I even reinerated the fact in my last post

Good day
Old 10-14-2003 | 12:20 PM
  #7  
WORNBOOTS's Avatar
My Feedback: (33)
 
Joined: Aug 2002
Posts: 1,147
Likes: 0
Received 0 Likes on 0 Posts
From: Texas, TX
Default RE: Virus Caution

Also, this is the only forum I belong to, so chances are it is from some low life who has read or reads RCU.
I am aware that worms spoof email addresses, headers, etc all the time, but this one was designed to appear as though it came from RCU (I reinerate that I said appear). The email was close enough to an original one from RCU that I probably would have opened it! My only intention of this post was to warn the readers of this issue and nothing else.
Sorry, but I thought I read youre entire post's (#1 & #4),

The attempt to warn us is appreciated emensly, its a lot of hassel when you do get a virus.

Thank's
Old 10-14-2003 | 12:27 PM
  #8  
*Crash*Johnson*'s Avatar
Senior Member
My Feedback: (7)
 
Joined: Apr 2003
Posts: 1,089
Likes: 0
Received 0 Likes on 0 Posts
From: Here, NJ
Default RE: Virus Caution

ORIGINAL: gfinan

All I am trying to get across is to be aware.

And that whoever sent you a virus is a gutless scum. Got it.
Old 10-14-2003 | 12:51 PM
  #9  
Senior Member
 
Joined: Mar 2003
Posts: 443
Likes: 0
Received 0 Likes on 0 Posts
From: southport, UNITED KINGDOM
Default RE: Virus Caution

i never give my e-mail address out. i usualy use my websites free email direction to post it to me. on the top of the email it says
[Forwarded from ****************]
The *****'s are the email it redirects it from.
Old 10-14-2003 | 01:24 PM
  #10  
Thread Starter
 
Joined: Oct 2002
Posts: 232
Likes: 0
Received 0 Likes on 0 Posts
From: Hazel Green, AL
Default RE: Virus Caution

rclooney,

The only reason I give out my email address is that I send out free field stand plans through the "Tips and Techniques" part of RCU. This generates about 10 - 20 emails a day. After sending out over 400 sets of plans, I guess my email is in a lot of address books. Maybe your right, it may be time to set up a web page.

I have never been infected by a virus, but I have repaired a lot of systems which have. Most of these are people like you and I who might not be able to buy that new airplane because they have to pay me to fix their system. This is not right...

Thanks, Greg
Old 10-14-2003 | 09:24 PM
  #11  
blue62's Avatar
Senior Member
My Feedback: (3)
 
Joined: Jul 2003
Posts: 316
Likes: 0
Received 0 Likes on 0 Posts
From: Rogers , TX,
Default RE: Virus Caution

whoever sent it in the first place, (wrote it) is a gutless scum in my opinion and i will hope they catch him and drag him around by his dangly parts!!!

john


Old 10-14-2003 | 09:59 PM
  #12  
Senior Member
My Feedback: (12)
 
Joined: Dec 2001
Posts: 5,133
Likes: 0
Received 0 Likes on 0 Posts
From: Pampa, TX
Default RE: Virus Caution

ORIGINAL: blue62

whoever sent it in the first place, (wrote it) is a gutless scum in my opinion and i will hope they catch him and drag him around by his dangly parts!!!

john


People who write viruses, by definition, are lacking in dangly parts.
Old 10-15-2003 | 09:09 AM
  #13  
*Crash*Johnson*'s Avatar
Senior Member
My Feedback: (7)
 
Joined: Apr 2003
Posts: 1,089
Likes: 0
Received 0 Likes on 0 Posts
From: Here, NJ
Default RE: Virus Caution

ORIGINAL: ChuckAuger

ORIGINAL: blue62

whoever sent it in the first place, (wrote it) is a gutless scum in my opinion and i will hope they catch him and drag him around by his dangly parts!!!

john


People who write viruses, by definition, are lacking in dangly parts.

That was probably the funniest thing I've read today! Thanks Chuck!
Old 10-16-2003 | 01:25 AM
  #14  
Antique's Avatar
Senior Member
My Feedback: (4)
 
Joined: Jul 2002
Posts: 9,825
Likes: 0
Received 1 Like on 1 Post
From: Somewhere, DC
Default RE: Virus Caution

What if everyone cleaned out their address book and left it blank ? Could a virus still spread ?
Old 10-16-2003 | 06:03 AM
  #15  
*Crash*Johnson*'s Avatar
Senior Member
My Feedback: (7)
 
Joined: Apr 2003
Posts: 1,089
Likes: 0
Received 0 Likes on 0 Posts
From: Here, NJ
Default RE: Virus Caution

depends on the virus. Some actually search documents on your computer (word docs, html files, ect) and can extract email addresses from that.
The trouble is, most people dont want to have to type in an email address when they send someone an email, so the address book is needed.

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is On
HTML code is Off
Trackbacks are Off
Pingbacks are Off
Refbacks are On



Contact Us - Archive - Advertising - Cookie Policy - Privacy Statement - Terms of Service

Copyright © 2026 MH Sub I, LLC dba Internet Brands. All rights reserved. Use of this site indicates your consent to the Terms of Use.