Sorry your browser is not supported!

You are using an outdated browser that does not support modern web technologies, in order to use this site please update to a new browser.

Browsers supported include Chrome, FireFox, Safari, Opera, Internet Explorer 10+ or Microsoft Edge.

Geek Culture / DB community , theres a worm going around

Author
Message
Eric T
21
Years of Service
User Offline
Joined: 7th Apr 2003
Location: My location is where I am at this time.
Posted: 27th Jul 2003 15:02 Edited at: 27th Jul 2003 15:02
Hello again people,

I, in the recent days, have recievied 2 emails, that have been approx. 170kb in size, and they have had a weird subject (as in Summary... and other stuff like that). When I have opened them up, absolutely nothing inside, blank, no attachments or so i thought. In looking throught the source of the email i find the file name "Dbpro_beat.bat". now i haven't yet extracted the file to see what it contains.

But being the very curious person i am, and after recieving numorous amounts of email saying that people have been recieving emails simalir to the one i have gotten, started to run virus scanners and trojan scanners and the works. I checked through my logs of every action i have done on my pc, and every action my pc does. Nothing at all refering to emailing these people. Then i Went through my pc searching for abnormal files.. and i found 2 files in the Windows/Temp directory.
So far i have recieved about 9 emails total 3 from vegetaletajin@msn.com, 3 rich_dbteam@hotmail.com, and 3 from Myself yusuke200013@hotmail.com

So just a warning, don't open any suspisious email. I will try to get to the bottom of this ASAP.

--Eric

Opinions are like a$$holes, Everybody has one.
Eric T
21
Years of Service
User Offline
Joined: 7th Apr 2003
Location: My location is where I am at this time.
Posted: 27th Jul 2003 15:20
heres what i get outta a file in notepad :



Opinions are like a$$holes, Everybody has one.
Richard Davey
Retired Moderator
22
Years of Service
User Offline
Joined: 30th Apr 2002
Location: On the Jupiter Probe
Posted: 27th Jul 2003 17:09
Hello Mr. Worm Virus.

If anyone ever receives mail from rich_dbteam@hotmail.com I can guarantee you I didn't send it, I don't think I've ever once logged into my hotmail account (to send mail).

Also check the mail headers carefully, I doubt they even come from the people listed.

Cheers,

Rich

"Gentlemen, we are about to short-circuit the Universe!"
New DBS Web Sites Coming Soon - All Change
Kanzure
21
Years of Service
User Offline
Joined: 19th Feb 2003
Location:
Posted: 27th Jul 2003 17:22
Meh, everybody shouldn't wory about this unless they use Outlook. If they use Yahoo or w/e then you should be smart enough not to open up .bat, .exe, .vbs, or .js files directly from it without scanning with Norton & McAfee!

~Morph/Kanzure
CodeNation
Solidz Snake
22
Years of Service
User Offline
Joined: 23rd Oct 2002
Location: United Kingdom
Posted: 27th Jul 2003 17:31
damn.. i got the same thing too..

only yesterday i got an email from an anynomous, she's asking me,
"hello, i'm sorry if this sounds rude, but who are u, and why did u send me a blank email?"

i never thought of it until Yusuke told me about it

it not only sent emails to all my contacts in me list, but also to ppl whom i dunno!

Snake? What happened? Snake? Snaaaaaaaaaaaaaaaake!!! - Colonel Roy Campbell

Eric T
21
Years of Service
User Offline
Joined: 7th Apr 2003
Location: My location is where I am at this time.
Posted: 27th Jul 2003 17:32
didn't open i'm not that stupid


but its just a warning for ya'll cause i don't wanna see someones comp messed up at all.

Opinions are like a$$holes, Everybody has one.
Kanzure
21
Years of Service
User Offline
Joined: 19th Feb 2003
Location:
Posted: 27th Jul 2003 17:39
What files are attached? Upload them to a server and let us take a look at 'em

~Morph/Kanzure
CodeNation
Eric T
21
Years of Service
User Offline
Joined: 7th Apr 2003
Location: My location is where I am at this time.
Posted: 27th Jul 2003 17:44
lmao accordeing to 3 annonimous(spelling) tipsters the file that is attachet is corrupted but it only accounts for like 80kbof the file the other 2 files i have are different and i have been looking at them in hex form.. and there source form..... any thing i could find in them is posted in that code snippet.

Opinions are like a$$holes, Everybody has one.
Eric T
21
Years of Service
User Offline
Joined: 7th Apr 2003
Location: My location is where I am at this time.
Posted: 27th Jul 2003 17:46
Quote: "Also check the mail headers carefully, I doubt they even come from the people listed."


That was the thing that got me.... they did, i checked the source and it was incoming form the correct email addresses. it seems to be an msn thing

Opinions are like a$$holes, Everybody has one.
Rob K
Retired Moderator
22
Years of Service
User Offline
Joined: 10th Sep 2002
Location: Surrey, United Kingdom
Posted: 27th Jul 2003 17:53
As I have received blank emails from Yusuke, I guess that others may receive blank emails which "supposedly" come from my address.

Check the email headers as Rich said above.

Eric T
21
Years of Service
User Offline
Joined: 7th Apr 2003
Location: My location is where I am at this time.
Posted: 27th Jul 2003 17:59
i did, they are coming form the corresponding persons email address


and i just ran a full virus update, then scan on all 220 GB and ran scan for trojans worms dialers and all that.. then i ran spybot. nothing

Opinions are like a$$holes, Everybody has one.
IanM
Retired Moderator
22
Years of Service
User Offline
Joined: 11th Sep 2002
Location: In my moon base
Posted: 27th Jul 2003 18:02
If you use Outlook, you should also use something like mailwasher to vet your email before you download it. That way you can also bounce back spam
randi
22
Years of Service
User Offline
Joined: 27th Aug 2002
Location: United States
Posted: 27th Jul 2003 18:07
I have received this too.
Mine was from pneumaticdryll@hotmail.com, and I use Outlook.
But Norton jumped all over it, so nothing happened.

Randi
Eric T
21
Years of Service
User Offline
Joined: 7th Apr 2003
Location: My location is where I am at this time.
Posted: 27th Jul 2003 18:15
Quote: "Mine was from pneumaticdryll@hotmail.com, and I use Outlook.
"


dosen't have pneumaticdryll in my address book, or atleats i shouldn't

Opinions are like a$$holes, Everybody has one.
Preston C
21
Years of Service
User Offline
Joined: 16th May 2003
Location: Penn State University Park
Posted: 27th Jul 2003 18:23
did anyone get this worm from my email address? I havent gotten it yet, but I want to know if there is anybody who wants to frame me.

At first glance, I'm a mediocre mech pilot. Look again and you will see my battlemech's computer code rushing through my eyes. My Mech And I Are One!
andrew11
21
Years of Service
User Offline
Joined: 23rd Feb 2003
Location: United States
Posted: 27th Jul 2003 18:28
It seems to only come from MSN or Hotmail accounts.

"All programmers are playwrites and all computers are lousy actors" -Anon
Cash Curtis III
21
Years of Service
User Offline
Joined: 12th May 2003
Location: Toronto, Canada
Posted: 27th Jul 2003 18:33

I got these months ago....
Kanzure
21
Years of Service
User Offline
Joined: 19th Feb 2003
Location:
Posted: 27th Jul 2003 18:59
The virus prolly copies the addresses its already been to :p

~Morph/Kanzure
CodeNation
8truths
21
Years of Service
User Offline
Joined: 10th May 2003
Location: United States
Posted: 27th Jul 2003 19:13
Maybe I'm out on a limb here . . .

But, is it possible it (or more likely its maker) is mining for names from the forum, then throwing them into the e-mail with msn.com and hotmail.com?

We can't stop here! This is bat country!
Troan
21
Years of Service
User Offline
Joined: 22nd Jan 2003
Location: Inner thought about nothing
Posted: 27th Jul 2003 20:48
i got hotmail didnt get it well i dont share e-mail
at bottem of post

---Troan---

"Love and Peace"-Vash the Stampede
MikeS
Retired Moderator
21
Years of Service
User Offline
Joined: 2nd Dec 2002
Location: United States
Posted: 27th Jul 2003 21:34
Interesting this is, I got one from Yusuke, and I think I got one from Tom, asking why I sent him a blank message. I do not like what is going on here, although it seems like a hotmail/msn error. Hopefully we will find the meaning of all this soon.



Yellow:Wanna publish my game microsoft, cuz i no u rich so...Can I have my bag of money now?
Microsoft: *snicker* Tip of the month-Microsoft will never(probebly) publish your game.
Eric T
21
Years of Service
User Offline
Joined: 7th Apr 2003
Location: My location is where I am at this time.
Posted: 27th Jul 2003 21:41
I never had yellow in my lists till 1 hour ago.. so its pretty wierd.

Opinions are like a$$holes, Everybody has one.
MikeS
Retired Moderator
21
Years of Service
User Offline
Joined: 2nd Dec 2002
Location: United States
Posted: 27th Jul 2003 21:48 Edited at: 27th Jul 2003 21:48
I've just removed my MSN,AIM from my display, and profile for safty precautions.Contact me personally on these forums if you'd like to communicate with me by these means.



Yellow:Wanna publish my game microsoft, cuz i no u rich so...Can I have my bag of money now?
Microsoft: *snicker* Tip of the month-Microsoft will never(probebly) publish your game.
adr
21
Years of Service
User Offline
Joined: 21st May 2003
Location: Job Centre
Posted: 27th Jul 2003 22:15 Edited at: 27th Jul 2003 22:16
I got about 5 in my inbox from this community alone - one from P-Dryll! (didn't recognise any of the other people)

Bender:Blackmail’s such an ugly word. I prefer extortion. The x makes it sound cool.
Ian T
22
Years of Service
User Offline
Joined: 12th Sep 2002
Location: Around
Posted: 27th Jul 2003 22:24
Appreciate the heads-up.

Luckily nobody ever mails me anything, so I'm not on anyones contact list, so I don't get the worm

--Mouse

Famous Fighting Furball
Solidz Snake
22
Years of Service
User Offline
Joined: 23rd Oct 2002
Location: United Kingdom
Posted: 27th Jul 2003 23:21
*planning to send an email to Mouse now

Snake? What happened? Snake? Snaaaaaaaaaaaaaaaake!!! - Colonel Roy Campbell

andrew11
21
Years of Service
User Offline
Joined: 23rd Feb 2003
Location: United States
Posted: 28th Jul 2003 03:15
I didn't have my email up, but Rich said you need to put in your email to move to the new site smoothly. You will need a valid email address to sign on, but you will probably be able to hide it.

"All programmers are playwrites and all computers are lousy actors" -Anon
Mattman
21
Years of Service
User Offline
Joined: 5th Jun 2003
Location: East Lansing
Posted: 28th Jul 2003 04:46
Haven't gotten it, but i have wow e-mail. Yellow, would ytou still like me to send you the document?

---Mattman
DID YOU KNOW THAT ???
MikeS
Retired Moderator
21
Years of Service
User Offline
Joined: 2nd Dec 2002
Location: United States
Posted: 28th Jul 2003 06:07
Yes, you may send it at any time. Although, it's about 10:00 P.M right now, I'll have a quick look at it and send it back early next morning.



Yellow:Wanna publish my game microsoft, cuz i no u rich so...Can I have my bag of money now?
Microsoft: *snicker* Tip of the month-Microsoft will never(probebly) publish your game.
MikeS
Retired Moderator
21
Years of Service
User Offline
Joined: 2nd Dec 2002
Location: United States
Posted: 28th Jul 2003 06:08
Wait, hold that thought mattman. I don't think it's safe that I send/recieve mail especially as important as our design-doc. So if you need anything, just post on your thread on the team request forums.



Yellow:Wanna publish my game microsoft, cuz i no u rich so...Can I have my bag of money now?
Microsoft: *snicker* Tip of the month-Microsoft will never(probebly) publish your game.
Mattman
21
Years of Service
User Offline
Joined: 5th Jun 2003
Location: East Lansing
Posted: 28th Jul 2003 06:22
o.k. i don't have it (i think. Will check soon.) I'll tell updates, and send to petret. btw, texture dude got e-mail!!!

---Mattman
DID YOU KNOW THAT ???
Dave J
Retired Moderator
21
Years of Service
User Offline
Joined: 11th Feb 2003
Location: Secret Military Pub, Down Under
Posted: 28th Jul 2003 15:12
Quote: "Luckily nobody ever mails me anything, so I'm not on anyones contact list, so I don't get the worm
"

Same here lol

"Computers are useless they can only give you answers."
adr
21
Years of Service
User Offline
Joined: 21st May 2003
Location: Job Centre
Posted: 28th Jul 2003 18:20
Someone's mailed me saying they've received an the virus from shizzle@fuzzee.co.uk. That made me think I had a virus, but then it occured to me that I can't send out from that address - outlook is only configued to send out from my private address at my domain (This way I can control the amount of shit in my inbox)...

We need to clean this up, and fast. The reply-to address, as well as the destination address is generated randomly to give it extra spreadability.

I started getting mails after some dude emailed me about his Mugen clone.... forgotten his name.

Rich - I know it's not your job to baby sit around here, but can you make a sticky post in the General DBP/DBC boards advising people to download symantec's klez wipe tool?

Bender:Blackmail’s such an ugly word. I prefer extortion. The x makes it sound cool.
Van B
Moderator
22
Years of Service
User Offline
Joined: 8th Oct 2002
Location: Sunnyvale
Posted: 28th Jul 2003 18:41
Klez takes a sent from address from your address book, so usually - the sender is not where it came from - it's funny how this is the 2nd or 3rd time we've been struck by Klez, yet it still gets some of us.

It's probably comming from one DB'ers machine which happens to have all our email addresses.

I reply to any virus telling the supposed sender to check their system, better to be safe than sorry.


Van-B

My cats breath smells of cat food.
Tommeh
21
Years of Service
User Offline
Joined: 15th Jun 2003
Location: United Kingdom
Posted: 28th Jul 2003 19:15 Edited at: 28th Jul 2003 19:17
Mmmmm... Im no good at batch files etc

But what its doing is finding all your contacts
from this code

"M a i n I d e n t i t y ' s C o n t a c t s "

Also it is Defenatly sending it to the other people because of..

"S M T P  0* A r r o w"

Which is sending it through SMTP

The thing that really puzzles me is this bit here

"{ 7 F 4 1 0 3 5 0 - 2 2 E F - 4 D C 1 - 9 5 6 9 - D 5 C 5 7 5 7 7 D 3 A B }"

That looks like a temp dir to me.

So find it using SEARCH ASAP

This is not nice, and should be tracked down asap
Remember, It may not be the person who sent it to you fault


Well done to yusuke200031 For finding this, Remember if you find a email with nothing in Try and find and delete that temp dir above
adr
21
Years of Service
User Offline
Joined: 21st May 2003
Location: Job Centre
Posted: 29th Jul 2003 12:31
Still alive - got two copies of it this morning.

Bender:Blackmail’s such an ugly word. I prefer extortion. The x makes it sound cool.
MikeS
Retired Moderator
21
Years of Service
User Offline
Joined: 2nd Dec 2002
Location: United States
Posted: 30th Jul 2003 06:25
Urgent

I've just got an e-mail from vegetaletajin, it ranges in about 135k's. It's titled "Eager to see you"

Unless Raven replies that it's safe too open, I will not open without further notice.

The worm's still going around, and hasn't stopped.



Jenny: New Recruit to Police Force Jacob: Jenny's Associate
Problem? You may soon find out. "It could take the world."
Andy Igoe
22
Years of Service
User Offline
Joined: 6th Oct 2002
Location: United Kingdom
Posted: 30th Jul 2003 07:11
One or more of the following people from MSN has a worm:

koolaid
glenn
graham/lcfcfan
kentaree
the darthster
jerico2day
raven
boltyboy
Database/DC David*

The person also has Randi on their contacts list.

I know this because Randi received a virussed email from 'pneumaticdryll@hotmail.com' which is my MSN username and has never been logged into (infact, I dont even know HOW to access it!).

Therefor the worm is taking two names from the address book, one to send to, one to use as from. Therefor somebody who knows Randi also has me on their contact list. The list above are those who have me on MSN, those with asterisks are those on ignore.

The only person whome I know this to be the case for is Raven. Perhaps others on the list above also contact Randi.

Pneumatic Dryll
MikeS
Retired Moderator
21
Years of Service
User Offline
Joined: 2nd Dec 2002
Location: United States
Posted: 30th Jul 2003 07:29
I think I may just delete my msn hotmail account(while I still remember the password to login ,lol) Later tomorrow I will do this.



Jenny: New Recruit to Police Force Jacob: Jenny's Associate
Problem? You may soon find out. "It could take the world."
Arrow
21
Years of Service
User Offline
Joined: 1st Jan 2003
Location: United States
Posted: 30th Jul 2003 15:13
Definatly going through MSN Profile pages, looks like it's recording peoples e-mails and such. Maybe a bad joke from a disgruntaled coder, or perhaps a new step in the anyoing field of spam. I've noticed I've been getting more of it since this showed up.

Teenage Male Geek + Female Remotly Intersted in Common Geek Activities = Teenage Male Jackass
Megaman Zero
21
Years of Service
User Offline
Joined: 25th Jan 2003
Location: United States
Posted: 31st Jul 2003 05:06
Yeah, I recieved this virus thing too in my bulk folder, so I deleted it, it was just from rich_dbteam, subject was...

Worm Klez.E Immunity, im just going to delete it, but be aware of the title. We need to report this to hotmail though, tell them that address is sending out worms & stuff, then have the guy who is sending it imprissoned for a while, then no computer for another 10 years, & perhaps that will serve as a warning to people who consider doing this.

Intentionaly implanting viruses is a federal crime that will give you quite a few years in prisson, with minimal parol, & normaly no computer access for quite some time after jail. So most of us should email hotmail & get the investigation started.

Just be warned about that email,

Zero (Formerly Shadow Guyver)
NRTP(TM)http://heero_yuy1983.tripod.com/
NRTP Message Boardshttp://nrtp.proboards22.com/index.cgi
John H
Retired Moderator
22
Years of Service
User Offline
Joined: 14th Oct 2002
Location: Burlington, VT
Posted: 31st Jul 2003 06:14
Guys - I got 2 of these
drdoomar
mikenmaz

Are the names, here are the titles:

drdoomer SmnSSrc
mikenmaz Var

The attachment sizes BOTH 131k

I OPENED THE EMAIL TO FIND IT WAS ALL BLANK

There was NO LINK to download the ATTACHMENT. Am I infected?! Please help me guys! I dont want my brand new computer broken!

I opened the email and norton didnt say anything - and I didnt download ANYTHING. Am I infected?

RPGamer

Current Project: Eternal Destiny
Porting all files to my new computer
bitJericho
22
Years of Service
User Offline
Joined: 9th Oct 2002
Location: United States
Posted: 31st Jul 2003 06:21
I'm in the same situation with RPGamer... i got a blank email from uwdesign... i also run norton...:/

The 3D Modeler's Group : http://groups.yahoo.com/group/3dModeler/
The Unofficial DB Software Group : http://groups.yahoo.com/group/dbsgroup/
John H
Retired Moderator
22
Years of Service
User Offline
Joined: 14th Oct 2002
Location: Burlington, VT
Posted: 31st Jul 2003 06:23
In my C:\Windows\Temp folder I found this folder

{60E80B13-8649-4A69-85E2-1AE99E061F43}

Its EMPTY

Should I delete it?

RPGamer

Current Project: Eternal Destiny
Porting all files to my new computer
heartbone
22
Years of Service
User Offline
Joined: 9th Nov 2002
Location:
Posted: 31st Jul 2003 06:41
This might sound somewhat petty, mean and vindictive but, if you are still using Outlook you deserve viruses.

Guys save yourself any more hassles and get a real email program.

Eudora

The more you see, the more you know.
The more you know, the more you see.
Arrow
21
Years of Service
User Offline
Joined: 1st Jan 2003
Location: United States
Posted: 31st Jul 2003 07:07
I don't even have out look installed on my com. It's using MSN.

Teenage Male Geek + Female Remotly Intersted in Common Geek Activities = Teenage Male Jackass
MikeS
Retired Moderator
21
Years of Service
User Offline
Joined: 2nd Dec 2002
Location: United States
Posted: 31st Jul 2003 07:09
@Heartbone
Yea, most of us(if not all) are using hotmail. I have a aol account, but I just send all my junk to the hotmail one. Like if I needa register to some site, or to get a download. heheheh



Jenny: New Recruit to Police Force Jacob: Jenny's Associate
Problem? You may soon find out. "It could take the world."
the_winch
21
Years of Service
User Offline
Joined: 1st Feb 2003
Location: Oxford, UK
Posted: 31st Jul 2003 16:46
Quote: "I don't even have out look installed on my com. It's using MSN."


Someone is using outlook and has your email in their address book.
At the root of most of these problems is a piece of microsoft software.

Quote: "In my C:\Windows\Temp folder I found this folder

{60E80B13-8649-4A69-85E2-1AE99E061F43}

Its EMPTY

Should I delete it?

RPGamer"

If your think you are infected format your pc. Otherwise your computer will start sending more infected emails.
Megaman Zero
21
Years of Service
User Offline
Joined: 25th Jan 2003
Location: United States
Posted: 1st Aug 2003 01:14
There should be some free virus tools somewhere on nortons website, that can detect & remove a lot of klez viruses, I had to use them a few weeks ago to get Norton 2k3 installed again on my comp because I upgraded to win xp, & there is some kind of weird upgrade issue with norton 2k3 from an older os to XP.

If you have already upgraded to XP & you cant get norton to work, I recomend you figure out how to uninstall norton 2k3, delete the registry keys for norton 2k3 (after backing up your registry of course,) running the klez removal tool, to scan for any & all viruses, then if you have it, delete the viruses, then go out & buy Norton 2k3 & install it.

However, if you have 2000 viruses like my friend had by downloading stuff from kazaa, I would recomend a nice format or system restore to clear up the problem, as it would take a few days to remove all of the viruses.

Zero (Formerly Shadow Guyver)
NRTP(TM)http://heero_yuy1983.tripod.com/
NRTP Message Boardshttp://nrtp.proboards22.com/index.cgi
Terabyte
21
Years of Service
User Offline
Joined: 28th Dec 2002
Location: UK
Posted: 1st Aug 2003 03:11
Hmm

ye i just got that email
said READ THIS!!!!!
open it it says

body = Hi


Weird thing is.
It came from my smgo_@hotmail.com to my Danjav@aol.com acount

heres the usual aol garbage stuck on the end

Return-Path: <nobody@cgi.wish.net>
Received: from rly-yc03.mx.aol.com (rly-yc03.mail.aol.com [172.18.149.35]) by air-yc01.mail.aol.com (v95.1) with ESMTP id MAILINYC12-1ca3f2994ff2e6; Thu, 31 Jul 2003 18:15:35 -0400
Received: from cgi.wish.net (cgi.wish.net [195.241.76.245]) by rly-yc03.mx.aol.com (v95.1) with ESMTP id MAILRELAYINYC38-1ca3f2994ff2e6; Thu, 31 Jul 2003 18:15:28 -0400
Received: (from nobody@localhost)
by cgi.wish.net (8.9.3/8.9.3) id AAA99029
for danjav@aol.com; Fri, 1 Aug 2003 00:43:22 +0200 (CEST)
(envelope-from nobody)
Date: Fri, 1 Aug 2003 00:43:22 +0200 (CEST)
Message-Id: <200307312243.AAA99029@cgi.wish.net>
From: empty empty <smgo_@hotmail.com>
To: <danjav@aol.com>
Cc:
Subject: Read This!:
X-AOL-IP: 195.241.76.245
X-AOL-SCOLL-SCORE: 0:XXX:XX
X-AOL-SCOLL-URL_COUNT: 0



my norton just upadted today
currently runing norton antivirus scan

>>TerraByte. Putting the Byte back into Terragramming<<

Login to post a reply

Server time is: 2024-11-23 17:05:40
Your offset time is: 2024-11-23 17:05:40