|
Author
|
Topic: Virus Warning for SDOEers, SirCam/Somme Trojan - READ!
|
Werner Molders JAG
|
posted 08-02- 10:33 PM
I think its the SirCam virus that infects your computer and then sends random files out to people in your mailing list... well tonight in the mail I got "somme3of5.zip.pif" sent to me, a whopping 8.5 megs. It's a dead giveaway if you've been sent the virus earlier in the week, with its " Hi! How are you?I send you this file in order to have your advice See you later. Thanks" ...however given that people frequently send files back and for on projects asking for advice, and since its an SDOE file, I thought it wise to mention here. Stay alert, and don't open the attachment, even if you recognize the filename! Werner ------------------ Abbeville Field: Dedicated to the SDOE Experience. IP: Logged |
Razer Pilot
|
posted 08-02- 10:37 PM
i've been getitng those, but I don't have anyone in my mailing list for this type or problem. [This message has been edited by Razer (edited 08-02-2001).] IP: Logged |
Werner Molders JAG
|
posted 08-02- 11:27 PM
This guy's obviously an SDOEer if the virus has infected a somme file, which means he reads this board. Ahem. Would one P. Chamberlain PLEASE REMOVE ME FROM YOUR ADDRESS BOOK. I now have two copies of this damnable thing in my inbox, and for some reason it won't let me delete the file straight off my mailserver, which is very serious for me - my email box limit is 20 megs, this c*** is now occupying 17 of those. At work I handle email straight off the server, no Outlook. If I get many more copies of this, it is going to affect my ability to work because I'm collaborating on a project that's 9 megs and gets circulated within our project group several times in a day. You see where I'm going with this? I realize this isn't being done intentionally, but its gone from being a garden variety pain in the butt to something that will impact my ability to work on a project where already we're seriously short on time. Thank you for your assistance and immediate cooperation in this matter. Regards, Werner Molders ------------------ Abbeville Field: Dedicated to the SDOE Experience. IP: Logged |
Barcat26AC Pilot
|
posted 08-02- 11:29 PM
I also use eudora to minimize the risks and eudora is nice because you can put in lots of diffrent e-posts account and get the mail by only one click.Its little more advanced and harder to config but safer - most viruses use Outlooks config. www.eudora.com [This message has been edited by Barcat26AC (edited 08-02-2001).] IP: Logged |
Werner Molders JAG
|
posted 08-02- 11:57 PM
Thanks Barcat, but the problem isn't Outlook, its that this *nasty -ing adjective* thing duplicates on my mailserver as I download it; cut one head off, another sprouts. I'm going to the offices of my ISP a couple blocks down from work tomorrow morning and talking to the tech guys in person. Might as well, I can't do any work like this until its fixed anyways.  Werner ------------------ Abbeville Field: Dedicated to the SDOE Experience. IP: Logged |
Gustavo Pilot
|
posted 08-03- 12:06 AM
Werner, if the file that I receive, also comes with the enclosed explanation from who sends it to me,ŋ ring the risk that it can be infected with the virus? IP: Logged |
Barcat26AC Pilot
|
posted 08-03- 12:33 AM
Rgr, and if i can be to any help can i make a webaccount for you temp with mailacess and possibility to send 4 mb files or maybe bigger.If xx.26ac.org (you canīt change password) maybe xx@26th-aircorps.org have same capacity to send but im not sure... there you can make your own passwords (security better for you maybe). I give you booth for a time if it can help you out in any way. If to any help send me a mail to Barcat@26th-aircorps.org and i give you one ... and my identity you find easy on net confirmed if you like to know how i am...  yours Barcat IP: Logged |
Werner Molders JAG
|
posted 08-03- 12:37 AM
Gustavo - Whatever you do, just be careful. Until this virus has run its course on the internet, you would be well advised to delete any emails with attachments that you weren't expecting. The text that comes with the SirCam virus is the following - "Hi! How are you? I send you this file in order to have your advice See you later. Thanks" There is a spanish version of the same, my father received it. I would post that text exactly but I've already purged his system. I'm sure BabelFish/Altavista will do a decent enough job translating this that you will know what to look for. As for your question specifically - My understanding is that you're safe unless and until you open the whatever.pif file. The .pif file is the virus! Don't open it!! As for my situation, I finished downloading all 17 megs of that rubbish from the server, and my fears have been allayed somewhat, they aren't duplicating on the server anymore. My ISP has an address where, when you send them the full email header of a spammer, they will block any messages from that sender to you. I know this isn't true spam, but as a measure of self-preservation I sent the header, I just hope the automatic handler program/database at the other end acts immediately, so I don't wake up to more copies of this. *grumble* Werner ------------------ Abbeville Field: Dedicated to the SDOE Experience. IP: Logged |
Werner Molders JAG
|
posted 08-03- 12:40 AM
Wow Barcat, thanks a million man, that's very generous of you. While executing plan A I set up a contingency in case I get beseiged again, so I should be ok. This is an example of why this community keeps me coming back, even if I haven't played the game in a while. Werner  ------------------ Abbeville Field: Dedicated to the SDOE Experience. IP: Logged |
Major Hippie Pilot
|
posted 08-03- 02:56 AM
I work phone tech support for DELL & we've been getting alot of Sirc32 virus calls. In fact, the last two days I worked, me and a buddy fielded over 15 calls on the SirC32.exe virus. And we were just 2 guys out of about thousand techs, so if you do the math, this little bugger is running rampant... I even got it sent to me, however it was sent to my Yahoo email & they have norton on thier server, so I detected it while it was still on thier server & then of course deleted it...Also be on the look out for the Red Worm Virus... People are always asking me how to keep from getting viruses... #1. get a good Anti-Virus program & REMEBER TO UPDATE IT AT LEAST ONCE A WEEK!!!! if it is not updated then it won't detect new viruses.... #2. NEVER OPEN UNSOLICITED EMAIL!!! If you don't know it, KILL IT!! especially anything with attacments!!! #3. IF YOU RECEIVE A FREINDLY Email with an attacment that you were not expecting, email the sender BEFORE you open it & ask them if they sent it. If it can't be confirmed, THEN DELETE IT ASAP!!! If you were expecting it, you still scan it (a habit I still need work on myself) #4. Do like me & get something like a yahoo email account like mine & give that address to any websites that request them. (this will help you deal with spam as well) The weird thing about the SirC that was sent to me was that it had NO SENDER & NO MESSAGE, basically just an attachment with my geocities.com email addy on it (yahoo owns geocities so that email is checked through my yahoo mail as well)... One last note about the Sirc virus, it CAN be removed from the system, you can find the info at www.VirusInfo.com & do a search on SirC32. HOWEVER, at work I found that even after the virus is removed, some will still have to reload windows as this virus corrupts the registry. Sometimes your can restore a previous registry & correct it, but many times not... For those who don't know how to this, here it is: Step One. BOOT TO DOS...not an DOS promt window either, I mean boot into PURE DOS Step Two. Go to the C:\WINDOWS\COMMAND Directory ("CD" with the quotation marks is the DOS command for Change Directory) & type in this: SCANREG /RESTORE and then press ENTER. Step Three. In a moment, you'll see a list of CAB files that read like dates. Highlight one (one dated BEFORE you got the virus) & press enter. Windows do a back up of existing (damaged) registry & restore the one you selected & will then ask for a reboot...so you press ENTER to reboot... Hopes this helps someone... If this info saves one computer from virus damage, I'll be happy  hip63  ------------------ ...remember always fly HIGH!!! http://groovygalaxy.50megs.com/psychedelicsquadron.html IP: Logged |
Snickers Pilot
|
posted 08-03- 09:39 AM
One thing I'll add to Hippies coimments..If you are expecting and email with an attachment, and you get it, >>> Look at the name of the attachment before you open it <<< Thats the way I got hit recently (with a different virus). Now all incoming mails, attachments are scanned as well as "hostile web sites" Thats right, things can happen just from surfing.... ------------------ Snickers =FC= Thou shalt maintaineth altitude, lest the earth rise up and smite thee. IP: Logged |
Barcat26AC Pilot
|
posted 08-03- 10:32 AM
I think a good choice is also to not have any files in the map "My doc". No adresses, and no Outlook and get all mail from a web-mail with a good virusprotection.Iīm right now redirecting all my mails to a account on a server with a good e-mailprotection on Barcat@26ac.org Smash the bugs ! also in 1 5 2 9 patch... 
IP: Logged |
ArgonV JAG
|
posted 08-03- 12:42 PM
This is very upsetting... I think I got one of these a LONG while back but my e-mail cant handle anything anywhere close to 8 megs so I believe it was empty. What exactly will this virus do to your computer??IP: Logged |
Snickers Pilot
|
posted 08-03- 01:55 PM
From McAfee:This mass-mailing virus attempts to send itself and local documents to all users found in the Windows Address Book and email addresses found in temporary Internet cached files (web browser cache). It may be received in an email message containing the following information: Subject: [filename (random)] Body: Hi! How are you? I send you this file in order to have your advice or I hope you can help me with this file that I send or I hope you like the file that I sendo you or This is the file with the information that you ask for See you later. Thanks This is the part I find interesting: >>>>> email addresses found in temporary Internet cached files (web browser cache). <<<<< IP: Logged |
Barcat26AC Pilot
|
posted 08-03- 02:24 PM
In the browsers settings "advanced" there are a setting to empty "temp stored files" when you are closing the browser. I have got from somewhere itīs making all safer if you using this possibility because itīs increasing your security also if your computer get "hacked" by someone.Iīm sorry i havent an english browser so i can guide you better but i think itīs - tools - advanced - security and "empty temp internetfiles when broser closes" or something like that... check that box and use it. I empty my browsers stored files because of that information i got - i think it was from a PC-magazine ... Maybe someone else knows more about this. [This message has been edited by Barcat26AC (edited 08-03-2001).] IP: Logged |
Snickers Pilot
|
posted 08-03- 03:12 PM
For IE 5.X it would be: Tools Internet Options Advanced In the security section(scroll down), check "Empty Temporary Internet Files folder when browser is closed" Click Apply[This message has been edited by Snickers (edited 08-03-2001).] IP: Logged |
Hentzau Pilot
|
posted 08-03- 09:00 PM
Ok thanks Snickers, just did that. I read a good tip in computer shopper to block viruses that rely on scripts. It says: "Most users rarely need to run Visual Basic, so here's an easy way to block viruses that rely on scripts. Using Notepad, creat a text file called TEMP.VBS and save it to the Desktop. Hold down the Shift key, right-click on the new icon, select "Open with," and click Notepad. Finally, check "Always use this program to open this type of file." Now, if you try to open a potentially dangerous attachment, it opens in Notepad and doesn't run. If you need to run the script, save it to your computer, then drag and drop it onto Internet Explorer." I've been thinking that I would just place all my email addresses for people in a real notebook instead of in outlook express also, to prevent sending anything out that comes my way. I think I saw that HTML should be disabled in your mail program also. Anyone know anything about that??? ------------------ FS_WW1_ONLINE_STANDARD_-_get_the_files_here IP: Logged |
Major Hippie Pilot
|
posted 08-03- 10:07 PM
Good idea Snick, but remember windows won't always get all the files, you still sometimes have to go in to the temp internet folder & delete the manually to get them all, all the time [what can I say, it's windows & it's goofy that way ]oh & the directory for that is usually:C:\WINDOWS\Temporary Internet Files\Temporary Internet Files hip63 
------------------ ...remember always fly HIGH!!! http://groovygalaxy.50megs.com/psychedelicsquadron.html IP: Logged |
Psi Pilot
|
posted 08-04- 01:11 AM
Snickers, all due respect, I took your advice and when I went to some sites they would not load completely. I went back into Tools and re-enabled it and everything loaded fine.P IP: Logged |
Barcat26AC Pilot
|
posted 08-04- 01:40 AM
Hi, my friend Psi !I have been surfing with that settings a couple of years (maybe) and never had any problem with it to load any site.... maybe you have some other settings also ...? or itīs depending on your connection speed ? When a virus hit all around itīs also easy to overreact - the best way is to have a good antivirusprotection - but i use this settings "just in case" because iīm more afraid of anyone going into my puter (some had that habbit in Janeīs or Hyperlobbys community) and checking up all my login files made by the browser. I hope this settings makes it little harder for them. [This message has been edited by Barcat26AC (edited 08-04-2001).] IP: Logged |
Snickers Pilot
|
posted 08-06- 10:26 AM
quote: Originally posted by Psi: Snickers, all due respect, I took your advice and when I went to some sites they would not load completely. I went back into Tools and re-enabled it and everything loaded fine.P
I was just giving the steps to set it up, it was someone elses idea (post just above mine). There is a trade off between security and convenience and that is up to the individual... I personally do the same thing Hippie does. I will let the browser go in and delete the temp files. In addition, I will go in by hand and delete files, include every cookie I can find. (this just means I need to remember some paswords as deleteting the cookie may mean that I get prompted for it again... It depends on the site....)
------------------ Snickers =FC= Thou shalt maintaineth altitude, lest the earth rise up and smite thee. IP: Logged |
Psi Pilot
|
posted 08-06- 11:41 AM
Well that's got to show how much respect I have for you Snickers and what you say I really don't spend all that much time surfing anymore and I'm not really concerned (till it happens I suppose) with a hack. I try to use caution and am careful about where I go on the net, I think this has a lot to do with it. But thanks guys for getting the word out...P IP: Logged |