PDA

View Full Version : New Virus??


ChromWolf
08-14-2003, 04:57 PM
I think I've contracted a new virus!!! I've tried various ways of trying to locate or detect it, and all have failed.... Here's the story....

At first, I started getting tons of forwards with attachments from one of my friends. He obviously wasn't sending them of his own volition, which indicated to me that he had some kind of mass-mailing worm that was using his Address Book. The subjects of these e-mails ranged across the following (before I stopped logging them due to my own system problems):

Fw: Who is ur Best Friends :-)
Fw: Stuff
Fw: U r the person? !
Fw: Send This to everybody u like :-)
Fw: charming relations to enjoy

And the attachments (again, before I stopped checking) included the following:

loversgang.scr
stuff.zip.bat
werfriends.scr
sharelove.scr
friends.scr
stuff.zip.scr
stuff.zip

I had received MANY MANY forwards from him, and after a while, had to block his e-mail address (though, FWIW, I was kind enough to notify him and tell him to communicate with me via some other method to notify me that he had fixed it).

However, in looking over the messages, I must have somehow contracted it myself....? I admit my security settings may have been inadequate, and I sometimes fall behind on Security updates, so something running automatically in the background is entirely possible....

Later, another friend said I was apparently broadcasting the first friend's passwords....? When Friend #2 told me what the broadcast password was, I recognized as indeed being a password Friend #1 uses, and knew this wasn't something I had seen on the Symantec site thus far. I've also searched over the Symantec site listing all of the above subject headings and attachment files, and found nothing.

Further more, I've run the Housecall webscan at the Trend Micro webpage, and that scan also came up with zero viruses.

What can I do? Who can I contact? (I don't want to pay Symantec their $25 or whatever fee just to help them do their job).... Incidentally, I run Windows 98SE, with Outlook Express 6. Only after getting the virus have I run the latest critical updates from Microsoft--today, specifically.

Also, FWIW, I note alot of the viruses lately attempt to shut down anything associated with a virus scanner, or the windows update applets----this did not appear to happen to me.

Can anyone help??

Redo40
08-14-2003, 05:46 PM
Sounds like the W32 Yaha.E (http://www.sarc.com/avcenter/venc/data/w32.yaha.e@mm.html). There is a removal tool if in fact it is this virus. If not, I would update virus defs and double check or download AVG anti-virus to triple check.

ChromWolf
08-14-2003, 08:47 PM
No, not Yaha--at least, not this particular variation... I had found that in my searches on Symantec, but found no symptoms or signs other than the small similarities between subjects and attachments. I'll try AVG, but actually, according to this thread:
http://forum.pcmech.com/showthread.php?threadid=70599
I may not have a virus afterall, and it may just be friend #2 getting e-mails from friend #1, even though they've got my name on them. Thoughts?

Redo40
08-14-2003, 09:22 PM
After reading the other thread, I would have to agree, it's possible that the headers are being spoofed with your address. Just to be safe I would download and run AVG anyway.

Has the friend scanned for a virus yet?

ChromWolf
08-15-2003, 12:50 PM
He did end up formatting his HD and re-installing. I'll post again if AVG finds anything, otherwise, I'll just consider myself clean... but we shall see if any more e-mails get sent.

ChromWolf
08-15-2003, 04:08 PM
Official result: AVG found no viruses.