Virus warning

B

Bill Quinton

I can't believe it's a coincidence. Within half an hour of
puting my real email address on this newsgroup, I'm being
bombarded with viruses.
 
G

Gary L. Chefetz

It's not a coincidence. The Sven virus is harvesting email addresses from
the news groups!


--
Gary Chefetz [MVP]
http://www.msprojectexperts.com
"We wrote the book on Project Server"

*** Remember to look for line breaks in links posted to the news group, use
cut and paste for these.
 
B

Bill Quinton

Don't Microsoft have any virus killers, then?

-----Original Message-----
It's not a coincidence. The Sven virus is harvesting email addresses from
the news groups!


--
Gary Chefetz [MVP]
http://www.msprojectexperts.com
"We wrote the book on Project Server"

*** Remember to look for line breaks in links posted to the news group, use
cut and paste for these.




.
 
G

Gary L. Chefetz

Bill,

Of course they do, but this one took everyone by surprise.

--

Gary Chefetz [MVP]
http://www.msprojectexperts.com
"We wrote the book on Project Server"

*** Remember to look for line breaks in links posted to the news group, use
cut and paste for these.
 
S

Steve House

It's not a matter of virus killers on the servers. First of all, the
message base on the newsgroup doesn't exist in any one location. Instead it
is mirrored on hundreds of servers all around the world, hundreds of
identical message pools. Killing an infected message on one server does
nothing to remove it from all of the others. When you access the news
server you DL message headers or complete messages, depending on your
personal preferences. If your PC gets hit with a virus, as it infects it
scans your entire drive and retrieves ALL email address and newsgroup
references it can find - mailboxes, address books, internet cache, newsgroup
header files, temp folders, imbedded in word documents - everything. It has
it's own smtp server so it starts to send mail and newsgroup posts to
everyone and everything it's found - it also spoofs the return address,
substituting one of the addresses it found for your real return address.
Thus EVERY recognizable email address and EVERY newsgroup reference that it
finds on your computer gets hit with a copy of the virus. So when you
posted a message on the newsgroup, your return address was in the header.
Someone somewhere who reads a newsgroup that you post to and/or had your
address on a message was stupid enough to open the virus infected attachment
and their computer was infected. It immediately sent messages to you and
everyone it recognized. Not only that, hundreds of people are getting
infected messages that appear to have come from you since it uses the same
address reservoir for the spoofed returns.


--
Steve House
MS Project MVP
Visit http://www.mvps.org/project/faqs.htm for the FAQs
 
G

Gary L. Chefetz

IMO, it's more a matter of all the folks that got fooled by this one. The
delivery package is very convincing to many people. The message with the
infected attachment left alone is benign. It's harmless when posted to news
groups or inboxes save for the gullability of the user.

The novelty of this one is it's use of the newsgroup to propogate itself. It
actually harvests the emails from the cached news group files on the users
system and then not only starts sending the virus to everyone on the list,
it also spoofs the mailing addresses by using them in the outgoing virus
messages. This leads to a continuous stream of virus messages and returned
mail messages where the virus has sent emails to bad addresses and used your
email as a reply-to-address.

This is a strong argument for setting your preview pane to off, setting
your news reader to read all news group messages in plain text, and not
posting your true email address to the news group unless it's an address
you're willing to "expose." Disguising the address helps a lot, but it's not
without risk.

--

Gary Chefetz [MVP]
http://www.msprojectexperts.com
"We wrote the book on Project Server"

*** Remember to look for line breaks in links posted to the news group, use
cut and paste for these.
 
B

Bill Quinton

A useful and interesting discussion. But I'm not sure if
you think it is my pc that was infected and started this
off. We think we have a good firewall and email checking
system, but if something got through to us, and then
mailed itself to everyone else, then we'll do more
checking of our systems.

I am more inclined to suspect that another contributor is
infected, and has harvested the email addresses (at least,
I'd like to hope so).

487 interceptions of infected emails by our internet
service so far!

Best wishes

Bill
 

Ask a Question

Want to reply to this thread or ask your own question?

You'll need to choose a username for the site, which only take a couple of moments. After that, you can post your question and our members will help you out.

Ask a Question

Top