Announcement

Collapse
No announcement yet.

XS virus alert

Collapse
X
 
  • Filter
  • Time
  • Show
Clear All
new posts

  • XS virus alert

    Fellow XSives -

    I've gotten a couple of suspicious emails from XSive sources. One message was supposedly a reply to the XS11_BI_2002 list from "lordarik_2000 lordarik @ hotpup.com" which had an attachment, "yourassismine.jpg.exe". The return address is bogus and likely was taken from someone's email address book.

    The other suspicious e-mail was from "allxs11s@bigsky.net RE: Digest Number 84" and included an attatchment, "song.scr".

    Both were filtered out, but it looks to me like an XSive somewhere has gotten infected.

    I have also received several replies from a guy who says he's received several nonsense emails from my "mrbike99@yahoo.com" address. They said it looked like the KLEZ virus, which is apparently the world's #1 right now. I've scanned my system and it's clean. I also don't use Outlook.

    A lot of people on this list might have all three addresses in their address book. So, ladies and gentlemen, please practice safe computing and check your systems!
    Bill K.
    1985 Yamaha XJ700 Maxim
    1986 Yamaha FZX700 Fazer

  • #2
    For what it's worth, you don't have to use Outlook to have a problem. Any mail program that can handle scripts can pass a virus through the address book. This includes almost any program available. To really be safe, you can save addresses in a simple text file and cut and paste to your message, but the best solution is to have an up to date virus scan program, use it religiously, and update the definitions at least once a week. Mine is set to update automatically and has done so 3 times in the last 5 days. I'm connected to the Internet by broadband, so I run an automatic full system scan every 12 hours, but have still been infected twice. Sidecarmikel
    Sidecarmikel
    aka Mike Laubenstein
    Lake Tainter, Wisconsin

    1980 XS1100 soon to have sidecar
    1980 XS850/Dnepr sidecar
    1989 TransAlp/ no sidecar yet, but I know where there's an Equalean!

    It may be that your sole purpose in life is simply to serve as a warning to others.

    Comment


    • #3
      Been there, done that. Cleaned the stuff, no accounts on yahoo.

      LP
      If it doesn't have an engine, it's not a sport, it's only a game.
      (stole that one from I-dont-know-who)

      Comment


      • #4
        hey there Bill,
        I got a similar email from another XS11 address, and it had the same attachment, *.jpg.exe . I deleted it. It bothers me about this last message you wrote about , because it used "MY" yahoo ID as a fake email address "LordArik_2000" that I used to use on the old Yahoo XS11 list!!

        I always visited the site, wasn't set up for the email digest format. I, too, am clean, virus updates automatically, on full monitor mode, using broadband as well. I do use OE and IE, have the latest version 6.x of both with all security patches available. So...I know I'm not the one sending it!!!!! I hope whoever is figures it out soon and gets it cleaned up!
        T. C. Gresham
        81SH "Godzilla" . . .1179cc super-rat.
        79SF "The Teacher" . . .basket case!
        History shows again and again,
        How nature points out the folly of men!

        Comment


        • #5
          klez spoofs email adrs, tricky, eh?
          Mike * Seattle * 82 F'n'XJ1100 *

          Comment


          • #6
            I just got hit with something yesterday, but it came from a .jpg file on the web rather than from an e-mail. I clicked it (filename was .jpg) then my screen went blank, and the computer began to re-start, it then came up with a screen that said it was examining one of my disks due to an error and said Microsoft, blah, blah. But you could tell the screen was phoney. So I pulled the cable and then shut it down. On start-up it wanted to keep running the disk 'inspection' so finally I let it, but with the cable unplugged. Then it started up but nothing would run properly, so I had to re-start again and this time everything seemed to work OK, I ran a full virus scan, and spy-ware scan, both came up empty. I also ran a search for files created that day and found nothing out of the ordinary created about that time. I looked at running processes and earlier that day it was 33, now it showed 36. I used 'start-up cop' to shut down a couple of them that looked funky both were 'deamons' one for networking and one for something else. Other than that I am not sure what it did...all seems OK, I turned my Internet security up to 'high' in hopes I would catch something, but all seems well now.anybody get an infected e-mail from me or something? Should I save the data I can and reformat or what, 5 years I have not got a single virus, now this thing hits!
            Gary Granger
            Remember, we are the caretakers of mechanical art.
            2013 Suzuki DR650SE, 2009 Kawasaki Concours 1400, 2003 Aprilia RSV Mille Tuono

            Comment


            • #7
              I don't know about "start-up cop". Sounds good, but where do I get it?
              Bill Murrin
              Nashville, TN
              1981 XS1100SH "Kick in the Ass"
              1981 XS650SH "Numb in the Ass"
              2005 DL1000 V-Strom "WOW"
              2005 FJR1300 Newest ride
              1993 ST1100 "For Sale $2,700" (Sold)
              2005 Ninja 250 For Sale $2,000 1100 miles

              Comment


              • #8
                Bill,

                http://www.pcmag.com/article2/0,4149,2173,00.asp

                Description:
                When Windows starts up, it automatically launches a number of programs for you. Some of these come from the Startup folder. Windows also looks in six other locations for files that should be launched at startup. Startup Cop helps you handle problems with programs that are automatically launched at startup by listing them and letting you disable, enable, or delete them. You can save the list of programs that are currently enabled or disabled as a profile that can be restored at a later time.
                Gary Granger
                Remember, we are the caretakers of mechanical art.
                2013 Suzuki DR650SE, 2009 Kawasaki Concours 1400, 2003 Aprilia RSV Mille Tuono

                Comment


                • #9
                  you can also clean up those pesky start-up programs by running this:
                  C:\WINDOWS\SYSTEM\MSCONFIG.EXE

                  It allows you to see everything that windows does when it starts up. I had almost half of my memory taken up by the horde of programs that Uncle Bill puts in windows.

                  I now run with about 85% of my memory free.

                  Comment


                  • #10
                    You can go here and see the latest threats here:
                    http://securityresponse.symantec.com/

                    You can do a search there, for instance "jpeg virus" will list the threats that deal with jpeg files. Also if you haven't, configure your Windows to show all files, and not "hide extensions of known file types". A file called "filename.jpg.v b s" (my spaces) may show up as "filename.jpg" if the extensions are hidden.

                    Be sure you have your anti-virus software set to scan all files, not just the .exe, .com, etc. This is not usually the default setting.

                    And I would recommend more ferquent updates of your virus definitions. I was doing it once per week, I have increased that to every couple of days.

                    SWMBO has her geneology hobby, and deals with um, well, folks from a simpler time. Some not up to speed with these types of PC issues and threats. I can always tell when there is a new threat, I can count on several email messages getting trapped by my Norton AV.
                    Marty in NW PA
                    Gone - 1978E - one of the first XS11 made
                    Gone - 2007A FJR - the only year of Dark Red Metallic
                    This IS my happy face.

                    Comment


                    • #11
                      Originally posted by dasuchbe
                      you can also clean up those pesky start-up programs by running this:
                      C:\WINDOWS\SYSTEM\MSCONFIG.EXE

                      It allows you to see everything that windows does when it starts up. I had almost half of my memory taken up by the horde of programs that Uncle Bill puts in windows.

                      I now run with about 85% of my memory free.
                      Wow, how much memory do you run. After reading your post I checked mine. I have an HP Pavilion Pentium 4, completely as purchased. Everything that came with it is still here with the exception of Netscape. With IE6 and Outlook open, running XP Professional, it says I'm bouncing between 2% and 7% utilization. What programs did you kill?
                      Sidecarmikel
                      aka Mike Laubenstein
                      Lake Tainter, Wisconsin

                      1980 XS1100 soon to have sidecar
                      1980 XS850/Dnepr sidecar
                      1989 TransAlp/ no sidecar yet, but I know where there's an Equalean!

                      It may be that your sole purpose in life is simply to serve as a warning to others.

                      Comment


                      • #12
                        I am not sure, but when I checked it in the constrol panel in system properties under preformance, I am currently at 50% Free under system resources.

                        I run Norton System Works that, if you aren't careful, will run several programs in the background. I also found that my video card was running several progams that are not needed. But the bulk of it is programs that windows runs. Also, Yahoo Instant Messanger and MSN messanger stay running so that they will automatically log me in.

                        Basically, any of those icons on the right side of your task bar are programs that run and slow you down.

                        I am only running a 400mhz computer with 64mb of ram.

                        Comment

                        Working...
                        X