independent and unofficial
Prince fan community
Welcome! Sign up or enter username and password to remember me
Forum jump
Forums > General Discussion > WARNING: Virus in the Prince community, check your computers
« Previous topic  Next topic »
  New topic   Printable     (Log in to 'subscribe' to this topic)
Author

Tweet     Share

Message
Thread started 08/20/03 3:45pm

cloud9mission

avatar

WARNING: Virus in the Prince community, check your computers

Hey all,

Ive been recieving emails all day from people I dont know personally but I recognise the addresses from some people's user names here. All the emails, though allegedly from different people, have the same content:

Subject Line: Re: your approval

Text: Please check out the attached file

The attatched file is a virus, do not open it wink. Ive emailed all the people that it got sent to me via to warn them & hopefully this thread gets to anyone else. If you have it, be sure to warn everyone in your email address book cos thats how it gets around.

God bless

Lewis
  - E-mail - orgNote - Report post to moderator
Reply #1 posted 08/20/03 3:48pm

cloud9mission

avatar

Bump this thread a few times so everyone sees it
  - E-mail - orgNote - Report post to moderator
Reply #2 posted 08/20/03 3:50pm

CherrieMoonKis
ses

avatar

Thanx Cloud9 smile
peace & wildsign
  - E-mail - orgNote - Report post to moderator
Reply #3 posted 08/20/03 3:52pm

madartista

avatar

A new variant of W32/Sobig, W32/Sobig.f@MM is a High Risk mass-mailing worm. It arrives as an email attachment with a .pif or .scr extension. When run, it infects the host computer, then emails itself (using its own SMTP engine) to harvested email addresses from the victim's machine. In addition, when it propagates, the worm "spoofs" the "from: field", using one of the harvested email addresses.

Note: The worm copies itself onto the infected machine as: C:\WINNT\WINPPR32.EXE

Caution: An infected email can come from addresses you recognize and may contain the following information:

WHAT TO LOOK FOR:

Subject: [content varies]
- Your details
- Thank you!
- Re: Thank you!
- Re: Details
- Re: Re: My details
- Re: Approved
- Re: Your application
- Re: Wicked screensaver
- Re: That movie

Body: [content varies]
- See the attached file for details
- Please see the attached file for details

Attachment: [content varies]
- your_document.pif
- document_all.pif
- thank_you.pif
- your_details.pif
- details.pif
- document_9446.pif
- application.pif
- wicked_scr.scr
- movie0045.pif

[This message was edited Wed Aug 20 16:02:18 PDT 2003 by madartista]
let me come over it's a beautiful day to play with you in the dark
http://elmadartista.tumblr.com/
http://twitter.com/madartista
  - E-mail - orgNote - Report post to moderator
Reply #4 posted 08/20/03 3:56pm

cloud9mission

avatar

madartista said:

A new variant of W32/Sobig, W32/Sobig.f@MM is a High Risk mass-mailing worm. It arrives as an email attachment with a .pif or .scr extension. When run, it infects the host computer, then emails itself (using its own SMTP engine) to harvested email addresses from the victim's machine. In addition, when it propagates, the worm "spoofs" the "from: field", using one of the harvested email addresses.



Note: The worm copies itself onto the infected machine as: C:\WINNT\WINPPR32.EXE



Caution: An infected email can come from addresses you recognize and may contain the following information:



WHAT TO LOOK FOR:




Subject: [content varies]
- Your details
- Thank you!
- Re: Thank you!
- Re: Details
- Re: Re: My details
- Re: Approved
- Re: Your application
- Re: Wicked screensaver
- Re: That movie



Body: [content varies]
- See the attached file for details
- Please see the attached file for details



Attachment: [content varies]
- your_document.pif
- document_all.pif
- thank_you.pif
- your_details.pif
- details.pif
- document_9446.pif
- application.pif
- wicked_scr.scr
- movie0045.pif

Thanx for the technical info
  - E-mail - orgNote - Report post to moderator
Reply #5 posted 08/20/03 4:01pm

madartista

avatar

cloud9mission said:


Thanx for the technical info


Yeah -- mainly wanted to show other subjects that could appear.
let me come over it's a beautiful day to play with you in the dark
http://elmadartista.tumblr.com/
http://twitter.com/madartista
  - E-mail - orgNote - Report post to moderator
Reply #6 posted 08/20/03 4:12pm

DJ506

avatar

Yeah...I've been getting these fuckers all day in my hotmail. mad

I just delete them.
  - E-mail - orgNote - Report post to moderator
Reply #7 posted 08/20/03 4:13pm

cloud9mission

avatar

madartista said:

cloud9mission said:


Thanx for the technical info


Yeah -- mainly wanted to show other subjects that could appear.

I just searched for WINPPR32.EXE cos sometimes Norton dont detect them straight away. My computer is clean yay!
  - E-mail - orgNote - Report post to moderator
Reply #8 posted 08/20/03 9:58pm

cloud9mission

avatar

DJ506 said:

Yeah...I've been getting these fuckers all day in my hotmail. mad

I just delete them.

yeah, users of hotmail & yahoo should be ok as if any one gets a virus, it will be hotmail or yahoo themselves. Just dont open that file
  - E-mail - orgNote - Report post to moderator
Reply #9 posted 08/21/03 11:15pm

pinkshoes

avatar

thanks for the info.


smile
-Pinky rainbow member of the gay org mafia.rainbow
Self-Love Club : Master of the Masturbators
  - E-mail - orgNote - Report post to moderator
  New topic   Printable     (Log in to 'subscribe' to this topic)
« Previous topic  Next topic »
Forums > General Discussion > WARNING: Virus in the Prince community, check your computers