Go Back  FlyerTalk Forums > Community > CommunityBuzz
Reload this Page >

A Virus Containing E-Mail from Tovaz

Community
Wiki Posts
Search

A Virus Containing E-Mail from Tovaz

Thread Tools
 
Search this Thread
 
Old Aug 19, 2001 | 2:30 pm
  #16  
Original Poster
 
Join Date: Apr 2000
Location: ATL, PAR, AMS & back to ATL
Programs: Delta SkyMiles, Hilton HHonors Gold, SPG Gold & Avis First
Posts: 1,222
Kremmen.....

The attachment I got was called "minsust.xls.bat" The link that you refer to is about a file called "W32.Sircam.Worm" I'm sorry I don't run daily searches about FT and viruses. My home page is www.msnbc.com so I do tend to stay pretty current on issues.

Now that the matter is cleared up, can essxjay just please close the thread.

Russ21Atl is offline  
Old Aug 19, 2001 | 3:06 pm
  #17  
Original Member
10 Countries Visited
100k
Community Influencer
25 Years on Site
 
Join Date: May 1998
Location: PDX
Programs: TSA Refusenik charter member
Posts: 16,126
Russ21Atl, I can certainly lock this thread if you like, but I don't think it really should be shut down.

You bring up some points that are relevant and on-topic in this forum, so I'm really disinclined to take such drastic measures as locking it down.
essxjay is offline  
Old Aug 19, 2001 | 4:20 pm
  #18  
 
Join Date: Apr 2000
Location: Monkeyville
Programs: Island DOs, very sticky toffee pud w vanilla ice cream n multi-coloured velvet pillows enthusiast
Posts: 4,647
Kremmen, just because that you know ONE thing more than another person, it is not justifiable to be so arrogantly assume, not once but twice, that he or she lives under a rock, metaphorically or not.....

Russ21ATL was a friend at Delta forum, he answered many questions that we asked, that we did not know, that may seem trivial to him, but never did he once tell us we lived under a rock

please do not bash people that ask questions, if you know the answers, help, otherwise, please, do not inject anything that is hurtful

belle

[This message has been edited by belle3388 (edited 08-19-2001).]
belle3388 is offline  
Old Aug 19, 2001 | 6:54 pm
  #19  
30 Countries Visited2M20 Years on Site
 
Join Date: Dec 2000
Location: Nr. Lugano
Programs: LH SEN, IHG Platinum, Marriott Lifetime Gold
Posts: 1,615
I received this same e-mail from a small German regional airline (Luftfahrtgesellschaft Walter) that flew me from Dortmund to Hamburg in May. I reserved online and must still have been stored on their PC.

I just sent it back saying that I must have received it in error.
Snoopy is offline  
Old Aug 19, 2001 | 10:39 pm
  #20  
 
Join Date: May 2001
Location: Tucson, AZ
Programs: US Gold, PC Platinum, BW Diamond
Posts: 406
Fellow FTers,

I didn't know this thread was open until tonight, but I wanted to comment on the events at hand.

On Thursday night, my 10 year-old opened an attachment from one of his friends. He didn't think anything of it at the time, and shut the computer down a few hours later. On Friday morning, I noticed when I accessed my Yahoo E-Mail account that an E-Mail from my Outlook Express had been received. Knowing I hadn't sent one, I checked the attachment, now labeled "minsust", and found out it was carrying the sircam virus.

I then took preventative measures as recommended by some of the virus websites, which was to notify those persons in my Address Book that if they received an E-Mail from me with this attachment to delete immediately.

I was contacted by Russ on Saturday morning with the message, along with a host of other people I didn't know. I thought (and still do) that a brief message saying to "delete now" was the best course to take, rather than a long, blow by blow explanation of what happened.

As a courtesy to Russ, on his follow-up to me, I did offer up this explanation, along with my apologies. It is kind of disconcerting, however, that he didn't feel the need to disclose this follow-up to the board, nor respond back to me.

Again, my apologies to anyone who received this E-Mail/Attachment. As you know by seeing some of these posts, I never knowingly sent any of these E-Mails out. My only fault in this is not having an up-to-date virus program.

tovaz

Additionally, I did notify FlyerTalk Admin of this situation last night once I found that the reach of the virus extended past the contents of my Address Book.

[This message has been edited by tovaz (edited 08-19-2001).]
tovaz is offline  
Old Aug 19, 2001 | 10:41 pm
  #21  
 
Join Date: Oct 2000
Location: BKK when I'm not in Princeton
Programs: UA MP:1P for life, TG:Gold, CO:Gold
Posts: 2,017
<font face="Verdana, Arial, Helvetica, sans-serif" size="2">Originally posted by Efrem:
A few suggestions, all of which can be found elsewhere but in this case bear repeating:
&lt;snip&gt;
3. Do not open attachments from ANYBODY unless you know what they are. When in doubt, confirm with the sender.
</font>
I agree that it would be best to verify an attachment before opening it, but at least for me, I routinely send and receive many file attachments to/from known companies, and generally proceed to open such attachments if there is otherwise nothing suspicious about them. That is what makes Sircam, and similar viruses that propagate based on stored addresses, so insidious. I was hit by Sircam last week from a server in a mainland Chinese company that I deal with all the time. Fortunately McAfee detected and quarantined the virus, but I was rather annoyed nonetheless, as I had specifically inquired whether the company had updated their virus signatures after the initial Sircam outbreak over a month ago. They assured me that they had.
UAL Traveler is offline  
Old Aug 20, 2001 | 12:01 am
  #22  
FlyerTalk Evangelist
All eyes on you!
20 Years on Site
 
Join Date: Apr 2001
Location: Reality, Freedom
Programs: AF FB Platinum For Life (F+ Rouge Vintage) / Hertz President's Circle / SNCF Grand Voyageur Le Club
Posts: 10,111
Tovaz,

I did not receive an infected e-mail from you, but thanks for your post anyhow. I'm sure no one blames you for what happened; if they did, they must be living under a rock!

I just received an e-mail with this virus this morning from an old family friend whom I haven't heard from in years. Pretty crafty virus, because the subject line was "Grand Marnier Truffles" and this fellow used to make truffles as a hobby and a small business.

But the message was in poorly written English, so I immediately deleted it before opening the file attachment.

So the virus is still active and people should be cautious about opening e-mail attachments even from friends before taking the necessary antivrus precautions.

P.S. My old "truffle" friend also has earthlink as an ISP



[This message has been edited by blairvanhorn (edited 08-20-2001).]
blairvanhorn is offline  
Old Aug 20, 2001 | 2:07 am
  #23  
20 Years on Site
 
Join Date: Dec 2000
Location: Tri-State
Posts: 1,888
<font face="Verdana, Arial, Helvetica, sans-serif" size="2">Originally posted by Larrude:
akhullar - This virus is not limited to the usual Outlook and Outlook Express. I got hit with this virus at my office and the email that I use there is Lotus Notes.

</font>
Strange, most folks at work use Notes. Of!Course no one uses Launch or Detach. I do know that pine is immune to it since it does
not execute no scripts anyway.
akhullar is offline  
Old Aug 20, 2001 | 3:40 am
  #24  
 
Join Date: Oct 2000
Location: BKK when I'm not in Princeton
Programs: UA MP:1P for life, TG:Gold, CO:Gold
Posts: 2,017
<font face="Verdana, Arial, Helvetica, sans-serif" size="2">Originally posted by blairvanhorn:
But the message was in poorly written English...&lt;snip&gt;</font>
Which is why I thought it authentic, coming from a mainland company I deal with all the time.

Its sad that the bad guys so often follow on the heels of the good guys... no matter where, cyberspace included.

UAL Traveler is offline  
Old Aug 20, 2001 | 5:53 am
  #25  
Original Member
10 Countries Visited
All eyes on you!
25 Years on Site
 
Join Date: May 1998
Location: Rochester, NY USA
Programs: Hilton - Diamond, IHG - Platinum
Posts: 1,433
<font face="Verdana, Arial, Helvetica, sans-serif" size="2">Originally posted by RichG:
Larrude: There's a difference between getting the virus, and being able to re-propagate it. Please confirm whether you just were "infected" with the virus, or if you know for sure that it sent out copies of itself as e-mail from your computer.[/B]</font>
I don't know for sure if it sent out email from my computer, but it was found by my anti virus program in locations OTHER than my incoming email directory.


[This message has been edited by Larrude (edited 08-20-2001).]
Larrude is offline  


Contact Us - Archive - Advertising - Cookie Policy - Privacy Statement - Terms of Service -

This site is owned, operated, and maintained by MH Sub I, LLC dba Internet Brands. Copyright © 2026 MH Sub I, LLC dba Internet Brands. All rights reserved. Designated trademarks are the property of their respective owners.