Please post to the newsgroup.
Thanks in advance for any help,
--
Ray :-)
Antispam: remove the numbers to reply.
I have a VIRUS, that sends a message exactly one minute later, with NO subject
matter in the subject line, and has changing titles, such as--
( I always send myself a CC of all email I send out)
---------------------------------------------------------
Subject:
Date: Sun, 25 Feb 2001 11:52:23 -0800
From: <ed-...@home.com>
Protect_your_credit.HTML.pif
Name: Protect_your_credit.HTML.pif
Type: Shortcut to MS-DOS Program
(application/x-unknown-content-type-piffile)
Encoding: base64
----------------------------------------------------
Subject:
Date: Sun, 25 Feb 2001 16:01:53 -0800
From: <ed-...@home.com>
JIMI_HMNDRIX.MP3.pif
Name: JIMI_HMNDRIX.MP3.pif
Type: Shortcut to MS-DOS Program
(application/x-unknown-content-type-piffile)
Encoding: base64
-----------------------------------------------------
TODAY, 2-26 the subject has changed to
Subject:
Date: Mon, 26 Feb 2001 21:41:10 -0800
From: <ed-...@home.com>
HANSON.SCR
Name: HANSON.SCR
Type: Screen Saver
(application/x-unknown-content-type-scrfile)
Encoding: base64
=======================================
>>>> Notice it is NO LONGER a pif file? <<<<
Notice how the title changes? The pattern varies, but usually it
will go 3 - 4 times before changing.
Incidentally, I DO NOT have a Jimi Hendrix mp3 in my system. One
other day the title was
ME_NUDE_AVI.pif and FREE_XXX_SITES.txt.pif -a friend called
me and said it wiped out his address book, and corrupted his access to @home
internet
(cable) which he had to call their techs to get reconnected. I'm a 63 year
old retired guy,
and while I have a couple years experience surfing the net, I'm certainly not
an expert.
I have a SONY VAIO desktop, bought 10/97 on Windows 95b, added to 96 SDRAM
and a 10 g harddrive 2 years ago.
I appreciate any advice you can give.
IMPORTANT- The VIRUS is NOT sent
through YAHOO- only from my Netscape INBOX-
Thanks. Ed Langley ed6...@yahoo.com
===========================================
at about.com --
http://windows.about.com/compute/windows/library/weekly/aa030200a.htm
NETSCAPE caused a stack fault in module <unknown> at 0000:10027573.
Registers:
EAX=65656661 CS=0157 EIP=10027573 EFLGS=00010246
EBX=00000000 SS=015f ESP=00a42000 EBP=0fc25971
ECX=000000b8 DS=015f ESI=00bf23a8 FS=0e47
EDX=000000c0 ES=015f EDI=1002740e GS=0000
Bytes at CS:EIP:
e8 fb ff ff ff 00 00 00 00 00 00 00 00 00 00 00
Stack dump:
10027578 10027578 10027578 10027578 10027578 10027578 10027578 10027578
10027578 10027578 10027578 10027578 10027578 10027578 10027578 10027578
------------------------------------
then immediately on closing that--
TALKBACK caused an invalid page fault in
module TALKBACK.EXE at 0157:00410b09.
Registers:
EAX=007a1153 CS=0157 EIP=00410b09 EFLGS=00010206
EBX=00000000 SS=015f ESP=0067f82c EBP=0067f838
ECX=007a0970 DS=015f ESI=007a1195 FS=7037
EDX=bffc1470 ES=015f EDI=00000000 GS=0000
Bytes at CS:EIP:
8a 07 ff 75 0c 88 45 08 47 e8 aa ff ff ff 59 8a
Stack dump:
00000000 007a0970 00000000 0067f860 0041233e 007a1194 00000053 00000002
007a0970 00411fac 00000000 0067f868 007a3be0 007a0970 0040eaeb 00000000
--------------------------------------
then opened Opera 3.1-
OPERA caused a stack fault in module <unknown> at 0000:00000003.
Registers:
EAX=10b61bbb CS=0157 EIP=00000003 EFLGS=00010213
EBX=00b6b9f0 SS=015f ESP=0076fb24 EBP=0000018a
ECX=03000000 DS=015f ESI=00000098 FS=37ef
EDX=816d754c ES=015f EDI=004055d5 GS=0000
Bytes at CS:EIP:
00 65 04 70 00 16 00 84 db 65 04 70 00 14 d7 1f
Stack dump:
00008170 00b622f0 00000000 0040577e 00000000 00b622f0 00000000 0000018a
0076fb58 00405fc7 00b600d0 00b6bd00 00000010 0076fb94 00470248 00008171
==========================================
NETSCAPE caused a stack fault in module <unknown> at 0000:10027573.
Registers:
EAX=65656661 CS=0157 EIP=10027573 EFLGS=00010246
EBX=00000000 SS=015f ESP=00a42000 EBP=0fc25971
ECX=00000108 DS=015f ESI=03b15f90 FS=0e37
EDX=00000110 ES=015f EDI=1002740e GS=0000
Bytes at CS:EIP:
e8 fb ff ff ff 00 00 00 00 00 00 00 00 00 00 00
Stack dump:
10027578 10027578 10027578 10027578 10027578 10027578 10027578 10027578
10027578 10027578 10027578 10027578 10027578 10027578 10027578 10027578