© 2003-2006 David Moles

Chrononautic Log

«  More iced tea, Mr. Secretary?
  Main  
What is it?  »

life

Email virus alert

1 o'clock, September 18, 2003

Okay, technically it’s a trojan horse, not a virus. But you get the idea.)

I’m getting a lot (like, a pair every five minutes — not sure why it’s coming in pairs) of pretty homogeneous, virus-laden email coming in to dm@chrononaut.org this morning. Since it’s only coming in to that address, I think there’s a reasonable chance that some folks out there with that address in their Outlook/Exchange mailboxes or address books have gotten infected. (It seems less likely that an email virus would be combined with a web screen-scraper, but I suppose it’s possible.) So any of you unfortunate enough to be on That Platform may want to do some virus checking.

And if you’re on Windows and you get an email that claims to be a Microsoft security update (with plenty of realistic-looking content in the message itself, including links and phone numbers) with an attached “patch file” or “audio file”, for God’s sake don’t open it.

A sample:

From: "MS Corporation Security Support"
To: "Commercial Customer"
Subject: Latest Net Upgrade

Microsoft Customer

this is the latest version of security update, the "September 2003, Cumulative Patch" update which eliminates all known security vulnerabilities affecting MS Internet Explorer, MS Outlook and MS Outlook Express. Install now to maintain the security of your computer from these vulnerabilities, the most serious of which could allow an attacker to run code on your computer. This update includes the functionality of all previously released patches.

System requirements: Windows 95/98/Me/2000/NT/XP This update applies to:

  • MS Internet Explorer, version 4.01 and later
  • MS Outlook, version 8.00 and later
  • MS Outlook Express, version 4.01 and later

Recommendation: Customers should install the patch at the earliest opportunity.

How to install: Run attached file. Choose Yes on displayed dialog box.

How to use: You don't need to do anything after installing this item.

(Except maybe kiss your sweet ass goodbye.)

Comments

*Just* received this myself, immediately after reading your post. If the headers are correct, seems like it's coming from the Netherlands (.nl(?)). And it was addressed to an e-mail account I only use on the sff.net newsgroups, so I suspect that may be where my addy got scraped. Different from: and to: fields though.

From: "Microsoft"
To: "Customer"

—— Scott Reilly, 1:37 PM, Thursday, September 18, 2003

And this is why I've spent the last week running around, trying to make sure all the employees here are properly patched, so they won't go and open messages like that, or if they do, nothing will happen.

—— Jon, 1:47 PM, Thursday, September 18, 2003

I find it particularly ironic that for some reason when I went to read these comments, there was a java script error and up popped the MS Script Debugger and crashing down came my system.

—— aphrael, 2:27 PM, Thursday, September 18, 2003

I'm getting the spam in all my accounts. bleh.

David's comments have always had a script error, at least according to IE:

Line: 256
Char: 9
Error: Object expected
Code: 0

Doesn't seem to hurt anything though.

—— Scott Janssens, 3:20 PM, Thursday, September 18, 2003

Scott - yeah, you're right. I was doing this on a new machine that doesn't have Opera yet, and i'd forgotten that it happened all the time before I switched browsers. The foolishness was me clicking on 'yes i want to debug'.

—— aphrael, 4:06 PM, Thursday, September 18, 2003

Probably I should just get rid of the pop-up and have it go directly to the archive page.

Either that, or add a button that says “this site doesn’t work on the browser that 95% of you are probably using.”

Which is sorta true anyway, at least as far as the CSS and tables are concerned.

—— David Moles, 4:12 PM, Thursday, September 18, 2003

Remember if Microsoft actually had a critical patch/update available, they would not include the actual file in an e-mail, but rather point you to a address containing info on the patch/update. Good post.

—— JT, 11:25 AM, Monday, September 22, 2003