Wilders Security Forums  

Go Back   Wilders Security Forums > Other Security Topics > malware problems & news
User Name
Password
Register FAQ Members List Calendar Search Today's Posts Mark Forums Read

 
 
Thread Tools Search this Thread
  #1  
Old February 16th, 2002, 01:51 PM
Detox's Avatar
Detox Detox is offline
Global Moderator
 
Join Date: Feb 2002
Location: Texas, USA
Posts: 8,508
Default those bastards

Hmm today I opened Outlook express and AVG was on the job, first time I've seen it in action. I had an email from "hahaha@sexyfun.net" (maybe com??) and it had an attached file "dwarf4u.exe" It told me what virus it was but i figured I would still be able to see it in the virus vault and I can't... The msg text was about snow white but I don't think AVG called the virus snow white.. anyway this is the second time i have received this, last time Vcatch caught it.
__________________
"The price of freedom is eternal vigilance."
- Thomas Jefferson
  #2  
Old February 16th, 2002, 01:53 PM
Detox's Avatar
Detox Detox is offline
Global Moderator
 
Join Date: Feb 2002
Location: Texas, USA
Posts: 8,508
Default Re: those bastards

oh I think it said "worm" something..
__________________
"The price of freedom is eternal vigilance."
- Thomas Jefferson
  #3  
Old February 16th, 2002, 02:15 PM
Paul Wilders's Avatar
Paul Wilders Paul Wilders is offline
Administrator
 
Join Date: Jul 2001
Location: The Netherlands
Posts: 12,383
Default Re: those bastards

Hi Detox,

This is Hybris (or a variant). Read the specs over here:

http://securityresponse.symantec.com/avcenter/venc/data/w95.hybris.gen.html

regards.

paul

__________________
01110010 01100101 01100111 01100001 01110010 01100100 01110011 00100000 01110000 01100001 01110101 01101100
  #4  
Old February 16th, 2002, 06:02 PM
Krusty's Avatar
Krusty Krusty is offline
Frequent Poster
 
Join Date: Feb 2002
Location: Finland
Posts: 431
Default Re: those bastards

Hello Detox
I got that same "hahaha thingy" and one encrypted file once together. You should remember that senders address and block it from your server. Atleast that option is on outlook express.(thank God) I also responded the sender and it was nothing I could put it here C/;: -). I got them from simlive@willmar.com and stevej353@excite.com. They won´t bother me anymore.
-Ari a.k.a Krusty
__________________
¿ Did you remember to make back up today ?
Please don´t call Gator\Claria as spyware; call it trojan horse.
RealPlayer breaks your puter.
Don´t do as I do, Do exactly I advice
  #5  
Old February 16th, 2002, 06:40 PM
wizard's Avatar
wizard wizard is offline
Frequent Poster
 
Join Date: Feb 2002
Location: Europe - Germany - Duesseldorf
Posts: 818
Default Re: those bastards

The worm uses a fake email address hahaha@sexyfun.net. Some people opened a webpage on http://www.sexyfun.net/ with a lot of good information and removal help about the hybris worm.

wizard
__________________
wizardRESEARCH - Malware Research & Analysis since 1989
  #6  
Old February 17th, 2002, 04:01 PM
Detox's Avatar
Detox Detox is offline
Global Moderator
 
Join Date: Feb 2002
Location: Texas, USA
Posts: 8,508
Default Re: those bastards

Very cool now I should try to figure out who has this that I know, since it would sound like someone with my address in their book is sending it to me unknowingly...

Thanks for the great links those were very informative! Now I definitely know exactly what is trying to attack me!
__________________
"The price of freedom is eternal vigilance."
- Thomas Jefferson
 

Wilders Security Forums > Other Security Topics > malware problems & news « Previous Thread | Next Thread »

Thread Tools Search this Thread
Search this Thread:

Advanced Search

Posting Settings
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

vB code is On
Smilies are On
[IMG] code is On
HTML code is Off
Forum Jump


All times are GMT -5. The time now is 11:02 AM.


Powered by vBulletin® Copyright ©2000 - 2009, Jelsoft Enterprises Ltd.
Copyright ©2002 - 2009, Wilders Security Forums