those bastards

Discussion in 'malware problems & news' started by Detox, Feb 16, 2002.

Thread Status:
Not open for further replies.
  1. Detox

    Detox Retired Moderator

    Joined:
    Feb 9, 2002
    Posts:
    8,507
    Location:
    Texas, USA
    Hmm today I opened Outlook express and AVG was on the job, first time I've seen it in action. I had an email from "hahaha@sexyfun.net" (maybe com??) and it had an attached file "dwarf4u.exe" It told me what virus it was but i figured I would still be able to see it in the virus vault and I can't... The msg text was about snow white but I don't think AVG called the virus snow white.. anyway this is the second time i have received this, last time Vcatch caught it.
     
  2. Detox

    Detox Retired Moderator

    Joined:
    Feb 9, 2002
    Posts:
    8,507
    Location:
    Texas, USA
    oh I think it said "worm" something..
     
  3. Paul Wilders

    Paul Wilders Administrator

    Joined:
    Jul 1, 2001
    Posts:
    12,472
    Location:
    The Netherlands
    Hi Detox,

    This is Hybris (or a variant). Read the specs over here:

    http://securityresponse.symantec.com/avcenter/venc/data/w95.hybris.gen.html

    regards.

    paul
     
  4. *Ari*

    *Ari* Registered Member

    Joined:
    Feb 15, 2002
    Posts:
    431
    Location:
    Finland
    Hello Detox
    I got that same "hahaha thingy" and one encrypted file once together. You should remember that senders address and block it from your server. Atleast that option is on outlook express.(thank God) I also responded the sender and it was nothing I could put it here C/;: -). I got them from simlive@willmar.com and stevej353@excite.com. They won´t bother me anymore.
    -Ari a.k.a Krusty
     
  5. wizard

    wizard Registered Member

    Joined:
    Feb 9, 2002
    Posts:
    818
    Location:
    Europe - Germany - Duesseldorf
    The worm uses a fake email address hahaha@sexyfun.net. Some people opened a webpage on http://www.sexyfun.net/ with a lot of good information and removal help about the hybris worm.

    wizard
     
  6. Detox

    Detox Retired Moderator

    Joined:
    Feb 9, 2002
    Posts:
    8,507
    Location:
    Texas, USA
    Very cool now I should try to figure out who has this that I know, since it would sound like someone with my address in their book is sending it to me unknowingly...

    Thanks for the great links those were very informative! Now I definitely know exactly what is trying to attack me!
     
Thread Status:
Not open for further replies.