About these virus...
-
nightman (imported)
- Articles: 0
- Posts: 6
- Joined: Sat Apr 27, 2002 2:00 am
-
Posting Rank
About these virus...
My PC once crashed cause I opened a .JPG file... some applications can hide extensions... and I had been an idiot since the icon was not the standard .JPG icon on my computer PLUS I was running without anti-virus and firewall then... even if I knew I was much better off with them...
I just wrote to say : be careful with ANY file from strangers EVEN from seemingly familiar persons ! Since this file had been sent to me on ICQ, someone hacking a friend's ICQ number !!!
Anyway, use your judgment and be careful and just open what you really want and need to open...
(this was a complement to the announcement above thank you)
I just wrote to say : be careful with ANY file from strangers EVEN from seemingly familiar persons ! Since this file had been sent to me on ICQ, someone hacking a friend's ICQ number !!!
Anyway, use your judgment and be careful and just open what you really want and need to open...
(this was a complement to the announcement above thank you)
Re: About these virus...
Good point.
Any file you intend to open up should be saved to disk and analyzed first - not immediately opened!
I had never considered the possibility of a sneaky application hiding the extension, but I suppose it is possible. You should know what your icons are supposed to look like. Obviously, if your JPG file doesn't have a red flat cat over the name (IrfanView3x) then it's probably not a JPG file, etc.
It's just amazing how many people out there have archive@eunuch.org in their address books, and seem to have some sort of trojan or worm running amok in their computer. Of course, not every email baddie of this type is meant to cause damage; it just 'nests' and 'has babies' then spreads them!
Also, should have put this in the announcement too ... if you need to send me some kind of file, or to the Archive for whatever reason, LET ME KNOW FIRST. I don't even open the messages with attachments. This would be stories you need help with, for whatever reason, or perhaps a pic to scale down for your avatar - which I will be happy to do.
:p
Any file you intend to open up should be saved to disk and analyzed first - not immediately opened!
I had never considered the possibility of a sneaky application hiding the extension, but I suppose it is possible. You should know what your icons are supposed to look like. Obviously, if your JPG file doesn't have a red flat cat over the name (IrfanView3x) then it's probably not a JPG file, etc.
It's just amazing how many people out there have archive@eunuch.org in their address books, and seem to have some sort of trojan or worm running amok in their computer. Of course, not every email baddie of this type is meant to cause damage; it just 'nests' and 'has babies' then spreads them!
Also, should have put this in the announcement too ... if you need to send me some kind of file, or to the Archive for whatever reason, LET ME KNOW FIRST. I don't even open the messages with attachments. This would be stories you need help with, for whatever reason, or perhaps a pic to scale down for your avatar - which I will be happy to do.
Re: About these virus...
It's quite probable that nightman opened a file that had an extension like:
whatever.jpg.exe
You see the jpg part of the extension and figure it is a photograph but when you go to open it it is an executable that can do whatever it wants. This is a flaw in most software in which it only displays the first extension and not the real extension. I've seen this on a friends computer who wanted to open a picture on a chatroom and got socked.
Unfortunatly even virus protection software cannot help you depending on what the executable does.
Your best bet is never, ever open a file from anyone unless you have trust and friendship with them. In this manner they will understand and forgive while you beat the living snot out of them with a pipe wrench for having given you a file that killed your computer.
tal
p.s. Most icons are in gif format, or at least they should be.
whatever.jpg.exe
You see the jpg part of the extension and figure it is a photograph but when you go to open it it is an executable that can do whatever it wants. This is a flaw in most software in which it only displays the first extension and not the real extension. I've seen this on a friends computer who wanted to open a picture on a chatroom and got socked.
Unfortunatly even virus protection software cannot help you depending on what the executable does.
Your best bet is never, ever open a file from anyone unless you have trust and friendship with them. In this manner they will understand and forgive while you beat the living snot out of them with a pipe wrench for having given you a file that killed your computer.
tal
p.s. Most icons are in gif format, or at least they should be.
-
nightman (imported)
- Articles: 0
- Posts: 6
- Joined: Sat Apr 27, 2002 2:00 am
-
Posting Rank
Re: About these virus...
There are applications created especially to hide file extensions.
I know cause I once wanted to know more about hacking and I downloaded and tried at least TWO of these applications. I had not worked hard enough with them to actually make them work.
I don't remember their name since it was 2 years ago and I guess they're hard to find now with the loss of freedom on the internet, the programs banned from download.com, and the hacking sites shut down.
My real .jpg icon was a woman's breasts (IrfanView) but the icon of the evil file was the standard .jpg icon Windows shows before you install any image software.
The evil person had showed up on ICQ on a friend's number and I had noticed that she was not acting as usual. I asked her and she told me she was my virtual friend's little sister. She sent me her picture and I saw the false icon but it was already too late, I had already double-clicked !
I know cause I once wanted to know more about hacking and I downloaded and tried at least TWO of these applications. I had not worked hard enough with them to actually make them work.
I don't remember their name since it was 2 years ago and I guess they're hard to find now with the loss of freedom on the internet, the programs banned from download.com, and the hacking sites shut down.
My real .jpg icon was a woman's breasts (IrfanView) but the icon of the evil file was the standard .jpg icon Windows shows before you install any image software.
The evil person had showed up on ICQ on a friend's number and I had noticed that she was not acting as usual. I asked her and she told me she was my virtual friend's little sister. She sent me her picture and I saw the false icon but it was already too late, I had already double-clicked !
-
nightman (imported)
- Articles: 0
- Posts: 6
- Joined: Sat Apr 27, 2002 2:00 am
-
Posting Rank
Re: About these virus...
Everything shut down.
When I rebooted, with a boot disk, Windows saw no file on C:
(I also had D:)
In fact the files were still there but invisible to Windows.
I used the fantastic program called FinalData with which you can recover lost data (invisible or deleted from the recycle bin).
I waited a little too long before using that program so I lost some date but anyway, after that, I have had to re-install Windows.
That's about the story.
Now never will I run without an anti-virus or 2
and a firewall or 2
It's also always good to know how some things work.
Éric
When I rebooted, with a boot disk, Windows saw no file on C:
(I also had D:)
In fact the files were still there but invisible to Windows.
I used the fantastic program called FinalData with which you can recover lost data (invisible or deleted from the recycle bin).
I waited a little too long before using that program so I lost some date but anyway, after that, I have had to re-install Windows.
That's about the story.
Now never will I run without an anti-virus or 2
and a firewall or 2
It's also always good to know how some things work.
Éric
-
torturemycock (imported)
- Articles: 0
- Posts: 89
- Joined: Mon Mar 11, 2002 10:36 pm
-
Posting Rank
Re: About these virus...
I received a virus from a guy called Kourtjester, and I started to open it. The Norton systrem kick in immediatly. I am glad. I usually wont open files from people I dont know. I am so glad I have Norton. I am not trying to advertise for them, but I would just say don't open files you don't know.
-
nightman (imported)
- Articles: 0
- Posts: 6
- Joined: Sat Apr 27, 2002 2:00 am
-
Posting Rank
Re: About these virus...
Most viruses out there are designed to target flaws and holes in Microsloth's Outlook Express / Outlook mail systems. Most of them are also targetted at Win 9x, ME, and 3.1x. Yes, there are still 3.1x systems out there, believe it ... I've found that systems running NT4, NT2000 or XP-pro usually aren't prone to a lot of the older viruses such as Magistrs, etc. However, this is no guarantee. There are also bugs out there that target NT etc only.
One thing you can do is to keep your regular email address that you have via your ISP to your friends only and ask that they not share it. E-cards like Blue Mountain and such are notorious for spamming you to death and getting you onto mailing lists. Avoid this.
For registering for something, like EA or any board, it's best to use something like HotMail or Yahoo. Even if you have virus scanning like Norton, Hotmail and most others scan the email as well with McAffee or somesuch. And in webmail, reading the message won't trigger the viral payload like Outlook will. Outlook is all too anxious to run things it gets!
Rest assured, EA is spam free and we do not collect email addresses to sell. We are nonprofit and toll-free and plan to stay that way.
One thing you can do is to keep your regular email address that you have via your ISP to your friends only and ask that they not share it. E-cards like Blue Mountain and such are notorious for spamming you to death and getting you onto mailing lists. Avoid this.
For registering for something, like EA or any board, it's best to use something like HotMail or Yahoo. Even if you have virus scanning like Norton, Hotmail and most others scan the email as well with McAffee or somesuch. And in webmail, reading the message won't trigger the viral payload like Outlook will. Outlook is all too anxious to run things it gets!
Rest assured, EA is spam free and we do not collect email addresses to sell. We are nonprofit and toll-free and plan to stay that way.
-
Charlieje (imported)
- Articles: 0
- Posts: 326
- Joined: Wed Nov 28, 2001 2:02 pm
-
Posting Rank
Re: About these virus...
Another defense is a better email program than Microsoft's, which is targeted by everyone. I have used a product called PMMAIL since 1995 and I love it. (I know, talula, this is a form of spam spam .) What can I say?
One of the nifty features of PMMAIL is called "remote control." I can set it to always use remote control when getting new mail, and it will show me a list of what's on the server before I ever download anything, and I can simply delete anything that is suspect before it ever sees my computer. If I do managed to download a virus, which I do from time to time, attachments are never opened automatically, and as Paolo has already suggested, they get saved to a file and scanned before they are opened.
Just another thought.

One of the nifty features of PMMAIL is called "remote control." I can set it to always use remote control when getting new mail, and it will show me a list of what's on the server before I ever download anything, and I can simply delete anything that is suspect before it ever sees my computer. If I do managed to download a virus, which I do from time to time, attachments are never opened automatically, and as Paolo has already suggested, they get saved to a file and scanned before they are opened.
Just another thought.