This is topic New virus in forum Film-Yak at Film-Tech Forum ARCHIVE.
To visit this topic, use this URL:
https://ft-forum.com/ft/cgi-bin/ubb/ultimatebb.cgi?ubb=get_topic;f=8;t=000045
Posted by Frank Rapisardi (Member # 435) on 10-07-2000, 03:26 AM:
Just wanted to pass this along.There is a new virus out there which there is no remedy for"It Takes Guts To Say Jesus" according to America Online ;it will wipe out all your files.In addition;the computer will not,cannot work.Please be careful!!!------------------
Posted by Brad Miller (Member # 2) on 10-07-2000, 10:52 AM:
POLLI'm curious, but with all the viruses out there, how many here actually still execute them? I stopped doing that a while back. I don't care if it's funny or not...it's not worth crashing my computer.
Posted by Mike Blakesley (Member # 26) on 10-07-2000, 11:22 AM:
I've had five computers over the past ten years and have NEVER had a problem with a virus. My secret is: Don't open ANY e-mail attachments unless you are DAMN SURE what you're getting.I am not much for downloading programs and the like (connecetions here in the sticks are too sloooooooow for that), so my "exposure" is admittedly lower than some...I don't play games or use things like screensavers, "themes," etc. either.
Posted by Leo Enticknap (Member # 534) on 10-07-2000, 03:26 PM:
The 'It takes guts to say Jesus' virus is a hoax. For full details, see:
www.syamtec.com/avcenter/venc/data/jesus-hoax.html IMHO, it's good netiquette to check out a virus warning to see if it's a hoax before passing it on. In particular, be very suspicious of warnings which say 'tell everyone' or words to that effect. There are a number of reputable sites you can use to do this; my favourite is:
www.sarc.com/avcenter/hoax.html
Posted by Leo Enticknap (Member # 534) on 10-07-2000, 03:33 PM:
Brad - I think you have a server problem. I got 'internal server error' three times when I attempted to send my last post, but when your system finally said it had accepted it, the message was there three times! Sorry...
Posted by Leo Enticknap (Member # 534) on 10-07-2000, 05:15 PM:
Sorry, there's a typo in the link in my earlier (three times duplicated) post. The link should be:
www.symantec.com/avcenter/venc/data/jesus-hoax.html
Posted by Brad Miller (Member # 2) on 10-08-2000, 02:41 AM:
The server error is a temporary issue. I made a note of it somewhere (who knows where though) on the forum, but my hands are tied right now on getting the hookup for the new server. It shouldn't be much longer. In the meantime, just hit your back button twice and then right click and select "reload frame". Your post will then appear.
Posted by Martin Frandsen (Member # 74) on 10-14-2000, 11:11 AM:
Don't all email hosts and web hotels etc. have virus protector programmes?
Posted by Scott Norwood (Member # 30) on 10-15-2000, 04:38 PM:
Depends on what you mean by "virus protector programs." Most mail servers are not configured to scan incoming mail attachments for virii, if that is what you're asking. If there's a big issue (like the "ILOVEU" worm from last spring), many ISPs will, however, auto-bounce mail that contains it (usually keyed off the file size or subject header), though.
The servers themselves don't generally require anti-virus software, since most server-grade operating systems (Unix, VMS, OS/390, etc.) have sufficient file permissions that virii don't really exist for those platforms. Further, even with a WinNT server, if the admin is clueful enough not to arbitrarily run executable code that originated from an untrusted source, there really isn't any need for anti-virus software either.
Posted by Randy Stankey (Member # 64) on 10-15-2000, 05:48 PM:
Not to say that this is a virus proof solution, (nothing really is) but my anti-virus strategy can be summed up in three letters... M-A-C.
Posted by Jason Burroughs (Member # 68) on 10-16-2000, 04:32 PM:
My solution, Never, Never, Never open a attahcment that has the *.VBS extention!! Best rule of thumb, unless you know exactly who it is comming from, and what it is, simply delete it. If it was imporant, who ever sent it to you will either re-send it or find annother way to contact you. I have not gotten a virus in over 10 years, only time I had a virus was when I ran a BBS many moons ago and a user uploaded a virus without my knowing.
Posted by Bernard Tonks (Member # 809) on 04-15-2002, 07:43 PM:
A new virus has just been discovered that has been classified by Microsoft as the most destructive ever! This virus was discovered yesterday afternoon by McAfee and no vaccine has yet been developed.
This virus simply destroys Sector Zero from the hard disk, where vital information for its functioning are stored.This virus acts in the following manner: It sends itself automatically to all contacts on your list with the title "A Card for You".
As soon as the supposed virtual card is opened, the computer freezes so that the user has to reboot. When the ctrl+alt+del keys or the reset button are pressed, the virus destroys Sector Zero, thus permanently destroying the hard disk. Yesterday in just a few hours this virus caused panic in New York, according to news broadcast by CNN. This alert was received by an employee of Microsoft itself.
So don't open any mails with subject: "A Virtual Card for You."
As soon as you get the mail, delete it!! Even if you know the sender or If you have to Confirm the e-mail withthe person before you open it, just to be safe, do it.!!!
Please pass this mail to all of your friends.
Forward this to everyone in your address book. I'm sure most people like myself, would rather receive this 25 times than not at all.
Also: Intel announced that a new and very destructive virus was discovered recently. If you receive an email called "An Internet Flower For You",Do not open it!!Delete it right away! This virus removes all dynamic libraries (.DLL files) from your computer. Your computer will not be able to boot up!!
Posted by Bob Maar (Member # 763) on 04-15-2002, 08:33 PM:
I was fortunate that a friend in Pittsburgh informed me that one of my off color jokes contained a virus. I took this joke off the internet. Matter of fact, my computer was acting funny and I sent a note to Brad as I thought I had destroyed Film-tech.com. Today my computer was frozen for seven hours and I finally boooted and all is well.Let's be carfull out in the world of Scott and Joe.
Now everyone reading this should go immediately to the closest bar and order a Beefeater Gobson straight up. If you don't like it send it to me.
Posted by Scott Norwood (Member # 30) on 04-15-2002, 09:22 PM:
FYI, the "Card for You" thing is a hoax:
http://vmyths.com/hoax.cfm?id=222&page=3
Posted by Gerard S. Cohen (Member # 994) on 04-15-2002, 09:41 PM:
Bernard gave another example of a virus hoax, if you didn't get his
spoof. "An Internet Flower for You" appears on the hoax web page
(op. cit.) under the words "Flower for You." I haven't spotted
"A Card For You" there, but suspect it might be listed on other sites.
Any Search Engine will provide lists of hoax and urban legend sites,
some run by the US government as a service to its citizens and businesses. Supplying them to your email correspondents doesn't always help--I'm still receiving recycled hoaxes from people I've
informed, kidded, and scolded for the past two or three years. Usually
the same people forward emails without removing the address lists of
all those who forwarded them in the past, no matter how often I beg them not to.
Posted by Bob Healey (Member # 1003) on 04-15-2002, 11:18 PM:
An annoying hoax that has caused me several hours of headaches trying to fix at work is one that says sulflnbk.exe in the c:\windows\command directory is a virus and to delete it immedietly. Interesting things happen when this file is delete and Windows 9x gets rebooted and it can't find the file.
Posted by Darryl Spicer (Member # 711) on 04-15-2002, 11:56 PM:
usually nothing happens when that file is deleted.however it does have something to do with identifying files with longer than 8 character names or something to that effect.
That subject was brought up on another thread on here somewhere.
Posted by Ron Lacheur (Member # 1126) on 04-16-2002, 03:02 AM:
Bob,If Windows is looking for that specific file on boot up, then it has associated it in the registry.
Posted by Dave Williams (Member # 299) on 04-16-2002, 05:08 AM:
I have only once had a virus let loose on my system, and that is because I put it there on purpose. I use to write viruses in my spare time to test my ability to do so. The best viruses are the most simple because they often are overlooked as a virus and do more damage in a shorter period of time.Although I never loosed them on anyone else, I am just not that mean.
Dave
Posted by Paul G. Thompson (Member # 655) on 04-16-2002, 01:11 PM:
Check the win.ini file in the windows directory. Look under the load= and see if there is a reference to the file you deleted. If there is, delete that reference.Back up the win.ini file first. 
Posted by Bernard Tonks (Member # 809) on 04-22-2002, 06:22 AM:
Another virus hoax I received but fortunately I didn't fall for it this time by checking the McAfee site first. Brought up before, fully reproduced after the notice. AVERT HOAX Notice!!
McAfee AVERT Labs would like to inform you of a new email HOAX.
This email message is just a HOAX. Although, the SULFNBK.EXE file may become infected by a number of valid viruses (most commonly W32/MAGISTr@MM , the details of this HOAX message are not based on actual events.
We are advising users who receive the email to delete the message and DO NOT pass it on as this is how an email HOAX propagates.
SULFNBK.EXE is a Microsoft Windows utility that is used to restore long file names
Below is the actual text from the message that may be received via email. There are numerous variations on these messages.
..................................................................
I found the "sulfnbk virus" in my computer, which McAfee did not detect. It sends itself to all the addresses in the address book of the computer it has arrived at. Since you are in our address book I thought you might want to check for this. The virus hides in the computer for 2 weeks & then damages the hard drive irreparably, so I'm told.
1. go to "Start" & click "Find"
2. in the box "find files or folders" type sulfnbk.exe which is the name of the virus
3. make sure you are searching in the hard or c-drive
4. click "find"
5. if the file is found, you will see an ugly black icon with name sulfnbk.exe , the file is a program. DO NOT OPEN IT.!!
6. click on the RIGHT button of the mouse, on the ugly black file icon, & then click on "delete" with the LEFT button on the mouse.
7. you will be asked if you want to send the file to the wastebasket/recycling bin. respond "yes".
8. go to the Desktop, open the wastebasket/recycling bin & eliminate the file, manually or by emptying the entire basket/bin.
9. if you find this virus in your computer, send this e-mail to all the people in your address book, because the virus is transmitted this way & if you don't warn them, aside from ruining their hard drive, it will come back to you if you are in their address books.
Posted by Dave Macaulay (Member # 813) on 04-22-2002, 07:54 AM:
There is a huge clue there that it's a hoax.
You are told to delete the file then immediately empty the trash or permanently delete the file from the trashbin.
Files in the trash can NOT be executed, trying only brings up the properties window for the file. The only reason for insisting on permanently deleting it is malicious - so you can't just replace it when you realize you were suckered. (plus - right click then shift-delete will permanently delete a file and bypass the trashbin. A big AV company should know that!)
But these things aren't targeted at people who know that kind of stuff I suppose.
Posted by Ian Price (Member # 14) on 04-22-2002, 05:45 PM:
On Friday April 16th I got a notice from AVG anti-virus program that there was a new patch to protect against this worm virus. I downloaded it.On Monday April 22 it found a worm virus in an email sent to our public account. I deleted it without a problem. I also forwarded it to abuse@earthlink.net but I suspect that they will not be able to do anything about it.
This is the first virus I have received from an anonymous source. The previous viruses first attacked our company servers and attached themselves to outgoing emails. My anti-virus program caught them too.
Ooh, I feel all dirty. 
My only advice is to keep your anti-virus programs current.
Mighty Mouse is here to save the day!
Posted by Joe Redifer (Member # 3) on 04-22-2002, 06:27 PM:
I have not read this thread in it's entirety, so forgive me if I bring up something that has already been discussed.Lately I have been getting a bunch of e-mails with files attached. Usually they are .HTML, .JPG, .EXE, and .BAT files. There is no text whatsoever in the e-mails. Of course the JPG files are not really JPG files since they won't open in my graphics programs on my Mac. These are not HTML mails I am receiving, either. Definitely viruses attached, and there seems to be a ton of 'em! The mail usually comes from someone I've never heard of and they have odd subjects like "NAV Bottom". That's about the closest thing to a pattern I can see.
Of course being on a Mac I am not affected, except that I get a lot of these e-mails. But it sure is annoying!
Posted by Paul G. Thompson (Member # 655) on 04-22-2002, 07:46 PM:
We got hit again with the sircam and ninja stuff at the radio station. Scanning the boss's machine, there were over 450 files that were plowed. I am going to have to format the drive. All this stuff is coming through Outlook Express. I can just look at the monitor, and out of nowhere, all these EML files just pop up on the monitor.
Now I have a suspicion why my computer sees and stops lots of port scan attacks. The other machines on the network don't have that software installed to see and block them.
I have to find a firewall program that will work with our old clunkers, as they are P-133's, and some of the anti-virus software slows those already painfully slow machines to a dead crawl.
Posted by Darryl Spicer (Member # 711) on 04-22-2002, 10:46 PM:
Go online to www.housecall.antivirus.com THis is a good site for checking your system for viruses, worms and all kinds of junk.
Posted by Leo Enticknap (Member # 534) on 04-23-2002, 03:20 AM:
Paul - the resident process for the free version of Zonealarm only claims to be eating 72k in the task manager. If your old P133s have plenty of memory I doubt if it would slow them down too much.
Posted by Adam Martin (Member # 641) on 06-15-2002, 12:32 AM:
This Klez crap is getting out of hand. Now I'm getting emails that say this:
quote:
Klez.E is the most common world-wide spreading worm.It's very dangerous by corrupting your files. Because of its very smart stealth and anti-anti-virus technic,most common AV software can't detect or clean it. We developed this free immunity tool to defeat the malicious virus.
You only need to run this tool once,and then Klez will never come into your PC.
NOTE: Because this tool acts as a fake Klez to fool the real worm,some AV monitor maybe cry when you run it. If so,Ignore the warning,and select 'continue'. If you have any question,please (email tag deleted) mail to me.
Hmmm... lessee ... if my AV monitor says it blocked the Klez virus, exactly why would I want your program to do the same thing?! Dumkopf.
Posted by Aaron Sisemore (Member # 145) on 06-15-2002, 04:07 AM:
Those 'Klez innoculator' emails usually contain the genuine Klez worm anyways. 
They are both a hoax and a threat.
-Aaron