vpFREE2 Forums

virus in personal email

did anyone else in this group get personal email from this address:

WFFaust@ aadvantage.info.aa.com - the attachment had a virus. the
message was about vp in vegas and had some personal items about
where to meet for dinner, etc. but no names and no greetings -
beginning or end. here is the message:

*******I hope your other good story is that you won the Jaguar
(maybe that's not until next weekend)! Anyway, I wonder what the
odds are for your Caesar two RF outcome? Getting it on two lines
needing two cards has to be really rare. We have never even seen it
on two lines only needing one card! But maybe next trip!

I don't know what is going on with the Palms but glad your raise
made your decrease less painful! I imagine they will have something
special during the 12-17 period as there is no BB on that date.
They may also have decreased it because of the four of a kind bonus
on Tues. and Thurs. It would be nice to play for that 125 coin
bonus but if we do that on the $, it will mess up our daily
average.

Dinner on Monday the 25th should work out well for us also. Maybe
we can all figure out how to play 3 card poker over dinner! I
assume we will see you at Caesars the week before for the tournament
and at LVH for the shopping.

  Attachment

bool9898 wrote:

did anyone else in this group get personal email from this address:

WFFaust@ aadvantage.info.aa.com - the attachment had a virus. the
message was about vp in vegas and had some personal items about
where to meet for dinner, etc. but no names and no greetings -
beginning or end. here is the message:

snip

I don't know about anyone else, but I never received it. I checked my folder where I keep current posts I am following, as well as the trash can for my e-mail (which I hadn't emptied since 11/9 (judging from the discarded posts that are still in it), and I can't find anything from that address. I assume that this was sent directly to you rather than through the VPFree group; it if had been sent via VPFree, I should have received a copy.

Unless the abilities of new viruses has increased yet again, it appears to me that you were very likely deliberately targeted with that virus. What I mean about 'abilities' is that, once a computer is infected, viruses can currently mail copies of infected files to addresses listed in the infected computer's address book without the knowledge of the owner, and the viruses also have the ability to add seemingly innocent subject lines ... even varying them to some degree. But I've never heard of a virus that could, for instance, analyze your mail-folders and then create a fictitious message that would have content of a similar nature to your folders in order to give it the appearance of a bona fide message and otherwise make it seem interesting enough to cause you to open the attachment That's a very scary prospect

But assuming that they still can't do that, there are two possibilities: first, and the easiest and most likely, is that someone deliberately targeted you (and possibly other folks, as well); the second is that it was a legitimate message which just happened to contain a virus because the sender was unaware that his computer is infected (this is most unlikely if you do not know the send and the message actually makes no sense to you, especially considering that there doesn't appear to be any other reason for the attachment than to spread the virus.

Sorry to hear about your problem.

Bill Velek

I got the same mail. There are still many virus mails running around
from the last storm with "senders" trying tyo appear to be related to
Microsoft. I still get 2-8 of those a day with the same 142 or 154k
attachments. Delte, delete, delete, sigh...

did anyone else in this group get personal email from this address:

WFFaust@ aadvantage.info.aa.com - the attachment had a virus. the
message was about vp in vegas and had some personal items about
where to meet for dinner, etc. but no names and no greetings -
beginning or end. here is the message:

*******I hope your other good story is that you won the Jaguar
(maybe that's not until next weekend)! Anyway, I wonder what the
odds are for your Caesar two RF outcome? Getting it on two lines
needing two cards has to be really rare. We have never even seen

it

on two lines only needing one card! But maybe next trip!

I don't know what is going on with the Palms but glad your raise
made your decrease less painful! I imagine they will have

something

special during the 12-17 period as there is no BB on that date.
They may also have decreased it because of the four of a kind bonus
on Tues. and Thurs. It would be nice to play for that 125 coin
bonus but if we do that on the $, it will mess up our daily
average.

Dinner on Monday the 25th should work out well for us also. Maybe
we can all figure out how to play 3 card poker over dinner! I
assume we will see you at Caesars the week before for the

tournament

···

--- In vpFREE@yahoogroups.com, "bool9898" <bool9898@y...> wrote:

and at LVH for the shopping.

  Attachment

Bill;
I think I may be able to shed some light on this subject, as I have spent a
lot of time dealing with the problem and investigating outbreaks that have
affected vp-mail users.

Bill Velek wrote:

Unless the abilities of new viruses has increased yet again, it appears
to me that you were very likely deliberately targeted with that virus.

I doubt this has happened. In no case that I have investigated has this
occurred. I know it's possible, but my guess is that these days, the chances
are about 1 in a 1,000.

What I mean about 'abilities' is that, once a computer is infected,
viruses can currently mail copies of infected files to addresses listed
in the infected computer's address book without the knowledge of the
owner, and the viruses also have the ability to add seemingly innocent
subject lines ... even varying them to some degree. But I've never
heard of a virus that could, for instance, analyze your mail-folders and
then create a fictitious message that would have content of a similar
nature to your folders in order to give it the appearance of a bona fide
message and otherwise make it seem interesting enough to cause you to
open the attachment That's a very scary prospect

There are a nmber of viruses that do exactly this. As a matter of fact it's
getting to be the norm. Here's what a typical modern virus can do, once it's
infected your computer.

It can scan documents on your computer for titles and text can use that title
for the attachment and/or subject.

It can scan your mail folders for addresses, subjects and text.

It will use the addresses it finds to spoof the From and To fields in the
message header. I have been able to examine the Return-Path field in the
past to find the actual sending computer, but I think that field may be
spoofed also by the newer viruses. Sometimes the virus will just make these
addresses (other than the To: address) up. That makes it harder to trace.
The virus may or may not spoof the IP address of the sender.

The body of the note may contain text from notes the virus has scanned or
from the documents it read.

All of this helps create the impression that a friend or acquaintance has
sent you an email with a document attached that is about a subject you are
familar with. This is great from the virus writer's perspective as it all
makes it more likely that an attachment may be opened. But it also has helped
me track down the source computer when one of vp-mail's members has been
infected:

When several people from the group start getting virus emails of a similar
type from different people, it becomes obvious that a member is infected. The
email addresses, the subject and attachment titles all are clues to the
sending computer. Often some of the sending addresses generated are not group
members, so that alone can narrow down the infectee, since only someone who
has that address in their mail folders or address book would be the infectee.
The same is true for the titles. By asking people if they have any documents
with those titles on their computers, I have been able to pin down a couple
of these. The combination of the titles and non-group email addresses can
quickly pinpoint the infected computer.

The nice thing about this is that even if someone is too embarrased to admit
their computer got infected, they can be alerted (through the group) and
disinfect their computer quietly and on their own.

But assuming that they still can't do that, there are two
possibilities: first, and the easiest and most likely, is that someone
deliberately targeted you (and possibly other folks, as well);

As I have noted, this is not only not the most likely, it is highly
unlikely. In all the years I have been hosting vp-mail I have never run
across a verifiable instance of this. It could happen, of course. Just not
very likely.

the
second is that it was a legitimate message which just happened to
contain a virus

While I guess this could also happen, I don't know of a case of it happening
either. Virus messages are almost always (my guess is 99.99% of the time)
Worms sent from the infected computer by the virus itself. This is the most
efficient way for viruses to work.

Here are some basic rules of thumb about modern worm type viruses:
- The sending computer is usually not (and more recently almost never) the
one in the "From:" field. It may or may not be the address in the
"return-Path" field.
- The sending computer is one that has your address in it somewhere, either
in the address book or (more likely these days) in your mail folders.
- The person whose computer sent you the virus does not know that it happed,
did not send you any emails personally and probably has no idea that their
computer is infected.
- You should never open an attachment unless you know EXACTLY what it is. If
you aren't sure you should contact the sender.
- Anyone who is on the Internet or uses email should have and use antivirus
software. This is just part of being a good "Netizen".
-One other item. Here is the single worst piece of advice well-meaning (but
ignorant) TV commentators offer about viruses - Never open an attachment from
someone you don't know. Well, yes, that is good advice but also very
misleading. Most of the virus infections happen by opening an attachment
"from" someone you know. Or think you know.

There are some links for info about viruses and hoaxes at
http://www.vphomepage.com/handystuff.html#VIRUS
Thanks,
Skip
www.vphomepage.com

I stand corrected. I had no idea that these virus had become _SO_ sophisticated. Thanks, Skip.

snipped a very informative post explaining in great detail the ability of viruses to actually copy text from non-infected files into the body of the message, as well as subject lines, 'from' fields, etc.

Gee, this really troubles me. I'd have to have some damned virus copy a confidential legal file and then send it out for all of the world to read: You know, something like: Well, Mr. Smith, even though you wife has plenty of evidence of your infidelities with a couple of men -- including those photographs of you and Misters Jones and Brown in a three-some, I still think we can probably negotiate a sufficiently agreeable property settlement so that we will never need to take this matter to court ... etc. Fortunately, I keep my antivirus and firewalls uptodate, but this makes me wonder whether all such confidential data ought not be kept strictly on removable media except while being used.

Cheers.

Bill Velek

Michael Boutot wrote:

I got the same mail. There are still many virus mails running around
from the last storm with "senders" trying tyo appear to be related to
Microsoft. I still get 2-8 of those a day with the same 142 or 154k
attachments. Delte, delete, delete, sigh...

snip

I got so sick and tired of deleting all of those phoney "MicroSoft" e-mails that I just setup a filter on my mailreader to automatically delete them for me. If you're uncomfortable with deleting mail that you've never seen, you could just have them moved automatically to another folder where you could be more mindful and cautious before opening them. If you have Netscape 7.1, you can also have them displayed in a different color to draw your attention to them and then be more cautious.

Bill Velek

correction:

Bill Velek wrote:

... I'd have to have some damned virus copy a
confidential legal file

Should have read: ... I'd HATE to have some damned virus ...

Might make more sense now.

Bill