vpFREE2 Forums

Virus received in bogus "Anthony Curtis" email

Because of the likelihood that others will have received the
virus-containing email that I did this evening, I wanted to report it.

The email, time stamped at 7:50 pm, listed the sender as "Anthony
Curtis" and had a subject line of "Hello".

The email was scanned upon receipt on my PC with Norton Antivirus which
identified an attachment, guzr.zip, as being infected with the virus
W32.Novarg.A@mm

···

------

If you've received the "Curtis" email and your antivirus software hasn't
flagged the virus, the email should be deleted upon receipt. It goes
without saying that attachments in suspicious emails (sender known or
unknown) shouldn't be opened.

If you don't have antivirus software active on your PC you're placing
yourself at great risk these days now that viral activity is at an
all-time high.

Make sure that your software regularly checks for virus definition
updates, preferably daily.

It's critical that you be confident that the email scanning feature of
the software is active. This isn't necessarily the default. If
uncertain, review the help files within the software and/or go to the
vendor's website for instructions.

- Harry

Excellent advice Harry. I have had several emails from people I know
with the same thing. I have been sending them an email back telling
them that they have been zapped. You can go up the Norton web site and
get the fix for it and flush it out of your computer. There are two
versions of this virus running around at the moment. Mydoom and Mydoom
B. You got the Mydoom. These are the popular name of the virus. I
have been told that February 1st through the 12th is when this virus
goes very active and will wreck havoc with your computer files if you
have it. Beware.

Bob

Harry D. Porter wrote:

Because of the likelihood that others will have received the
virus-containing email that I did this evening, I wanted to report it.

The email, time stamped at 7:50 pm, listed the sender as "Anthony
Curtis" and had a subject line of "Hello".

The email was scanned upon receipt on my PC with Norton Antivirus which
identified an attachment, guzr.zip, as being infected with the virus
W32.Novarg.A@mm

------

If you've received the "Curtis" email and your antivirus software hasn't
flagged the virus, the email should be deleted upon receipt. It goes
without saying that attachments in suspicious emails (sender known or
unknown) shouldn't be opened.

If you don't have antivirus software active on your PC you're placing
yourself at great risk these days now that viral activity is at an
all-time high.

Make sure that your software regularly checks for virus definition
updates, preferably daily.

It's critical that you be confident that the email scanning feature of
the software is active. This isn't necessarily the default. If
uncertain, review the help files within the software and/or go to the
vendor's website for instructions.

------------------------------------------------------------------------
Yahoo! Groups Links

    * To visit your group on the web, go to:
      http://groups.yahoo.com/group/vpFREE/
       
    * To unsubscribe from this group, send an email to:
      vpFREE-unsubscribe@yahoogroups.com
      <mailto:vpFREE-unsubscr…@…com?subject=Unsubscribe>
       
    * Your use of Yahoo! Groups is subject to the Yahoo! Terms of
      Service <http://docs.yahoo.com/info/terms/>.

[Non-text portions of this message have been removed]

Bob Sommer wrote:

I have had several emails from people I know with the same thing. I
have been sending them an email back telling them that they have
been zapped.

Actually, in many (likely most) cases the "sender" of the email, or
their PC, isn't involved at all. The virus "spoofs" (artificially
inserts) that sender's name and/or address by picking it up on the
computer that's actually infected -- from another email, the address
book, or by scanning other files.

In the case of the email virus I received, it's unlikely that Anthony
Curtis (or LVA) has an infected computer but that it was instead
generated by the computer of a LVA Lite recipient.

Nonetheless, it doesn't hurt to make that "sender" aware and suggest
that they may want to immediately perform a full virus scan of their
system.

You can go up the Norton web site and get the fix for it and flush
it out of your computer.

This is necessary once your antivirus program flags your computer as
being infected. But hopefully, if your email scanning option is
active, the email will be intercepted before it has a chance of
causing infection and no further action will be necessary.

- Harry

Harry Porter wrote:

> You can go up the Norton web site and get the fix for it and flush
> it out of your computer.

This is necessary once your antivirus program flags your computer as
being infected. But hopefully, if your email scanning option is
active, the email will be intercepted before it has a chance of
causing infection and no further action will be necessary.

Actually you can run the Norton fix and if infected, it will give you the cure, and if you are not infected, it will tell you that also when the program finishes. If you don't have an anti-virus program running, I would suggest people do this. It's free and easy to do. Just follow the instructions.

Bob

···

At the risk of overkill, I wanted to provide a background info that I
hope might be a little enlightening concerning this virus, and the
subject in general:

-- It should be emphasized that the virus in the "Anthony Curtis" email
did not originate with his computer, or any of those at LV Advisor.

-- Any computer when infected with this virus from another source will
generate an email with the attachment, encode the email with a Sender
selected from mail in the inbox (in this case "Curtis"), and send it out
to all the email addresses found in the address book and in other
messages in the inbox.

···

============

-- Given that at least 3 members of the winpoker Yahoo! group have
reported receiving the "Curtis" virus email, it's very likely that one
source is an infected winpoker member who receives individual emails of
the group posts.

-- I expect those who have posted to winpoker (at least recently), or to
any other group from which this person receives individual emailed
posts, are susceptible to receiving this virus email.

============

By the way, for what it's worth, this virus is not one of those that
attempt to corrupt a recipient's PC system itself (e.g. deletion of
system files). Instead, when activated (by opening the email
attachment) between the dates of Feb. 1 and Feb. 12, it will configure
your PC to repeatedly "hit" the Microsoft Corp. and SCO Group websites.
With enough hits by multiple infected computers these websites/servers
will be disrupted. This isn't the first such attack. A similar assault
in December on SCO produced over 600,000 hits on their system.

However, if your computer is affected, those repeated hits by your
computer will severely reduce it's response to any program use or to
internet access.

============

Removal of the virus if infected
--------------------------------

- If infected, a removal tool can be downloaded from the website of
antivirus software providers (even if you don't have their product).

- Users of Windows XP or ME need to take an initial step before use of
the tool.

================================
Extended discussion on removal:

--> You may wish to skip this unless you actually become infected :slight_smile:

If you don't have virus software on your system that scans incoming
emails for virus attachments (and removes the virus before you even see
the email), and you should become infected (note that it's necessary
that you open the attachment to the email to become infected), you can
download a removal tool for the virus from an antivirus website such as
Symantec.com.

However, if you're running Windows XP or Windows ME there's a step that
is critical to take before running the tool.

These two operating systems have a feature called the System Restore
Utility. The purpose of this utility is to backup certain system files
(such as the Registry) anytime there's a modification. This way, if
there's a subsequent problem for any reason, these files can be restored
to their state before the change.

In order to ensure the integrity of the backups, Windows doesn't permit
any external program to modify them. Consequently, if a backup was
performed by System Restore at any point subsequent to the infection,
the backups can't be repaired by the removal tool. If there's a need to
later restore these backups to your system the virus will be reinstated.

For this reason, Windows ME/XP users must turn off the System Restore
Utility before running the virus removal tool (and turn it back on
after). Instructions should be included in those for the removal tool.
Be certain not to skip this step if applicable.

- Harry

Bob Sommer - Top of the World Coins wrote:

Harry Porter wrote:

>
> > You can go up the Norton web site and get the fix for it and flush
> > it out of your computer.
>
> This is necessary once your antivirus program flags your computer as
> being infected. But hopefully, if your email scanning option is
> active, the email will be intercepted before it has a chance of
> causing infection and no further action will be necessary.

Actually you can run the Norton fix and if infected, it will give you
the cure, and if you are not infected, it will tell you that also when
the program finishes. If you don't have an anti-virus program running,
I would suggest people do this. It's free and easy to do. Just follow
the instructions.

It's _FREE_ and easy to do?? Norton's makes me pay an annual fee. Where are you getting it for free? Or are you referring to the fix? As for it doing things automatically, which Norton's program do you have? Last year my son's computer became infected with a worm, and we were using Norton's at the time (I think it was probably 2002), but he wasn't keeping it up to date; anyway, the problem he was having was his computer shut-down after just a minute or two on-line, so that made it impossible for his computer to download anything of any length. I had to use _my_ computer to download the fix, transfer it to him computer via diskette, and fixed it that way. I guess it depends on the type of virus. Anyway, I later upgraded to Norton's Internet protection package (whatever it's called) with firewall and more bells and whistles, and had so much trouble with my system because of it that I just went back to the regular Norton Anti-Virus 2003 and a different firewall.

Bill Velek

it was necessary for me to download the fix

Bill;

A cheap trick. Around this time of year you can find Norton
Systemworks bundled with their anti-virus program at places like
CompUSA. They have a manufacturers rebate AND an upgrade rebate.
Together they equal the sales price. They have now configured the
programs so they will load over older versions. In essence you get
the updates and another year of anti-virus protection free.

Marc

It's _FREE_ and easy to do?? Norton's makes me pay an annual

fee.

···

Where are you getting it for free? a different firewall.

Bill Velek

Great suggestion! You can buy the disk for Norton's Systemworks Pro on ebay. I've been able to get mine for approx. $10 year for the last few years. It has some great extras besides virus protection. The best extra to me is a program called Go Back. If you have a glitch with your computer you can use Go Back to go back in time to when your computer was working correctly.. This program has saved my bacon a few times..

Carol
www.CountlessPages.com
For a 10% discount on any books purchased
on our site, please use this coupon code:
10CP053104

  <<Bill;

  A cheap trick. Around this time of year you can find Norton
  Systemworks bundled with their anti-virus program at places like
  CompUSA.>>

[Non-text portions of this message have been removed]

free online virus scanner:
http://housecall.trendmicro.com/
free malware scanners:
http://www.lavasoft.de/
http://www.safer-networking.org/
http://www.spywareinfo.com/
free port security scan (ShieldsUP!):
http://www.grc.com/default.htm
free sun java replacement for discontinued microsoft java:
http://www.microsoft.com/mscorp/java/
microsoft security info:
http://www.microsoft.com/security/home/

concerning this virus

I received it too, and the subject from Curtis was "hi" for me not "hello". I am not a member of Winpoker group, so it is somewhere else if it is there. Member of VpFree and was on the message forums in LVA....

For what is it worth.

Pid

···

"Harry D. Porter" <harry.porter@verizon.net> wrote:

---------------------------------
Do you Yahoo!?
Yahoo! SiteBuilder - Free web site building tool. Try it!

[Non-text portions of this message have been removed]

In the case of the email virus I received, it's unlikely that

Anthony

Curtis (or LVA) has an infected computer but that it was instead
generated by the computer of a LVA Lite recipient.

I received this email today from LVA :
"We've discovered that a computer virus was e-mailed to a portion of
our LVA Lite online mail list. We have corrected the problem and
installed very potent anti-virus software on our e-mail program."

This would lead me to believe that some at the Advisor DID have the
virus.

I earlier noted the likelihood that the "Anthony Curtis" email
containing virus was "spoofed" and from another source.

Curtis has notified LVA members that one of LVA staff's PC's was indeed
the source. (As started to become apparent with the growing number of
reports of the email that started to pop up on the LVA discussion groups
today.)

And, it was suggested to me that when you fully display the email header
(an option in you email program) the details on the network path through
which the message had been transmitted made it clear that LVA was the
likely source and not simply a spoofed Sender substitution.

···

------

By the way, I've again received another variant of this virus
(intercepted by Norton AV) this evening from another source (in this
case, clearly spoofed). It's becoming apparent that we're in for some
rough weather over the next few days.

As I've emphasized: Ensure that the email scanning option of your virus
program is enabled if you use a PC based email program (such as MS
Outlook or Netscape Messenger). An internet based client like hotmail
has a built in scanner that should detect a problem with any attachments
that you might open and eliminate it from the message.

- Harry