Hi to Group (and blind copies to a few friends involved with other
groups so they can let their groups know),
I'm sending Bill and Carol-Ann's entire message. I had never heard
of this one.
:)
whitegoose
Message:
<< I just spent $75 getting rid of a virus that came to me
(unsolicited of course!) on the internet. It was an e-mail titled
"Snow White and the Seven Dwarfs - the REAL Story." When I opened
it, it was blank, so I got rid of it. Too late! A few
weeks later (actually, last Tuesday night), my system crashed. You
might warn everybody on your maililng list to watch
out for it. (If I had seen the address "sexyfun" I wouldn't have
even opened it, but that never appeared.)
God Bless,
Bill & Carol Ann (Read Below Please)
Have you been receive spam mail from "hahaha@..."?
Subject: Snowhite and the Seven Dwarfs - The REAL story!
!! DO NOT OPEN THE EMAILS. DO NOT RUN THE ATTACHMENTS !!
!! THEY ARE INFECTED AND HAVE A FAKE RETURN ADDRESS !!
=====
Preface:
I get lots of unsolicited e-mail, with so many addresses
exposed to the Internet address scroungers, so for me to see
a new message from some unheard-of person or company is not at
all unusual. So, I've overlooked the following for a while.
Information:
From: Hahaha@... <== Major nasty little virus.
Subject: Snowhite and the Seven Dwarfs - The REAL story!
If and when you get a message from this address, watch it.
It has attachment of a variety of 31 different files.
If you open any of them, you'll wish you hadn't.
I've not ascertained what the little bugger will do,
but it is touted as "the most sophisticated virus yet."
Background:
It is similar to the "Happy.exe" virus, which was apparently
harmless, but spread itself by sending itself to everyone new
address you write to. Lovely, huh? It's still going too.
It began at the end of 1999, as I recall, so you can see its
longevity...
Well, this new one is like that too, but fancier. This one even
goes to various sources to update itself, and may even open a trap
door to your computer, or any other thing the programmer(s)
wish to do in the next version once you have it on your system.
Anyway, enough of that. Just know, first, don't open ANY file
that comes to you in e-mail, as a .exe or a .scr filetype if you
value your virus free status. Especially ones from
Hahaha@.... (I also DO NOT open any .doc files)
False Sense of Security:
"Oh, you're silly, Jeff. I have virus protection..."
Yeah, you may think so, but the programmers of viruses pride
themselves on hiding their programs in new ways, and there is
always some lag time before virus protection programs catch the
latest and greatest of viruses.
Trust those famous last words with great caution too:
"Check out this funny little program! I've checked it
with 3 virus checker programs. It's SAFE!"
The way I look at it, I only trust programs coming directly
from the source, and even that can be suspect. Hell, Microsoft
included a virus in its own Operating System (OS) once... :-(
State-of-the-art Hybris Virus:
This one takes many such measures to hide itself, including
128 bit encryption of the code and rewrites various files in
ways that don't hide the changes... and so on. As I said, it
is the state-of-the-art effort at messing over your life.
It is all over the 'Net too. So look out!
I get a dozen copies a day (which I automatically delete with
filtering). I even know someone who started a new address at
a large provider yesterday, never mailed with it once, and
already received two different variations of this Hybris virus
in her new mailbox the very first day!! Wow.
Apparently, her new ISP is infected, and is spreading it
through their mail servers...
"When a computer is infected with the virus, the virus harvests
email addresses sent and received over the computer's Internet
connection, and then emails itself out to those addresses."
--SpamCop.net
How do I get rid of it?
For those of you who are saying, "Oh my God... I just opened
that cute little program from HaHaHa@.... I was just
SURE I was going to get a nifty show..."
Below you can find a link to a FREE program to remove it,
and some background on how to do so.
http://www.datafellows.com/v-descs/hybris.shtml
F-Prot is one of the best virus removal systems.
It is a very tricky little bugger though.
(This virus has to be removed at the DOS level.)
Learn More:
If you're the type who would like to read about the latest and
greatest in viscous programming, have a look. (Or just want to
know more so you can better protect yourself.)
HERE is a write up from Symantec's site:
http://www.norton.com/avcenter/venc/data/w95.hybris.gen.html
HERE is a write up from Sophos's site:
http://www.sophos.com/virusinfo/analyses/w32hybrisc.html
HERE is a write up from F-Prot's site:
http://www.datafellows.com/v-descs/hybris.shtml
HERE is a write up from Kaspersky Labs:
http://www.kaspersky.com/news.asp?tnews=0&nview=1&id=134&page=0
And here is a write up from SpamCop.net:
http://news.spamcop.net/pipermail/spamcop-help/2000-December/000263.html
=====
Visit Strokesurvivors International website at http://strokesurvivors.org