PPRuNe Forums - View Single Post - BEWARE, YET ANOTHER NASTY VIRUS......
View Single Post
Old 22nd Jul 2001, 13:49
  #11 (permalink)  
CrashDive
Moderator
 
Join Date: May 1998
Location: .
Posts: 250
Likes: 0
Received 0 Likes on 0 Posts
Post

I had it too, e.g. I got in from a flight at 1am this morning and it looks like the wife had earlier decided to read two new emails sent to me - one started with the ubiquitous "Hi there,.... " and the other with "I send you this file in order to have your advice", and both of which included an attachment.

Now what tipped me off was my ZoneAlarm firewall software asking me if it was ok to allow an application called Sirc32.exe to access the internet ( "Uhm, what the bloody'ell is that ?!" thought I ) - no doubt so that it could make use of its embedded SMTP connectivity to spread itself about to all the contacts in my email list.

Nb. That warning from ZoneAlarm occurred literally as I opened MS-Outlook, as apparently what triggers the virus to run is you running any .exe program.

I then spent the next 10 minutes getting rid of it, via the instructions from Symantec (see below).

Nb. It has not been mentioned above, but the Symantec anti-virus centre reports that there is a 1 in 20 chance that this virus can delete all the files on your C: drive !!!
I'd accordingly highly recommend a good read of: Symantec - Security Updates - W32.Sircam.Worm@mm

Of course, as many of us PPRuNers have each others email address, one can see just why we are all simultaneously experiencing this virus.

Ps. I normally instantly bin all emails with attachments from unknown sources - which is what I subsequently did in this instance - I've also since bollocked the wife about opening emails, and I've also (re)applied passwords to my computer - talk about Pandora's box !

PPs. When / if you get infected by this virus, have a look in CWindows\Applog folder for a file with a name like Sirc32 and open it with Notepad / Wordpad and you might be able to see from who's computer the virus was spread to you, or to whom it was trying to send itself next....
CrashDive is offline