rec.autos.simulators

Virus alert

Mark Seer

Virus alert

by Mark Seer » Thu, 11 Nov 1999 04:00:00

It seems thatit's finally happened :-(. Take care guys.

<Snip>
We usually will not issue NOTAMS about virus alerts, but this one is so
dangerous, it's important that you all be aware of this virus and it's
implications.  Please read the following and visit the website provided for
further information.

From MSNBC:

New breed of virus unleashed

First-of-its-kind 'BubbleBoy' infects users just reading e-mail

By Bob Sullivan
MSNBC

Nov. 9 - A long-feared new breed of computer virus has finally emerged,
according to antivirus firms. The so-called BubbleBoy virus can infect
Internet users when they open, or even simply preview, an infected e-mail.
"Historically we've always said, as long as you don't open attachments, you'
re safe," Network Associates spokesman Sal Viveros said. "That's not true
any more."

More information available at http://www.racesimcentral.net/
<unsnip>

Andre Warring

Virus alert

by Andre Warring » Thu, 11 Nov 1999 04:00:00

First impression, I can't believe this, but I'm very curious to read
the explanation for the possibility of this. But the link doesn't
work...

Thanks for the warning anyway, hope this really is a hoax.

Andre

On Wed, 10 Nov 1999 21:03:25 -0000, "Mark Seery"


>It seems thatit's finally happened :-(. Take care guys.

><Snip>
>We usually will not issue NOTAMS about virus alerts, but this one is so
>dangerous, it's important that you all be aware of this virus and it's
>implications.  Please read the following and visit the website provided for
>further information.

>From MSNBC:

>New breed of virus unleashed

>First-of-its-kind 'BubbleBoy' infects users just reading e-mail

>By Bob Sullivan
>MSNBC

>Nov. 9 - A long-feared new breed of computer virus has finally emerged,
>according to antivirus firms. The so-called BubbleBoy virus can infect
>Internet users when they open, or even simply preview, an infected e-mail.
>"Historically we've always said, as long as you don't open attachments, you'
>re safe," Network Associates spokesman Sal Viveros said. "That's not true
>any more."

>More information available at http://www.msnbc.com/news/333265.asp
><unsnip>

Jo Hels

Virus alert

by Jo Hels » Thu, 11 Nov 1999 04:00:00

It is true, and then again it's not _completely_ true.

Here's what Network Associates (McAfee AV)has to say:
=================
Virus Name
VBS/Bubbleboy

Date Added
11/8/99

Virus Characteristics
This is an Internet worm that requires Internet Explorer 5 with Windows
Scripting Host installed (WSH is standard in Windows 98 and Windows 2000
installations). It does not run on Windows NT due to hard-coded limitations. The
Internet worm is embedded within an email message of HTML format and does not
contain an attachment. This worm is written in VB Script. There are two
variants; the .b variant is encrypted.

In MS Outlook, this worm requires that you "open" the email. It will not run if
using "Preview Pane".

In MS Outlook Express, the worm is activated if "Preview Pane" is used!

In both the above, if security settings for Internet Zone in IE5 are set to
High, the worm will not be executed. The vulnerability exploited by this worm
has been addressed by Microsoft with a security patch. Installing this Internet
Explorer patch will prevent the execution of this worm under default security
settings. Network Associates recommends to apply this patch for all desktops
running IE.

Microsoft "scriplet.typelib/Eyedog" Patch

After the VB Script executes, it writes the file UPDATE.HTA to the local machine
and during the next Windows startup, the .HTA file is invoked. The UPDATE.HTA
file is coded to do the following-

* Change the registered owner via the registry to "BubbleBoy"

* Change the registered organization to "Vandelay Industries"

* Send itself embedded in an email message to EVERY contact in EVERY EMAIL
ADDRESS BOOK of MS Outlook

* Sets the registry key to indicate that the email distribution has occurred.
(Email distribution will not be repeated.)

The email is a message with the following information:

From: (person who sent worm unintentionally)
Subject: BubbleBoy is back!

Message Body: The BubbleBoy incident, pictures and sounds

http://www.towns.com/dorms/tom/bblboy.htm

This is not a valid web page.

Indications Of Infection
Registry key modification:
HKEY_LOCAL_MACHIN\Software\OUTLOOK.BubbleBoy\ = OUTLOOK.Bubbleboy 1.0 by Zulu
or
HKEY_LOCAL_MACHIN\Software\OUTLOOK.BubbleBoy\ = OUTLOOK.Bubbleboy 1.1 by Zulu

HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\RegisteredOwner =
Bubbleboy
HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\RegisteredOrganization
= Vandelay Industries

NOTE:
AVERT Recommends scanning for all files at the gateway. For desktops, add .HT?
to the extensions list of files scanned by VShield for both the VirusScan 9x and
VirusScan NT products. Adding .HT? to the extension list for on-demand scanning
will provide protection as well.

AVERT recommends filtering the subject line with the WebShield SMTP product -
see www.nai.com for more information about this product.

Method Of Infection
This worm creates the file "UPDATE.HTA" in the "C:\windows\start
menu\programs\startup" folder. Upon Windows startup or restart, the worm code is
invoked.

Extra DAT Support
Download EXTRA.DAT for VirusScan 4.0.25 (and higher)- download here
Download EXTRA.DRV for Toolkit 7.99 - download here
Download Hourly Scan for 3x download here

Virus Information
  Discovery Date: 11/8/99
  Type: VBScript
  Risk Assessment: low
  Minimum DAT: 4052 (Available 11/18/99)

Variants
.A, .B

Aliases
VBS/Bubbleboy
=============


Please remove *anti-spam* from the email when replying.
=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=
When everything else failed, we can still become im-
mortal by making an enormous blunder....

                             John Kenneth Galbraith
=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=

Werner Hube

Virus alert

by Werner Hube » Thu, 11 Nov 1999 04:00:00

I've read the same facts at Symantec Antivirus Research Center
www.symantec.com/avcenter/index.html.

I mean, if you use IE5, what do you need a virus for?
Isn't IE5 a virus itself? Or does it just behave like a virus? ;-)

A virus-free time to everbody
Werner

David Pric

Virus alert

by David Pric » Fri, 12 Nov 1999 04:00:00

good one mate, IE5 is much more stable than netscrape


cunawari

Virus alert

by cunawari » Fri, 12 Nov 1999 04:00:00


> good one mate, IE5 is much more stable than netscrape

And Lynx is more stable than IE5 and Navigator put toguether.
Jan Hoviu

Virus alert

by Jan Hoviu » Fri, 12 Nov 1999 04:00:00

Andre,

According to varying resources it really IS true! But I don't really understand
the warnigs: There's not much you can do other than not using Outlook (Express)
to prevent becoming infected.
(Don't know whether other Mail Clients (e.g. Communicator's Messenger) are
sensitive to this virus too).

Jan.


> First impression, I can't believe this, but I'm very curious to read
> the explanation for the possibility of this. But the link doesn't
> work...

> Thanks for the warning anyway, hope this really is a hoax.

> Andre

> On Wed, 10 Nov 1999 21:03:25 -0000, "Mark Seery"

> >It seems thatit's finally happened :-(. Take care guys.

> ><Snip>
> >We usually will not issue NOTAMS about virus alerts, but this one is so
> >dangerous, it's important that you all be aware of this virus and it's
> >implications.  Please read the following and visit the website provided for
> >further information.

> >From MSNBC:

> >New breed of virus unleashed

> >First-of-its-kind 'BubbleBoy' infects users just reading e-mail

> >By Bob Sullivan
> >MSNBC

> >Nov. 9 - A long-feared new breed of computer virus has finally emerged,
> >according to antivirus firms. The so-called BubbleBoy virus can infect
> >Internet users when they open, or even simply preview, an infected e-mail.
> >"Historically we've always said, as long as you don't open attachments, you'
> >re safe," Network Associates spokesman Sal Viveros said. "That's not true
> >any more."

> >More information available at http://www.msnbc.com/news/333265.asp
> ><unsnip>

  J.H.Hovius.vcf
< 1K Download
Ian Hil

Virus alert

by Ian Hil » Fri, 12 Nov 1999 04:00:00


According to the full article (URL above) it's only Outlook Express that's
affected (and also the full Outlook, if you run minimum security settings).
There's a link to a patch which will give OE the same level of immunity as
Outlook itself - ie if you leave the security settings at the default then
you'll be OK.

HTH
Ian

Daxe Rexfor

Virus alert

by Daxe Rexfor » Fri, 12 Nov 1999 04:00:00


>You can also download the MS security fix at this URL:

http://support.microsoft.com/support/kb/articles/Q240/3/08.ASP

my duh.

~daxe

  -----------== Posted via Newsfeeds.Com, Uncensored Usenet News ==----------
   http://www.newsfeeds.com       The Largest Usenet Servers in the World!
------== Over 73,000 Newsgroups - Including  Dedicated  Binaries Servers ==-----

Daxe Rexfor

Virus alert

by Daxe Rexfor » Fri, 12 Nov 1999 04:00:00


>There's not much you can do other than not using Outlook (Express)
>to prevent becoming infected

Sure there is.

In "My Computer" (or whatever you've renamed it) go to View | Folder Options

Go to the "File Types" Tab.

Scroll down until you find the "HTML APPLICATION" file type.  The extension
is .hta

Highlight it and click "Edit"

In this dialog, highlight the "open" action and hit "remove".

This will completely prevent the virus from activating on your computer.

You can also download the MS security fix at this URL:

  -----------== Posted via Newsfeeds.Com, Uncensored Usenet News ==----------
   http://www.newsfeeds.com       The Largest Usenet Servers in the World!
------== Over 73,000 Newsgroups - Including  Dedicated  Binaries Servers ==-----

Ian Argen

Virus alert

by Ian Argen » Fri, 12 Nov 1999 04:00:00




> > Andre,

> > According to varying resources it really IS true! But I don't really
> understand
> > the warnigs: There's not much you can do other than not using Outlook
> (Express)
> > to prevent becoming infected.
> <snip>
> > > >More information available at http://www.msnbc.com/news/333265.asp

> According to the full article (URL above) it's only Outlook Express that's
> affected (and also the full Outlook, if you run minimum security
settings).
> There's a link to a patch which will give OE the same level of immunity as
> Outlook itself - ie if you leave the security settings at the default then
> you'll be OK.

Furthermore, since it exploits some patched vulnerabilities on IE 4&5, if
you have gotten the scriptlet.typelib and Eyedog patches you should be OK.
Obviously, if you don't have either of these browsers installed, you're OK:)

Also, this virus has *not* been spotted in the wild yet, it was apparently
sent to a viral lab, possibly by the author, and as seen, is a
"proof-of-concept" virus, with no destructive habits.

--
Ian Silvercat claims the above in the name of himself!
--------------
Those who would give up a little freedom for security
deserve neither freedom nor security - Benjamin Franklin
That which does not exist has never been named - Mirumoto Nohito

Joel Willstei

Virus alert

by Joel Willstei » Fri, 12 Nov 1999 04:00:00

     I'm assuming that the current thread is on the email virus for Outlook
express/IE5.0. the name of the virus is BubbleBoy,and it is very real. You
can read more about it at McAfees and Microsofts site,(the URL can be found
at McAfees as well).  What this virus does is invade you address book when
you open up the message with the header :BubbleBoy is back. It then is sent
to every person in your address book on time only.

     Contrary to some posts here,there is a temp DAT.file at McAfee and a
fix at Microsoft. You can also disable window scripting host and deactivate
your preview screen.

Joel Willstein

Uwe Schuerka

Virus alert

by Uwe Schuerka » Fri, 12 Nov 1999 04:00:00


>further information.

>From MSNBC:

>New breed of virus unleashed

>First-of-its-kind 'BubbleBoy' infects users just reading e-mail

>By Bob Sullivan
>MSNBC

Needless to say, the Virus *only* affects Microsoft based systems.
Use Linux, and never again worry about this crap.

Uwe

--
Uwe Schuerkamp http://www.schuerkamp.de/
Herford, Germany (52.0N/8h30mE)
Ever wondered what's wrong with the world? http://bnetwork.com/
PGP Fingerprint:  2E 13 20 22 9A 3F 63 7F  67 6F E9 B1 A8 36 A4 61

Chuck Kandle

Virus alert

by Chuck Kandle » Sat, 13 Nov 1999 04:00:00



> >further information.

> >From MSNBC:

> >New breed of virus unleashed

> >First-of-its-kind 'BubbleBoy' infects users just reading e-mail

> >By Bob Sullivan
> >MSNBC

> Needless to say, the Virus *only* affects Microsoft based systems.
> Use Linux, and never again worry about this crap.

True.  It also only affects Microsoft internet products.  For those not brave enough
to venture into Linux, even a switch to Netscape will keep your behind protected in
this particular case.  Shame on you M$!!  Got get them, DOJ!

--
Chuck Kandler  #70
ChuckK or KS70 on Won.net
K&S Racing
http://www.fortunecity.com/silverstone/thepits/195
The box said "Windows 95 or better", so I installed LINUX!

glen

Virus alert

by glen » Sat, 13 Nov 1999 04:00:00



>Needless to say, the Virus *only* affects Microsoft based systems.
>Use Linux, and never again worry about this crap.

Seeing as how you're advocating Linux in rec.autos.simulators...  Please, tell
us what race driving sims are available for Linux.

I like Linux, but I miss my games, then I go back to windows.  

Anyway, I'm using a non-HTML mail client so I don't need to worry about
bubble-boy anyway.

glen


rec.autos.simulators is a usenet newsgroup formed in December, 1993. As this group was always unmoderated there may be some spam or off topic articles included. Some links do point back to racesimcentral.net as we could not validate the original address. Please report any pages that you believe warrant deletion from this archive (include the link in your email). RaceSimCentral.net is in no way responsible and does not endorse any of the content herein.