# Wednesday, October 19, 2005
« Happy Birthday Windows | Main | Connected Systems Developer Competition ... »

I got in to work Monday and had an e-mail that said it was from our corporate IT and that my password had been changed as part of the weekend maintenance. I don't know what made me do it but I opened the attached .zip file to see what I needed to do to get into the affected systems. When WinZip opened it showed an empty file. I thought that was strange and just closed WinZip and went on with putting a CD into the drive to install some software that I needed. A few seconds later the "run as" dialog popped up telling me that I didn't have administrator rights and asking what user to install the software as. I assumed this was from the CD I had inserted and closed that dialog as I was already running "MakeMeAdmin" to install the sofware in my user account. It wasn't until I read the next e-mail that things started to fall into place. The e-mail was also from our corporate IT department and said that the previous e-mail and another one with a different subject and text were spoffed to come from them but really were a result of the MyTob virus. I checked and the CD did not have an autorun that tried to install software so the dialog box was caused by the virus trying to install. So the lessons that I should have learned over 15 years ago when I picked up my first computer virus are:

  1. Don't run as administrator. I am currently doing this and it has helped me to avoid this virus by asking me who to install as. If I had not just put a CD in the drive it would have been very obvious that something was wrong when the message popped up.
  2. Keep up to date on patches. According to the virus detection/removal tool that I ran I need 2 patches from Microsoft to avoid being infected by MyTob. I had both installed thanks to Windows Update.
  3. Never trust e-mail. Back in college I had a project to write an e-mail client. As part of that I learned the SMTP protocol and would regularly send e-mails with a return address of the.monster@under.your.bed (sorry if you got one of those). I should have thought that the e-mail telling me that my password has been changed was in a system that I used the supposedly changed password to access and therefore spoofed but I didn't.
  4. Don't ever open e-mail attachments. Well never can be a problem if you are expecting a word document but you should at least attempt to verify attachments. I was reading the e-mail through the web mail interface. Outlook would have flagged the attachment as having some other extension (probably .exe, .scr, or .cmd) past the .zip and would have warned me.

As I said at the begining of this post, this all happened on Monday. I intended to blog about it Monday night but got busy with some last minute details for the Connected Systems Developer Competition and getting ready for a customer meeting on Tuesday I didn't get around to blogging it but thought I would do it first thing Tuesday morning. Very early Tuesday morning I woke up with the flu. Somewhere in the wee hours of the morning in the delerium caused by the fever I found myself thinking it would be nice if I could run my body in non-administrator mode. That way when I got a virus from somewhere else I could just click on the cancel button and not have it infect me. Of course that is not possible, but it would have saved me two days of laying in bed feeling miserable.

Wednesday, October 19, 2005 6:00:24 PM (Mountain Standard Time, UTC-07:00)  #    Disclaimer  |  Comments [0]  |  Related posts:
Do You Know How Fast Your Computer Is?
Business Rules Engine Survey
Silverlight 2 Released
Breaking News - Press Overreacts to "Sell More Newspapers" - IBM to Pull out of Standards Bodies
Zune 3.0
Update to Live Search
Tracked by:
"phentermine" (phentermine) [Trackback]
"mortgage equity" (mortgage equity) [Trackback]
"citicard" (citicard) [Trackback]
"atlanta hotels" (atlanta hotels) [Trackback]
"drugs online" (drugs online) [Trackback]
"free online poker" (free online poker) [Trackback]
"ultimate bet" (ultimate bet) [Trackback]
"insurance jobs" (insurance jobs) [Trackback]
"mortgage leads" (mortgage leads) [Trackback]
"hilton hotel" (hilton hotel) [Trackback]
"asian porn" (Jackson_Blog) [Trackback]
"porn" (porn) [Trackback]
"sex" (sex) [Trackback]
"tits" (tits) [Trackback]
"incest stories" (incest stories) [Trackback]
"lesbian porn" (lesbian porn) [Trackback]
"shemale" (shemale) [Trackback]
"Europe Hotels" (Cheap Hotels) [Trackback]
"discount hotels" (cheap hotels) [Trackback]
"discount hotels" (cheap hotels) [Trackback]
"sweepstakes may 2006" (sweepstakes may 2006) [Trackback]
"female escorts in chattanooga" (female escorts in chattanooga) [Trackback]
"water stop rubber gloves" (water stop rubber gloves) [Trackback]
"jeremy paxman interview" (jeremy paxman interview) [Trackback]
"lets talk dirty" (lets talk dirty) [Trackback]
"free videos female ejaculation" (free videos female ejaculation) [Trackback]
"endodontic infections" (endodontic infections) [Trackback]
"wild girl college party" (wild girl college party) [Trackback]
"disneyland ca" (disneyland ca) [Trackback]
"college dorm nudity" (college dorm nudity) [Trackback]
"welding hoods" (welding hoods) [Trackback]
"joplin missouri" (joplin missouri) [Trackback]
"heavyweight vinyl envelopes" (heavyweight vinyl envelopes) [Trackback]
"us citizenship questions" (us citizenship questions) [Trackback]
"nude on the boat" (nude on the boat) [Trackback]
"Houston act software training" (Houston act software training) [Trackback]
"mother fuck" (mother fuck) [Trackback]
"garmin 72 handheld gps" (garmin 72 handheld gps) [Trackback]
"black gay porn" (black gay porn) [Trackback]
"evil deeds" (evil deeds) [Trackback]
"no teletrack or verification payday loans" (no teletrack or verification payday... [Trackback]
"nastiest whore in porn" (nastiest whore in porn) [Trackback]
"C2 Constellation" (C2 Constellation) [Trackback]
"minor league baseball" (minor league baseball) [Trackback]
"naturist friends gallery" (naturist friends gallery) [Trackback]
"italian amateur porn" (italian amateur porn) [Trackback]
"doxycycline used for" (doxycycline used for) [Trackback]
"amateur girls kissing" (amateur girls kissing) [Trackback]
"traffic ticket texas" (traffic ticket texas) [Trackback]
"hot springs village hotel" (hot springs village hotel) [Trackback]
"dating gay" (dating gay) [Trackback]
"final fantasy animated gifs" (final fantasy animated gifs) [Trackback]
"myspace whore me button" (myspace whore me button) [Trackback]
"hentai dating sim game" (hentai dating sim game) [Trackback]
"hummer H2 SUT" (hummer H2 SUT) [Trackback]
"candida albicans alcoholism" (candida albicans alcoholism) [Trackback]
"dirty lilly sucking" (dirty lilly sucking) [Trackback]
"dirty bear sex gallery grizzly" (dirty bear sex gallery grizzly) [Trackback]
"farm animal cake sprinkles" (farm animal cake sprinkles) [Trackback]
"latina girls going wild" (latina girls going wild) [Trackback]
"Angina Symptoms" (Angina Symptoms) [Trackback]
"buy used car" (buy used car) [Trackback]
"tae kwon do winchester va" (tae kwon do winchester va) [Trackback]
"window" (window) [Trackback]
"cypress hill insane in the brain" (cypress hill insane in the brain) [Trackback]
"Flonase AND comments" (Flonase AND comments) [Trackback]
"Online Consultation for Provigil" (Online Consultation for Provigil) [Trackback]
"italia" (italia) [Trackback]
"Jamn 945" (Jamn 945) [Trackback]
"bamboo easel" (bamboo easel) [Trackback]
"ab lounge ultimate" (ab lounge ultimate) [Trackback]
"Seattle Facelift" (Seattle Facelift) [Trackback]
"black bros white hoes" (black bros white hoes) [Trackback]
"purple heart donations" (purple heart donations) [Trackback]
"alabama department of transportation" (alabama department of transportation) [Trackback]
"vitamins minerals" (vitamins minerals) [Trackback]
"residence marmorata" (residence marmorata) [Trackback]
"rosary bracelets" (rosary bracelets) [Trackback]
"meeting facility dfw" (meeting facility dfw) [Trackback]
"microsoft project scheduler" (microsoft project scheduler) [Trackback]
"Free Fall Graphics" (Free Fall Graphics) [Trackback]
"Cowboy Bebop Music" (Cowboy Bebop Music) [Trackback]
"creative gift idea" (creative gift idea) [Trackback]
"addiction recovery program" (addiction recovery program) [Trackback]
"efx foreign exchange" (efx foreign exchange) [Trackback]
"pebuilder plugins" (pebuilder plugins) [Trackback]
"Download Windows Xp Pro for Free" (Download Windows Xp Pro for Free) [Trackback]
"transexual escort copenhagen" (transexual escort copenhagen) [Trackback]
"industrial parts washers" (industrial parts washers) [Trackback]
"topamax anti inflammatory" (topamax anti inflammatory) [Trackback]
"infertility vaginal scan" (infertility vaginal scan) [Trackback]
"vancouver auto electric distributor repair" (vancouver auto electric distributo... [Trackback]
"teen masturbating with toys" (teen masturbating with toys) [Trackback]
"estimating program" (estimating program) [Trackback]
"buying and selling used cars" (buying and selling used cars) [Trackback]
"whirlpool washer dryer" (whirlpool washer dryer) [Trackback]
"radio online" (radio online) [Trackback]
"corporate meeting solution" (corporate meeting solution) [Trackback]
"hound dog" (hound dog) [Trackback]
"holly hobbie plates" (holly hobbie plates) [Trackback]
"Kids Bikini" (Kids Bikini) [Trackback]
"Darvocet N500" (Darvocet N500) [Trackback]
"domain hosting and registration" (domain hosting and registration) [Trackback]
"let me love you remix" (let me love you remix) [Trackback]
"soulseek" (soulseek) [Trackback]
"emailed katrina lore moore" (emailed katrina lore moore) [Trackback]
"dirt killer pressure washer" (dirt killer pressure washer) [Trackback]
"GED Reading questions" (GED Reading questions) [Trackback]
"Girls gone wild" (Girls gone wild) [Trackback]
"marauder mens basketball" (marauder mens basketball) [Trackback]
"Ugg Boot Press" (Ugg Boot Press) [Trackback]
"dewalt mitre saw" (dewalt mitre saw) [Trackback]
"5th wheel hitches" (5th wheel hitches) [Trackback]
"How do %2B Hybrid cars work" (How do %2B Hybrid cars work) [Trackback]
"army tales" (army tales) [Trackback]
"history of printing" (history of printing) [Trackback]
"protonix and stomachaches" (protonix and stomachaches) [Trackback]
"cat 6 patch panels" (cat 6 patch panels) [Trackback]
"new orleans jazz festival" (new orleans jazz festival) [Trackback]
"outdoor art prints" (outdoor art prints) [Trackback]
"casapadova" (casapadova) [Trackback]
"guam deca" (guam deca) [Trackback]
"impiantoeletricocivile" (impiantoeletricocivile) [Trackback]
"basil oil" (basil oil) [Trackback]
"incontriamicizia" (incontriamicizia) [Trackback]
"perfectgirls" (perfectgirls) [Trackback]
"omni water filters" (omni water filters) [Trackback]
"remodeling basement excavation" (remodeling basement excavation) [Trackback]
"country singer songwriter" (country singer songwriter) [Trackback]
"glass museum" (glass museum) [Trackback]