Find » News » Avoiding the Ecard.EXE Virus

Avoiding the Ecard.EXE Virus

Common Sense Can Keep You Safe

By G. Keith Evans, published Jul 03, 2007
Published Content: 41  Total Views: 23,078  Favorited By: 5 CPs
Embed:  
Rating: 4.7 of 5
A malicious new virus has been circulating the Internet recently, trying to sneak into your computer's back door by posing as a friendly greeting from a loved one. As Americans celebrate Independence Day and others throughout the world are on edge over recent terrorist activity, the temptation to have our hearts touched by those close to us can be overwhelming. When opening e-cards, though, use common sense and protect yourself from this dangerous new virus.

The SPAM email looks innocent enough. With a common-looking subject line such as, "You've received an e-card from a family member!" and an apparent well-known sender (such as e-card giants AmericanGreetings.com, BlueMountain.com and Hallmark.com), it's easy to fall victim to opening up the email.

Fortunately, this virus requires you to do a little more than open the email in order to download the harmful virus software. This step is where common sense plays a factor:

First and foremost, if you ever receive an email like the one described above, DO NOT click the link! HTML links are very easily masked to resemble reputable companies. Hovering your mouse on the link, though, will show you that the link actually points to someone's IP address- likely somewhere overseas and out of American jurisdiction- instead of to the company where the e-card supposedly originated. Never clicking on links in unsolicited emails is the first rule of keeping your computer safe. If you absolutely must know if the link is valid, highlight the link, copy it and paste it directly into your browser's address bar.

After following that general rule, here are a few more common-sense guidelines which, if followed, can keep your computer safe:

Telltale warning signs:
--The subject line says, "a family member" instead of a specific person's name. If someone had actually sent you a card, the system would know their name and would list it instead of a generic term.

--As mentioned above, the hyperlink may have an IP address instead of a domain name. If the link were legitimate, it would start with http://www.americangreetings.com instead of http://xx.xx.xx.xx/somethinglonghere.

Avoiding the Ecard.EXE Virus
Comments
Showing Comments 1 - 15 of 15
 
 
The virus is also known as W32.Nuwar.GU worm, and basically spreads itself by rummaging through certain files on the filesystem looking for email addresses, and then sending a short email to all of these addresses. nasty little sucker. The description in the earlier comment about how to remove it seems to work. Again, like others not on Windows machines, I laugh.

Posted on 08/10/2007 at 5:08:00 PM

 
I stupidly copied and pasted the link. a page opened with a pop up download box for the ecard. Instead of clicking open I clicked cancel. Did I download the virus anyway?

Posted on 08/02/2007 at 8:08:00 PM

 
I have a Mac so I just laff this one off.

Posted on 07/27/2007 at 7:07:00 PM

 
Found this, found a way to remove it. Here is goes. 1. Disable System Restore 2. Boot into safe mode (possibly didn't try doing it without) 3. Once in safe mode go to device manager (in system properties) 4. Click view and 'Show Hidden Devices' 5. Find the device under 'non plug and play devices' that looks suspicious, i've seen variants that start Windev - fourrandom characters - fourrandomcharacters, and some that start vdo - somethings - something 6. Uninstall this device 7. Browse to your C:windowssystem32 directory and find the file name that corresponds to the device that was shown in device manager and delete it 8. Search the registry for that same string, and delete all references, there hsould be one in current config, and somewhere else I believe, THis process worked for me, hopefully it will work for other people

Posted on 07/27/2007 at 8:07:00 AM

 
Hey...I received one of these today and decided...what the heck...I downloaded to my smartphone (Dash phone)..The file size is 95.2 KB and will not execute under Windows mobile OS I have..Just thought I'd share.. If you are going to click links, don't do it a computer you can't afford to rebuild..

Posted on 07/24/2007 at 5:07:00 PM

 
What happens to your computer if you open the file?

Posted on 07/07/2007 at 12:07:00 PM

 
This is an excellent warning. I, too, have been bombarded. The Snopes article is very helpful, also. I always check this site first and recommend everyone's subscribing to the Snopes newsletter. http://www.snopes.com/computer/virus/postcard.asp

Posted on 07/07/2007 at 12:07:00 PM

 
Well written! Thank You for the information!

Posted on 07/04/2007 at 9:07:00 AM

 
I've been getting a lot of these lately. Great article

Posted on 07/04/2007 at 9:07:00 AM

 
haven't gotten any yet, i don't think...but it wouldn't make it through my filter, so i'm safe. although it does make me wish i had a mac a little more, lol

Posted on 07/04/2007 at 7:07:00 AM

 
I received one from 123Greetings.com - I almost clicked on it as I'd just sent a greeting from there an hour previous. Good info for everyone!

Posted on 07/04/2007 at 12:07:00 AM

 
I've gotten one almost every day for two weeks!

Posted on 07/04/2007 at 12:07:00 AM

 
Good article. First time I got one of these a few days back, it almost fooled me since the initial link to american greetings was legit. But it's nowhere near my birthday, and my family members don't get sentimental over the 4th of July, so I figured it was bogus. Thanks for the info.

Posted on 07/03/2007 at 8:07:00 PM

 
I've received TONS of these recently and never once thought to write an article about it. Good job!

Posted on 07/03/2007 at 8:07:00 PM

 
Ah! So that's what that was! I received one of these today and was suspicious. Thankfully, I didn't open it as it was as you wrote... anonymous. Good reporting!

Posted on 07/03/2007 at 7:07:00 PM

Type in Your Comments Below - (1000 characters left)
Your name:

Submit your own content on this or any topic. Get started »
Showing Comments 1 - 15 of 15
 
Most Commented On