# "Invisible" computer virus: Is this true?

**URL:** <https://boards.straightdope.com/t/invisible-computer-virus-is-this-true/200504>\
**Category:** Factual Questions\
**Created:** [September 9, 2003, 12:51pm UTC](https://boards.straightdope.com/t/invisible-computer-virus-is-this-true/200504 "2003-09-09T12:51:19Z")\
**Posts on this page:** 9\
**Page:** 1

<div class="post-metadata">

**Author:** ![furryman](https://sea3.discourse-cdn.com/straightdope/user_avatar/boards.straightdope.com/furryman/32/99_2.png) [@furryman](https://boards.straightdope.com/u/furryman)\
**Post date:** [September 9, 2003, 12:51pm UTC](https://boards.straightdope.com/t/invisible-computer-virus-is-this-true/200504/1 "2003-09-09T12:51:19Z")

</div>

A freind told me that there’s a computer virus that you can place **in** the E-mail itself. Not in the attachment but in the E-Mail itself. Not only that but Norton anti-virus can’t detect it either. Is this true? If it is true Is there anyway to tell if my computer has these viruses (virii?)?

---

<div class="post-metadata">

**Author:** ![jjimm](https://avatars.discourse-cdn.com/v4/letter/j/ba8739/32.png) [@jjimm](https://boards.straightdope.com/u/jjimm)\
**Post date:** [September 9, 2003, 1:01pm UTC](https://boards.straightdope.com/t/invisible-computer-virus-is-this-true/200504/2 "2003-09-09T13:01:53Z")

</div>

Sounds like crapola to me. Unless you’re using HTML email, perhaps, there’s a very outside chance of embedded AtiveX controls or the like, but it’s impossible with regular plain-text email. Check the [Symantec](http://securityresponse.symantec.com/avcenter/vinfodb.html) website whenever you hear about a new virus.

---

<div class="post-metadata">

**Author:** ![Ice\_Wolf](https://avatars.discourse-cdn.com/v4/letter/i/dfb087/32.png) [@Ice\_Wolf](https://boards.straightdope.com/u/Ice_Wolf)\
**Post date:** [September 9, 2003, 1:08pm UTC](https://boards.straightdope.com/t/invisible-computer-virus-is-this-true/200504/3 "2003-09-09T13:08:15Z")

</div>

Something like this was reported in February 2001 [here.](http://www.silicon.com/news/500013/1/1022820.html)

---

<div class="post-metadata">

**Author:** ![Futile\_Gesture](https://avatars.discourse-cdn.com/v4/letter/f/f05b48/32.png) [@Futile\_Gesture](https://boards.straightdope.com/u/Futile_Gesture)\
**Post date:** [September 9, 2003, 1:55pm UTC](https://boards.straightdope.com/t/invisible-computer-virus-is-this-true/200504/4 "2003-09-09T13:55:54Z")

</div>

You can’t hide a virus in (Ebola) text without it being noticed.

---

<div class="post-metadata">

**Author:** ![jjimm](https://avatars.discourse-cdn.com/v4/letter/j/ba8739/32.png) [@jjimm](https://boards.straightdope.com/u/jjimm)\
**Post date:** [September 9, 2003, 2:43pm UTC](https://boards.straightdope.com/t/invisible-computer-virus-is-this-true/200504/5 "2003-09-09T14:43:31Z")

</div>

I dunno, I’ve herpes simplex that you can.

---

<div class="post-metadata">

**Author:** ![Garnet](https://avatars.discourse-cdn.com/v4/letter/g/9de0a6/32.png) [@Garnet](https://boards.straightdope.com/u/Garnet)\
**Post date:** [September 9, 2003, 2:46pm UTC](https://boards.straightdope.com/t/invisible-computer-virus-is-this-true/200504/6 "2003-09-09T14:46:40Z")

</div>

I have heard of something sort of like this - a few years back, there was a vulnerability in MS Outlook Express discovered: if it received an email with a really, really, really long title, it could cause a buffer overflow on your system, without you ever actually having to open the email. I don’t think it was ever put into practice, and the vulnerability is long since patched though.

[http://www.securiteam.com/securitynews/6N0071P3FY.html](http://www.securiteam.com/securitynews/6N0071P3FY.html)

There’s a story about a similar phenomenon for Macintosh Outlook Express. I guess the moral of the story is: keep up-to-date with the latest patches and bugfixes.

---

<div class="post-metadata">

**Author:** ![Futile\_Gesture](https://avatars.discourse-cdn.com/v4/letter/f/f05b48/32.png) [@Futile\_Gesture](https://boards.straightdope.com/u/Futile_Gesture)\
**Post date:** [September 9, 2003, 4:16pm UTC](https://boards.straightdope.com/t/invisible-computer-virus-is-this-true/200504/7 "2003-09-09T16:16:58Z")

</div>

> [@](#):
>
> \*Originally posted by Garnet \*  
> \*\*I guess the moral of the story is: keep up-to-date with the latest patches and bugfixes. \*\*

I can think of a better moral. Punchier too.

Don’t use Outlook.

---

<div class="post-metadata">

**Author:** ![DarrenS](https://avatars.discourse-cdn.com/v4/letter/d/977dab/32.png) [@DarrenS](https://boards.straightdope.com/u/DarrenS)\
**Post date:** [September 9, 2003, 6:32pm UTC](https://boards.straightdope.com/t/invisible-computer-virus-is-this-true/200504/8 "2003-09-09T18:32:22Z")

</div>

In general, any information about a virus “from a friend”, or forwarded in an e-mail full of hysterical language like “Goes straight past Norton and McAfee!!!” is to be assumed false until verified.

---

<div class="post-metadata">

**Author:** ![ftg](https://sea3.discourse-cdn.com/straightdope/user_avatar/boards.straightdope.com/ftg/32/2801_2.png) [@ftg](https://boards.straightdope.com/u/ftg)\
**Post date:** [September 10, 2003, 3:09am UTC](https://boards.straightdope.com/t/invisible-computer-virus-is-this-true/200504/9 "2003-09-10T03:09:44Z")

</div>

**Garnet** has it. Programs have flaws. Bad programs have really bad flaws. Lots of bad things in MS Outlook. New ones are discovered all the time. Worms/Viruses/OtherBadThings can be written to exploit them. To fix the source of the problem is the software suppliers jobs (if they feel like it).

Anti-virus programs can only deal with it once it’s started to do it’s thing. (More “traditional” email viruses have signatures and such that can be checked directly. These kind may not even look like executable code.)

The best solution is to not use the most heavily used and buggy email program on the planet. There are hundreds of others, almost all of which are better written, that also have the advantage of being less likely targeted.
