PDA

View Full Version : Garnishing virus emails ....


Oggin Aviator
27th Feb 2004, 11:51
Hi,

Just recently, over the last 2 days in fact, I have been sent email after email with the virus W32/Netsky.b@MM attached from a whole host of unknown people.

Now I am fastidious (if that is the right word) about keeping my PC squeaky clean - I have an always up to date antivirus program and a decent firewall. I have followed Liam's excellent advice :ok: and removed all the adware and spyware cr@p that was lurking on my hard disk and even since then I have received another pesky email. My virus checker is intercepting these no problem, and the rest of my system is clear so can anyone fathom what is going on?

cheers

Oggin

Blacksheep
27th Feb 2004, 12:56
I have a Yahoo webmail address that is visible on my website under an 'e-mail webmaster' link. Starting from Sunday the Spam attack rate on this e-mail address reached truly monstrous proportions. Today it received 780 Spam messages that have shut down the webmail address completely - I can't even get on to empty the Bulkmail folder and clear the storage. I've also noted two occasions this week when I couldn't get onto the Yahoo mail site at all and received a message that the 'service is not available right now, try again later.'

It would appear that Yahoo's mail service is under some form of Denial of Service Attack - given the time frame of two days that you mention, I wonder if this latest version of the Netsky virus has something to do with it?

Oggin Aviator
27th Feb 2004, 13:42
Maybe.

I notice from the Mcaffee site that this virus was released on Feb 18 and is a standard mass mailing type thing - just wondered why it took so long to get to me - I guess due to the millions of PC's hooked up to the Internet it takes a finite while to get around.

cheers

Oggin

p.s. I think Borneo is great - flew some sorties from the ship off the Bornean coast in 97'. How's the Sultan?

boeingbus2002
12th Apr 2004, 22:03
Been reading through a few of the postings here regarding emails with viruses.
Over past few weeks, I have received 2 emails from "Administrators" from certain companies saying emails that I have sent to them with attachments have been returned as they are infected with viruses!!
To say i'm bemused is un understatment as I don't recall sending these messages!
Some details in case it helps:
Win 98, AOLv8, using Hotmail account.

1st is from Air Seychelles - The following was cut and pasted from what the admin said my email had sent to them. A file private_01_entre.txt was the attachment.

--------------------------------------------------------------------------
Title: Is this your document


FILE DELETED
------------

Antigen for Exchange removed Body of Message since it
was found to be infected with VIRUS= Win32/Netsky.P.ZIP.Trojan
(CA(InoculateIT),CA(Vet),Kaspersky,Sophos,NAI) virus.
------------------------------------------------------------------------------
2nd message: from admin at [email protected]
it returned this messgae it says i sent!
-----------------------------------------------------------------------------
Subject :
Oh my God

Sent :
10 April 2004 18:15:19

Attachment : shocked-text.pif (57 KB)
I was surprised, too! :-(
Who could suspect something like that?


*** Anti-Virus: No Virus!
*** BLAIRCONSULAR.CO Anti Virus
*** http://www.blairconsular.co.uk
--------------------------------------------------------------------------------
In this case Hotmail has permanently blocked the file as it is malicious. Once again the admin think I have sent the file to them and this is undeliverable due to the infection.

Hope someone can help!
Thanks

btw..I havent checked what the blairconsular site is, as I was worried in case it was a malicious one. I havent heard of their antivirus before!

Naples Air Center, Inc.
12th Apr 2004, 23:25
boeingbus2002,

That is the virus itself sending emails to you spoofing email addresses, not the Admin of a company.

Do not let those emails fool you. If you are worried about your system, follow the steps from the guide in the sticky above to check your system.

Take Care,

Richard

boeingbus2002
13th Apr 2004, 22:11
Cheers Richard :ok:

Just to add, i use Norton with updates too.
A few questions though regarding hotmail.

If i open these messages but NOT the attachment themselves does that still pose a risk?

There are many viruses which are sent via email, which automatically send themselves to everyone in your address book. (I love you etc.) Is hotmail and my addresses on there still succeptable to this? I dont use Outlook Express or anything, instead just checking the aco**** via internet explorer.

I was worried in case somehow my account was used to send companies viruses. Just curious as to the coincidence how an airline was used...considering applications being made!

Thanks again

Naples Air Center, Inc.
14th Apr 2004, 00:19
boeingbus2002,

You should be all right checking though Internet Explorer. Just make sure you keep up with all of Microsoft's Security Patches. ;)

Take Care,

Richard

mazzy1026
14th Apr 2004, 12:00
This all started for me too about 2 months ago. I have an ntl email address which is relatively good regarding junk - I dont give it out etc so dont really receive any junk mail. However, one day I received about 2 emails all similar to the above, with the virus attatched and some cheeky arse comment like 'heres the file you wanted' - in a zip archive with extensions like .pif or .bin .rtf etc.

As the days went on, I was getting maybe 3-4 then sometimes maybe 7-8 a day, this was really starting to get on my t1ts.

The weird thing is that I use AVG antivirus, Spybot S&D, Spyware blaster etc etc and the Sygate personal firewall. AVG was set to scan every email so sometimes it would tell me it had been moved to the virus vault and sometimes it couldnt do it. Yet when I ran a virus scan, I was infected twice with the virus, and then ran it again a month later and hey presto, there it was again! How is the virus getting onto the system if AVG sais it picks them up? I am using Outlook 6 etc.

Cheers

Maz :{