PDA

View Full Version : Virus? This probably has been mentioned before, but ...


Squawk7777
7th Nov 2002, 23:39
I feel like a complete idiot! :o

I received an email on my Yahoo! account, and - without paying attention to it - opened it. I receive many of those emails and always delete them w/o opening. They are from people unknown to me have different subject titels but are always around 124k - 127K in size. When you open the email, it is blank. There's no attachment.

So the BIG question is: Is it a virus or a false alarm?

I got McAfee (current) and ZoneAlarm and none of them triggered an alarm...

7 7 7 7

PaperTiger
8th Nov 2002, 05:32
No telling really. If you still have the email, turn off the preview pane (if you haven't already done so), then right click on the header. Select Properties then Details then Message Source. You will then see the contents in a safe window.

If you are still worried http://housecall.trendmicro.com/ will scan your hard drive(s) in realtime.

Hamrah
8th Nov 2002, 07:11
It's possible that it WAS a virus, but the McAfee/ZoneAlarm combination has just removed it. I get a similar situation regularly with AVG/Zone ALarm.

H

fobotcso
8th Nov 2002, 22:39
Time to ViruScan your C:\ Drive, or at the very least, your Windows or WINNT folder. (You didn't tell us your OS...).

Make sure you include all sub-folders so as to scan your Documents (Documents and Settings in Win 2K and XP) and also your Temorary Internet Files and, of course, your E-mail Client storage folders.

Unlikely that you caught something because McAfee is good at alerting you when a Virus or Worm arrives.

I had a bad couple of days about 9-10 days ago when I was temporarily unprotected and was caught by W32/Opaserv.worm.gen. It created the dreaded scrsvr.exe and alevir.exe files but McAfee quickly saw them off.

This does seem to be a part of our normal life these days.

Squawk7777
9th Nov 2002, 01:01
here are more details from the header:

Object: Hello,congratulations
MIME-Version: 1.0
Content-Type: multipart/alternative; boundary=E617fcgp821V46jO24
Message-Id: <200211072107461.SM00956@Xjh>
Date: Thu, 7 Nov 2002 21:08:04 -0600
Content-Length: 68113

don't know this individual, message shows a size of 154K, and it contains nothing. Got another the other day that was 127K big.

McAfee and ZA do not alert me and I got Win98 ( :o )

There's also one I got over and over again, titled A funny Game and it is around 120K big and says something like:

Hello,This is a special funny game
This game is my first work.
You're the first player.
I wish you would enjoy it.

:confused:

fobotcso what does it mean when McAfee's V-shield icon shows a little sword? Is there anything to it?

7 7 7 7

PaperTiger
9th Nov 2002, 02:43
That email is almost certainly the klez worm. Whether your AVS caught it or not is hard to say. It should have and probably did, since this is an old trojan. http://antivirus.about.com/library/blklez.htm

And the other one you mention (but didn't open, right?) may fit the badtrans m.o.

As suggested, do a system scan to be sure.

fobotcso
9th Nov 2002, 17:08
S7777, about that sword.

McAfee have made changes to their VirusScan User Interface with each major version change. I've recently reverted to Ver 5.21 (which I bought on-line) from Ver 7 (which I bought in a box) because Ver 7 doesn't sit happily with Win 2K.

With Ver 5.21 there is a desktop icon labelled "VirusScan Central" and this leads you to the Interface where you configure the three main functions, System, Download and Internet Scan. (There is actually a fourth called E-mail Scan but you have no control over that because it is automatically configured when you configure Download Scan. It displays "Disabled" permanently which is very confusing and disturbing until you find out that it is OK.)

The icon for System Scan is the Shield with the sword. The icon on the Systray of my Task Bar doesn't have a sword no matter what I do so I don't know what it is supposed to tell you.

Check the exclusions tab for each of the configurable options. It is possible that a virus/trojan has changed the exclusions options and that that is why you are not getting virus alerts.

Only my System Scan has an exclusions option and that was set on installation to the default of "/Recycled/".

Squawk7777
12th Nov 2002, 05:09
Thank you for your replies. I performed a system check and nothing was found. Checked the setting - all systems clear. Hopefully this was just a false alarm. :rolleyes:

The McAfee VShield still displays the little sword and I cannot make out what the significance is (Version 6.02.3000), and at this point in time I don't bother.

7 7 7 7