Wikiposts
Search

Notices
Computer/Internet Issues & Troubleshooting Anyone with questions about the terribly complex world of computers or the internet should try here. NOT FOR REPORTING ISSUES WITH PPRuNe FORUMS! Please use the subforum "PPRuNe Problems or Queries."

Garnishing virus emails ....

Thread Tools
 
Search this Thread
 
Old 27th February 2004 | 11:51
  #1 (permalink)  
Thread Starter
 
Joined: Dec 2000
Posts: 541
Likes: 0
From: Red Red Back to Bed
Garnishing virus emails ....

Hi,

Just recently, over the last 2 days in fact, I have been sent email after email with the virus W32/Netsky.b@MM attached from a whole host of unknown people.

Now I am fastidious (if that is the right word) about keeping my PC squeaky clean - I have an always up to date antivirus program and a decent firewall. I have followed Liam's excellent advice and removed all the adware and spyware cr@p that was lurking on my hard disk and even since then I have received another pesky email. My virus checker is intercepting these no problem, and the rest of my system is clear so can anyone fathom what is going on?

cheers

Oggin
Oggin Aviator is offline  
Old 27th February 2004 | 12:56
  #2 (permalink)  
Cunning Artificer
20 Anniversary
 
Joined: Jun 2001
Posts: 3,125
Likes: 7
From: The spiritual home of DeHavilland
Question

I have a Yahoo webmail address that is visible on my website under an 'e-mail webmaster' link. Starting from Sunday the Spam attack rate on this e-mail address reached truly monstrous proportions. Today it received 780 Spam messages that have shut down the webmail address completely - I can't even get on to empty the Bulkmail folder and clear the storage. I've also noted two occasions this week when I couldn't get onto the Yahoo mail site at all and received a message that the 'service is not available right now, try again later.'

It would appear that Yahoo's mail service is under some form of Denial of Service Attack - given the time frame of two days that you mention, I wonder if this latest version of the Netsky virus has something to do with it?
Blacksheep is offline  
Old 27th February 2004 | 13:42
  #3 (permalink)  
Thread Starter
 
Joined: Dec 2000
Posts: 541
Likes: 0
From: Red Red Back to Bed
Maybe.

I notice from the Mcaffee site that this virus was released on Feb 18 and is a standard mass mailing type thing - just wondered why it took so long to get to me - I guess due to the millions of PC's hooked up to the Internet it takes a finite while to get around.

cheers

Oggin

p.s. I think Borneo is great - flew some sorties from the ship off the Bornean coast in 97'. How's the Sultan?
Oggin Aviator is offline  
Old 12th April 2004 | 22:03
  #4 (permalink)  
 
Joined: Jan 2002
Posts: 444
Likes: 0
From: London
Been reading through a few of the postings here regarding emails with viruses.
Over past few weeks, I have received 2 emails from "Administrators" from certain companies saying emails that I have sent to them with attachments have been returned as they are infected with viruses!!
To say i'm bemused is un understatment as I don't recall sending these messages!
Some details in case it helps:
Win 98, AOLv8, using Hotmail account.

1st is from Air Seychelles - The following was cut and pasted from what the admin said my email had sent to them. A file private_01_entre.txt was the attachment.

--------------------------------------------------------------------------
Title: Is this your document


FILE DELETED
------------

Antigen for Exchange removed Body of Message since it
was found to be infected with VIRUS= Win32/Netsky.P.ZIP.Trojan
(CA(InoculateIT),CA(Vet),Kaspersky,Sophos,NAI) virus.
------------------------------------------------------------------------------
2nd message: from admin at [email protected]
it returned this messgae it says i sent!
-----------------------------------------------------------------------------
Subject :
Oh my God

Sent :
10 April 2004 18:15:19

Attachment : shocked-text.pif (57 KB)
I was surprised, too! :-(
Who could suspect something like that?


*** Anti-Virus: No Virus!
*** BLAIRCONSULAR.CO Anti Virus
*** http://www.blairconsular.co.uk
--------------------------------------------------------------------------------
In this case Hotmail has permanently blocked the file as it is malicious. Once again the admin think I have sent the file to them and this is undeliverable due to the infection.

Hope someone can help!
Thanks

btw..I havent checked what the blairconsular site is, as I was worried in case it was a malicious one. I havent heard of their antivirus before!
boeingbus2002 is offline  
Old 12th April 2004 | 23:25
  #5 (permalink)  
The Oracle
 
Joined: Aug 2001
Posts: 2,902
Likes: 0
From: Naples, Florida U.S.A.
boeingbus2002,

That is the virus itself sending emails to you spoofing email addresses, not the Admin of a company.

Do not let those emails fool you. If you are worried about your system, follow the steps from the guide in the sticky above to check your system.

Take Care,

Richard
Naples Air Center, Inc. is offline  
Old 13th April 2004 | 22:11
  #6 (permalink)  
 
Joined: Jan 2002
Posts: 444
Likes: 0
From: London
Cheers Richard

Just to add, i use Norton with updates too.
A few questions though regarding hotmail.

If i open these messages but NOT the attachment themselves does that still pose a risk?

There are many viruses which are sent via email, which automatically send themselves to everyone in your address book. (I love you etc.) Is hotmail and my addresses on there still succeptable to this? I dont use Outlook Express or anything, instead just checking the aco**** via internet explorer.

I was worried in case somehow my account was used to send companies viruses. Just curious as to the coincidence how an airline was used...considering applications being made!

Thanks again
boeingbus2002 is offline  
Old 14th April 2004 | 00:19
  #7 (permalink)  
The Oracle
 
Joined: Aug 2001
Posts: 2,902
Likes: 0
From: Naples, Florida U.S.A.
boeingbus2002,

You should be all right checking though Internet Explorer. Just make sure you keep up with all of Microsoft's Security Patches.

Take Care,

Richard
Naples Air Center, Inc. is offline  
Old 14th April 2004 | 12:00
  #8 (permalink)  

Spicy Meatball
 
Joined: Jan 2004
Posts: 1,115
Likes: 0
From: Liverpool UK
This all started for me too about 2 months ago. I have an ntl email address which is relatively good regarding junk - I dont give it out etc so dont really receive any junk mail. However, one day I received about 2 emails all similar to the above, with the virus attatched and some cheeky arse comment like 'heres the file you wanted' - in a zip archive with extensions like .pif or .bin .rtf etc.

As the days went on, I was getting maybe 3-4 then sometimes maybe 7-8 a day, this was really starting to get on my t1ts.

The weird thing is that I use AVG antivirus, Spybot S&D, Spyware blaster etc etc and the Sygate personal firewall. AVG was set to scan every email so sometimes it would tell me it had been moved to the virus vault and sometimes it couldnt do it. Yet when I ran a virus scan, I was infected twice with the virus, and then ran it again a month later and hey presto, there it was again! How is the virus getting onto the system if AVG sais it picks them up? I am using Outlook 6 etc.

Cheers

Maz
mazzy1026 is offline  

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is On
HTML code is Off
Trackbacks are Off
Pingbacks are Off
Refbacks are Off



Contact Us - Archive - Advertising - Cookie Policy - Privacy Statement - Terms of Service

Copyright © 2026 MH Sub I, LLC dba Internet Brands. All rights reserved. Use of this site indicates your consent to the Terms of Use.