Possible e-mail virus??

Please use this forum for general discussions or questions related to Carvoeiro life ONLY
Post Reply
djprescott
CVO Master
CVO Master
Posts: 637
Joined: Fri Jun 20, 2003 9:53 am
Location: Warwick UK & Sesmarias
Contact:

Possible e-mail virus??

Post by djprescott »

I have just received an email with an address biffa@carvoeiro.org which contains no text but has an attachment titled body.exe.

As it is an exe file I am very suspicious and have therefore not opened it up. Just letting everyone know just in case. Dave.
Rob

Re: Possible e-mail virus??

Post by Rob »

djprescott wrote:I have just received an email with an address biffa@carvoeiro.org which contains no text but has an attachment titled body.exe.

As it is an exe file I am very suspicious and have therefore not opened it up. Just letting everyone know just in case. Dave.
Hi, U should be careful for today I received a body.zip file in my mail box. This file contained a virus so I'd suggest not to open it!

cheers
Rob
Michael Crane
CVO Oracle
CVO Oracle
Posts: 11216
Joined: Tue Feb 18, 2003 5:51 pm
Location: Lincoln
Contact:

Post by Michael Crane »

So far today Norton has stopped 24 virus attacks on my PC!
Michael Crane
CVO Oracle
CVO Oracle
Posts: 11216
Joined: Tue Feb 18, 2003 5:51 pm
Location: Lincoln
Contact:

Post by Michael Crane »

Just been attacked again. This is the virus that's having a go at me: w32.novarg.a@mm

Look at the Norton web site for details:
http://securityresponse.symantec.com/av ... .a@mm.html
biffa
CVO Master
CVO Master
Posts: 1469
Joined: Wed Jan 08, 2003 3:36 pm
Location: Portimão
Contact:

Virus

Post by biffa »

Strange cos this Biffa hasn't used carvoeiro.org at all

Maybe I am being cloned?
ANDY
CVO Senior
CVO Senior
Posts: 345
Joined: Tue Jan 14, 2003 8:09 pm
Location: Vale de milho carvoeiro
Contact:

Post by ANDY »

We have today had over 24 virus's from:
postmaster@infiniteenergy.com, norton has picked it up everytime!! watch out guys!
biffa
CVO Master
CVO Master
Posts: 1469
Joined: Wed Jan 08, 2003 3:36 pm
Location: Portimão
Contact:

Post by biffa »

Virus: W32/MyDoom-A

Aliases
Mimail.R, Novarg.A, Shimg, W32.Novarg.A@mm, W32/Mydoom@MM

Type
Win32 worm



Description
W32/MyDoom-A is a worm which spreads by email. When the infected
attachment is launched, the worm harvests email addresses from address
books and from files with the following extensions: wab, txt, htm, sht, php,
asp, dbx, tbb, adb and pl.
W32/MyDoom-A creates a file called Message in the temp folder and runs Notepad to display the contents, which displays random characters.

W32/MyDoom-A uses randomly chosen email addresses in the "To:" and
"From:" fields as well as a randomly chosen subject line. The emails
distributing this worm have the following characteristics.

Subject lines
error
hello
hi
mail delivery system
mail transaction failed
server report
status
test
[random collection of characters]

Message texts
test
Mail transaction failed. Partial message is available.
The message contains Unicode characters and has been sent as a binary attachment.
Mail transaction failed. Partial message is available.

Attachment filenames
body
data
doc
document
file
message
readme
test
[random collection of characters]

Attached files will have an extension of BAT, CMD, EXE, PIF, SCR or ZIP
djprescott
CVO Master
CVO Master
Posts: 637
Joined: Fri Jun 20, 2003 9:53 am
Location: Warwick UK & Sesmarias
Contact:

Post by djprescott »

Hi, I also had an email today with one of my customers domain name with message.zip, presumably from a similar source. I wasn't suggesting it had orinated from this site, by the way, I just wanted to make people aware. The .org extension alerted me to this fact.
Dave.
biffa
CVO Master
CVO Master
Posts: 1469
Joined: Wed Jan 08, 2003 3:36 pm
Location: Portimão
Contact:

Virus

Post by biffa »

The file name body.exe is a bad one as shown on previous post taken from the Sophos anti virus web site
Francoise

Post by Francoise »

can anyone translate this into English or even French! for me please/ s'il vous plait? :)
Gerry Cullen
CVO Master
CVO Master
Posts: 774
Joined: Thu Jan 16, 2003 12:39 am
Location: Southern Ireland

Post by Gerry Cullen »

Does this mean that i max out the credit card ?or Pray?
Gerry Cullen
CVO Master
CVO Master
Posts: 774
Joined: Thu Jan 16, 2003 12:39 am
Location: Southern Ireland

Post by Gerry Cullen »

Being serious| many thanks to all of you who took the time to warn us on this, some of these posts took a bit of time and even though i don,t understand it all i,m greatful for your efforts,
gerry
Guest

Post by Guest »

:lol: Gerry, my pc cillin antivirus software flashes Congratulations when it hasnt found a virus doing its check which makes me very :D - can be the highlight of my week actually :lol: So what does it say when it has found a virus??-- U R F*****!?? :shock:
Gerry Cullen
CVO Master
CVO Master
Posts: 774
Joined: Thu Jan 16, 2003 12:39 am
Location: Southern Ireland

Post by Gerry Cullen »

:lol: :lol: :lol: by the way there was a spot on the irish news about this new bug,seems to be serious shit as one of the software cos is offering250,000e reward for info be carefull out there
petermeachem
CVO Senior
CVO Senior
Posts: 253
Joined: Thu Oct 09, 2003 10:32 am

Post by petermeachem »

The reason for that Gerry is that the virus will use infected pc's to attack SCO (a Unix firm) between the 1st and 13th of Feb. SCO are currently demanding royalties from Linux, which may well be pertinent. Apparently 1 in 12 emails are currently the virus and quite a lot more are AV programmes and Mail Servers sending mail back to where the virus says it came from to say 'Oh I found a virus'. As the virus invents the From address, this is a complete waste of time, they are just using it as an excuse for advertising. I cleared just under 200 copies off a customers mail server today, it seems the worst is over, just a few new ones have turned up.
Post Reply