1. You are viewing our forum as a guest. For full access please Register. WindowsBBS.com is completely free, paid for by advertisers and donations.

New Email Virus

Discussion in 'Security and Privacy' started by PeteC, 2003/09/20.

Thread Status:
Not open for further replies.
  1. 2003/09/20
    PeteC

    PeteC SuperGeek Staff Thread Starter

    Joined:
    2002/05/10
    Messages:
    28,896
    Likes Received:
    389
    WARNING

    If you receive an email purporting to be from Microsoft Security Division with an attachment DO NOT OPEN IT - it is contains a virus - and is not from Microsoft.

    Here is what my ISP found

    "The file Q251746.exe attached to this message was found to contain the malicious virus Worm.Automat.AHB and has been removed by BT Openworld Email Protection Service powered by Symantec. "
     
  2. 2003/09/20
    Dennis L Lifetime Subscription

    Dennis L Inactive Alumni

    Joined:
    2002/06/07
    Messages:
    2,557
    Likes Received:
    2
    Have received 3 in the last two days.
    First one yesterday... 156Kb, My Norton deleted it. Norton also reported it was Worm.Automat.AHB.
    Today before I opened email client, I used my ISP web view..
    Two more there today.... 143Kb, 156Kb. The "Subject" and "From" where different among all 3. The ONE thing they did contain, the word Microsoft in subject or from field. I deleted both on ISP server. Received this virus alert from Symantec, stating......
    "NOTE: This threat was previously detected as Worm.Automat.AHB by definitions automatically created by Symantec's Digital Immune System. Due to an increase in submissions, Symantec Security Response has upgraded W32.Swen.A@mm to Category 3, as of 6:30pm Thursday, September 18, 2003........ "
     
    Last edited: 2003/09/20

  3. to hide this advert.

  4. 2003/09/21
    bikerchick4God

    bikerchick4God Inactive

    Joined:
    2003/06/22
    Messages:
    5
    Likes Received:
    0
    bulk mail from MS

    I started receiving anywhere from 10-20 bulk msgs from various MS titled senders. Its been about 5 days now. I got a clue they were viruses from the headers, seeing the size of the files 144-156k, and deleted them as they came in.
    Do I just wait until they stop sending them to me or can I head it off... its just a nuisance for now as my Outlook Express only downloads headers. I am grateful Symantec is on duty, just looking for some advice.
    Thanks
    nancy
     
  5. 2003/09/21
    FireDancer Lifetime Subscription

    FireDancer Inactive

    Joined:
    2003/04/14
    Messages:
    460
    Likes Received:
    0
    bikerchick4God,

    You can use this mail utility for free... it is called MailWasher and will let you look at mail and delete/add to the blacklist while still at your server before downloading to your computer.

    It is very easy to use and set up, it is free
    for one single acount only though. If you would like to use for mutiple accounts you must make a donation. hope this
    helps.

    MailWasher

    Regards,

    FireDancer
     
    Last edited: 2003/09/21
  6. 2003/09/21
    MinnesotaMike

    MinnesotaMike Geek Member

    Joined:
    2002/01/07
    Messages:
    1,396
    Likes Received:
    3
    I've gotten about 50-60 in the last 3 days. Kind of a pain, but Norton's catches them and I delete them. Hopefully, they won't last too much longer.

    Mike
     
    Last edited: 2003/09/21
  7. 2003/09/21
    bikerchick4God

    bikerchick4God Inactive

    Joined:
    2003/06/22
    Messages:
    5
    Likes Received:
    0
    thanks firedancer.
    Mike, nice to hear from others with the same prob.
    ciao
    nancy
     
  8. 2003/09/21
    leeart

    leeart Inactive

    Joined:
    2002/01/07
    Messages:
    7
    Likes Received:
    0
    I started getting them yesterday and the rate went up to 20 in a half hour this morning. It seems to have stopped for now.
    Art
     
  9. 2003/09/22
    PeteC

    PeteC SuperGeek Staff Thread Starter

    Joined:
    2002/05/10
    Messages:
    28,896
    Likes Received:
    389
    As a matter of interest ..........

    As a matter of interest do none of your ISP's offer an email scanning service?

    My ISP (British Telecom in the UK) scans all my incoming mail with Symantec products for free and only forwards the cleaned up version. It is almost 100% - needless to say I run antivirus - NAV 2004 as well.

    The message in my opening post is typical of their response if a virus is found.
     
  10. 2003/09/22
    Ryder

    Ryder Inactive

    Joined:
    2003/09/01
    Messages:
    124
    Likes Received:
    0
    I can't beleive that there are ISPs in the civilised world that don't do scanning. Even here in Africa, all but one ISP scan messages on the server, using different products. Of course, being in Africa, it takes a while for viruses to start popping up here, for the most part. There are exceptions, but only recently with the Blaster worm, and also Sobig. Other than that, tho, by the time they show up, your personal antivisur has known about it for at least a month.
    I miss real civilisation tho....
     
  11. 2003/09/22
    Newt

    Newt Inactive

    Joined:
    2002/01/07
    Messages:
    10,974
    Likes Received:
    2
    Ryder, PeteC - I might like to have my ISP scan for infected mail if:
    - I had control over what the did with it. For instance, if I could elect to have the post deleted silently and at the ISP.
    - I could turn off the "feature" when & if I wanted.

    I understand why an ISP would run such a service. Fewer infected PCs on their system means less junk traffic taking up bandwidth.

    I do not understand the benefit to the user if you have to hear about every infection and since you still need to run your own AV software to guard against non-email infections.

    If the AV feature is simply there and you have no controls, it strikes me as one of those unpleasant Big Brother things. The ISP saying, in effect, "You poor stupid user - we will try to protect you since you probably can't protect yourself ".
     
  12. 2003/09/22
    PeteC

    PeteC SuperGeek Staff Thread Starter

    Joined:
    2002/05/10
    Messages:
    28,896
    Likes Received:
    389
    Newt,

    I'm partly with you - email scanning on my ISP is opt in - I opted in.

    The benefit, as I see it, is that it does exactly what Norton does on my PC, but at a distance (and the virus never gets downloaded to my PC) and I would expect that their virus defs to be updated more frequently than mine (updated weekly). Anyway Norton scans all my oncoming mail regardless of the ISP scan.

    The end result is essentially the same - without ISP scanning my Norton (hopefully) finds the virus and tells me - so does my ISP.

    It is their duty to let the user know that he/she had mail; the fact that it was infected and has been cleaned is the bonus.

    As we know some BBS users do not have antivirus - or a firewall - I would suggst that this is a service to the user rather than Big Brother.

    I can't think of a reason to open mail that has a virus.
     
  13. 2003/09/22
    Newt

    Newt Inactive

    Joined:
    2002/01/07
    Messages:
    10,974
    Likes Received:
    2
    PeteC - in this day and age I also can't think of a reason to open a post with an infected attachment. At one time there was sometimes benefit to cleaning the infection and retaining what was left of the attachment. But not in recent years.

    I agree that an ISP that is scanning email and finds an infected one has an obligation to inform the addressee if the addressee wants to be told. But personally, I don't want or need to know about the junk emails.

    Out of curiosity, why do you only update your virus def files once a week? I check daily and update Norton if there is one.
     
  14. 2003/09/22
    James Martin

    James Martin Geek Member

    Joined:
    2003/05/15
    Messages:
    2,655
    Likes Received:
    79
    Does anybody know how to stop these virus laden e-mails from piling up in a web based e-mail provider such as yahoo??
    So far I haven't had this problem with my ISP's e-mail yet.

    J. M.
     
  15. 2003/09/23
    PeteC

    PeteC SuperGeek Staff Thread Starter

    Joined:
    2002/05/10
    Messages:
    28,896
    Likes Received:
    389
    Newt

    Automatic Live Update - in the UK and in the States (I understand - from Charlesvar (?)) updates on a weekly basis, occasionally more often.

    I also understand that it is possible to update daily - but you have to download all all the virus definitions, not just the new ones - a few meg.

    Would be glad to hear if there is another option.

    On the question of junk/spam my ISP also blocks these - quite effectively, but there no notification (that would be pointless!) and the spam is kept in my account at the ISP where I can view it should I so wish - after 15 days it is automatically deleted.
     
  16. 2003/09/23
    MinnesotaMike

    MinnesotaMike Geek Member

    Joined:
    2002/01/07
    Messages:
    1,396
    Likes Received:
    3
    PeteC,

    I have Norton's also and use the Live Update feature to check for updates occasionally. As far as I know, it only downloads the new definitions after comparing what you have and what they have. Do you use LU to check for updates? Since I have broadband, my Norton's is also set to check for new definitions everytime I start my system.

    Mike
     
  17. 2003/09/23
    Newt

    Newt Inactive

    Joined:
    2002/01/07
    Messages:
    10,974
    Likes Received:
    2
    Mike - we get live updates made available over here more often than the UK does from what I understand.

    PeteC - I just pull down the 4Mb thing and run it. DSL so not a long process. If you have dial-up or a monthly download limit or something, that wouldn't be practical though and there is no other choice I'm aware of.
     
  18. 2003/09/23
    PeteC

    PeteC SuperGeek Staff Thread Starter

    Joined:
    2002/05/10
    Messages:
    28,896
    Likes Received:
    389
    I have dial up and a monthly limit - 150 hrs, not that that's a problem. No broadband in my area.

    Thinking about Mike's comment I have seen Live Updates on days other than Wednesdays, - and I am 'on' a couple of hours each day minimum, so maybe Symantec send them out more often when the need demands. Must check to see if Live update engine is normally running.
     
  19. 2003/09/23
    MinnesotaMike

    MinnesotaMike Geek Member

    Joined:
    2002/01/07
    Messages:
    1,396
    Likes Received:
    3
    Newt,

    Didn't realize there was a difference with the updates. See, I'm still learning things! :D

    Mike
     
  20. 2003/09/26
    Panda Lifetime Subscription

    Panda Inactive

    Joined:
    2002/01/07
    Messages:
    498
    Likes Received:
    0
    My goodness! But, this is one busy worm! Two days after hearing about I've been getting it in my mail at least 3 times a day. The FROM line is always different, but the subject line is a dead giveaway when you read it. Unreal. Glad my NORTON is catching it!

    :)
     
  21. 2003/09/27
    MinnesotaMike

    MinnesotaMike Geek Member

    Joined:
    2002/01/07
    Messages:
    1,396
    Likes Received:
    3
    The good news is that the number that I had been getting, 10-20/day, is down to 2-3 a day. This makes it a little quicker getting through my email!

    Mike
     
Thread Status:
Not open for further replies.

Share This Page

  1. This site uses cookies to help personalise content, tailor your experience and to keep you logged in if you register.
    By continuing to use this site, you are consenting to our use of cookies.