1. You are viewing our forum as a guest. For full access please Register. WindowsBBS.com is completely free, paid for by advertisers and donations.

Received today with an exe attachment

Discussion in 'Microsoft Mail (Outlook / OE / Windows Mail)' started by mojo13, 2006/09/09.

  1. 2006/09/09
    mojo13 Lifetime Subscription

    mojo13 Well-Known Member Thread Starter

    Joined:
    2002/01/07
    Messages:
    547
    Likes Received:
    0
    Mail server report.

    Our firewall determined the e-mails containing worm copies are being sent from your computer.

    Nowadays it happens from many computers, because this is a new virus type (Network Worms).


    Using the new bug in the Windows, these viruses infect the computer unnoticeably.
    After the penetrating into the computer the virus harvests all the e-mail addresses and sends the copies of itself to these e-mail addresses

    Please install updates for worm elimination and your computer restoring.

    Best regards,
    Customers support service


    Attachment: KB8546-x86.exe
     
  2. 2006/09/10
    Welshjim

    Welshjim Inactive

    Joined:
    2002/01/07
    Messages:
    5,643
    Likes Received:
    0
    mojo13--That looks like spam to me. How official did the email look? (You really should not open suspicious email. :) You should rather look at the headers to see if it really came from your email provider? Post back if you do not know how to look at headers without opening email. )
    Now that you have opened the email, when you hover over any links in the email like the download site for "KB8546-x86.exe ", what url is shown in the Status Bar? Anything other than your email provider's URL?
    I could not find info on anything new called Network Worms, although that name has been around for some time as a generic description of certain worms
    http://www.users.qwest.net/~eballen1/nws/
    Also that KB executable is missing a few digits to be a legitimate MS KB number. And there was nothing about KB8546-x86.exe on Google.
    If you are practicing good housekeeping on your PC with antivirus, antispyware, firewall, etc., your PC should be OK. But you can always check using the procedures here
    http://www.windowsbbs.com/showthread.php?t=37074
    I think you should report this email as spam to your email service provider if they offer such a service. In the case of Comcast, I copy the header, right click on the unopened email|Forward as Attachment and send to missed-spam@comcast.net. Perhaps your email provider has something similar. Or phone the email provider.
     

  3. to hide this advert.

  4. 2006/09/10
    mojo13 Lifetime Subscription

    mojo13 Well-Known Member Thread Starter

    Joined:
    2002/01/07
    Messages:
    547
    Likes Received:
    0
    The header etc. has been sent to the ISP for analysis.

    The attached file was uploaded to www.virustotal.com with the following results;

    Authentium -- W32/Flurry.A
    BitDefender -- Generic.Stration.2346B2CB
    CAT-QuickHeal -- (Suspicious) - DNAScan
    ClamAV -- Worm.Stration.X
    Fortinet -- suspicious
    F-Prot -- security risk named W32/Flurry.A
    F-Prot4 -- W32/Flurry.A
    Kasperski -- E-mail-Worm.Win32.Warezov.s
    Norman -- W32/Suspicious_M.gen
    Panda -- Suspicious file
    Sophos -- W32/Stration-S
    Symantec -- W32.Stration.A@mm
    VirusBuster -- Trojan.Opnis.Gen!Pac
     
  5. 2006/09/10
    Welshjim

    Welshjim Inactive

    Joined:
    2002/01/07
    Messages:
    5,643
    Likes Received:
    0
    mojo13--I am no expert on getting rid of baddies, but obviously this .exe is one. So I hope you have not opened it. :eek:
    If you have not opened it, you still might consider the following
    http://www.windowsbbs.com/showthread.php?t=37074
    to be sure you have no baddies.
    Or you can just ignore and delete the email and hope it was a one time event.
     
  6. 2006/09/10
    mojo13 Lifetime Subscription

    mojo13 Well-Known Member Thread Starter

    Joined:
    2002/01/07
    Messages:
    547
    Likes Received:
    0
    I never open attachments like that. I was suspicious the first time I looked at it and sent it to the authorities...:)
     

Share This Page

  1. This site uses cookies to help personalise content, tailor your experience and to keep you logged in if you register.
    By continuing to use this site, you are consenting to our use of cookies.