![]() ![]() |
Apr 7 2004, 01:08 AM
Post
#1
|
|
![]() Tireless Mailing Machine ![]() ![]() ![]() ![]() ![]() ![]() ![]() ![]() ![]() ![]() Group: Contributor Posts: 6,064 Joined: 18-September 03 From: Hash, Inc. Vancouver, WA Member No.: 6 |
From: "Stuart Rogers"
Date: 2004-4-07 10:01:40 Some OT advice for list members. I believe someone who's on the mailing list (either now or in the past) has acquired a virus... In the last few hours I've received three e-mails with attached ..pif files. The mails have subject lines along the line of "Secure delivery", "Re: Old Photos", "Re: Is this your document?" The attachments are about 40kB in size. Two of the e-mails have 'from' & 'return path' that mention "animationmaster.com", hence my suspicion that someone on the list is infected. All of them mention prodigy.net.mx The manner of the e-mails reek of nefariousness! It's almost certainly a PC user that's affected. If any PC users on the list/forum gets one of these, I suggest you don't open the file, but do delete the e-mail. Best wishes Stuart |
|
|
|
Apr 7 2004, 04:13 AM
Post
#2
|
|
|
Tinkering Gnome ![]() ![]() ![]() ![]() ![]() ![]() ![]() ![]() ![]() ![]() Group: Hash Fellow Posts: 4,714 Joined: 20-September 03 From: Milwaukee WI Member No.: 254 |
Yes I have received 2 here the old photos one was one of them and the address I use for the list is just for the list and so it points to a list member. THe message got flagged immediately by Mcafee
-------------------- http://johnl3d.blogspot.com/ http://www.youtube.com/watch?v=qqTiI2zA8Gw "Try not! Do or do not. There is no try." Yoda "Some people dream of accomplishments... others stay up late and do them" Probably an Animator |
|
|
|
Apr 7 2004, 05:23 AM
Post
#3
|
|
![]() Tireless Mailing Machine ![]() ![]() ![]() ![]() ![]() ![]() ![]() ![]() ![]() ![]() Group: Contributor Posts: 6,064 Joined: 18-September 03 From: Hash, Inc. Vancouver, WA Member No.: 6 |
From: "Richard Harrowell"
Date: 2004-4-07 23:12:51 Same here. I have received emails containing the Netsky.P virus from a Hash list member. The infected computer is a dialup connection to the PRODIGY.NET.MX network. I believe the dialup is located at Arizpe in Coahuila de Zaragoza, Mexico. Please would anyone using prodigy from around Arizpe check for the virus. The following links describe the virus, and how to identify and remove it. Richard. > > > Some OT advice for list members. > > I believe someone who's on the mailing list (either now or in > the past) has acquired a virus... > > In the last few hours I've received three e-mails with attached > .pif files. The mails have subject lines along the line of > "Secure delivery", "Re: Old Photos", "Re: Is this your document?" > The attachments are about 40kB in size. > > Two of the e-mails have 'from' & 'return path' that mention > "animationmaster.com", hence my suspicion that someone on the > list is infected. All of them mention prodigy.net.mx > The manner of the e-mails reek of nefariousness! > > It's almost certainly a PC user that's affected. If any PC > users on the list/forum gets one of these, I suggest you don't > open the file, but do delete the e-mail. > > Best wishes > > Stuart > > > === Animaster Mailing list === Unsubscribe and other options @ www.hash.com/support/maillist.asp === > . |
|
|
|
Apr 7 2004, 06:38 AM
Post
#4
|
|
![]() Tireless Mailing Machine ![]() ![]() ![]() ![]() ![]() ![]() ![]() ![]() ![]() ![]() Group: Contributor Posts: 6,064 Joined: 18-September 03 From: Hash, Inc. Vancouver, WA Member No.: 6 |
From: "Gareth Hardy"
Date: 2004-4-7 15:27:40 How did you locate the infected computer so accurately? The best I can manage is "It's someone on this list 'cos I don't use this address for anything else." > The infected computer is a dialup connection to the > PRODIGY.NET.MX network. I believe the dialup is > located at Arizpe in Coahuila de Zaragoza, Mexico. Html-Removed |
|
|
|
Apr 7 2004, 06:53 AM
Post
#5
|
|
![]() Sweet Lincoln's mullet! ![]() ![]() ![]() ![]() ![]() ![]() ![]() ![]() ![]() ![]() Group: Members Posts: 880 Joined: 19-September 03 From: Nashville, TN USA Member No.: 190 Contests Won:* |
I suppose this is good reason to use the forums vs. the maillist.
-------------------- <span style='font-family:verdana'>Dios te bendiga,
Chris Thom ChrisThom.net My A:M Gallery "Earth’s crammed with heaven, and every common bush afire with God; And only he who sees takes off his shoes; The rest sit round it and pluck blackberries." ~ Elizabeth Barrett Browning "Time flies like the wind. Fruit Flies like bananas." ~ Groucho Marx</span> |
|
|
|
Apr 7 2004, 08:46 AM
Post
#6
|
|
|
Master ![]() ![]() ![]() ![]() ![]() ![]() ![]() ![]() ![]() ![]() Group: Contributor Posts: 1,110 Joined: 18-September 03 Member No.: 51 Contests Won:** |
these types of viruses usually find their victims in the address books of infected machines, but the spam/trojan email they create almost always has a forged 'from' address. you can find out the originating server by checking the detailed headers in the email, which is often hidden by email readers.
the best advice i can give is don't open an attachment from anyone unless you are expecting it, and don't use outlook! -jon |
|
|
|
Apr 7 2004, 10:28 PM
Post
#7
|
|
![]() Tireless Mailing Machine ![]() ![]() ![]() ![]() ![]() ![]() ![]() ![]() ![]() ![]() Group: Contributor Posts: 6,064 Joined: 18-September 03 From: Hash, Inc. Vancouver, WA Member No.: 6 |
From: pedro galvez
Date: 2004-4-08 01:21:58 for every 10 mails i get from the animaster mailing list, 4 of them are virus ----- Original Message ----- From: johnathan darkly To: Sent: Wednesday, April 07, 2004 11:48 AM Subject: Re: OT: Virus alert > > From: jon : johnathan darkly : > > these types of viruses usually find their victims in the address books of infected machines, but the spam/trojan email they create almost always has a forged 'from' address. you can find out the originating server by checking the detailed headers in the email, which is often hidden by email readers. > > the best advice i can give is don't open an attachment from anyone unless you are expecting it, and don't use outlook! > > -jon > > *** View Entire Thread @ http://www.hash.com/forums/index.php?showt...view=getnewpost > www.hash.com/support/maillist.asp === |
|
|
|
Apr 9 2004, 10:03 AM
Post
#8
|
|
![]() Tireless Mailing Machine ![]() ![]() ![]() ![]() ![]() ![]() ![]() ![]() ![]() ![]() Group: Contributor Posts: 6,064 Joined: 18-September 03 From: Hash, Inc. Vancouver, WA Member No.: 6 |
From: pedro galvez
Date: 2004-4-08 16:35:12 yes i had it but not anymore because i had to format my pc, and yes my anti virus don't detect it Thanks ----- Original Message ----- From: Richard Harrowell To: pedro galvez Sent: Thursday, April 08, 2004 1:52 AM Subject: RE: OT: Virus alert > Pedro, > > Have you checked to see if you have the Netsky.P virus? (Do you > have a file FVProtect.exe in your C:Windows or C:Winnt folder?) > > The point is that your dialup connects using the 200.64.130.xxx subnet. > I have received 2 infected emails sent from an infected computer on > the 200.64.130.xxx subnet. > > This virus has its own SMTP mail server and will quite happily send > infected emails back to yourself. this would explain the fact you are > getting the 4 out of 10 infected messages. > > It is not enough that you have an anti-virus package - once you are > infected, most modern viruses often disable the antivirus protection. > > If they are not coming from you, have you looked at the IP addresses > that the viruses are coming from? > > Regards > > Richard. > > > > for every 10 mails i get from the animaster mailing list, 4 of them are > > virus > > ----- Original Message ----- > > From: johnathan darkly > > To: > > Sent: Wednesday, April 07, 2004 11:48 AM > > Subject: Re: OT: Virus alert > > > > > > > > > > From: jon : johnathan darkly : > > > > > > these types of viruses usually find their victims in the address books of > > infected machines, but the spam/trojan email they create almost always has a > > forged 'from' address. you can find out the originating server by checking > > the detailed headers in the email, which is often hidden by email readers. > > > > > > the best advice i can give is don't open an attachment from anyone unless > > you are expecting it, and don't use outlook! > > > > > > -jon > > > > > > > > > > > > *** View Entire Thread @ > > http://www.hash.com/forums/index.php?showt...view=getnewpost > > > > > > > > > > > > > > > > > > > > > > > > www.hash.com/support/maillist.asp === |
|
|
|
Apr 9 2004, 10:03 AM
Post
#9
|
|
![]() Tireless Mailing Machine ![]() ![]() ![]() ![]() ![]() ![]() ![]() ![]() ![]() ![]() Group: Contributor Posts: 6,064 Joined: 18-September 03 From: Hash, Inc. Vancouver, WA Member No.: 6 |
From: pedro galvez
Date: 2004-4-08 16:40:41 i had that file and it cause me a lot of troubles, so i had to format my entire HD, but, how or from where i got infected with this virus? ----- Original Message ----- From: Richard Harrowell To: pedro galvez Sent: Thursday, April 08, 2004 1:52 AM Subject: RE: OT: Virus alert > Pedro, > > Have you checked to see if you have the Netsky.P virus? (Do you > have a file FVProtect.exe in your C:Windows or C:Winnt folder?) > > The point is that your dialup connects using the 200.64.130.xxx subnet. > I have received 2 infected emails sent from an infected computer on > the 200.64.130.xxx subnet. > > This virus has its own SMTP mail server and will quite happily send > infected emails back to yourself. this would explain the fact you are > getting the 4 out of 10 infected messages. > > It is not enough that you have an anti-virus package - once you are > infected, most modern viruses often disable the antivirus protection. > > If they are not coming from you, have you looked at the IP addresses > that the viruses are coming from? > > Regards > > Richard. > > > > for every 10 mails i get from the animaster mailing list, 4 of them are > > virus > > ----- Original Message ----- > > From: johnathan darkly > > To: > > Sent: Wednesday, April 07, 2004 11:48 AM > > Subject: Re: OT: Virus alert > > > > > > > > > > From: jon : johnathan darkly : > > > > > > these types of viruses usually find their victims in the address books of > > infected machines, but the spam/trojan email they create almost always has a > > forged 'from' address. you can find out the originating server by checking > > the detailed headers in the email, which is often hidden by email readers. > > > > > > the best advice i can give is don't open an attachment from anyone unless > > you are expecting it, and don't use outlook! > > > > > > -jon > > > > > > > > > > > > *** View Entire Thread @ > > http://www.hash.com/forums/index.php?showt...view=getnewpost > > > > > > > > > > > > > > > > > > > > > > > > www.hash.com/support/maillist.asp === |
|
|
|
Apr 9 2004, 02:15 PM
Post
#10
|
|
|
Master ![]() ![]() ![]() ![]() ![]() ![]() ![]() ![]() ![]() ![]() Group: Contributor Posts: 1,110 Joined: 18-September 03 Member No.: 51 Contests Won:** |
QUOTE i had that file and it cause me a lot of troubles, so i had to format my entire HD, but, how or from where i got infected with this virus? you got the virus by opening an infected attachment from an email sent from yet another computer user who did the same thing. these latest email viruses spread out thanks to ms outlook's swiss cheese security. -jon |
|
|
|
Apr 9 2004, 04:11 PM
Post
#11
|
|
|
Poo-flinging monkey ![]() ![]() ![]() ![]() ![]() ![]() ![]() ![]() ![]() ![]() Group: Contributor Posts: 1,046 Joined: 25-September 03 From: Sunnyvale, California (near San Francisco Member No.: 405 |
QUOTE The infected computer is a dialup connection to the PRODIGY.NET.MX network. I believe the dialup is located at Arizpe in Coahuila de Zaragoza, Mexico. Please would anyone using prodigy from around Arizpe check for the virus. The following links describe the virus, and how to identify and remove it. Unfortunately, when you see a virus coming from outside the US, 50% of the time, the IP is forged. For the person who didn't know how to find out this info: He found the IP in the extednded Headers. Then he just used an IP address locator. -------------------- Zachary Taich
www.zack3d.com - Coming soon: Adventure takes a whole new form (see website for details). http://www.zack3d.com/wiki/ - The Hash A:M Wiki (please add!) |
|
|
|
![]() ![]() |
|
Lo-Fi Version | Time is now: 2nd September 2010 - 06:23 AM |