IPB
AM:Stills * AM:Films

Welcome Guest ( Log In | Register )

 
Reply to this topicStart new topic
> OT: Virus alert
animaster
post Apr 7 2004, 01:08 AM
Post #1


Tireless Mailing Machine
**********

Group: Contributor
Posts: 6,064
Joined: 18-September 03
From: Hash, Inc. Vancouver, WA
Member No.: 6



From: "Stuart Rogers" stuart.rogers@clara.co.uk
Date: 2004-4-07 10:01:40

Some OT advice for list members.

I believe someone who's on the mailing list (either now or in
the past) has acquired a virus...

In the last few hours I've received three e-mails with attached
..pif files. The mails have subject lines along the line of
"Secure delivery", "Re: Old Photos", "Re: Is this your document?"
The attachments are about 40kB in size.

Two of the e-mails have 'from' & 'return path' that mention
"animationmaster.com", hence my suspicion that someone on the
list is infected. All of them mention prodigy.net.mx
The manner of the e-mails reek of nefariousness!

It's almost certainly a PC user that's affected. If any PC
users on the list/forum gets one of these, I suggest you don't
open the file, but do delete the e-mail.

Best wishes

Stuart
Go to the top of the page
 
+Quote Post
johnl3d
post Apr 7 2004, 04:13 AM
Post #2


Tinkering Gnome
**********

Group: Hash Fellow
Posts: 4,714
Joined: 20-September 03
From: Milwaukee WI
Member No.: 254



Yes I have received 2 here the old photos one was one of them and the address I use for the list is just for the list and so it points to a list member. THe message got flagged immediately by Mcafee


--------------------











http://johnl3d.blogspot.com/

http://www.youtube.com/watch?v=qqTiI2zA8Gw

"Try not! Do or do not. There is no try." Yoda

"Some people dream of accomplishments...
others stay up late and do them" Probably an Animator
Go to the top of the page
 
+Quote Post
animaster
post Apr 7 2004, 05:23 AM
Post #3


Tireless Mailing Machine
**********

Group: Contributor
Posts: 6,064
Joined: 18-September 03
From: Hash, Inc. Vancouver, WA
Member No.: 6



From: "Richard Harrowell" rick@rivernet.com.au
Date: 2004-4-07 23:12:51






Same here. I have received emails containing the Netsky.P virus from a Hash list
member.




The infected computer is a dialup connection to the PRODIGY.NET.MX network.  I
believe the dialup is located at Arizpe in Coahuila de Zaragoza, Mexico.  Please would
anyone using prodigy from around Arizpe check for the virus. The following links
describe the virus, and how to identify and remove it.







Richard.




>

>

> Some OT advice for list members.

>

> I believe someone who's on the mailing list (either now or in

> the past) has acquired a virus...

>

> In the last few hours I've received three e-mails with attached

> .pif files.  The mails have subject lines along the line of

> "Secure delivery", "Re: Old Photos", "Re: Is this your document?"

> The attachments are about 40kB in size.

>

> Two of the e-mails have 'from' & 'return path' that mention

> "animationmaster.com", hence my suspicion that someone on the

> list is infected.  All of them mention prodigy.net.mx

> The manner of the e-mails reek of nefariousness!

>

> It's almost certainly a PC user that's affected.  If any PC

> users on the list/forum gets one of these, I suggest you don't

> open the file, but do delete the e-mail.

>

> Best wishes

>

> Stuart

>

>

> === Animaster Mailing list === Unsubscribe and other options @ www.hash.com/support/maillist.asp
===

>






.
Go to the top of the page
 
+Quote Post
animaster
post Apr 7 2004, 06:38 AM
Post #4


Tireless Mailing Machine
**********

Group: Contributor
Posts: 6,064
Joined: 18-September 03
From: Hash, Inc. Vancouver, WA
Member No.: 6



From: "Gareth Hardy" animaster@dvdreams.co.uk
Date: 2004-4-7 15:27:40



How did you locate the infected computer so accurately? The best I can manage is "It's someone on this list 'cos I don't use this address for anything else."
> The infected computer is a dialup connection to the
> PRODIGY.NET.MX network. I believe the dialup is
> located at Arizpe in Coahuila de Zaragoza, Mexico.

Html-Removed
Go to the top of the page
 
+Quote Post
ChrisThom
post Apr 7 2004, 06:53 AM
Post #5


Sweet Lincoln's mullet!
**********

Group: Members
Posts: 880
Joined: 19-September 03
From: Nashville, TN USA
Member No.: 190
Contests Won:*



I suppose this is good reason to use the forums vs. the maillist.


--------------------
<span style='font-family:verdana'>Dios te bendiga,
Chris Thom
ChrisThom.net

My A:M Gallery

"Earth’s crammed with heaven, and every common bush afire with God;
And only he who sees takes off his shoes; The rest sit round it and pluck blackberries."
~ Elizabeth Barrett Browning

"Time flies like the wind. Fruit Flies like bananas."
~ Groucho Marx</span>
Go to the top of the page
 
+Quote Post
jon
post Apr 7 2004, 08:46 AM
Post #6


Master
**********

Group: Contributor
Posts: 1,110
Joined: 18-September 03
Member No.: 51
Contests Won:**



these types of viruses usually find their victims in the address books of infected machines, but the spam/trojan email they create almost always has a forged 'from' address. you can find out the originating server by checking the detailed headers in the email, which is often hidden by email readers.

the best advice i can give is don't open an attachment from anyone unless you are expecting it, and don't use outlook!

-jon
Go to the top of the page
 
+Quote Post
animaster
post Apr 7 2004, 10:28 PM
Post #7


Tireless Mailing Machine
**********

Group: Contributor
Posts: 6,064
Joined: 18-September 03
From: Hash, Inc. Vancouver, WA
Member No.: 6



From: pedro galvez galvezmanzo@prodigy.net.mx
Date: 2004-4-08 01:21:58

for every 10 mails i get from the animaster mailing list, 4 of them are
virus
----- Original Message -----
From: johnathan darkly
To:
Sent: Wednesday, April 07, 2004 11:48 AM
Subject: Re: OT: Virus alert
>
> From: jon : johnathan darkly :
>
> these types of viruses usually find their victims in the address books of
infected machines, but the spam/trojan email they create almost always has a
forged 'from' address. you can find out the originating server by checking
the detailed headers in the email, which is often hidden by email readers.
>
> the best advice i can give is don't open an attachment from anyone unless
you are expecting it, and don't use outlook!
>
> -jon
>
> *** View Entire Thread @
http://www.hash.com/forums/index.php?showt...view=getnewpost

>

www.hash.com/support/maillist.asp ===
Go to the top of the page
 
+Quote Post
animaster
post Apr 9 2004, 10:03 AM
Post #8


Tireless Mailing Machine
**********

Group: Contributor
Posts: 6,064
Joined: 18-September 03
From: Hash, Inc. Vancouver, WA
Member No.: 6



From: pedro galvez galvezmanzo@prodigy.net.mx
Date: 2004-4-08 16:35:12

yes i had it but not anymore because i had to format my pc, and yes my anti
virus don't detect it Thanks
----- Original Message -----
From: Richard Harrowell
To: pedro galvez
Sent: Thursday, April 08, 2004 1:52 AM
Subject: RE: OT: Virus alert
> Pedro,
>
> Have you checked to see if you have the Netsky.P virus? (Do you
> have a file FVProtect.exe in your C:Windows or C:Winnt folder?)
>
> The point is that your dialup connects using the 200.64.130.xxx subnet.
> I have received 2 infected emails sent from an infected computer on
> the 200.64.130.xxx subnet.
>
> This virus has its own SMTP mail server and will quite happily send
> infected emails back to yourself. this would explain the fact you are
> getting the 4 out of 10 infected messages.
>
> It is not enough that you have an anti-virus package - once you are
> infected, most modern viruses often disable the antivirus protection.
>
> If they are not coming from you, have you looked at the IP addresses
> that the viruses are coming from?
>
> Regards
>
> Richard.
> >
> > for every 10 mails i get from the animaster mailing list, 4 of them are
> > virus
> > ----- Original Message -----
> > From: johnathan darkly
> > To:
> > Sent: Wednesday, April 07, 2004 11:48 AM
> > Subject: Re: OT: Virus alert
> >
> >
> > >
> > > From: jon : johnathan darkly :
> > >
> > > these types of viruses usually find their victims in the address
books of
> > infected machines, but the spam/trojan email they create almost always
has a
> > forged 'from' address. you can find out the originating server by
checking
> > the detailed headers in the email, which is often hidden by email
readers.
> > >
> > > the best advice i can give is don't open an attachment from anyone
unless
> > you are expecting it, and don't use outlook!
> > >
> > > -jon
> > >
> > >
> > >
> > > *** View Entire Thread @
> > http://www.hash.com/forums/index.php?showt...view=getnewpost
> > >

> > >
> > >
> > >
> > >

> >
> > >
> >
> >

www.hash.com/support/maillist.asp ===
Go to the top of the page
 
+Quote Post
animaster
post Apr 9 2004, 10:03 AM
Post #9


Tireless Mailing Machine
**********

Group: Contributor
Posts: 6,064
Joined: 18-September 03
From: Hash, Inc. Vancouver, WA
Member No.: 6



From: pedro galvez galvezmanzo@prodigy.net.mx
Date: 2004-4-08 16:40:41

i had that file and it cause me a lot of troubles, so i had to format my
entire HD, but, how or from where i got infected with this virus?
----- Original Message -----
From: Richard Harrowell
To: pedro galvez
Sent: Thursday, April 08, 2004 1:52 AM
Subject: RE: OT: Virus alert
> Pedro,
>
> Have you checked to see if you have the Netsky.P virus? (Do you
> have a file FVProtect.exe in your C:Windows or C:Winnt folder?)
>
> The point is that your dialup connects using the 200.64.130.xxx subnet.
> I have received 2 infected emails sent from an infected computer on
> the 200.64.130.xxx subnet.
>
> This virus has its own SMTP mail server and will quite happily send
> infected emails back to yourself. this would explain the fact you are
> getting the 4 out of 10 infected messages.
>
> It is not enough that you have an anti-virus package - once you are
> infected, most modern viruses often disable the antivirus protection.
>
> If they are not coming from you, have you looked at the IP addresses
> that the viruses are coming from?
>
> Regards
>
> Richard.
> >
> > for every 10 mails i get from the animaster mailing list, 4 of them are
> > virus
> > ----- Original Message -----
> > From: johnathan darkly
> > To:
> > Sent: Wednesday, April 07, 2004 11:48 AM
> > Subject: Re: OT: Virus alert
> >
> >
> > >
> > > From: jon : johnathan darkly :
> > >
> > > these types of viruses usually find their victims in the address
books of
> > infected machines, but the spam/trojan email they create almost always
has a
> > forged 'from' address. you can find out the originating server by
checking
> > the detailed headers in the email, which is often hidden by email
readers.
> > >
> > > the best advice i can give is don't open an attachment from anyone
unless
> > you are expecting it, and don't use outlook!
> > >
> > > -jon
> > >
> > >
> > >
> > > *** View Entire Thread @
> > http://www.hash.com/forums/index.php?showt...view=getnewpost
> > >

> > >
> > >
> > >
> > >

> >
> > >
> >
> >

www.hash.com/support/maillist.asp ===
Go to the top of the page
 
+Quote Post
jon
post Apr 9 2004, 02:15 PM
Post #10


Master
**********

Group: Contributor
Posts: 1,110
Joined: 18-September 03
Member No.: 51
Contests Won:**



QUOTE
i had that file and it cause me a lot of troubles, so i had to format my
entire HD, but, how or from where i got infected with this virus?

you got the virus by opening an infected attachment from an email sent from yet another computer user who did the same thing.

these latest email viruses spread out thanks to ms outlook's swiss cheese security.

-jon
Go to the top of the page
 
+Quote Post
zacktaich
post Apr 9 2004, 04:11 PM
Post #11


Poo-flinging monkey
**********

Group: Contributor
Posts: 1,046
Joined: 25-September 03
From: Sunnyvale, California (near San Francisco
Member No.: 405



QUOTE
The infected computer is a dialup connection to the PRODIGY.NET.MX network.  I
believe the dialup is located at Arizpe in Coahuila de Zaragoza, Mexico.  Please would
anyone using prodigy from around Arizpe check for the virus. The following links
describe the virus, and how to identify and remove it.


Unfortunately, when you see a virus coming from outside the US, 50% of the time, the IP is forged. For the person who didn't know how to find out this info: He found the IP in the extednded Headers. Then he just used an IP address locator.


--------------------
Zachary Taich
www.zack3d.com - Coming soon: Adventure takes a whole new form (see website for details).
http://www.zack3d.com/wiki/ - The Hash A:M Wiki (please add!)
Go to the top of the page
 
+Quote Post

Reply to this topicStart new topic
2 User(s) are reading this topic (2 Guests and 0 Anonymous Users)
0 Members:

 



- Lo-Fi Version Time is now: 2nd September 2010 - 06:23 AM