![]() | |
|
Welcome to the ABXZone Computer Forums forums. You are currently viewing our boards as a guest which gives you limited access to view most discussions and access our other features. By joining our free community you will have access to post topics, communicate privately with other members (PM), respond to polls, upload content and access many other special features. Registration is fast, simple and absolutely free so please, join our community today! If you have any problems with the registration process or your account login, please contact contact us. |
![]() |
| | LinkBack | Thread Tools | Display Modes |
| | #16 |
| Never Ending Join Date: Jul 2002 Location: Vancouver, Washington (State)
Posts: 4,188
| Your a scary fella Fraoch -wayne
__________________ System-1 (primary) Intel D875PBZLK FMB 1.5 > Pentium 4/ 3.0E (D0) > Crucial Ballistix 512mb PC4000 (Dual Channel) > ATI Radeon 9500 Pro (128) > Audigy 2 Platinum > Thermaltake P4 Spark 7+ (Xaser Edition) - Antec 80x80mm x5 > 1x 80GB WD SE - 2x Seagate 200GB 7200RPM Barracuda 7200.7 Plus SATA > Lite-On LDW811s dvd +/- Tashiba SDM1712 DvD > Antec 430 TP > WinXP W/SP-2 Gigabit Network, Linksys WRT54GS, Linksys EG008W 8-port gigabit switch, ximeta network storage, Motorola SB4200 |
| (Offline) | |
| | #17 | |
| Resident ABX Wizard ![]() Join Date: May 2003 Location: London, Ontario
Posts: 8,814
| Quote:
| |
| (Offline) | |
| | #18 |
| Resident ABX Wizard ![]() Join Date: May 2003 Location: London, Ontario
Posts: 8,814
| ...and another one today. This was a business contact, I'm sure I was in this guy's address book for legitimate purposes. What the heck's going on? Nothing for 6 years and suddenly half-a-dozen in a few weeks? Is there a big Netsky-C incident raging right now? BTW to help this guy out I recommended McAfee Stinger. You don't have to get the IT department involved right away, it's a single executable, it scans reasonably fast and it's free. It's also current as of Dec. 14th. Edit: at least things aren't as bad as Strong Bad... Last edited by Fraoch : 12-20-2004 at 11:46 AM. |
| (Offline) | |
| | #19 | |
| Resident ABX Wizard ![]() Join Date: May 2003 Location: London, Ontario
Posts: 8,814
| I'm getting 1-2 of these per day now. Most seem to be from business contacts? Today I have evidence that my webmail address has been hijacked! I can find no evidence that my machine is infected and the intended recipient is not in my address book. What's bizarre is that the intended recipient works for a company that COULD be a business contact, but isn't currently. Below is a quoted message, with addys removed: Quote:
| |
| (Offline) | |
| | #20 |
| Resident ABX Wizard ![]() Join Date: May 2003 Location: London, Ontario
Posts: 8,814
| Bump on this last question. Since then I've scanned my computer for viruses, spyware and adware and come up clean. This means someone has hijacked my e-mail address (or can they spoof it?) I have changed my password to get into the e-mail account. Also I see that there are no suspicious e-mails in the sent items folder, meaning it wasn't done through conventional "hacking" into my account. I will try some online virus scanning of my PC though from different AV manufacturers just to be sure. |
| (Offline) | |
| | #21 |
| PHX Join Date: Jul 2004 Location: Phoenix
Posts: 2,569
| What about trojans and worms? Did you run TDS-3 on it?
__________________ D875PBZLK, MAC G4-933 |
| (Offline) | |
| | #22 |
| Resident ABX Wizard ![]() Join Date: May 2003 Location: London, Ontario
Posts: 8,814
| I've never heard of TDS-3 before, I'll give that a shot. I tried McAfee Stinger, which can detect Netsky worms - clean. Panda ActiveScan doesn't work on this PC. |
| (Offline) | |
| | #23 | |
| Registered User Join Date: Aug 2004
Posts: 802
| Quote:
1. A very irate (and likely uninformed) recipient notifies you that you are sending him / her infected emails (though you aren't); 2. The recipient address is "bad", and the mail gets returned to your address, giving the appearance to even you that it originated from you or your machine (though it didn't); This is not so much worrisome as bothersome, since there is very little you can do about it (determining who is actually infected and notifying them is difficult, to say the least, as evidenced by the specific scenario you described; neither you nor the recipient is the source of the infection, you are both targets of another [unknown] infected machine). I have been passively following the ABXZone thread recently started discussing how some people claim to not need antivirus software. They seem to think if they get trashed, the impact is only to them, and they can withstand the hassle of reformatting. However illogical that may be even if it applied to only them, the truth is, when they get compromised, many other people suffer from their neglect. That is how virus writers get their viruses to propagate...through the lack of care of a vast number of computer users. As to why this is sneaking through Yahoo mail scanners, I can only say that some newsgroup articles indicate that Yahoo's antivirus system is somewhat hit and miss, maybe by as much as 50% hit / 50% miss in some cases. I don't know if this is due to poor quality scanners or a matter related to volume and delivery expedition. I tend to suspect more of the latter than former, but it could be due to something entirely different. | |
| (Offline) | |
| | #24 |
| Registered User Join Date: Dec 2004 Location: Toronto, Ontario, Canada
Posts: 2,912
| Froach, maybe its just for us up nortrh people (i'm in to to I got like 28 i thin kit was netsky or something viruses (found all by mcafee scanner and auto detected); deleted them and they kept coming back. That was pissing me off but i was okay with it untill my wireless was getting hijacked/ screwed and then my web was randomly getting hijacked by some wtdqsd something thing so i went googling and didn't find any positive results; ended up formating on the 10th and im clean now. This was very strange, i rarely ever check my hotmail or gmail emails to be honest; although i just scanned with norton 2005 this time (dumped mcafee for now) been about 2-3 weeks after format and it found a key logger which imo is something to be very scared about. I removed it but those keyloggers make me very worried; i mean formatting my comp is one thing but knowing all my passwords..... thats just scarey |
| (Offline) | |
| | #25 |
| Resident ABX Wizard ![]() Join Date: May 2003 Location: London, Ontario
Posts: 8,814
| Aboard - thanks for your explanation. I'm sure this is the case as scans of my computer using multiple software products from multiple software vendors turn up nothing. Plus I have better protection than 95% of the average computer users out there, and even slightly better than the average ABXZone member. You are probably bang on in the scenario - one infected contact is sending out e-mails to other contacts (one being me), more machines are getting infected, some of which have my e-mail address as a contact, etc. I was not aware that the virus can spoof e-mail addresses based on what it finds in address books though. In fact, I don't see that based on a brief review of http://securityresponse.symantec.com...tsky.c@mm.html You are right - I've done everything I can at my end. My computer remains secure and any other affected users will have to work on their own machines as there's nothing more I can do. I just hope some potential business contact doesn't think I'm sending him viruses when I actually am not. |
| (Offline) | |
| | #26 |
| Registered User Join Date: Dec 2004 Location: Toronto, Ontario, Canada
Posts: 2,912
| Fraoch, if it's going to affect your business at all; maybe its time for that format if your hearing me, although only idiot could tell you that. Although; you could get the virus again; i am confused that i did not get it again after i formatted, possibly because i am not going to any of these inappropriate sites offtopic *i remember a while ago reading your thread about buying a laptop which you have talked about your new centrino many times in new threads; what did you end up buying? |
| (Offline) | |
| | #27 | |
| Registered User Join Date: Aug 2004
Posts: 802
| Quote:
"12. The email has the following characteristics: From: (Spoofed) Note: This email address could be one of the addresses retrieved by the worm, as indicated in step 9." ------- If you are concerned about your contacts believing you are the source of possibly infected emails, you could send a notice to each explaining the situation (i.e., you are not the true source). This could serve the additional purpose of causing the recipient to check his own machine for compromise (without you having to be accusatory), but it could also lead to confusion amongst those that don't understand the sneaky modus operandi of such worms (i.e., your notice may cause more questions / discussion than it's worth). The call is yours, of course. | |
| (Offline) | |
| | #28 | |
| Resident ABX Wizard ![]() Join Date: May 2003 Location: London, Ontario
Posts: 8,814
| Quote:
Actually my parent company just gave me a spare laptop they already had. It's much better than the ones I was looking at - Pentium M 1.5 GHz "Banias" with Centrino. This was the supplier - it seems this company handles all the parent company's computer hardware requirements and they got a good deal on it. They have several of these configured identically so they can swap out components to repair them. ABoard - I apologize for missing that. It was a very long document and I scrolled through it too quickly. I should refrain from responding to these e-mails (done this twice now, but only with suppliers rather than customers) since it's potentially not them that's sending out the e-mails. | |
| (Offline) | |
| | #29 |
| Registered User Join Date: Dec 2003
Posts: 107
| What about a digital sig? Mike |
| (Offline) | |
| | #30 | |
| Resident ABX Wizard ![]() Join Date: May 2003 Location: London, Ontario
Posts: 8,814
| Quote:
| |
| (Offline) | |
![]() |
| Thread Tools | |
| Display Modes | |
| |