home hardware prices news articles forums photos user reviews
Go Back   Tech Support Forums - TechIMO.com > PC Hardware and Tech > Security and Privacy Issues
Ask a Tech Support Question (free)!

UPS email attachment virus

Reply
Get bargains at  »  Dealighted.com
 
Thread Tools Search this Thread
Currently Active Users: 2869
Discussions: 200,967, Posts: 2,379,659, Members: 246,333
Old July 23rd, 2008, 12:05 PM     #11 (permalink)
Junior Member
 
Join Date: Jul 2008
Posts: 1
Message title

There are different tracking numbers quoted in the message subject line. Mine says "UPS Tracking Number 9686554756". The invoice number in the attachment seems to be constant though.
Tim UK is offline   Reply With Quote
Old July 23rd, 2008, 12:29 PM     #12 (permalink)
Junior Member
 
Join Date: Jul 2008
Posts: 1
UPS Email

We got this too:

Subject line: [RE] UPS Tracking Number 7337122362

Body:
Unfortunately we were not able to deliver postal package you sent on July
the 1st in time
because the recipient’s address is not correct.
Please print out the invoice copy attached and collect the package at our
office

Your UPS

No virus found in this incoming message.
Checked by AVG.
Version: 7.5.526 / Virus Database: 270.5.5/1568 - Release Date: 7/23/2008
6:55 AM

Sender: rqwyhiygwxd@bmwpartstore.com

Attachment: UPS_INVOICE_187271.zip

Good ol' AVG Free! (Being snide)

Fortunately, we don't ship anything UPS, so this immediately caught our eye; not to mention the recipient does not exist--we receive everything to our domain.
jimcripps is offline   Reply With Quote
Old July 23rd, 2008, 05:46 PM     #13 (permalink)
Junior Member
 
Join Date: Jul 2008
Posts: 1
UPS Virus

Quote:
Originally Posted by SiliconJon View Post
Attention Virus Warning

There's an email going around claiming to be from UPS that is not. It claims a package delivery failure and asks the recipient to open the attached waybill, which is the actual viral payload.

Does anyone have any exact details of this email's current structure? I've found one person who said the subject was "UPS Tracking Number ....." - If anyone has any more details regarding this email I would appreciate it.

I just got this today. Luckily my antivirus removed it right away. It was a UPS tracking number, but the number was quite a bit shorter than an actual UPS tracking number. It had no UPS logos or anything. It just said that I had shipped a package on July 1st, and it had an incorrect address and to open the attachment to print the invoice to take to the UPS store to pick up my package.
ChristieG is offline   Reply With Quote
Old July 23rd, 2008, 06:12 PM     #14 (permalink)
Junior Member
 
Join Date: Jul 2008
Posts: 1
UPS bogus email

I just got it - do you want me to forward it to you? If so, please email me at gigi@charmingstation.com
ggmcbreen is offline   Reply With Quote
Old July 23rd, 2008, 06:38 PM     #15 (permalink)
983571056^983571056
 
SiliconJon's Avatar
 
Join Date: Feb 2003
Location: Bethalto, IL
Posts: 7,012
Blog Entries: 1
Quote:
Originally Posted by ggmcbreen View Post
I just got it - do you want me to forward it to you? If so, please email me at gigi@charmingstation.com

No, but thanks! I'm not looking to analyze the payload, only aid in preventing its detection and/or prevention. Somebody will probably want to check it out, though.
__________________
Just because there is nothing wrong with saying what you are thinking does not mean there is nothing wrong with what you are thinking. - Jon Silveus
SiliconJon is offline   Reply With Quote
Old July 23rd, 2008, 11:40 PM     #16 (permalink)
Junior Member
 
Join Date: Jul 2008
Posts: 1
More info about this virus

I had a client who opened this attachment today, within 10 minutes it had downloaded and installed multiple pieces of spyware, one of them being a fake windows security center warning.

The spyware infects startup items, AppInit_dlls (registry), userinit= (registry), and added a winlogon value (called 'crypt.dll' in my instance). I was able to remove the winlogon file with the utility 'moveonboot', google it or search for it on download.com, seems to work pretty good.

Hope this helps.

-Brad Grorud
bgrorud is offline   Reply With Quote
Old July 24th, 2008, 05:11 AM     #17 (permalink)
Junior Member
 
Join Date: Jul 2008
Posts: 2
UPS Email virus

Received this virus on a work computer unfortunately as a lady in admin opened the attachment.
the virus is a malware trojan braviax.exe which upon removal reappears as buritos.exe.
Can be removed from the registry files Cm2 consulting have good instructions CM2 Consulting however I am not confident when deleting registry entries, Norton wouldn't pick up the trojan just detected it as PERFCOO , I then found AVG wouldn't install onto the machine so used SDFix and combofix from the myantispyware.com website. Following these instructions left me with buritos.exe trojan. AVG would then install and quickly cleaned up all the crap that was downloaded and looking at the full list of processes running it seems to have removed all trace of the trojan.

Hope this helps someone

Nick Pearson, UK
biffo_pea is offline   Reply With Quote
Old July 24th, 2008, 07:07 AM     #18 (permalink)
Junior Member
 
Join Date: Jul 2008
Posts: 4
So far this is the only way to remove the UPS virus. Follow the given link and do as instructed to fix UPS virus.
Fixed! UPS Virus - braviax.exe and burito.exe - Bicester Computers Support
laurentio is offline   Reply With Quote
Old July 24th, 2008, 08:07 AM     #19 (permalink)
Junior Member
 
Join Date: Jul 2008
Posts: 1
I downloaded the zip file, opened it but as soon as I noticed it was an exe file I quickly deleted it (so I didn't extract it or anything like that, Winzip was only showing me what the file was). Is my computer infected? I haven't noticed anything unusual (thus far)

edit: Oh yeah, the email was from teeq@abi.qc.ca

"invoice_8712.zip (49KB)"
UPS Tracking Number 8142018720

Last edited by backslahsio : July 24th, 2008 at 08:09 AM.
backslahsio is offline   Reply With Quote
Old July 24th, 2008, 01:01 PM     #20 (permalink)
Junior Member
 
Join Date: Jul 2008
Posts: 1
UPS Viral Email

Gmail has informed me the attachment is unsafe - could be viral, malware or spyware, I'm not downloading to find out.

from United Parcel Service <oeeh@bodygraphics.com.au>
to ***********
date Jul 23, 2008 9:52 PM
subject UPS Tracking Number 4499228271

Unfortunately we were not able to deliver postal package you sent on July the 1st in time
because the recipient’s address is not correct.
Please print out the invoice copy attached and collect the package at our office

Your UPS



attachment
invoice_8712.zip
Jared Clarkson is offline   Reply With Quote
Reply
Thread Tools Search this Thread
Search this Thread:

Advanced Search

Similar Threads
Thread Thread Starter Forum Replies Last Post
Send email w/attachment - email goes thru, but no attachment?? plucky duck Technical Support 4 February 20th, 2009 01:31 PM
MS Access ACtion button Send Email WITH ATTACHMENT Marvinator Applications and Operating Systems 0 November 5th, 2007 01:26 PM
email attachment Part 1.2? Turnip12 Technical Support 6 February 9th, 2005 03:40 AM
email attachment virus marie_selle General Tech Discussion 5 November 12th, 2004 01:37 AM
Is there an Email reader for *.email attachment? H T I Tech General Tech Discussion 6 April 13th, 2004 05:10 PM


Currently Active Users Viewing This Thread: 1 (0 members and 1 guests)
 
Most Active Discussions
Is It Just Me? (3021)
Forty-six years ago today (11)
The disrespect of Obama by Russian .. (46)
Laptop with wireless problem. (12)
Wireless Televisions. (12)
CPU fan stops spinning randomly (11)
Regular Build (11)
Internet Lost (5)
windows 7 problem (7)
windows vista security holes (15)
Point and Shoot Camera Suggestions. (6)
Is the PSU I received dead? (13)
radeon x850xt platinum & shader.. (6)
HIS HD5770 graphic card question (15)
Recent Discussions
Delete an OS (8)
help me pls laptop just stopped worki.. (0)
Open With ..... Win7 (3)
windows vista security holes (15)
Help getting around port 80 for camer.. (4)
Laptop with wireless problem. (12)
Internet Lost (5)
Skillsoft Network+ Study Software Que.. (9)
virus blocking exe. files (1)
Point and Shoot Camera Suggestions. (6)
CPU fan stops spinning randomly (11)
Nvidia GTX 260 problem (1)
Modern Warfare 2: Who Bought It? (65)
Is the PSU I received dead? (13)
Print spooler problem (16)
Kingston Bluetooth Dongle Driver (1)
Multiple Restarts Required at Boot (3)
webcam (0)
upgrade for hp a6101 (0)
tv not turn on-makes clicking sound (2)
EVGA 9800 gtx help with finding a goo.. (11)
Regular Build (11)
Help with onclick and buttons (0)
Virus advise (8)
My monitor won't turn on after instal.. (1)


All times are GMT -4. The time now is 03:54 PM.
TechIMO Copyright 2009 All Enthusiast, Inc.



1 2 3 4 5 6 7 8 9 10 11 12 13 14 15 16 17 18 19 20 21 22 23 24 25 26 27 28