home hardware prices news articles forums photos user reviews
Go Back   Tech Support Forums - TechIMO.com > PC Hardware and Tech > Security and Privacy Issues
Ask a Tech Support Question (free)!

UPS email attachment virus

Reply
Get bargains at  »  Dealighted.com
 
Thread Tools Search this Thread
Currently Active Users: 2793
Discussions: 200,966, Posts: 2,379,646, Members: 246,332
Old July 24th, 2008, 04:14 PM     #21 (permalink)
Junior Member
 
Join Date: Jul 2008
Posts: 1
We opened the UPS file-- Bad results!

By mistake, one of my employees opened the email that is the subject of this thread. It was bad news! His computer is now not operable. We cannot open Outlook, or any web browser, or any programs. We have our techies working on it.

It is BAD NEWS! The email was quite clever-- I had received several of these emails (without opening it fortunately) but I had to look closely to recognize that it was not UPS.

DO NOT OPEN THE FAKE UPS EMAILS!
Just Helping is offline   Reply With Quote
Old July 24th, 2008, 09:00 PM     #22 (permalink)
Member
 
Tygur's Avatar
 
Join Date: Feb 2002
Posts: 199
I thought I'd describe my experience with this thing. It has a rootkit, which makes detection and removal difficult.

The files I quickly found were:
c:\windows\braviax.exe
c:\windows\buritos.exe
c:\windows\system32\buritos.exe
c:\windows\system32\crypts.dll
c:\windows\system32\ntos.exe
(i think that was all of them)

In addition, its rootkit kept adding cru629.dat to AppInit_DLLs, which I don't think I ever did find.

I used hijackthis (renamed to ht.exe because the rootkit blocked hijackthis.exe from running) to find them. I used my standard procedure of booting off a linux cd and deleting them when they don't have a chance to undo my actions. After discovering that I couldn't log back into the computer with ntos.exe gone (I hadn't cleaned it with hijackthis before removing it, since I thought that to be pointless), I replaced it with a copy of ping.exe, and then deleted that later after cleaning with hijackthis.

I also used Rootkit Hook Analyzer to discover that beep.sys was infected, so I (from linux again) overwrote it with a good copy from an uninfected computer. I also deleted the beep.sys copy I found in c:\windows\system32\dllcache.

In addition, one out of the four infected computers I saw had an additional driver file called Wel63.sys (in my case anyway) that was spamming itself out to other computers like mad. This was more difficult to find, because using normal tools, it just looks like svchost.exe (launched with no arguments) is doing it. I found it by looking at the drivers listed by Rootkit Hook Analyzer for anything suspicious.

After all that, I double-checked on each computer to make sure everything was really gone - a combination of monitoring network connections, checking the existence of the files, and making sure hijackthis is no longer blocked from running. By the way, it also blocked Mcafee and SuperAntiSpyware.

This is what I did, but my suggestion to anyone else is to find some easy directions someplace - maybe a recommended antivirus that actually works, or a tool that's easier to use.

EDIT: Oh yeah, and it also installed "XPSecurityCenter" on some of the computers too, which I removed. And it does also make some files in your temp directory, so you might want to clear that.

Last edited by Tygur : July 24th, 2008 at 09:04 PM.
Tygur is offline   Reply With Quote
Old July 24th, 2008, 10:34 PM     #23 (permalink)
983571056^983571056
 
SiliconJon's Avatar
 
Join Date: Feb 2003
Location: Bethalto, IL
Posts: 7,012
Blog Entries: 1
^ Fantastic notes, I hope I don't need them
__________________
Just because there is nothing wrong with saying what you are thinking does not mean there is nothing wrong with what you are thinking. - Jon Silveus
SiliconJon is offline   Reply With Quote
Old July 27th, 2008, 10:48 AM     #24 (permalink)
Junior Member
 
Join Date: Jul 2008
Posts: 4
Thumbs up

An easier solution, remove UPS virus in just minutes:
Malicious Software - Bicester Computers Support
Good luck!
laurentio is offline   Reply With Quote
Old July 27th, 2008, 05:18 PM     #25 (permalink)
Junior Member
 
Join Date: Jul 2008
Posts: 1
Update on UPS virus

Someone's changed the date to make it more current, so there'll probably be a new run of it going round.


[NO-REPLY] UPS Tracking Number 8694489495

Unfortunately we were not able to deliver postal package you sent on July the 25 in time
because the recipient’s address is not correct.
Please print out the invoice copy attached and collect the package at our office

Your UPS
UPS Global Home

It now has an attachment called UPS_192011.rar, which I'm not about to touch, so I don't know what's in it.
Nxala is offline   Reply With Quote
Old August 7th, 2008, 06:14 AM     #26 (permalink)
Junior Member
 
Join Date: Aug 2008
Posts: 1
invoice virus

[This email is for informational purposes only. Do not reply to the
email address above.

A payment to Carrington Mortgage Services LLC in the amount of $8489.85
has been made from your Checking account

For further information about this transaction, please download attached invoice file (Password for ZIP archive: "invoice" ) password is invoice

If you did not authorize this payment to be made, please contact your
financial institution or card issuer immediately for further
instructions.

FKNC Privacy Statement: The information contained in this electronic
mail transmission is intended by Fort Knox National Company for the
use of the named individual or entity to which it is originally
directed and may contain information that is privileged or otherwise
confidential. It is not intended for transmission to, or receipt by
anyone other than the named addressee (or a person authorized to
deliver it to the named addressee). It should not be copied or
forwarded to any unauthorized persons. If you have received this
electronic mail transmission in error, please delete it from your
system without copying or forwarding it, and notify the sender of the
error by reply email or by calling Fort Knox National Company at
866-359-6602. Unauthorized use, dissemination, distribution, or
reproduction of this message is strictly prohibited and may be
unlawful.

above email I received with attachment of IN87129_717a.zip (IN87129_717a.exe)
once you click on the exe and run Braviax.exe created on windows\system32 folder and others
whole winxp was useless.

from
invoice virus victim.
j168 is offline   Reply With Quote
Old August 11th, 2008, 09:59 PM     #27 (permalink)
Junior Member
 
Join Date: Aug 2008
Posts: 1
ups postal service email

Quote:
Originally Posted by SiliconJon View Post
Attention Virus Warning

There's an email going around claiming to be from UPS that is not. It claims a package delivery failure and asks the recipient to open the attached waybill, which is the actual viral payload.

Does anyone have any exact details of this email's current structure? I've found one person who said the subject was "UPS Tracking Number ....." - If anyone has any more details regarding this email I would appreciate it.

Hi, i received 2 emails of this kind which didn't go into my junk folder. its reads as follows:Unfortunately we were not able to deliver postal package you sent on July the 25 in time
because the recipient's address is not correct.
Please print out the invoice copy attached and collect the package at our office.

Your UPS

They both came with attachments in zip files. one called WW_671282 and the other WWW_99120.

I scanned with norton internet security (i have heard norton isnt as good as some but it came with the computer) both scans found three files but no spyware.
As for the details of the emails structure i can give them to you as i only got them before i posted this. Just let me know what details you need.
beitzy is offline   Reply With Quote
Old August 12th, 2008, 11:52 AM     #28 (permalink)
983571056^983571056
 
SiliconJon's Avatar
 
Join Date: Feb 2003
Location: Bethalto, IL
Posts: 7,012
Blog Entries: 1
The primary details I was asking for were those that many have provided, and I'm still glad to receive updated notes on what the emails consists of. Such details that I am looking for are primarily the message title, body, and attachment name. Granted these will morph, they are useful in aiding in detection and prevention of such email penetration into our system. Any other details are most welcome as they can be useful for other purposes.
SiliconJon is offline   Reply With Quote
Old August 13th, 2008, 09:42 AM     #29 (permalink)
Junior Member
 
Join Date: Aug 2008
Posts: 1
I just received a few emails from UPS with viruses. I even received one from US customs?? Its funny because my virus software didnt pick it up.
aelk5579 is offline   Reply With Quote
Old August 13th, 2008, 11:50 AM     #30 (permalink)
Junior Member
 
Join Date: Aug 2008
Posts: 1
UPS virus email

I just received this email myself and knew better to open it when I saw a ".zip file" attached as the invoice.

People need to be aware that unless they know the person sending an email, DO NOT OPEN a ".zip" file or an ".exe" file, as both were attached to my phony UPS email and I honestly know that UPS is a very good company and will never ask you to verify information via email because without the proper information with the package, they will not take it.



Quote:
Originally Posted by SiliconJon View Post
Attention Virus Warning

There's an email going around claiming to be from UPS that is not. It claims a package delivery failure and asks the recipient to open the attached waybill, which is the actual viral payload.

Does anyone have any exact details of this email's current structure? I've found one person who said the subject was "UPS Tracking Number ....." - If anyone has any more details regarding this email I would appreciate it.

diamondlady is offline   Reply With Quote
Reply
Thread Tools Search this Thread
Search this Thread:

Advanced Search

Similar Threads
Thread Thread Starter Forum Replies Last Post
Send email w/attachment - email goes thru, but no attachment?? plucky duck Technical Support 4 February 20th, 2009 01:31 PM
MS Access ACtion button Send Email WITH ATTACHMENT Marvinator Applications and Operating Systems 0 November 5th, 2007 01:26 PM
email attachment Part 1.2? Turnip12 Technical Support 6 February 9th, 2005 03:40 AM
email attachment virus marie_selle General Tech Discussion 5 November 12th, 2004 01:37 AM
Is there an Email reader for *.email attachment? H T I Tech General Tech Discussion 6 April 13th, 2004 05:10 PM


Currently Active Users Viewing This Thread: 1 (0 members and 1 guests)
 
Most Active Discussions
Is It Just Me? (3014)
Forty-six years ago today (9)
The disrespect of Obama by Russian .. (46)
Laptop with wireless problem. (12)
Wireless Televisions. (12)
CPU fan stops spinning randomly (11)
Regular Build (11)
Internet Lost (5)
windows 7 problem (7)
windows vista security holes (15)
Point and Shoot Camera Suggestions. (6)
Is the PSU I received dead? (13)
radeon x850xt platinum & shader.. (6)
HIS HD5770 graphic card question (15)
Recent Discussions
Open With ..... Win7 (3)
windows vista security holes (15)
Help getting around port 80 for camer.. (4)
Laptop with wireless problem. (12)
Internet Lost (5)
Skillsoft Network+ Study Software Que.. (9)
virus blocking exe. files (1)
Point and Shoot Camera Suggestions. (6)
CPU fan stops spinning randomly (11)
Nvidia GTX 260 problem (1)
Modern Warfare 2: Who Bought It? (65)
Is the PSU I received dead? (13)
Print spooler problem (16)
Kingston Bluetooth Dongle Driver (1)
Multiple Restarts Required at Boot (3)
webcam (0)
upgrade for hp a6101 (0)
tv not turn on-makes clicking sound (2)
EVGA 9800 gtx help with finding a goo.. (11)
Regular Build (11)
Help with onclick and buttons (0)
Virus advise (8)
My monitor won't turn on after instal.. (1)
Dept. of HS: NSA 'Helped' Develop Vis.. (16)
Ideal cheap graph card for PC-Gaming? (18)


All times are GMT -4. The time now is 03:19 PM.
TechIMO Copyright 2009 All Enthusiast, Inc.



1 2 3 4 5 6 7 8 9 10 11 12 13 14 15 16 17 18 19 20 21 22 23 24 25 26 27 28