home hardware prices news articles forums photos user reviews
Go Back   Tech Support Forums - TechIMO.com > PC Hardware and Tech > Security and Privacy Issues
Join TechIMO for Free!
Register Blogs FAQ Members List Calendar Search Today's Posts Mark Forums Read
Reply Get bargains at  »  Dealighted.com
 
Thread Tools
Currently Active Users: 2182
Discussions: 186,591, Posts: 2,226,888, Members: 230,214
Free Scan: Update Your PC's Outdated Drivers to Optimize Performance
Old July 15th, 2008, 02:16 PM   Digg it!   #1 (permalink)
Ultimate Member
 
SiliconJon's Avatar
 
Join Date: Feb 2003
Location: Bethalto, IL
Posts: 6,224
Blog Entries: 1
UPS email attachment virus

Attention Virus Warning

There's an email going around claiming to be from UPS that is not. It claims a package delivery failure and asks the recipient to open the attached waybill, which is the actual viral payload.

Does anyone have any exact details of this email's current structure? I've found one person who said the subject was "UPS Tracking Number ....." - If anyone has any more details regarding this email I would appreciate it.
__________________
"We are on the verge of global transformation. All we need is the right major crisis..." David Rockefeller
.

SiliconJon is offline   Reply With Quote
TechIMO.com Ads - Login or register for less ads.
How many errors does your computer have?

You no longer need to guess! This free stability scan and registry cleaner download will give you a complete diagnosis of your Windows registry, identifying errors and conflicts.

FREE instant scan


Guest, Register Free! to remove this ad and get your tech support questions answered in minutes!
Old July 16th, 2008, 12:05 PM     #2 (permalink)
Junior Member
 
Join Date: Jul 2008
Posts: 1
UPS Attachment Virus

Just an FYI this morning I had to call UPS about delivery of a package. The customer service agent was sure to let me know to be on the alert for any UPS emails received that contain attachements. Apparently, there is an UPS email circulating that appears to contain a shipping exception but asks you to open an attachment to see what the exception is. The attachment, when open, contains a virus.

camartino is offline   Reply With Quote
Old July 22nd, 2008, 02:06 AM     #3 (permalink)
Junior Member
 
Join Date: Jul 2008
Posts: 2
Exclamation
UPS EMAIL VIRUS

I got this email today, it said;

Unfortunately we were not able to deliver postal package you sent on July the 1st in time because the recipient’s address is not correct.
Please print out the invoice copy attached and collect the package at our office

Your UPS

It contained a file called UPS_INVOICE_978172.zip (which is an archive containing an exe file --> the virus).

The spoofed email addressed used was gujmodmbmwax@branchoffice.com.au

housten is offline   Reply With Quote
Old July 22nd, 2008, 02:08 AM     #4 (permalink)
Junior Member
 
Join Date: Jul 2008
Posts: 2
Exclamation
UPS EMAIL VIRUS

I got this email today, it said;

Unfortunately we were not able to deliver postal package you sent on July the 1st in time because the recipient’s address is not correct.
Please print out the invoice copy attached and collect the package at our office

Your UPS

It contained a file called UPS_INVOICE_978172.zip (which is an archive containing an exe file --> the virus).

The spoofed email addressed used was gujmodmbmwax@branchoffice.com.au
housten is offline   Reply With Quote
Old July 22nd, 2008, 11:37 AM     #5 (permalink)
Ultimate Member
 
SiliconJon's Avatar
 
Join Date: Feb 2003
Location: Bethalto, IL
Posts: 6,224
Blog Entries: 1
Thank you - I was looking for some of the text that is in the email to assist in filtering the message from entering our email system should one try.
SiliconJon is offline   Reply With Quote
Old July 22nd, 2008, 11:55 AM     #6 (permalink)
Junior Member
 
Join Date: Jul 2008
Posts: 1
UPS_INVOICE_978172.zip

I too have received this e-mail but was not bright enough to recognise it for what it was. As I just happen to be overdue a package from UPS I jumped straight in and opened the attachment. I phoned UPS who have an automated message warning about the e-mail and attaching virus but they gave no more detail. All I can tell you is that the e-mail I received used the following:-

Subject: UPS Tracking Number 0595577501
Attachments: UPS_INVOICE_978171.zip
Sent from United Parcel Services (dsrtyyksygw@bobdillonwindsorchairs.com)

The following website appears to have a copy of the attachment but I dare not open it again so I do not know what it actual does:-
This Was In My Email - BitDefender Forum

I have run and rerun my Norton 360 antivirus which detects and quarantines some Tracking Cookies but I am none the wiser as to the effects and whether my laptop is infected. To date I have not noticed any ill-effects. If you have any further information an update would be much appreciated.

Does anyone know what the virus actually does?
ianb281 is offline   Reply With Quote
Old July 22nd, 2008, 12:04 PM     #7 (permalink)
Ultimate Member
 
SiliconJon's Avatar
 
Join Date: Feb 2003
Location: Bethalto, IL
Posts: 6,224
Blog Entries: 1
This Post states the cleanup to be easy, though I have not experienced an infection nor come across any AV vendor or security sites (whose analysis is needed) that confirm removal to be as simple.
Quote:
**Note**Right click my computer and go to properties,click system restore tab and turn it off,otherwise you're saving your virus!

1:delete the email from the sent items,inbox,outbox and deleted items in Outlook.

2:delete every file (not folders) from your "c:/documents and settings/yourusername/localsettings/temp... folder (I suggest using spybots file shredder with a 5 pass overwrite)

3:reboot and rerun a few cleanup scans with your antispy/malware and then with your antivirus and you should be good to go.

Simple as that!
You will want to delete any restore points created since the arrival of the infected email.
SiliconJon is offline   Reply With Quote
Old July 22nd, 2008, 07:17 PM     #8 (permalink)
Junior Member
 
Join Date: Jul 2008
Posts: 1
Cool
UPS email file attachment

Quote:
Originally Posted by SiliconJon View Post
Attention Virus Warning

There's an email going around claiming to be from UPS that is not. It claims a package delivery failure and asks the recipient to open the attached waybill, which is the actual viral payload.

Does anyone have any exact details of this email's current structure? I've found one person who said the subject was "UPS Tracking Number ....." - If anyone has any more details regarding this email I would appreciate it.
This is what I just received, I thought it was a bit suss and glad I did a bit of research before opening the attachment.

Return-Path: <jjvv@blem.com>
Received: from nskntingx05p.mx.bigpond.com ([216.212.61.154])
by nskntmtas05p.mx.bigpond.com with ESMTP
id <20080722130507.UARA16527.nskntmtas05p.mx.bigpond. com@nskntingx05p.mx.bigpond.com>;
Tue, 22 Jul 2008 13:05:07 +0000
Received: from host61-154.birch.net ([216.212.61.154])
by nskntingx05p.mx.bigpond.com with ESMTP
id <20080722130504.TXCI2223.nskntingx05p.mx.bigpond.c om@host61-154.birch.net>;
Tue, 22 Jul 2008 13:05:04 +0000
Received: from [216.212.61.154] by vmx0.viatel.net; Tue, 22 Jul 2008 07:05:04 -0600
Message-ID: <01c8ebc9$43e39000$9a3dd4d8@jjvv>
From: "United Parcel Service" <jjvv@blem.com>
To: <shantidwyer@bigpond.com>
Subject: UPS Tracking Number 3897844287
Date: Tue, 22 Jul 2008 07:05:04 -0600
MIME-Version: 1.0
Content-Type: multipart/mixed;
boundary="----=_NextPart_000_0006_01C8EBC9.43E39000"
X-Priority: 3
X-MSMail-Priority: Normal
X-Mailer: Microsoft Outlook Express 4.72.2106.4
X-MimeOLE: Produced By Microsoft MimeOLE V4.72.2106.4
X-RPD-ScanID: Class bulk; VirusThreatLevel high, RefID str=0001.0A150202.488542CC.0004,ss=3,sh,vtr=0001.0 A150204.488518F4.0081,vl=2,vh,fgs=0
X-Antivirus: AVG for E-mail 8.0.138 [270.5.3/1565]


This is a multi-part message in MIME format.

------=_NextPart_000_0006_01C8EBC9.43E39000
Content-Type: text/plain;
charset="iso-8859-1"
Content-Transfer-Encoding: 7bit

Unfortunately we were not able to deliver postal package you sent on July the 1st in time
because the recipient’s address is not correct.
Please print out the invoice copy attached and collect the package at our office

Your UPS


No virus found in this incoming message.
Checked by AVG - AVG Anti-Virus and Internet Security - Real-time protection against viruses, spyware and malicious websites
Version: 8.0.138 / Virus Database: 270.5.3/1565 - Release Date: 7/21/2008 6:36 PM


------=_NextPart_000_0006_01C8EBC9.43E39000
Content-Type: application/zip;
name="UPS_INVOICE_978172.zip"
Content-Transfer-Encoding: base64
Content-Disposition: attachment;
filename="UPS_INVOICE_978172.zip"
shauna31 is offline   Reply With Quote
Old July 23rd, 2008, 08:36 AM     #9 (permalink)
Junior Member
 
Join Date: Jul 2008
Posts: 1
UPS virus email

Quote:
Originally Posted by SiliconJon View Post
Attention Virus Warning

There's an email going around claiming to be from UPS that is not. It claims a package delivery failure and asks the recipient to open the attached waybill, which is the actual viral payload.

Does anyone have any exact details of this email's current structure? I've found one person who said the subject was "UPS Tracking Number ....." - If anyone has any more details regarding this email I would appreciate it.

Here's a copy and paste from the email:
-----Original Message-----
From: United Parcel Service [mailto:ter@tequa.com]
Sent: Monday, July 21, 2008 5:58 PM
To:
Subject: UPS Tracking Number 3414109644

Viruses found in the attached files.
The file UPS_INVOICE_978172.zip: Trojan horse SHeur.BXZJ. The attachment was moved to the virus vault.

The original message follows:
Unfortunately we were not able to deliver postal package you sent on July the 1st in time because the recipient's address is not correct.
Please print out the invoice copy attached and collect the package at our office

Your UPS
Broomhilda99 is offline   Reply With Quote
Old July 23rd, 2008, 10:33 AM     #10 (permalink)
Junior Member
 
Join Date: Jul 2008
Posts: 1
UPS virus

I have today received this e-mail from 'UPS':

Unfortunately we were not able to deliver postal package you sent on July the 1st in time
because the recipient’s address is not correct.
Please print out the invoice copy attached and collect the package at our office

Your UPS

The attachment is a zip file which made me immediately suspicious adding to the strange e-mail sender's address (tennisqueen5dd@pokigo.net)

Hope this helps!


Quote:
Originally Posted by SiliconJon View Post
Attention Virus Warning

There's an email going around claiming to be from UPS that is not. It claims a package delivery failure and asks the recipient to open the attached waybill, which is the actual viral payload.

Does anyone have any exact details of this email's current structure? I've found one person who said the subject was "UPS Tracking Number ....." - If anyone has any more details regarding this email I would appreciate it.
owlcastle is offline   Reply With Quote
Reply


Currently Active Users Viewing This Thread: 2 (0 members and 2 guests)
 
Thread Tools

Posting Rules
You may post new threads
You may post replies
You may not post attachments
You may not edit your posts

vB code is On
Smilies are On
[IMG] code is On
HTML code is Off
Trackbacks are Off
Pingbacks are On
Refbacks are Off

Similar Threads
Thread Thread Starter Forum Replies Last Post
MS Access ACtion button Send Email WITH ATTACHMENT Marvinator Applications and Operating Systems 0 November 5th, 2007 01:26 PM
email attachment Part 1.2? Turnip12 Technical Support 6 February 9th, 2005 03:40 AM
email attachment virus marie_selle General Tech Discussion 5 November 12th, 2004 01:37 AM
Is there an Email reader for *.email attachment? H T I Tech General Tech Discussion 6 April 13th, 2004 05:10 PM
Send email w/attachment - email goes thru, but no attachment?? plucky duck Technical Support 3 February 22nd, 2002 10:32 PM

Most Active Discussions
Is It Just Me? (492)
heatsink issue (8)
Why Does the MOON Grow Bigger as It.. (11)
Word Association!! (1650)
SSD's, RAID, and External Backup (6)
New Mobo (16)
1 internet. 1 house. 3 computer. ho.. (11)
UPGRADING C/D DRIVE TO 250GB & .. (10)
Is This A Compatible Gaming PC? (16)
Recent Discussions
Letter Count Array (3)
Hard Core Overclock (9)
C++ compiler suggestions (1)
SSD's, RAID, and External Backu.. (6)
Folderchat: The Holiday thread (113)
1 internet. 1 house. 3 computer.. (11)
heatsink issue (8)
FS: New Benny Hill Megaset DVD .. (6)
Computer won't start (2)
New Mobo (16)
FS: Dell 6000 laptop, modded 36.. (2)
Apple iPod touch 16 GB $200 (4)


All times are GMT -4. The time now is 12:42 AM.
TechIMO Copyright 2008 All Enthusiast, Inc.



1 2 3 4 5 6 7 8 9 10 11 12 13 14 15 16 17 18 19 20 21 22 23 24 25 26 27 28