home hardware prices news articles forums photos user reviews
Go Back   Tech Support Forums - TechIMO.com > PC Hardware and Tech > Security and Privacy Issues
Ask a Tech Support Question (free)!

HOTMAIL: Virus SPAM

Reply
Get bargains at  »  Dealighted.com
 
Thread Tools Search this Thread
Currently Active Users: 1692
Discussions: 200,909, Posts: 2,378,935, Members: 246,276
Old August 20th, 2003, 08:30 AM   Digg it!   #1 (permalink)
Member
 
MatrixmaN's Avatar
 
Join Date: Jan 2003
Posts: 444
HOTMAIL: Virus SPAM

WTF Is this?

I have gotten a total of about 10 e-mails from one of my hotmail account saying that an E-mail was sent back to me or was failed to be delivered. Then I found this one today and guess what this is:

-----------
Recipient of the infected attachment: CHOW, KIN\Inbox
Subject of the message: Re: Approved
One or more attachments were deleted
Attachment document_9446.pif was Deleted for the following reasons:
Virus W32.Sobig.F@mm was found.
-----------

That was included with 5 similar to this in my mailbox this morning:

--------------
This message was created automatically by mail delivery software.

A message that you sent could not be delivered to one or more of its
recipients. This is a permanent error. The following address(es) failed:

tech@oe2000.com
This message has been rejected because it has
a potentially executable attachment "document_9446.pif"
This form of attachment has been used by
recent viruses or other malware.
If you meant to send this file then please
package it up as a zip file and resend it.

------ This is a copy of the message, including all the headers. ------

Return-path: <namxirtamitlu@hotmail.com>
Received: from [198.86.105.42] (helo=838-117659)
by host15.imagelinkusa.net with esmtp (Exim 4.20)
id 19pGnd-0001kA-66
for tech@oe2000.com; Tue, 19 Aug 2003 20:26:05 -0400
From: <namxirtamitlu@hotmail.com>
To: <tech@oe2000.com>
Subject: Re: Re: My details
Date: Tue, 19 Aug 2003 20:16:05 --0400
X-MailScanner: Found to be clean
Importance: Normal
X-Mailer: Microsoft Outlook Express 6.00.2600.0000
X-MSMail-Priority: Normal
X-Priority: 3 (Normal)
MIME-Version: 1.0
Content-Type: multipart/mixed;
boundary="_NextPart_000_02C75050"
Message-Id: <E19pGnd-0001kA-66@host15.imagelinkusa.net>

This is a multipart message in MIME format

--_NextPart_000_02C75050
Content-Type: text/plain;
charset="iso-8859-1"
Content-Transfer-Encoding: 7bit

Please see the attached file for details.
--_NextPart_000_02C75050
Content-Type: application/octet-stream;
name="document_9446.pif"
Content-Transfer-Encoding: base64
Content-Disposition: attachment;
filename="document_9446.pif"

TVqQAAMAAAAEAAAA//8AALgAAAAAAAAAQAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAA AAAAAAAA
AAAA4AAAAA4fug4AtAnNIbgBTM0hVGhpcyBwcm9ncmFtIGNhbm 5vdCBiZSBydW4gaW4gRE9TIG1v
ZGUuDQ0KJAAAAAAAAADToEjPl8EmnJfBJpyXwSacFN0onI3BJp x/3iyc7cEmnMHeNZyawSacl8Em
nJTBJpyXwSecBsEmnPXeNZyawSacf94tnI3BJpxSaWNol8EmnA AAAAAAAAAAAAAAAAAAAABQRQAA
TAEEAF2zPz8AAAAAAAAAAOAADwELAQYAAAAAAABwAAAAAAAA1u sBAAAQAAAAYAEAAABAAAAQAAAA
AgAABAAAAAAAAAAEAAAAAAAAAAAAAgAAEAAAF/EBAAIAAAAAABAAABAAAAAAEAAAEAAAAAAAABAA
AAAAAAAAAAAAAOLrAQCcAAAAAAAAAAAAAAAAAAAAAAAAAAAAAA AAAAAAfuwBAAgAAAAAAAAAAAAA
AAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAA AAAAAAAAAAAAAAAAAAAAAAAAAA
AAAAAAAAAAAAAAAAAAAgAC5zaHJpbmsAAFABAAAQAAAAxAAAAB AAAAAAAAAAAAAAAAAAAEAAAMAu
c2hyaW5rAAAwAAAAYAEAABIAAADUAAAAAAAAAAAAAAAAAABAAA DALnNocmluawAAQAAAAJABAAAS
AAAA5gAAAAAAAAAAAAAAAAAAQAAAwC5zaHJpbmsAADAAAADQAQ AAIgAAAPgAAAAAAAAAAAAAAAAA

(with a bunch of jibberish like that continuing for a very long time)
--------------------

And this one which is a new type (it was in spanish but I hit a translator online):

-------------------

The original message was received at Tue, 19 Aug 2003 18:39:45 -0400 from rs26s6.ric.cantv.net [10.128.131.133]



************************************************** ***************************



THIS INFORMACION CAN BE OF UTILITY TO UNDERSTAND THE ERROR OR PROBLEM



************************************************** *****************************



This it is a message of error generated in automatic form by the Cantv net e-mail platform. Further on you
will find information that can result of utility for the diagnosis and solution of the problem that originated
this message. This information can seem difficult to understand. If in effect is thus, please before
contacting to ours Central of Attention al Client, verifies the following thing:



* That the directions of the recipients of your message be the correct.



* Many systems of mail have limitations in the long maximum of the message. In the case of Cantv net, the
limit is of 10 Mbytes to avoid objections to the majority of the users, related to the download time of the
message.



* Some servants of mail do not have a connection dedicated 24 hours al day to Internet or can experience you
fail temporary, for which this message would be able to be only a notice that the mail has not been able to be
delivered immediate. The system of e-mail will treat during several days to cause to arrive the message to
its destiny.



Al final of this text the message of error is found that contains the necessary information to identify
because himself could not be completed the delivery of the message. The most common errors are the following:



1) addressee unknown: the direction of the recipient is incorrect or said user does not exist. 2) permission denied: the message could not be
delivered therefore could not be obtained permission of scripture on the mailbox; this message of error occurs when the size of the sent message is
upper al so great of the mailbox of the recipient. 3) temp failure; user is invited to retry: the message could not be delivered due to a temporary
condition; this message of error is reported when the mailbox of the recipient does not have available space to lodge the message.



If you cannot resolve the problem or do not understand it, we suggest to pass a copy of this message to your
administrator of systems or local department of backup. If this it was not possible, or if you are a user of
Cantv net, can contact to ours Central of Backup through the following media:



E-mail: soporte@cantv.net Telephone: 0500-SOPORTE



For a diagnostic adequate one of the problem, we require a copy of this message. In the event that the
message contain private or sensitive information, you can eliminate the text of the same one, but should not
alter the headlines (headers) that appear more down.

------------------------------------------------------------------------------- . The message of error begins but down. -----------------------------------------------------------------------------

----- The following addresses had permanent fatal errors -----
\cibernetica01
(reason: Deferred)
(expanded from: <cibernetica01@cantv.net>)

----- Transcript of session follows -----
\cibernetica01... Deferred: local mailer (/usr/local/bin/mlocalclient) exited with EX_TEMPFAIL
Message could not be delivered for 4 hours
Message will be deleted from queue
============================================
=============================================


OK NOW IS THAT JUST STRANGE TO YOU OR IS IT JUST ME?

I find it very odd because it keeps saying that I sent those viruses although I know I did not or something of the like. IT keeps saying it originated from me. I even went in and changed my pword after the first 6 of them yesterday. But it seems there is soemthing wrong with my e-mail address.

Any Comments or Suggestions?
MatrixmaN is offline   Reply With Quote
Old August 20th, 2003, 08:40 AM     #2 (permalink)
Fact Checker
 
Gomer's Avatar
 
Join Date: Feb 2000
Location: MSU- E. Lansing, MI
Posts: 6,253
The vurus spoofs the address from which it is sent. So if an infected computer has your address in it it could send emails to people using your email.

Go to www.pccillin.com and run "housecall" to see if you are infected. It doesn't matter about your pword as it just grabs your address books and sends from its own server.
Gomer is offline   Reply With Quote
Old August 20th, 2003, 08:41 AM     #3 (permalink)
Free Thinker
 
M_Six's Avatar
 
Join Date: Oct 2001
Location: Charleston, Illinois
Posts: 4,522
This doesn't necessarily mean your PC is infected, although it could be. This virus will masquerade as just about anything, including legitimate looking stuff from your ISP.

Do you have an anti-virus program you can use to scan your PC?

EDIT: Blast! Slow out of the gate again.
__________________
You can't fix stupidity.

Last edited by M_Six : August 20th, 2003 at 08:45 AM.
M_Six is offline   Reply With Quote
Old August 20th, 2003, 08:48 AM     #4 (permalink)
Ultimate Member
 
nomaxim's Avatar
 
Join Date: May 2002
Location: Stow, Ohio, Sol III
Posts: 1,199
Just found this on CNN

Some new worm/mass-mailer called Sobig.F that uses .scr and .pif files.

Last edited by nomaxim : August 20th, 2003 at 08:51 AM.
nomaxim is offline   Reply With Quote
Old August 20th, 2003, 08:58 AM     #5 (permalink)
Free Thinker
 
M_Six's Avatar
 
Join Date: Oct 2001
Location: Charleston, Illinois
Posts: 4,522
Thumbs up

BTW, nice link there, Gomer.
M_Six is offline   Reply With Quote
Old August 20th, 2003, 10:17 AM     #6 (permalink)
Member
 
MatrixmaN's Avatar
 
Join Date: Jan 2003
Posts: 444
Sheesh,

I havn't opened any attachments thru my e-mails in awhile though and none that were in any e-mail I didn't know. Besides that I don't have anybody in my Address Book so I know it didn't send it to people I know because I have another e-mail address for that.

1 Question though:

How the hell do I get it to leave my e-mail address alone. It started yesterday and I'm getting about 5 a day. Thats one of my main addresses even tho it has no contacts. How would I go about kicking this bastiche off my account?
MatrixmaN is offline   Reply With Quote
Old August 20th, 2003, 10:36 AM     #7 (permalink)
Ultimate Member
 
nomaxim's Avatar
 
Join Date: May 2002
Location: Stow, Ohio, Sol III
Posts: 1,199
I just got one of those messages from one of my Univ. e-mail accounts, I havn't sent anything through that account in over a year!

What could be happening is that someone that has your e-mail address in thier address book has got the virus and thier comp. is sending the messages and spoofing your address.

Look at the recieved field in the message you got. Note the IP address, that might be the comp. that is sending the message.
(no evidence that this worm spoofs the recieved from field yet, at least per the KSU Help Desk or McAfee.

Also note that this worm only affects Outlook and Outlook Express. That's why I use AOL and Netscape.

EDIT:
McAfee
Info on this one.

Last edited by nomaxim : August 20th, 2003 at 11:04 AM.
nomaxim is offline   Reply With Quote
Old September 26th, 2003, 01:22 AM     #8 (permalink)
Junior Member
 
Join Date: Sep 2003
Posts: 1
I, too, have been getting several such messages a day. Enough to put me over the 1MB limit they set. They are all 144k or 155k in size. I assume they are all virus laden so I havent trusted my anti-virus enough to open one to find out. What virus is doing this?
bobtail is offline   Reply With Quote
Reply
Thread Tools Search this Thread
Search this Thread:

Advanced Search


Currently Active Users Viewing This Thread: 1 (0 members and 1 guests)
 
Most Active Discussions
Is It Just Me? (2815)
California Passes Anti-Flat-HDTV Le.. (39)
Is the PSU I received dead? (10)
Install XP pro and a Vista laptop ?.. (8)
HIS HD5770 graphic card question (14)
A good PSU? (10)
Foreign voltage (6)
New Computer wont recognize XP disc (7)
Dept. of HS: NSA 'Helped' Develop V.. (12)
Print spooler problem (7)
Ideal cheap graph card for PC-Gamin.. (15)
EVGA 9800 gtx help with finding a g.. (7)
Modern Warfare 2: Who Bought It? (60)
Mysterious Boot manager (9)
Recent Discussions
Asus P4G8X Mobo (3)
Print spooler problem (7)
windows vista security holes (2)
World's largest Monopoly Game using G.. (329)
EVGA 9800 gtx help with finding a goo.. (7)
Need hard disk drivers (4)
windows 7 internet problem (4)
What OS for a home server? (other tha.. (1)
Boot Problem? (0)
Logitech G9 laser gaming mouse $59.95.. (2)
$5 off any item with the purchase of .. (1)
Foreign voltage (6)
Ideal cheap graph card for PC-Gaming? (15)
HIS HD5770 graphic card question (14)
Install XP pro and a Vista laptop ?? (8)
Cloning old drive to new drive (6)
Amptron monitor G17FP-Black (0)
A good PSU? (10)
Is the PSU I received dead? (10)
HP Pavillion Laptop ze4220 won't turn.. (7)
Dept. of HS: NSA 'Helped' Develop Vis.. (12)
Convert 5 pin Keyboard to USB (11)
hybernate option (2)
Steam ID's, Gamertags etc... (1)
New Computer wont recognize XP disc (7)


All times are GMT -4. The time now is 09:50 AM.
TechIMO Copyright 2009 All Enthusiast, Inc.



1 2 3 4 5 6 7 8 9 10 11 12 13 14 15 16 17 18 19 20 21 22 23 24 25 26 27 28