Computing.Net > Forums > Security and Virus > Did I send a virus in mail?

Did I send a virus in mail?

Reply to Message Icon

Original Message
Name: snkupo
Date: November 8, 2006 at 07:24:18 Pacific
Subject: Did I send a virus in mail?
OS: XP Sp2
CPU/Ram: 3Ghz AMD atholong 1,5 ddr
Model/Manufacturer: --
Comment:

Hello.

I am very terrified now. Some moments ago, I got offered a job on email. I replied to the mail using Thunderbird mail program as usual..
However, some seconds later I got a mail from

"jane.garcia@motorsportwarehouse.com" (not the address I replied to) saying the following message:

Warning: This message has had one or more attachments removed
Warning: (attach4091..txt. exe).
Warning: Please read the "/opt/Fortress/engine/etc/reports/FIRMANETT-NO-Attachment-Warning.txt" attachment(s) for more information.

The received letter contained some errors. It is delivered as an attachment.

------
Mail server note.


__________ NOD32 1.1857 (20061107) Information __________

This message was checked by NOD32 antivirus system.
http://www.eset.com

This is a message from the MailScanner E-Mail Virus Protection Service
------------
The original e-mail attachment "attach4091..txt. exe"
was believed to be infected by a virus and has been replaced by this warning
message.

If you wish to receive a copy of the *infected* attachment, please
e-mail helpdesk and include the whole of this message
in your request. Alternatively, you can call them, with
the contents of this message to hand when you call.

At Wed Nov 8 15:45:30 2006 the virus scanner said:
Bitdefender: Found virus DeepScan:Generic.Stration.A24B3E49 in file attach4091..txt. exe
F-Secure: attach4091..txt. exe: Infected: Email-Worm.Win32.Warezov.fh [AVP]
MailScanner: No programs allowed (attach4091..txt. exe)

Note to Help Desk: Look on the MailScanner in /var/spool/MailScanner/quarantine/20061108 (message kA8EjGMs023141).
-- Postmaster Firmanett as www.firmanett.no

Does this mean that when I sent the mail to the man that offered me a job, I sent a VIRUS along with it??


Help!


Report Offensive Message For Removal


Response Number 1
Name: murr
Date: November 8, 2006 at 09:38:51 Pacific
Reply: (edit)

Your post is somewhat confusing but yes it sounds like a 'Worm'.

Download ATF-Cleaner to your desktop from this link
http://www.atribune.org/content/vie... You will need it later in safe mode.

Download and install A-squared here - http://www.emsisoft.com/en/software...
Download and install AVG Antispyware (Ewido) here - http://www.grisoft.cz/softw/70/file...

Update both programs and reboot into safemode by doing the following.

After hearing your computer beep once during startup, but before the Windows icon appears, tap the F8 key continually;

Instead of Windows loading as normal, a menu with options should appear;

Select the first option, to run Windows in Safe Mode, then press "Enter".

Choose your usual account.

Run A-squared and delete what it finds.

Run AVG Antispyware - make sure of the following settings.

Select the "Scanner" icon at the top of the screen, then select the "Settings" tab.
Once in the Settings screen click on "Recommended actions" and then select "Quarantine".
Under "Reports"

Select "Automatically generate report after every scan"
Un-Select "Only if threats were found"
Save this scan log.

Run ATF-Cleaner from safe mode.Double-click ATF-Cleaner.exe to run the program.
Under Main choose: Select All
Click the Empty Selected button.
If you use firefox also, select at top of ATF cleaner-tick Select all and run again.

Reboot into normal windows, run ATF cleaner again and post the safemode scan log from AVG Antispyware.


Report Offensive Follow Up For Removal







Use following form to reply to current message:

   Name: From My Computing.Net Settings
 E-Mail: From My Computing.Net Settings

Subject: Did I send a virus in mail?

Comments:

 


  Homepage URL (*): 
Homepage Title (*): 
         Image URL: 
 
Data Recovery Software




Have you ever used OpenOffice?

Yes, as my main suite.
Yes, occationally.
Yes, but only once.
No, never.


View Results

Poll Finishes In 5 Days.
Discuss in The Lounge