Computing.Net > Forums > Security and Virus > Spoofed from field. W32.Beagle.X@mm

Computer Problems? Computing.Net has over 1,000,000 posts about all things technology related! Over 90% answered within 24 hours! Click here to start participating now! Also, be sure to check out the New User Guide.

Spoofed from field. W32.Beagle.X@mm

Reply to Message Icon

Name: Punk
Date: June 26, 2004 at 09:22:38 Pacific
OS: WinXP Pro
CPU/Ram: Athlon 3200+ / 512 MB
Comment:

Hello-
This might get confusing....

I recently did some computer work for a friend, we'll call her Donna. It involved formatting and re-instaling the OS on two computers. One with Windows XP Home (SP1) and one with Windows ME. Both are currently up-to-date with patches etc. from Microsoft. Grisoft's AVG Antivirus installed on both.

Here's the problem: Donna's sister (Betty) keeps receiving email from Donna that is infected with the "W32.Beagle.X@mm" virus.
Both of Donna's computers have passed every free antivirus scan I know of. (On line and off, demo version or otherwise) I am confident that neither of Donna's computers are infected with that virus.

Betty forwarded 2 messages that Yahoo determined was infected with the virus. (Yahoo deleted the attachment). Upon looking at the headers and tracing the originating IP (using www.senderbase.org) it seems that the mail is coming from zeecon.com.

Nobody involved in any of this has any dealings with zeecon.com. Donna's ISP is Charter. I'm not sure what ISP Betty uses, but she uses Yahoo for her email. When Betty sends me email, the originating IP traces back to Charter.

What can be done? Does Betty just have to be thankful that Yahoo is catching the virus? Is it possible that the originating IP is spoofed? If not, does zeecon.com have ant responsibility to straighten this out?

Thanks for your advice-
Scott



Sponsored Link
Ads by Google

Response Number 1
Name: Thresher
Date: June 26, 2004 at 17:47:48 Pacific
Reply:

Did you run Stinger? :

Download Stinger here http://vil.nai.com/vil/stinger/

Stinger list for W32.Beagle, run it again on all your machines, run it from safe mode. If your AVG comes clean in safe mode, then it looks like you are being spoofed by a mailer. I would also download, update and run Spybot and Adaware from safe mode, and then do a good general clean up: expose hidden files and Dump TIF, %TEMP, cookies, recycle bin, did you disable the system restore on those systems? I would, just to be safe.

I don't know anything about Zeecom, and after reading your post I am disinclined to go there, and have some implant jump out at me, so I cannot help you there.

It is listed on Google as "the best calling card site in the US." Only one listing. Sounds fishy.

Go to tools > internet options > security tab > click on the red "restricted" icon, click "sites" in "Add this website to the zone" list www.zeecom.com. click ok > click ok > -- and that lists zeecom as a site to be blocked.


Thresher


0

Response Number 2
Name: Punk
Date: June 27, 2004 at 11:32:02 Pacific
Reply:

Thanks Thresher-

I'll try the Stinger app you linked to.
I've got an email into tech support at zecon.com. They are a ISP specializing in wireless access, I don't think that they are directly responsible for the mailings, but one of subsrcibers are infected.

Ad-aware and Spybot are the first things I run when troubleshooting a computer. Ya gotta love those two apps. :-)

Thanks again-
Scott


0

Sponsored Link
Ads by Google
Reply to Message Icon

Related Posts

See More







Post Locked

This post is quite old and has been locked from receiving new replies. Please create a new posting instead.


Go to Security and Virus Forum Home


Sponsored links

Ads by Google


Results for: Spoofed from field. W32.Beagle.X@mm

W32.Beagle.AG@mm keeps sending itse www.computing.net/answers/security/w32beagleagmm-keeps-sending-itse/16032.html

W32/Rontokbro.U@MM Cannot remove it www.computing.net/answers/security/w32rontokbroumm-cannot-remove-it/18065.html

email virus!! at wit's end .. help! www.computing.net/answers/security/email-virus-at-wits-end-help/11994.html