PDA

View Full Version : Computer/Network Guru Help



RiverKitty
10-20-2004, 10:49 AM
Ok all you brilliant, talented, geeks out there....maybe you can help me figure this one out.
I just got an e-mail that had a virus in it (w32netsky) but the attachement was deleted by Norton's before it made it to my e-mail.
This is what it said (too bizzare and totally bogus):
-------------------------------------------------------
Dear user of "Riverkitty.com" mailing system,
Your e-mail account will be disabled because of improper using in next
three days, if you are still wishing to use it, please, resign your
account information.
Advanced details can be found in attached file.
For security reasons attached file is password protected. The password
is "15326".
Best wishes,
The Riverkitty.com team
----------------------------------------------------
The message said it had a text file attached but in reality it was a zip file (with a virus in it).
This was the message header:
------------------------------------------------------
Return-path: <r.kid@juno.com>
Envelope-to: riverkitty@riverkitty.com
Delivery-date: Wed, 20 Oct 2004 11:21:26 -0700
Received: from [64.186.232.70] (helo=Tabscomputer)
with smtp (Exim 4.43)
id 1CKL5S-0003hd-A0
for riverkitty@riverkitty.com; Wed, 20 Oct 2004 11:21:26 -0700
Date: Wed, 20 Oct 2004 11:21:22 -0800
To: riverkitty@riverkitty.com
Subject: Notify about your e-mail account utilization.
From: management@riverkitty.com
Message-ID: <wjmywcumkusfhdpbpmn@riverkitty.com>
MIME-Version: 1.0
Content-Type: multipart/mixed;
boundary="--------kfjfdehghwmrqhcytpgc"
--------------------------------------------------
Any Ideas? :confused:

uvindex
10-20-2004, 10:53 AM
Hey RK,
It looks to me that it was a "phishing" attempt (you can tell from the bad grammar and the fact that they're trying to lure you into "resigning up", which is how they would have gotten your email account, password, etc.)
If your system is showing up clean when you scan it for viruses now, I wouldn't worry about it.
Have a good day!

HM
10-20-2004, 10:53 AM
The virus is gone, so just delete the e-mail. The message means nothing.
Contact ntwotrance and forward him the e-mail. He will have it traced and if it is a phony (yes it is) he will report this activity to the isp and take care of it.

Some Kind Of Monster
10-20-2004, 11:00 AM
Any Ideas? :confused:
:delete: :D

BajaMike
10-20-2004, 12:23 PM
It does sound like a "phishing" attempt. Do not respond to the e-mail, go to the link, or open the attachment. Delete it.
w32netsky is a very nasty virus, but it looks like your anti virus software caught it.
You can double check, with a free, up to date scan over the Internet at:
Trend Anti-Virus Free Scan-"Housecall" (http://housecall.trendmicro.com/housecall/start_corp.asp)
Good luck. :D