Merry Christmas Virus

 
Thread Tools Search this Thread Display Modes
Old 12-16-2004, 10:57 AM   #1
Chief Toilet Mover
 
Mike Finley's Avatar
 
Trade: Bathroom Remodeling
Join Date: Apr 2004
Location: Littleton, Colorado
Posts: 14,078

Merry Christmas Virus


Today I got about 2000 bounced back email messages saying they couldn't be delivered. They were being sent to names of a company I have never heard of and the sending email address was one listed as a contact on one of my websites. The sending email address doesn't exist as an email account. This website I own just forwards that email address to a private email account I own.

I think this is the virus: W32.Erkez.D@mm is a mass-mailing worm that sends itself to email addresses gathered from the infected computer. The worm may also attempt to lower security settings, terminate processes, and open a back door on the compromised computer.

Would I be correct to assume that Verio's computer that is hosting my site is the one infected? Do you think there is any danger because I looked at a few of the bounced back emails to see what was going on? They all had attachments which I didn't open. Could you get infected by looking at the email on AOL or would have have to open the attachment to get infected?

Mike Finley is offline  
Warning: The topics covered on this site include activities in which there exists the potential for serious injury or death. ContractorTalk.com DOES NOT guarantee the accuracy or completeness of any information contained on this site. Always use proper safety precaution and reference reliable outside sources before attempting any construction or remodeling task!

Old 12-16-2004, 10:53 PM   #2
Member
 
Neil_K's Avatar
 
Trade: Handyman?
Join Date: Dec 2004
Location: Fort Mill, SC
Posts: 83

Re: Merry Christmas Virus


Unfortunately, its most likely that the problem is not from your web host. The virus (also known as Zafi.d from McAfee) "spoofs" the sender's address. That means that someone else's computer had the address from your website and several other email addresses when the person invoked the virus. These virii don't just use your addressbook like the old days, but scans your temporary internet files for email addresses to use. It can pick up an email address that was just listed on a page. The virus sends out boatloads of emails and makes them look like they came from you. Hence, the underliverable messages all come back to you. The undeliverable message would tell you why it was returned. It could be the user or domain doesn't exist or even that you sent them a virus and their mail system rejected it.


It is safe to open the undeliverable message, but I hope you did not try to open any attachment that had a .zip extension, as that may have been the virus. In this specific virus, a popup would have stated "ERROR IN PACKED FILE" when you try to open the attachment.

Please search your computer for the following to make sure you did not invoke the virus:

winamp 5.7 new!.exe
ICQ 2005a new!.exe


If you did, go to this website and read the manual instructions on how to remove the virus:

http://vil.nai.com/vil/content/v_130371.htm

NAI is Network Associates, who owns McAfee antivirus.

Good luck.

Neil
Neil_K is offline  
Old 12-17-2004, 10:31 AM   #3
Chief Toilet Mover
 
Mike Finley's Avatar
 
Trade: Bathroom Remodeling
Join Date: Apr 2004
Location: Littleton, Colorado
Posts: 14,078

Re: Merry Christmas Virus


So you are saying that because I have emails on my computer that were forwarded to me that have the address listed on my website that that is why my websites email address is listed as the sender?

The undeliverable and the virus found is the message contained in the bounced emails.

I didn't open any attachments and no trace of those 2 files is on my computer.

So you think my AOL account is sending these emails out directly and not Verios mail server that is hosting my website?
Mike Finley is offline  
Old 12-17-2004, 10:54 PM   #4
Member
 
Neil_K's Avatar
 
Trade: Handyman?
Join Date: Dec 2004
Location: Fort Mill, SC
Posts: 83

Re: Merry Christmas Virus


How about I give the likely scenario?

Joe Surfer visits your website. Then he gets a christmas card via email from Patricia. He opens it, but its really a virus.

The virus scans his computer for email addresses, then starts sending messages out to the addresses it finds. At least one unfortunate soul (in this case, its the email address on your website) looks like the sender. The recipient list is typically other email addresses found on other websites or from other emails Joe has sent or received.

I have to get geeky for a minute - The infected computer becomes its own SMTP relay (Simple Mail Transfer Protocol). The SMTP relay sends messages to the recipient domain, which typically accepts messages from any outbound relay.

The recipient domain returns the message to the sender (it looks at the email address) and sends you back a message saying the message is undeliverable. Most likely, either because the recipient doesn't exist or because the recipient mail system found a virus and rejected your message.

Did I make things worse?
Neil_K is offline  
Old 12-18-2004, 12:05 AM   #5
Pro
 
Teetorbilt's Avatar
 
Trade: Residential Contractor
Join Date: Feb 2004
Location: Jensen Beach, FL
Posts: 10,475

Re: Merry Christmas Virus


Neil, I was able to follow that and I see you as an invaluable member. Visit often.
Teetorbilt is offline  
Old 12-18-2004, 01:12 PM   #6
Chief Toilet Mover
 
Mike Finley's Avatar
 
Trade: Bathroom Remodeling
Join Date: Apr 2004
Location: Littleton, Colorado
Posts: 14,078

Re: Merry Christmas Virus


Not worse, It is becoming at least clearer than mud, probably like murky swamp water at this point.

But what I think you are saying is that just because I am getting the bounce backs doesn't mean they are being sent by my computer or my email account with AOL, nor the mail server associated with my website with Verio, is that right?

When will I stop getting them? I'm still getting like 1000 a day.
Mike Finley is offline  
Old 12-18-2004, 02:59 PM   #7
Member
 
Neil_K's Avatar
 
Trade: Handyman?
Join Date: Dec 2004
Location: Fort Mill, SC
Posts: 83

Re: Merry Christmas Virus


you are exactly right.

Unfortunately, you won't stop until the infected in-duh-vidual cleans their computer. You could set up a "rule" within your mail that automatically dumps the undeliverable mail straight to the trash can.
Neil_K is offline  
Old 12-18-2004, 03:00 PM   #8
Member
 
Neil_K's Avatar
 
Trade: Handyman?
Join Date: Dec 2004
Location: Fort Mill, SC
Posts: 83

Re: Merry Christmas Virus


That should be you won't stop *receiving the messages* until...
Neil_K is offline  
Old 12-18-2004, 11:10 PM   #9
Custom Builder
 
Glasshousebltr's Avatar
 
Trade: From dirt to ridge vent
Join Date: Feb 2004
Location: South Central Illinois
Posts: 4,403
Send a message via AIM to Glasshousebltr Send a message via Yahoo to Glasshousebltr

Re: Merry Christmas Virus


Quote:
Originally Posted by Teetorbilt
Neil, I was able to follow that and I see you as an invaluable member. Visit often.
Bravo Teetor, I agree, Neil come on by every time you get the chance.

Bob
Glasshousebltr is offline  
Old 12-20-2004, 09:29 AM   #10
Member
 
Neil_K's Avatar
 
Trade: Handyman?
Join Date: Dec 2004
Location: Fort Mill, SC
Posts: 83
Smile

Re: Merry Christmas Virus


I varied off the contstruction trade in college and took a route in computers. I'll gladly add my $.02 whenever possible. :Thumbs:
Neil_K is offline  
Old 01-02-2005, 09:34 PM   #11
Member
 
Neil_K's Avatar
 
Trade: Handyman?
Join Date: Dec 2004
Location: Fort Mill, SC
Posts: 83

Re: Merry Christmas Virus


Hey Mike - have the messages slowed down or subsided?
Neil_K is offline  
Old 01-03-2005, 10:11 AM   #12
Chief Toilet Mover
 
Mike Finley's Avatar
 
Trade: Bathroom Remodeling
Join Date: Apr 2004
Location: Littleton, Colorado
Posts: 14,078

Re: Merry Christmas Virus


Yeah Neil, it took about a week but they finally stopped. Thanks for the help.
Mike Finley is offline  
Old 01-03-2005, 09:56 PM   #13
Member
 
Neil_K's Avatar
 
Trade: Handyman?
Join Date: Dec 2004
Location: Fort Mill, SC
Posts: 83

Re: Merry Christmas Virus


anytime, Mike.
Neil_K is offline  


Thread Tools Search this Thread
Search this Thread:

Advanced Search
Display Modes Rate This Thread
Rate This Thread:

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is On
HTML code is Off
Trackbacks are Off
Pingbacks are Off
Refbacks are Off


Similar Threads
Thread Thread Starter Forum Replies Last Post
Merry Christmas! DecksEtc Off Topic (Non Trade) 24 12-24-2007 03:21 PM
Merry Christmas....new toys? Woodcrafter74 Off Topic (Non Trade) 23 12-29-2006 03:59 PM
Merry Christmas & Happy Holidays to ALL!!! LennyV-NHSNOLA Painting & Finish Work 3 12-25-2006 03:48 PM
Merry Christmas locofoco General Discussion 1 12-24-2005 10:22 PM
Merry Christmas Nathan Off Topic (Non Trade) 10 12-23-2004 08:08 PM

Join Now... It's Fast and FREE!

Privacy Badge
I am a professional contractor
I am a DIY Homeowner
ContractorTalk.com is for
PROFESSIONAL CONTRACTORS ONLY!

At ContractorTalk.com we cater exlusivly to professional contractors who make their living as a contractor. Knowing that many homeowners and DIYers are looking for a community to call home, we've created www.DIYChatroom.com DIY Chatroom is full of helpful advices and perfect for DIY homeowners.

Redirecing in 10 seconds
No Thanks
terms of service

Already Have an Account?