Click here for AnswerPool.com Home page


Google

    AnswerPool.com  Hop To Forum Categories  Computers  Hop To Forums  Security Issues    WORM, TROJAN, VIRUS ?????

Moderators: Dwight
Go
Post
Find
Notify
Tools
Reply
  
  Login/Join 
Gold
Enthusiast
Posted
My e-mails (OE) have been innundated lately with emails that are a file attachment. The "from" is sometimes a corrupted form of the name of people we know and are in our e-mail address book. I am wondering if all these person's computers are infected with a worm (?) or is it in our computer that is infected and sending us these e-mails from our own address book. Any suggestions?

DD
 
Posts: 1033 | Location: The River | Registered: 07-04-02Reply With QuoteEdit or Delete MessageReport This Post
Diamond Enthusiast

Picture of bedstor
Posted Hide Post
Hi DD
If it is from your email box check first your "sent mail" box there may be a clue there?

I had somebody swipe my address the other week and I "posted" many emails off this address in an hour (about 100,nearly got a warning off the ISP Frown)
Only noticed this while checking my old sent mail.
Remedy: Change password (rotate them?) every other week and don't use an autologin Smile

Moving on... I Posted a free virus checker can you download and run this and see if anything abnormal is posted? Roll Eyes Copy and paste the list here.

http://housecall.trendmicro.com/housecall/start_corp.asp(puts a button on your IE toolbar)

Some one may know the removal method if there is a bad version present.

The 3rd possibility is Malware of the Keylogger variety Mad I think the Adaware program will spot this and delete it. Will post the download address if you want to check this out? Smile

Looking further ahead,The best protection is restricting access to OE via Spyware by Downloading Spywareblaster or SpyBot Smile
and enabling a Firewall (Some free ones to try) Smile
But first find the cause of this prob. and rectify it Wink
It is called spoofing when you see your own address being sent around in a corrupt form. Not a virus, possibly been keylogged? ( via spyware) run Adaware program scan ASAP and delete findings also Delete Cookies and Temp Files. Install SpyBot or Spywareblaster enable
all links to prevent any more of these pests from getting a Hold. Wink
Means manual log ons & and Slow webpage load Frown But normal speed next time Smile
 
Posts: 13353 | Location: 6 miles west of Wigan UK | Registered: 06-05-02Reply With QuoteEdit or Delete MessageReport This Post
Gold
Enthusiast
Posted Hide Post
I ran HOUSECALL and it found BAGLE.AH in Progamfiles\commonfiles (38 infected) and Webshare (19 infected). I suspect that my husband opened one of those suspicious e-mails last night because the files were all created on the 26th at 8:01 pm, just the time when he would have been checking e-mails.

Now I need to know how to desinfect those files. I went into safe mode and eliminated the ones I could find but I am afraid that the problem may be deeper than that. Is there a free program that I can use. I used Sophos to get rid of Netsky.P but I don't think they have anything for Bagle.

I have been deleting the temp files every few days and manually cleaning out the cookies at the same time (ever since the problem with Netsky.P). There isn't anything unusual going on in the "sent item." I have also put "do not download" for all attachments. What a nuisance!

DD
 
Posts: 1033 | Location: The River | Registered: 07-04-02Reply With QuoteEdit or Delete MessageReport This Post
Diamond Enthusiast

Picture of bedstor
Posted Hide Post
DD
There is a removal link for Bagal.AH
on this link .Have to do some digging as well Frown and read through the Stats
According to this page, this variation is quite new (July)

www.pandasoftware.com/virus_info/encyclopedia/overview.aspx?IdVirus=49863&sind=0
Will post shortly on the other Pest
 
Posts: 13353 | Location: 6 miles west of Wigan UK | Registered: 06-05-02Reply With QuoteEdit or Delete MessageReport This Post
Diamond Enthusiast

Picture of bedstor
Posted Hide Post
The Webshare files are to do with the Webshare toolbar which could have been half deleted?
www.handyarchive.com/Internet/Search-Tools/519-A-WebShare-Meta-Finder.html
Download and install it then go into Add remove programs(Control Panel) and see if there is an uninstall link there OR..on the Start Menu?...OR...in the folder that the program unzipped to? Smile It'll be in one of these locations
 
Posts: 13353 | Location: 6 miles west of Wigan UK | Registered: 06-05-02Reply With QuoteEdit or Delete MessageReport This Post
 Previous Topic | Next Topic powered by eve community  
 

    AnswerPool.com  Hop To Forum Categories  Computers  Hop To Forums  Security Issues    WORM, TROJAN, VIRUS ?????

© 2002-2008 AnswerPool.com



Visit DiscussionPool.com!