Virus Alert

tome

Well-Known Member
Joined
28 Mar 2002
Messages
8,201
Location
kprick
www.google.co.uk
Received this yesterday from our IT boys: I also received two variants of the subject virus so it's doing the rounds. I'm sure they won't mind me passing the info on.
======


Please be aware of a new virus threat that is propagating via e:mail. Below you will find information on this virus including the name, what you can expect to see in the From, Subject, and Body of the message and examples of attachment filenames that may be carried with the message. Also, included is the version of McAfee DAT that is required to protect against this virus. If you are not sure how to check your anti-virus to see if it is up-to-date please contact the Global ServiceDesk .

Most importantly if the subject heading or message content looks suspicious, Do Not Open the Attachment even if the senders address appears to be credible.

W32/Bagle.j@MM is a variant of the original Bagle virus.

What to look for:

From: Randomly generated (could however be an address you recognize)

Subject : Varies (examples include):

E-mail account security warning.
Notify about using the e-mail account.
Warning about your e-mail account.
Important notify about your e-mail account.
Email account utilization warning.
Notify about your e-mail account utilization.
E-mail account disabling warning.

Main message body - :

Your e-mail account has been temporary disabled because of unauthorized access.
Our main mailing server will be temporary unavailable for next two days, to continue receiving mail in these days you have to configure our free auto-forwarding service.
Your e-mail account will be disabled because of improper using in next three days, if you are still wishing to use it, please, resign your account information.
We warn you about some attacks on your e-mail account. Your computer may contain viruses, in order to keep your computer and e-mail account safe, please, follow the instructions.
Our antivirus software has detected a large ammount of viruses outgoing from your email account, you may use our free anti-virus tool to clean up your computer software.
Some of our clients complained about the spam (negative e-mail content) outgoing from your e-mail account. Probably, you have been infected by a proxy-relay trojan server. In order to keep your computer safe, follow the instructions.

Attachment: (May be .EXE .PIF or .ZIP) Attach:

Information
Readme
Document
Info
TextDocument
TextFile
MoreInfo
Message

Do NOT
Open any attachments

Do
Update VIrusScan

McAfee
Mcafee DAT's 4332 are available and will correctly clean and detect this virus


Schlumberger SIS
Infrastructure Services

<hr width=100% size=1>
 
Should have mentioned that both infected messages I received had a zip+ attachment with a password provided in the body text. The use of a password for a zip file means that conventional virus checking software cannot open the attachment to check the file, a cunning little twist.

<hr width=100% size=1>
 
If you have Norton virus checker with an up-to-date virus list which is turned on to check incoming mail, it will automatically delete the attachment.

I've been receiving half a dozen of these things every day for the last few days.

See the BBC website for an update on the 'virus writers war' which is going on at the moment. Shame they can't put their talents to something more useful.

<hr width=100% size=1>
 
i've been getting things mainly from france & switzerland with titles such as 'Re. Excel Spreadsheet' i.e. sounding vaguely of interest but nothing specific. they all have .exe attachments around 24k.

hotmail flags them with a warning.

<hr width=100% size=1>
 
Top