Ask The Trades
https://www.askthetrades.co.uk/cgi-bin/yabb/YaBB.pl
DIY Forum >> Alarms, Phones, Aerials, CCTV & Datacomms >> e-mail
https://www.askthetrades.co.uk/cgi-bin/yabb/YaBB.pl?num=1100541539

Message started by supersparky on Nov 15th, 2004, 5:34pm

Title: e-mail
Post by supersparky on Nov 15th, 2004, 5:34pm

Dear user supersparky@novoserve.no-ip.biz, administration of novoserve.no-ip.biz would like to inform you that:

Your account was used to send a large amount of unsolicited commercial email messages during this week.
Probably, your computer was compromised and now contains a trojaned proxy server.

We recommend that you follow instruction in order to keep your computer safe.

Sincerely yours,
The novoserve.no-ip.biz support team.


the attachment is in notepad and reads;

Norton AntiVirus removed the attachment: message.cmd.
The attachment was infected with the W32.Mydoom.M@mm virus.



now, what is this?

ss

Title: Re: e-mail
Post by plugwash on Nov 15th, 2004, 5:58pm

its a virus mail

its a common social enginnering trick to try to get you to open executable attachments (which as you can see norton identified as a virus and stripped out) by appearing to be a threat from your internet provider

theese are VERY common

you were lucky the fact that you use mail at your own (sub)domain made the mail into nonsense and you had a virus scanner to strip the harmfull attachment

Title: Re: e-mail
Post by Dewy on Nov 15th, 2004, 6:33pm

MyDoom is one of the latest virus's which came out about the same time as the bagel one.

Title: Re: e-mail
Post by Lectrician on Nov 15th, 2004, 8:14pm

I am being affected by a virus, connected with this site....I have had a couple of emails from people on this site, that nortan has deleted for me.

Any one else??

Title: Re: e-mail
Post by billythekid on Nov 15th, 2004, 8:24pm

SS thats the exact email i got first, from me(cept it had the-kid.org instead of novoserve.) The next two i got were the form of returned email. i.e you tried to send an email that didnt go through to x domain the message is returned see message.zip
all 3 contained mydoom and were promptly killed. Glad to know i am not the only sufferer. Had a thought that its a trawling bot sending to email addies on hosted domains the-kid, novoserve et al. (plus the-kid.org has a link to novo somewhere on it). I was like wtf, who is admin for the-kid, thought it was me. lol stupid feckin virus writers, they could use their skills for so much good coz they are decent programmers kwim.

Ask The Trades » Powered by YaBB 2.3!
YaBB © 2000-2008. All Rights Reserved.