Major Spam Warning: Trojans About

The technical section

Moderator: Global Moderators

ArchiveCookie
Posts: 22
Joined: Wed Jul 04, 2007 5:16 pm
Location: Montreal, Quebec

Post by ArchiveCookie » Thu Jul 05, 2007 12:37 am

Just posted the details in the People forum... :D

fmackay
Posts: 364
Joined: Sat Dec 31, 2005 11:40 pm
Location: East Lothian

Post by fmackay » Thu Jul 05, 2007 5:26 am

Bob C wrote:There was a posting about this on a computer security site I follow this past Friday as the attack started to grow. Also, a new method of SPAM using pdf files is starting to grow. I have received five pdf messages just today but the spam filter at my ISP caught them and put them in the "Junk" folder.

Bob C
I have received 3 of these pdf emails in the space of 1 day, thankfully my spam filter caught them :evil:
Looking for
Mackay Morrison Manson - Sutherland
Bain Sinclair Gunn Henderson Levack Dunnet Lyall More Corner Miller-Caithness
Wylie Brown Louttit Banks Hourston Spence Drever Bews Irvine Whitelaw/Whitelay Linklater - Orkney

Tracey
Global Moderator
Posts: 2617
Joined: Fri May 13, 2005 10:27 am
Location: England

Post by Tracey » Thu Jul 05, 2007 9:21 pm

ArchiveCookie wrote:Thank you for the warm welcome, Lesley! It was actually an admin here who pointed me in this direction from another forum we're both on, as I was having difficulty finding info about Glasgow! Looks like I'll be playing catch-up for the first little bit...

[book]
Hi ArchiveCookie

Pleased you found us ! Im not quite admin but do help out a bit :wink:

Tracey
Scotland - Donaldson / Moggach / Shaw / Geddes / Sim / Gray / Mackie / Richards / Joel / Coull / Mckimmie / Panton / McGregor
Ireland and Scotland - Casey / McDade / Phillips / McCandle / Dinely / Comaskey + various spellings

LesleyB
Posts: 8184
Joined: Fri Mar 18, 2005 12:18 am
Location: Scotland

Post by LesleyB » Thu Jul 05, 2007 9:26 pm

Im not quite admin but do help out a bit
:wink:
Ha! I was wondering who it was..... :lol:

Tracey
Global Moderator
Posts: 2617
Joined: Fri May 13, 2005 10:27 am
Location: England

Post by Tracey » Thu Jul 05, 2007 9:30 pm

Not only do i not know my abreviations i am too honest for my own good - mostly !
Scotland - Donaldson / Moggach / Shaw / Geddes / Sim / Gray / Mackie / Richards / Joel / Coull / Mckimmie / Panton / McGregor
Ireland and Scotland - Casey / McDade / Phillips / McCandle / Dinely / Comaskey + various spellings

ArchiveCookie
Posts: 22
Joined: Wed Jul 04, 2007 5:16 pm
Location: Montreal, Quebec

Post by ArchiveCookie » Thu Jul 05, 2007 10:46 pm

Tracey wrote:
ArchiveCookie wrote:Thank you for the warm welcome, Lesley! It was actually an admin here who pointed me in this direction from another forum we're both on, as I was having difficulty finding info about Glasgow! Looks like I'll be playing catch-up for the first little bit...

[book]
Hi ArchiveCookie

Pleased you found us ! Im not quite admin but do help out a bit :wink:

Tracey
*Oooops* :oops:

Bob C
Posts: 76
Joined: Sun Mar 26, 2006 1:06 am
Location: North Carolina USA

Re: Major Spam Warning: Trojans About

Post by Bob C » Wed Jul 11, 2007 10:31 pm

DavidWW wrote: ... there was one email with the subject line of "A Card From Your Neighbour"
David
This has now been changed to:

"... emails with subjects such as:

* Spyware Detected!
* Malware Alert!
* Virus Detected!

The Storm virus from the last week or so (greeting cards) has morphed into this new version. Nothing new, the texts has changed somewhat and the subject line is different. By en large it is still the same attempt to get people to download an exe file. " http:// isc.sans.org/diary.html?date=2007-07-09

Be careful of opening emails from people you don't know and then clicking on embedded links!

Bob C
<dodgy URL disabled...just in case! :D LesleyB>
Searching for Baillie in
Kettle, Collessie, Auchtermuchty and Markinch Fife
South Leith Midlothian
Larbert and Stirling

DavidWW
Posts: 5057
Joined: Sat Dec 11, 2004 9:47 pm

Post by DavidWW » Sun Jul 15, 2007 8:35 pm

The saga continues, .................... maybe ...............

Y'day I noticed that Norton's automatic update hadn't happened since a week or so ago...... this is the procedure of updating the virus definitions held by the programme on my computer, so used by a scan, and updated automatically at very regular and frequent intervals.

The advantage of such an automatic procedure is that you don't have to remember to do it; but the disadvantage may be that you don't always check that it has taken place ..........

So I ran the procedure manually, but it failed.

The Norton error message led me to an automatic programme on the Norton site that would correct the problem with the LiveUpdate files on my 'puter, but this failed.

The manual method further recommended by Norton for deleting these LiveUpdate files also failed .........

:!: WARNING :!: this now gets technical. It looks like Norton somehow manages to prevent the deletion of these files unless the relevant programme setup option to disenable this protection is activated.

Even at the C:\ prompt level I was unable to delete these files, or change the file attributes (presumably "read only") preventing such deletion.

Now....... many sosphisticated trojans are known to interfere with major anti-virus packages such as Norton, McAfee, AVG etc........... so that I started to get worried that my experiences that led to this thread had somehow interfered with my 'puter.


Soooo.. .after a few deep breathes, I decided to use the utility that I obtained from Norton earlier this year when I need to reinstall the programme, this only being possible if it was first completely removed.

Ran this programme, and it stalled, - I can only assume because it ran into problems deleting the Norton LiveUpdate files at my end.

A consequence of this was that my 'puter started to run at a 1/100th of its normal speed ..........

Panic?, - not quite, as the use of the Windows XP Restore function put my 'puter back to where it was when a restore point from around 10 days ago was created, - this allows you to put everything back to the way it was back at the point that the Restore Point was created.

In this case Norton's sanity was restored, and everything has been hunky dory since, but it's taught me a real lesson in terms of opening any email with an attachment or link to a website, even when it looks like a mate has sent it ..........

David

DavidWW
Posts: 5057
Joined: Sat Dec 11, 2004 9:47 pm

Post by DavidWW » Sun Jul 15, 2007 9:27 pm

Collins English Dictionary, - "The Authority on Current English"

"disenable, - to cause to become incapable; prevent", especially, DWW comment, when something that has been positively enabled is reversed !

"disable, - to make ineffective, unfit, or incapable, as by crippling.", but without the implied meaning that a positive step has previously been taken to make something effective, fit, or capable in the first place :shock:

Similar, but subtly different, I'd argue :wink:

See also Fowler's Modern English Usage :!:

David

PS Ehhh!!! There was a post here to which the above was a tongue-in-cheek response, but said post appears to have gone walkies ..............

sporran
Posts: 496
Joined: Sat Dec 11, 2004 11:40 pm
Location: Leominster, Herefordshire, UK

Re: viruses

Post by sporran » Sun Jul 15, 2007 10:49 pm

Hello David,


I put my hand up. I posted about your dictionary being corrupted by the virus to create disenable out of disable, then edited it when I checked and found the word. After second thoughts, I deleted the post, not to avoid looking stupid (which I frequently am), but in case it was not thought to be tongue-in-cheek.

Although my New Gresham English Dictionary (new in 1930!) has disenable as meaning disable, I see the difference.


Regards,

John