[email protected] mail, DONT OPEN

I just got them, I got 2 mails: one about an app, and one about 'requested' info.

It says: all you requested info is in the atatchment. These mails are viruses, so don't open them.
I got them in my outlook, (I have an account by hccnet ) not active on hotmail as far as I know....

just letting you know
7,433 views 24 replies
Reply #1 Top
yeah I got one a few days ago... I recommend that everyone should have a program that can bounce back messages. I use Mail Washer and bouced it back without opening it.
Reply #3 Top
http://www.microsoft-watch.com/ is as close as I can get to the story on this . Item is at bottom of page



Powered by SkinBrowser!
[Message Edited]
Reply #4 Top

Got about 500 of those at stardock support.

All viruses.  The IP address that it comes from changes and it's not from Microsoft (the virus is spoofing the sender info).

Reply #5 Top
Hahaha, what happends if you send them back? das microsoft gets them?
Reply #6 Top
lets try this again.. nope..will have to work on my link finger.....Grrrrr



Powered by SkinBrowser!
[Message Edited]
Reply #7 Top
Good looking out, Styl
Reply #8 Top
well the bounce back should return it to the mail server that sent it to your isp's server and in turn that server should return it to the location it recieved it from. However if the viri writer was able to spoof the header and prevent the mail servers from adding their info somehow... who knows where it would end up on a bounce back...
Reply #9 Top
The subject lines include:

Your Password
Screensaver
Re: Movie
Your details
Approved (Ref: 38446-263)
Re: Approved (Ref: 3394-65467)
Cool screensaver
Re: My details
Re: My application
Re: Movie

The message body reads, "All information is in attached file."
Reply #10 Top
http://security.ziffdavis.com/?kc=SCZD10303TTX1B0000566



Powered by SkinBrowser!
Reply #11 Top
Hehe i was on tech support with Microsoft a while back when i got those emails. They demanded me to forward them and was more worried about that then my exchange 2000 issue hehehe. Bastages!

Not sure this is from the same source but i tend to get this with in mins of the microsoft support virus emails.

From [email protected] Sun Jun 13 04:44:52 1999
X-Apparently-To: via 66.218.78.207; 19 May 2003 04:36:31 -0700 (PDT)
X-YahooFilteredBulk: 217.164.79.23
Return-Path:
Received: from 217.164.79.23 (EHLO ANUP) (217.164.79.23) by mta123.mail.sc5.yahoo.com with SMTP; 19 May 2003 04:36:23 -0700 (PDT)
From: [email protected]
To:
Subject: Re: Sample
Date: Sun, 13 Jun 1999 15:44:52 +0400
Importance: Normal
X-Mailer: Microsoft Outlook Express 6.00.2600.0000
X-MSMail-Priority: Normal
X-Priority: 3 (Normal)
MIME-Version: 1.0
Content-Type: multipart/mixed; boundary="CSmtpMsgPart123X456_000_0042AF12"
Content-Length: 64394

So don't open these either
Reply #12 Top
I just got it tonight.
I knew something was fishy when it said 're:movie'
I immediately though yeah, Microsoft is emailing me regarding a movie. Alrighty then.
Norton's scanned it and noticed the virus. Are you ready for it's title? Nortons report can be unclean file, blah blah but showed the title inside of it being "SoBIG@BOOM!"

Reply #13 Top
Hi all,

I just got it too, my application.
My e-mail had a message telling me they (optonline) caught it and deleted it. So i did a scan with norton and it said no viruses. Anything else i should do to make sure my PC is CLEAN???
Thanks
Reply #14 Top
I used Mailwasher to delete the e-mail while it was still on the server. Between that, my ISP's scanning service and Nortons, I'm 'reasonably' safe. There's no such thing as 100% safe, but you can get close. Edited typo...
[Message Edited]
Reply #16 Top
Styl....not any more...but you have one too many 'p's in tripple....Spell checker
Reply #17 Top
'Tripple', yea I thought it looked funny. I have yet to get the infamous email...Anyone have any idea on what the virus'es payload is?
Reply #18 Top
Like Vtach, Im on Optonline and they caught the virus. The message I received was:

An e-mail delivered to you contained a virus. The virus was
identified by the Optimum Online E-mail Virus Protection system
using Symantec's Norton Anti Virus Technology. Please contact
and advise the sender of the virus-specific information provided below.

your_details.pif was infected with the malicious virus W32.HLLW.Mankx@mm
and has been deleted because the file cannot be cleaned.

I followed the header info to RIPE who only issued the Domain and their "whois" gave an addy in the Czech Republic

inetnum: 213.180.32.0 - 213.180.47.255
netname: CLNET
descr: CL-NET s.r.o.
descr: Ceska Lipa
country: CZ
admin-c: OP23-RIPE
tech-c: CLOP1-RIPE
status: ASSIGNED PA
notify: [email protected]
mnt-by: CLNET-MNT
changed: [email protected] 20010824
changed: [email protected] 20020226
source: RIPE

route: 213.180.32.0/19
descr: CLNET
descr: CZ
origin: AS16246
mnt-by: CLNET-MNT
changed: [email protected] 20010720
source: RIPE

role: CLNet Operations Team
address: Jindricha z Lipe 91
address: Ceska Lipa
address: 47001
address: Czech Republic
phone: +420 487 824333
phone: +420 724 397444
fax-no: +420 487 832923
e-mail: [email protected]
admin-c: OP23-RIPE
tech-c: OP23-RIPE
nic-hdl: CLOP1-RIPE
mnt-by: CLNET-MNT
changed: [email protected] 20021108
source: RIPE

person: Ondrej Pejsa
address: CL-Net, Ltd.
address: Jindricha z Lipe 124
address: Ceska Lipa
address: 470 01
address: Czech Republic
phone: +420 425 824333
fax-no: +420 425 823452
e-mail: [email protected]
nic-hdl: OP23-RIPE
changed: [email protected] 19980402
source: RIPE

Maybe we could send a mail bomb there



Powered by SkinBrowser!
Reply #19 Top
Jafo, you might want to considder to charge 1 dollar for evry spelling mistake you find on the forum, you would become rich
Reply #20 Top
I've told jafo that a million times it seems. Who needs a spellchecker? We have good ol' Jafo
Reply #21 Top
Thanks for the information. I always delete messages from unknown soruces or from sources that I didn't request information.
If I do get this message on hotmail, I will contact Microsoft myself and I'm sure that they can trace it. I'm also sure that the Czech Republic doesn't want viruses created in their country as it would hurt them too. To me, this is just another form of terrorism. >
Reply #22 Top
Yes,
I did have trouble posting and it was a triple
And thanks for the info and the laugh!
My posting do not seem to go through...well see if this one does, eh.
Reply #23 Top
Thank - you Styl skinner for the heads up.
I just received one in the past hour and promptly deleted it.
It came as Support @ microsoft.com RE: Movie.



Powered by SkinBrowser!
[Message Edited]