[Date Prev][Date Next][Thread Prev][Thread Next][Date Index][Thread Index]

Re: [cobalt-users] Help Needed - RaQ4 & Spam/Virus Outbreak!



At 08:09 AM 9/23/2003, you wrote:

I am not sure what will help in filtering, since I am seeing a lot of the
"Microsoft" messages coming in as "returned mail," except that the return
path is bogus.

BTW, does anyone know what the virus is that is attached to all the
"Microsoft" messages?


it is an executable with a random name.  (an exe file)

the sites claim certain name combinations, one of the first two I ran into did not conform to their naming list though close.

From Symantec:
The attachment name is created by:
Selecting one of the following predetermined names:
·       Patch
·       Upgrade
·       Update
·       Installer
·       Install
·       Pack
·       Q

Followed by a series of random numbers.

And a file extension that is either .exe or .zip.


I found once a computer is infected and the antivirus software deletes it, you have major troubles fixing the computer. It took info from Symantec and Trend Micro as well as my own knowledge to fix the computer.

If someone needs assistance, contact me and I will try and  write it all up.

David


--
This message has been scanned for viruses and
dangerous content by MailScanner, and is
believed to be clean.