[Full-Disclosure] malware

From: Papp Geza (pappgeza_at_tolna.net)
Date: 12/30/03

  • Next message: Daniel H. Renner: "[Full-Disclosure] Reverse http traffic"
    To: full-disclosure@lists.netsys.com
    Date: Tue, 30 Dec 2003 02:25:06 +0100
    
    

    Hello

    2003. december 29., 18:39:58, írtad:

    MT> A friend of mine was opening an email in front of me
    MT> when her XP machine crashed. I thought maybe it was a
    MT> power spike or something so she powered up and went
    MT> back to the email, clicked to view the message from
    MT> hotmail.com, the machine powered off again. She
    MT> erased the message before I could forward it to an
    MT> offsite machine, but the details as I remember them
    MT> were:

    MT> Sender=Jefferson (she knows a Jefferson)
    MT> Subject=(blank)
    MT> Open the message and immediately powers off the
    MT> machine.

    MT> My question to you is, now that her machine is
    MT> possibly comprimised, what tools can I use to check
    MT> for trojans or other things that could have been
    MT> installed. I've run her Symantec System Scanning
    MT> tool, and it shows no known problems. Has anyone
    MT> heard of this specific message, and is it simply
    MT> designed to be annoying or does it install malware on
    MT> the machine? I know this information is vague, any
    MT> advise is welcome.

    MT> Kindest Regards,
    MT> Matt

    Hy,
    I love NAV not, and my machine not run Symantec program. Real Time and
    on acces functions not good.

    If yuo have virus, worm other trojan you visite the machine with online
    virus scanner program.

    http://uk.trendmicro-europe.com/consumer/products/housecall_pre.php

    other

    http://www.ravantivirus.com

    Online trojan et malware program is:

    http://www.pestscan.com/Scan.asp

    other

    http://www.eaglepro.net/antivirus/ ----- this complex page (avir et
    ad aware)

    And intall yuo good antivirus :)

    Kinds Regards

    Üdvözlettel,
      Geysap

    MT> __________ NOD32 1.587 (20031229) Information __________

    MT> This message was checked by NOD32 Antivirus System.
    MT> part000.txt - is OK

    MT> http://www.nod32.com

    -- 
    Üdvözlettel,
        Geza Papp dr.
        Med. Foensic. (Criminal) and
        Networksecurity & Virusanalyst
        IT. Tittle and Designation from AVIEN
                                                                mailto:pappgeza@tolna.net
    www.gyik.com
    "VIRUS CORE TEAM"
    ============================================================================
    Regular Member of ComSec Online Limited Professional Services Company - >
    Company Secretarial Service | http://www.comseconline.com/en/about.php
    ----------------------------------------------------------------------------
    Time out of Mind Registered Active Associate SpamCop.net,
    and The SPAMHOUS Project - > (ROKSO and Spamhaus Block List)
    http://www.spamhaus.org/index.lasso | http://spamcop.net/
    ----------------------------------------------------------------------------
    One from charter member Public letter concerning the Writing of Viruses
    & How it Does Not Teach about Virus Prevention
    from Hungary | www.avien.org/publicletter.htm
    ============================================================================
    Fiat justitia, pereat mundus!
    This system protects Tiny Professional Personal Firewall(c)
    ============================================================================
    _______________________________________________
    Full-Disclosure - We believe in it.
    Charter: http://lists.netsys.com/full-disclosure-charter.html
    

  • Next message: Daniel H. Renner: "[Full-Disclosure] Reverse http traffic"

    Relevant Pages

    • Re: dont want to format my C drive...
      ... it is very difficult to get online now because of the popups. ... what is panda by the way? ... > Have you tried an online virus scan with Panda: ... i believe the trojan is trojan.downloader.kavsav, ...
      (microsoft.public.windowsxp.help_and_support)
    • >>>> REMOVE MANUALLY <<<<
      ... Remove Virus Manually ... How To Remove Spyware Manually ... Manually Remove Trojan Horse ... Manually Remove Symantec Antivirus ...
      (sci.math.num-analysis)
    • Re: trojan virus PLEASE HELP!
      ... There are anti virus News Groups specifically for this type of discussion. ... How do you know you have a Trojan on your PC? ... This will bring up the initial menu of choices and should be executed in Normal Mode. ... You can choose to go to each menu item and just download the needed files or you can ...
      (microsoft.public.windowsupdate)
    • Re: Virus infection as soon as Im online! Help
      ... really do this before going online: ... Tried to delete or heal the viruses that AVG Free found but no luck. ... I finally decided to re-install the system (luckily I ... another 10 minutes, here came VIRUS again!!! ...
      (microsoft.public.security)
    • Re: Vicious Vundo Infection
      ... Spybot) but cannot get rid of it. ... The virus puts a new entry in the startup command every time I re- boot. ... The Active Boot Disk has a 10 day trial, ... that the trojan created. ...
      (alt.comp.anti-virus)