Re: Email Issues

From: Roger A. Grimes (roger_at_banneretcs.com)
Date: 02/26/04

  • Next message: Kuhl, Vince (DotComm): "security related RSS feeds"
    To: <sean.osullivan@ise.ie>, <security-basics@securityfocus.com>
    Date: Thu, 26 Feb 2004 15:05:02 -0500
    
    

    Sounds like the virus was stripped by another AV gateway and you're getting
    what's left.

    Roger

    ****************************************************************************
    ****
    *Roger A. Grimes, Computer Security Consultant
    *CPA, MCSE:Security (NT/2000/2003/MVP), CNE (3/4), A+
    *email: roger@banneretcs.com
    *cell: 757-615-3355
    *Author of Malicious Mobile Code: Virus Protection for Windows by O'Reilly
    *http://www.oreilly.com/catalog/malmobcode
    *Author of upcoming Honeypots for Windows (Apress)
    ****************************************************************************
    *****

    ----- Original Message -----
    From: <sean.osullivan@ise.ie>
    To: <security-basics@securityfocus.com>
    Sent: Thursday, February 26, 2004 4:51 AM
    Subject: Email Issues

    > Hi All
    >
    > Something weird has been happening the last three days. We have been
    getting
    > mails that look like the NetSky virus (smae text and attachments), to a
    certain mailboxs, but the weird thing is
    > that the .zip attachment is 78 Bytes, the actual virus .zip file is 22,016
    > bytes. Another things is our Mailsweeper is set to block all .zip files
    but
    > this one is getting through. I did a test and sent a mail with a normal
    .zip
    > attachment to this mail box and it got blocked. Has anyone seen this or
    > have any ideas on what its all about?
    >
    > Thanks in advance.
    >
    > Sean
    >
    >
    > **********************************************************************
    > This footnote also confirms that this email message has been swept by
    > MIMEsweeper for the presence of computer viruses.
    >
    > www.mimesweeper.com
    > **********************************************************************
    >
    >
    > --------------------------------------------------------------------------
    -
    > --------------------------------------------------------------------------

    --
    >
    >
    ---------------------------------------------------------------------------
    ----------------------------------------------------------------------------
    

  • Next message: Kuhl, Vince (DotComm): "security related RSS feeds"

    Relevant Pages

    • Re: Please advise
      ... It could be spyware and / or malware and not just a virus. ... > then Format/HTML, the message would display. ... Because of this tendency of attachments to infect, Microsoft has now set OE to block all attachments. ... If you choose to adjust OE to allow attachments, make sure you save the attachment to disk first and then scan it with your antivirus software. ...
      (microsoft.public.windows.inetexplorer.ie6_outlookexpress)
    • Re: Locking up
      ... Most computer infections are the result of the user opening email attachments. ... The attachment usually contains a virus or worm or trojan that infects the system when it is opened. ... If you choose to adjust OE to allow attachments, make sure you save the attachment to disk first and then scan it with your antivirus software. ... Note that dbx files are hidden in Windows 2000 and Windows XP. ...
      (microsoft.public.windows.inetexplorer.ie6_outlookexpress)
    • CERT Advisory CA-2004-02 Email-borne Viruses
      ... CERT Advisory CA-2004-02 Email-borne Viruses ... Source: CERT/CC ... Unsolicited email messages containing attachments are sent ... A virus infection can have significant consquences on your computer ...
      (Cert)
    • CERT Advisory CA-2004-02 Email-borne Viruses
      ... CERT Advisory CA-2004-02 Email-borne Viruses ... Source: CERT/CC ... Unsolicited email messages containing attachments are sent ... A virus infection can have significant consquences on your computer ...
      (Cert)
    • Re: help on outlook express wont start
      ... the anti virus software was conflicting with OE ... Don't open attachments. ... Turn off email scanning in your antivirus software. ... attempting to infect your system, ...
      (microsoft.public.windows.inetexplorer.ie6_outlookexpress)