Virus from Lister-Petter

Aug 10, 2004 16 Replies

I wasn't going to bother posting about this one, but I had confirmation from Mailwasher this morning that this was a virus:


+++++++++++++++++++++++++++++++++++++++++++++++++++ A new variant of the Bagle e-mail worm has been spreading quickly on the Internet since Monday. It's called W32/Bagle.aq@MM and it infects your PC by fooling you into opening a ZIP-file email attachment.
+++++++++++++++++++++++++++++++++++++++++++++++++++

My little package came from snipped-for-privacy@lister-petter.com



It has a small 5.8kBytes attachment named "new price" the attached file name is "08_price.zm9"



I'd be interested to know how my email address came to be in the Lister-Petter system.....



Peter


-- Peter & Rita Forbes snipped-for-privacy@easynet.co.uk Engine pages for preservation info:

formatting link


My one came from Martin Perman....

Scan your system, Martin.

Arthur G

Martin may not be the source Arthur as the one that hit me "came" from Roland. It got through the virus checker on Yahoo as well.

Regards

JohnR

confirmation from

The latest viruses are capable of forging the email "from" address, one of the most recent trawls through Google to find them. If one of yours gets forged you will soon know from the bounces that some of the more clueless ISP's and MailWasher users will inflict on you. A virus which appears to be from someone you trust is much more likely to be opened than one which appears to come from someone you have never heard of. I regularly get them to admin@mydomain as I am the admin for the domain it is immediately obvious that something is not quite kosher. Given that some come viruses masquerade as being from admin at the users ISP it is understandable that newer net users will get fooled into getting their PC's infected. A common one claims that the users email is about to expire and that the attached file needs to be run to maintain the email account.

That explains why the antivirus I have on my machine which updates it's virus definitions automatically, did not pick the virus up until after I had gone to the website and did a manual update.

Regards

JohnR

very clever nowadays,

the virus will get into the address book, it then picks out an address to send to, and then an address to change the senders address in the message.

Martin may not be the source Arthur as the one that hit me "came" from

confirmation

Arthur,

That you have a virus, possibly from me, I check my computer almost every day and at least once a week but for you after this message I will do it again :-)) Martin P

On Tue, 10 Aug 2004 07:00:32 +0000 (UTC), Peter A Forbes

Are you running zone alarm or zone alarm pro as a firewall?

Yes (Pro) and a USR Broadband router, and we have NAV (Updated religiously) and we have Mailwasher Pro and..........

Running out of things to hang of the 'pooter now, if we have much more in the way of 'anti' software it will take forever to get the damm thing fired up each day! :-))

Note that as we use Agent for email, it just comes through as an attachment with the details. Only if you try and open the attachment will it do any damage. It was sent very quickly to the great trash bin in the sky, which was also emptied.

Peter

-- Peter & Rita Forbes snipped-for-privacy@easynet.co.uk Engine pages for preservation info:

formatting link

I suspect that ZA Pro, with inbound mailsafe set on, has done its business and change the file type to .zm9 to quarantine the file so it cannot be executed by clicking on it.

Arthur, This evening I scanned my machine for you and found nothing, I have since looked at the Semantic web site, Norton Antivirus, who are aware of it and they site tells me the tool I need is in my computer. I also have Mailwasher and a Zone alarm so I am pretty well covered. Again I apologise but it didnt come from me.

Martin P

Martin, seems I scared you unnecessarily, sorry for that.

It caused me no problem, just gave my AV software some excitement for a few seconds after Mailwasher looked at it.

I use Kerio Firewall and in addition at work, we have a hardwall firewall in our router.

Regards, Arthur G

I think the way the virus operates the source is almost impossible to locate unless you have the resources that the main antivirus companies do. My NAV virus files were updated only three days previously and I have Zonealarm fitted but it still got through those and a virus scan from Yahoo.

Regards

JohnR

Arthur, I must admit I was a little pieved but also forgot to put the happy face on my post, its the heat you know..........................

Martin P

Some would be more truthful put it down to old age.....:-)))

Peter

-- Peter A Forbes Prepair Ltd, Luton, UK snipped-for-privacy@easynet.co.uk

formatting link

Like your good self for instance :-))

Martin P

One of the feature of Bagle is that it spoofs the "from" field from an address in the infected computer's name and address book.

J

In message , Peter A Forbes writes

Join the Discussion

Have something to add? Share your thoughts — no account required.

Didn't find your answer?

Ask the community — no account required