Guest awarner [MVP] Posted May 19, 2003 Report Posted May 19, 2003 Tonight I've been getting numerous emails from [email protected] all with different headers. Norton has quarantined one of them as a virus :? The headers of the emails are My details Your details Movie Re: Approved (Ref: 3394-65467) This one cannot be an RE as I have never contacted Microsoft Anyone else had this?
Guest ClintEastman Posted May 19, 2003 Report Posted May 19, 2003 Computer users are being warned about a new worm doing the rounds which arrives in an email purporting to be from [email protected]. Major anti-virus vendors have already issued highest-priority warnings for the self-replicating worm, called Palyh, which is spreading via global email and around local area networks. Travelling under the guise of a message from Microsoft's technical team the virus is engineered to trick users into activating it by clicking on an attachment. And it appears to be working - infections have already been recorded in several countries worldwide according to security firm Kaspersky Labs. Once activated the Palyh worm copies itself into the Windows directory under the name "MSCCN32.EXE" and registers this file in the system registry's auto-run key so that it is placed into system memory and automatically launched upon operating system start-up. In keeping with other self-replicating worms Palyh then scans for email addresses to forward itself onto. It searches for files with the extensions txt, eml, html, htm, dbx, wab and selects lines from them that it believes to be email addresses. Then Palyh will use the SMTP server to send out copies of itself to all email addresses found on the infected machine. All infected email messages sent out by the worm contain the falsified address [email protected], though they contain various subject lines, body texts and attached file names. Removal Tool
Guest awarner [MVP] Posted May 19, 2003 Report Posted May 19, 2003 Cheers I owe you one :) Looks like I got away with out being infected
Guest adam Posted May 19, 2003 Report Posted May 19, 2003 Clint, is there anything you can't find out?
Guest ClintEastman Posted May 19, 2003 Report Posted May 19, 2003 Clint, is there anything you can't find out? :) :( 8)
Guest Monolithix [MVP] Posted May 19, 2003 Report Posted May 19, 2003 I've had this in every e-mail account i own bar one. Hotmail First time for everything, eh?
Guest madu Posted May 19, 2003 Report Posted May 19, 2003 Same here. On one of my hotmail accounts. It said all info in attachment. No attachment. Duh!
Guest siu99spj Posted May 20, 2003 Report Posted May 20, 2003 Strangely, although most people at work had it I did not. Yet Yahoo informed me that it had removed all E-Mails in my account from [email protected] stating that if I needed any all I had to do is ask and they would fish out the safe one. Nice chaps!
Guest Chris b.a.r.f. Posted May 20, 2003 Report Posted May 20, 2003 Same here. On one of my hotmail accounts. It said all info in attachment. No attachment. Duh! Hotmail use McAfee to scan all emails AFAIR - so you'll get the mails but not the infected attachments...
Guest martinb Posted May 20, 2003 Report Posted May 20, 2003 Hotmail use McAfee to scan all emails AFAIR - so you'll get the mails but not the infected attachments... It's actually Brightmail. See http://www.brightmail.com/pressreleases/09...otmail_MSN.html Rgds, martin
Guest Chris b.a.r.f. Posted May 20, 2003 Report Posted May 20, 2003 OK - It used to be McAfee, I'm sure. Haven't actually visited hotmail.com for ages, as I always use OE to get to my hotmail accounts.
Guest asif @ planus Posted May 20, 2003 Report Posted May 20, 2003 Hi, I believe McAfee still do the virus checking, and brightmail stop the spam (not doing a very good job tho :)) Anyway, enough of my rambling...
Guest NederSoren Posted May 20, 2003 Report Posted May 20, 2003 i've got this messege 4 times... plus i got a file sent from [email protected] and i suspect it to be the same file,,..
Guest Chris b.a.r.f. Posted May 20, 2003 Report Posted May 20, 2003 'course you have, it's a mass mailing virus. Probably not the last you'll get. I only received one mail with the virus, to my hotmail address a week or so ago. Had none since. More info on Palyh/Sobig: http://securityresponse.symantec.com/[email protected]
Recommended Posts
Please sign in to comment
You will be able to leave a comment after signing in
Sign In Now