YAVT: Slick new virus: Sends zip with password in email

SendTrash

Platinum Member
Apr 18, 2000
2,581
0
76
I tried a search for "virus" and didn't find any relavant threads.

I just got two emails this morning and to me, at first they looked totally legit. The first one had the message of:

"Argh, i don't like the plaintext

..btw, "03388" is a password for archive"

On a second thought, it is obviously a virus, but it was coming from a girl, so I understood the smiley face, and I like plaintext, but I understand some people don't like it... and hey, a zip.. that's not a virus (yeah, stupid thinking)..

Then I got another email with a totally different message,

"I don't bite, weah!

password: 16672"

But this is obvious, whenever someone tells you they don't bite, they do (personal experience)

But I thought this was a slick virus because both the email title and message were different and the payload is in a zip, and regular AV scanners skip zip files right? Plus I thought the email message was tempting to make me open the attachement for a second.

Is there such a thing as YAVT = Yet Another Virus Thread?
 

BAMAVOO

Diamond Member
Oct 9, 1999
8,089
41
91
Seeing that here at work as well. Just had someone email me they received the two mails back to back.

I scanned them with Norton and it was clean? So I don't know if it is a virus, unless it is that new and not being caught yet.
 

JulesMaximus

No Lifer
Jul 3, 2003
74,472
867
126
I got 2 e-mails at home the other day with virus files attached. NAV quarantined them before I had a chance to see what they were.

I believe you can set NAV to scan zipped files.
 

Beau

Lifer
Jun 25, 2001
17,731
0
76
www.beauscott.com
Originally posted by: JulesMaximus
I got 2 e-mails at home the other day with virus files attached. NAV quarantined them before I had a chance to see what they were.

I believe you can set NAV to scan zipped files.

I don't think NAV or anything else can scan a password protected zipped file, most they could do is match the file size.
 

SendTrash

Platinum Member
Apr 18, 2000
2,581
0
76
Originally posted by: JulesMaximus
I got 2 e-mails at home the other day with virus files attached. NAV quarantined them before I had a chance to see what they were.

I believe you can set NAV to scan zipped files.

Wow, your Norton caught them already? My sophos AV is slow then.
 

OZEE

Senior member
Feb 23, 2001
985
0
0
AVG can be set to scan everything: Service > Test Settings > Test All Extensions... But you're right, it doesn't do it by default.
 

Daishiki

Golden Member
Nov 9, 2001
1,943
36
91
yea, my friend was saying how he got one of these yesterday.

and a passworded zip just can't be extracted without a password. you might be thinking of a file that is encrypted
 

CraigRT

Lifer
Jun 16, 2000
31,440
5
0
lots of new crap like this lately.. i get a lot of Netsky.D's in my inbox in the last 2 days.
 

JulesMaximus

No Lifer
Jul 3, 2003
74,472
867
126
Originally posted by: SendTrash
Originally posted by: JulesMaximus
I got 2 e-mails at home the other day with virus files attached. NAV quarantined them before I had a chance to see what they were.

I believe you can set NAV to scan zipped files.

Wow, your Norton caught them already? My sophos AV is slow then.

I don't know if the infected files I received are the same as the ones mentioned above. I haven't looked at them in detail yet. Just saying that I did get two the other day and that I thought you could set NAV to scan compressed files. The two statements were not necessarily related.
 

dabuddha

Lifer
Apr 10, 2000
19,579
17
81
Up at work, we started deleting zip file attachments. Yesterday alone, over 48,000 zip files were deleted apparently.
 

fonzinator

Senior member
Nov 5, 2002
953
0
0
I got this same virus today in my Yahoo email acct. It had a message posing as Yahoo system admins from "staff@yahoo.com" It was very deceptive. I'm sure MANY people will open this up and be hosed.
 

Grey

Platinum Member
Oct 14, 1999
2,737
2
81
Ditto have received several versions of it but its essentially this each time.
-------------------------

Subj: Warning about your e-mail account.
Date: Tue, 02 Mar 2004 23:19:41 -0500
From: noreply@njdevs.com
----------------------------------------------------------------
Hello user of Njdevs.com e-mail server,

We warn you about some attacks on your e-mail account. Your computer may
contain viruses, in order to keep your computer and e-mail account safe,
please, follow the instructions.

Advanced details can be found in attached file.

Attached file protected with the password for security reasons. Password is 45164.

Have a good day,
The Njdevs.com team http://www.njdevs.com


=============== Attachment ================
Readme.zip
 

deejayshakur

Platinum Member
Aug 7, 2000
2,585
0
0
Dear user of Ucla.edu gateway e-mail server,

Your e-mail account has been temporary disabled because of unauthorized access.

Further details can be obtained from attached file.

In order to read the attach you have to use the following password: 45536.

The Management,
The Ucla.edu team http://www.ucla.edu

tricky!
 

EagleKeeper

Discussion Club Moderator<br>Elite Member
Staff member
Oct 30, 2000
42,591
5
0
Received early this week an e-mail in Yahoo box that had an attachment with the extension .SIF

Did not recognize the sender of format. Sent a reply back asking for clarification and deleted the file.
Better be safe than sorry.
 

Brutuskend

Lifer
Apr 2, 2001
26,558
4
0
I've been getting a lot of emails lately with attachments.

When in doubt, I just delete them and add them to my spam filter.

Any mail from someone I don't know is "In doubt"
 

Crusty

Lifer
Sep 30, 2001
12,684
2
81
Dear user, the management of Utexas.edu mailing system wants to let you know that,

Some of our clients complained about the spam (negative e-mail content)
outgoing from your e-mail account. Probably, you have been infected by
a proxy-relay trojan server. In order to keep your computer safe,
follow the instructions.

For more information see the attached file.

Attached file protected with the password for security reasons. Password is 67627.

Best wishes,
The Utexas.edu team http://www.utexas.edu


_________________________________________________________

That's the email I got with a .zip...kinda odd that it came from UT acting as UT since I goto UT. Of course I didn't open it, Norton went nuts once the email arrived.
 

ndee

Lifer
Jul 18, 2000
12,680
1
0
ok guys, you can stop with the "Any mail from someone I don't know is "In doubt""-attitude. It can also come from someone you know cuz they fake the sender. You have to be suspicious about every "weird" email you get, doesn't matter if you know the person or not.
 

Brutuskend

Lifer
Apr 2, 2001
26,558
4
0
Originally posted by: ndee
ok guys, you can stop with the "Any mail from someone I don't know is "In doubt""-attitude. It can also come from someone you know cuz they fake the sender. You have to be suspicious about every "weird" email you get, doesn't matter if you know the person or not.

Well I also have Norton, so if I get anything from anyone it gets caught.
 

ndee

Lifer
Jul 18, 2000
12,680
1
0
Originally posted by: Brutuskend
Originally posted by: ndee
ok guys, you can stop with the "Any mail from someone I don't know is "In doubt""-attitude. It can also come from someone you know cuz they fake the sender. You have to be suspicious about every "weird" email you get, doesn't matter if you know the person or not.

Well I also have Norton, so if I get anything from anyone it gets caught.

I just went to the thread and your post just reminded me of some friends. "If... if... if it's an email from someone I don't know, I surely wont open it!"
 
sale-70-410-exam    | Exam-200-125-pdf    | we-sale-70-410-exam    | hot-sale-70-410-exam    | Latest-exam-700-603-Dumps    | Dumps-98-363-exams-date    | Certs-200-125-date    | Dumps-300-075-exams-date    | hot-sale-book-C8010-726-book    | Hot-Sale-200-310-Exam    | Exam-Description-200-310-dumps?    | hot-sale-book-200-125-book    | Latest-Updated-300-209-Exam    | Dumps-210-260-exams-date    | Download-200-125-Exam-PDF    | Exam-Description-300-101-dumps    | Certs-300-101-date    | Hot-Sale-300-075-Exam    | Latest-exam-200-125-Dumps    | Exam-Description-200-125-dumps    | Latest-Updated-300-075-Exam    | hot-sale-book-210-260-book    | Dumps-200-901-exams-date    | Certs-200-901-date    | Latest-exam-1Z0-062-Dumps    | Hot-Sale-1Z0-062-Exam    | Certs-CSSLP-date    | 100%-Pass-70-383-Exams    | Latest-JN0-360-real-exam-questions    | 100%-Pass-4A0-100-Real-Exam-Questions    | Dumps-300-135-exams-date    | Passed-200-105-Tech-Exams    | Latest-Updated-200-310-Exam    | Download-300-070-Exam-PDF    | Hot-Sale-JN0-360-Exam    | 100%-Pass-JN0-360-Exams    | 100%-Pass-JN0-360-Real-Exam-Questions    | Dumps-JN0-360-exams-date    | Exam-Description-1Z0-876-dumps    | Latest-exam-1Z0-876-Dumps    | Dumps-HPE0-Y53-exams-date    | 2017-Latest-HPE0-Y53-Exam    | 100%-Pass-HPE0-Y53-Real-Exam-Questions    | Pass-4A0-100-Exam    | Latest-4A0-100-Questions    | Dumps-98-365-exams-date    | 2017-Latest-98-365-Exam    | 100%-Pass-VCS-254-Exams    | 2017-Latest-VCS-273-Exam    | Dumps-200-355-exams-date    | 2017-Latest-300-320-Exam    | Pass-300-101-Exam    | 100%-Pass-300-115-Exams    |
http://www.portvapes.co.uk/    | http://www.portvapes.co.uk/    |