The Classic Opel Forums  

Go Back   The Classic Opel Forums > OpelGT.com > Site Feedback, Comments, & Requests > News
Home Opel Groups Calendar Members Map FAQ eBay Search

News Site News

Reply
 
LinkBack Thread Tools Display Modes
Old 06-03-2005   #1 (permalink)
Site Admin
 
Gary's Avatar
 
Join Date: Mar 2002
Location: Swansea, MA
Posts: 5,268
Real Name: Gary
Gary will become famous soon enough
Garage
Alert - Possible Email Worm

I received a message tonight from 'mail "at" opelgt.com' with the subject titled: ACCOUNT ALERT informing me that my account was suspended. Attached was a file called: Information.zip.

No message of this sort was sent from opelgt.com. Googling the attachments name showed it could contain a worm.

If you receive a similar message, delete it and do not open the zip file.
Gary is offline  
Digg this Post!Add Post to del.icio.usBookmark Post in Technorati
Reply With Quote Top home
Old 06-03-2005   #2 (permalink)
Opeler
 
Dan-MI's Avatar
 
Join Date: Mar 2005
Location: Michigan
Posts: 175
Dan-MI is on a distinguished road
This is a new virus just going around. Here is some info on it.

Description:

A new variant of the Mytob worm family that has been reported in the wild. Win32/Mytob.DO is a mass-mailing worm that uses social engineering techniques to send e-mails with a spoofed sender's name, posing as an account suspension notification. The e-mail messages have varying subjects, message texts and attachment file names, with either a .BAT, .CMD, .EXE, .SCR, .PIF or .ZIP file extension. Mytob.DO drops a copy of itself and a backdoor component, and then creates registry RUN keys in order to enable automatic execution at every system startup. The worm also attempts to terminate existing antivirus processes and to modify the HOSTS file to prevent the user from visiting specific anti-virus web sites.

When run, Mytob.DO drops a copy of itself in the Windows System directory:

LIEN VAN DE KELDER.EXE
Email Properties:

From: (spoofed address; e-mail sender from an infected machine's Windows Address Book)

Subject: (one of the following)

<blank>
<random characters>
Notice: **Last Warning**
*DETECTED* Online User Violation
Your Email Account is Suspended For Security Reasons
Account Alert
Important Notification
*WARNING* Your Email Account Will Be Closed
Security measures
Email Account Suspension
Notice of account limitation
Message Text: (one of the following)

Once you have completed the form in the attached file , your account records will not be interrupted and will continue as normal.
please look at attached document.
Please read the attached document and follow it's instructions.
Please see the attachement.
The original message has been included as an attachment.
To safeguard your email account from possible termination, please see the attached file.
To unblock your email account acces, please see the attachement.
We attached some important information regarding your account.
We have suspended some of your email services, to resolve the problem you should read the attached document.
We regret to inform you that your account has been suspended due to the violation of our site policy, more info is attached.
Attachment: (one of the following with any of these extensions: BAT, CMD, EXE, SCR, PIF, ZIP)

email-info
email-doc
information
account-details
document
INFO
instructions
info-text
information
Backdoor Component:

This worm also has backdoor capabilities. It comes with a built-in Internet Relay Chat (IRC) bot functionality, which is an automated software program that can execute certain commands when it receives specific input coming from a remote malicious user. the worm is designed to contact the following IRC server, join a specified channel, and wait for further instructions:

irc.blackcarder.net (on TCP port 4512) on channel #RWNT
Dan-MI is offline  
Digg this Post!Add Post to del.icio.usBookmark Post in Technorati
Reply With Quote Top home
Old 06-03-2005   #3 (permalink)
Site Admin
 
Gary's Avatar
 
Join Date: Mar 2002
Location: Swansea, MA
Posts: 5,268
Real Name: Gary
Gary will become famous soon enough
Garage
Thanks, Dan.

Translation: be very wary of email attachments with BAT, CMD, EXE, SCR, PIF, ZIP extensions.
Gary is offline  
Digg this Post!Add Post to del.icio.usBookmark Post in Technorati
Reply With Quote Top home
Reply

Bookmarks


Currently Active Users Viewing This Thread: 1 (0 members and 1 guests)
 
Thread Tools
Display Modes

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is On
HTML code is Off
Trackbacks are On
Pingbacks are On
Refbacks are On



All times are GMT -4. The time now is 05:25 PM.


Powered by vBulletin® Version 3.8.4
Copyright ©2000 - 2009, Jelsoft Enterprises Ltd.
Search Engine Optimization by vBSEO 3.3.0
Clubs, Garage Plus vBulletin Plugins by Drive Thru Online, Inc.
1998-2009 OpelGT.com - OpelGT .com is not affiliated with General Motors Corp. or it's Adam Opel Division.