k_grdn1 Posted March 1, 2004 Report Share Posted March 1, 2004 Hi, recieved an email earlier from: [email protected] <[email protected]> , subject: thanks. There was an attachment which was a DOS sortcut, title:message_part2.pif. The mail message was your file is attached. I opened the sortcut and it attempted to access the internet. Should I be worried?K_grdn1 Quote Link to comment Share on other sites More sharing options...
Sir Radfordin Posted March 1, 2004 Report Share Posted March 1, 2004 There is a good chance that it could be a virus (given the .pif file type) - do you have any Anti Virus software running on your PC?May be a good idea to visit http://housecall.trendmicro.com/ for a free online scan and then visit http://www.grisoft.com/us/us_index.php and download a free Anti Virus Package called AVG. Quote Link to comment Share on other sites More sharing options...
k_grdn1 Posted March 1, 2004 Author Report Share Posted March 1, 2004 Sir RadfordinI have run norton and nothings been picked up and zone alarm blocked attempted internet connection. Quote Link to comment Share on other sites More sharing options...
-pops- Posted March 2, 2004 Report Share Posted March 2, 2004 A good rule is NEVER to open attachments on emails unless you are ABSOLUTELY certain of their origin.You could also extend that to never opening emails at all unless you are certain of their origin.In addition to Sir R's wise words, can I suggest you install something like Mailwasher Mailwasher or (one that I've just installed and am impressed with) eprompter both of these will allow you to read your mail without downloading into your own machine and you can delete from there.Also, set your antivirus to check all email when it arrives. Quote Link to comment Share on other sites More sharing options...
nellie2 Posted March 2, 2004 Report Share Posted March 2, 2004 k_grdn1 If you haven't already done an online scan then I suggest you do one. Sir Radfordin is right and is sounds very much like a virus to me. :( If nothing shows up in the online scan then post a hijack log in the hijack board just so that we can make sure you haven't got anything new!!!-pops- is giving you some spot on advice there by the way! ;) Quote Link to comment Share on other sites More sharing options...
k_grdn1 Posted March 2, 2004 Author Report Share Posted March 2, 2004 Hi All,Thanks for all the input. Full System scan(latest definitions Feb29th) showed nothing, so I quarentined the attachment and submitted it to SARC.It turns out it's a varient of W32.Netsky.D@mm, a mass-mailing worm. The worm scans drives C through Z for email addresses and sends itself to those that are found.The Subject, Body, and Attachment names vary. The attachment will have a .pif file extension.Sorry for breaking the golden rule of opening attachments, I suspected malicious content but curiosity won the battle.Protection March 1st definitions. :D Hope this is of some use.K_grdn1 Quote Link to comment Share on other sites More sharing options...
andsome Posted March 9, 2004 Report Share Posted March 9, 2004 Sorry for breaking the golden rule of opening attachments, I suspected malicious content but curiosity won the battle.Very very naughty, let that be a lesson. Get Mailwasher as suggested. You can right click on a message and read it while it is still on the server, in text form only. You won't get a virus that way, and you can delete the message rather than download it. That same e-mail was sent to me, but I deleted it while it was still at NTL using Mailwasher. Quote Link to comment Share on other sites More sharing options...
Boris Posted March 9, 2004 Report Share Posted March 9, 2004 Mailwasher final Beta :thumbup: Quote Link to comment Share on other sites More sharing options...
Recommended Posts
Join the conversation
You can post now and register later. If you have an account, sign in now to post with your account.