Antique Engines and Old Iron
[Home] - [HELP] - [Forums] - [Articles] - [Photo Gallery] - [Chat Room] - [Groups] - [Classified Ads] - [Subscribe] - [Links] - [Books] - [Sponsors]

Go Back   SmokStak > SmokStak® General Discussion > Computer, Camera and ISP Problems
Forgot Password? Join Us!

Computer, Camera and ISP Problems

LATEST threat


Here's one I just received with an attached zip file named hotfix-37583.zip. YUP! I'm SURE it'll...

this thread has 15 replies and has been viewed 1024 times

Reply
 
Thread Tools Display Modes
  #1  
Old 04-12-2007, 07:58 PM
Craig A's Avatar
Craig A Craig A is offline
Sponsor
 
Join Date: Nov 2004
Location: Wisconsin USA
Posts: 6,172
Images: 18
Thanks: 2,527
Thanked 2,956 Times in 1,084 Posts
Exclamation LATEST threat

Here's one I just received with an attached zip file named hotfix-37583.zip.
YUP! I'm SURE it'll fix me right up!!!!!!!!!!!!!!
And the "text" was sent as an image file so I couldn't even copy it!
It originated in Amsterdam...............
Attached Thumbnails
Click image for larger version

Name:	threat.gif
Views:	222
Size:	4.8 KB
ID:	18247  
Reply With Quote
Sponsored Links
  #2  
Old 04-12-2007, 08:14 PM
JKWidener's Avatar
JKWidener JKWidener is online now
Subscriber
 
Join Date: Aug 2006
Location: Alexandria, Indiana USA
Posts: 2,472
Images: 26
Thanks: 580
Thanked 855 Times in 342 Posts
Default Re: LATEST threat

In the past two days i have been getting emails sent to me from overseas providers with the atatchment of greetingcard.exe and alot of other .exe files in other emails... I have my outlook set up to not accept and file like the ones mentioned. So outlook only shows the name of the atachment only and tells me its an .exe file... What i wouldnt give to have there home and email adresses ....
Reply With Quote
  #3  
Old 04-12-2007, 08:31 PM
Craig A's Avatar
Craig A Craig A is offline
Sponsor
 
Join Date: Nov 2004
Location: Wisconsin USA
Posts: 6,172
Images: 18
Thanks: 2,527
Thanked 2,956 Times in 1,084 Posts
Default Re: LATEST threat

JK.......SOMETIMES, in the header, you will find an email address that may or may not work.....WHEN I find one I USE it.......as this is a family oriented site I can't say what the response is but TRUST ME.......it ain't pretty......
Also, in brackets like this: [1923.168.1.16] you will find the source of the email which you can use to trace it here: http://www.network-tools.com/
Check the EXPRESS box and see what happens.
At the minimum you will usually find an abuse reporting address.
Reply With Quote
  #4  
Old 04-13-2007, 08:42 AM
JKWidener's Avatar
JKWidener JKWidener is online now
Subscriber
 
Join Date: Aug 2006
Location: Alexandria, Indiana USA
Posts: 2,472
Images: 26
Thanks: 580
Thanked 855 Times in 342 Posts
Default Re: LATEST threat

Well as i sit back down at the computer this morning i had another email. It was the same as you got. hotfix.ZIP. And there is something else interesting about this, it is getting past the virus scanner with my isp Sbcglobal/yahoo, It tells me that they were unable to scan this message for a virus. This is the only type of messages that are going through unscanned...
Reply With Quote
  #5  
Old 04-13-2007, 10:09 AM
Bill Geyer's Avatar
Bill Geyer Bill Geyer is offline
Subscriber
 
Join Date: Jul 2005
Location: Granbury, Texas USA
Posts: 1,175
Images: 11
Thanks: 116
Thanked 46 Times in 36 Posts
Default Re: LATEST threat

I don't even open Emails like that.
__________________
May the Stak be with you
Bill
Reply With Quote
  #6  
Old 04-13-2007, 12:42 PM
Craig A's Avatar
Craig A Craig A is offline
Sponsor
 
Join Date: Nov 2004
Location: Wisconsin USA
Posts: 6,172
Images: 18
Thanks: 2,527
Thanked 2,956 Times in 1,084 Posts
Default Re: LATEST threat

I virus scanned the hotfix.ZIP. and it passed the scan....which is neither here nor there....except they are getting smarter and smarter.
FYI that message WAS trapped in my spam filter but I had it delivered to see what was what and to report it.
My Spam filter prescans all emails with McAfee and it passed that too.
I wish someone could extract and analyze that zipped file to see what the payload is...............
Some kid with an offline "junk" computer probably could figure it out in 2 minutes..............
Craig
Reply With Quote
  #7  
Old 04-13-2007, 01:05 PM
JKWidener's Avatar
JKWidener JKWidener is online now
Subscriber
 
Join Date: Aug 2006
Location: Alexandria, Indiana USA
Posts: 2,472
Images: 26
Thanks: 580
Thanked 855 Times in 342 Posts
Default Re: LATEST threat

If i get another one sent to me then i will burn it to disk and i will use an old computer i have here that needs some work to open it...Offline of course. Then mabey it will open some doors "Or just close all of them" lol but with this computer, i have nothing to lose. It was gave to me for parts but i did get everything working but the onboard sound. Its an old 386 running win98..... I will keep you updated....
Reply With Quote
  #8  
Old 04-13-2007, 01:16 PM
Craig A's Avatar
Craig A Craig A is offline
Sponsor
 
Join Date: Nov 2004
Location: Wisconsin USA
Posts: 6,172
Images: 18
Thanks: 2,527
Thanked 2,956 Times in 1,084 Posts
Default Re: LATEST threat

JK!!!!!!!!!
I FOUND the ZIP in my online sent folder...............
If you want to play with it email me (with a real email address so you can get the attachment) and I'll send it to you............
Craig

(Enquiring minds want to know..........)
Reply With Quote
  #9  
Old 04-13-2007, 02:04 PM
JKWidener's Avatar
JKWidener JKWidener is online now
Subscriber
 
Join Date: Aug 2006
Location: Alexandria, Indiana USA
Posts: 2,472
Images: 26
Thanks: 580
Thanked 855 Times in 342 Posts
Default Re: LATEST threat

Here is what it is... DONT OPEN IT....

The attachment is in the ZIP file. It contains a trojan horse that will install itself on the system as a system driver and then will download other malicious programs from various computers on the Internet. The file contained within the ZIP file will be detected as Trojan.Packed.13. If the user executes this file it will create another file that will be detected as Trojan.Peacomm
__________________
It takes only a moment to say I love you and a lifetime to say goodbye.

Last edited by JKWidener; 04-13-2007 at 02:33 PM.
Reply With Quote
  #10  
Old 04-13-2007, 02:09 PM
JKWidener's Avatar
JKWidener JKWidener is online now
Subscriber
 
Join Date: Aug 2006
Location: Alexandria, Indiana USA
Posts: 2,472
Images: 26
Thanks: 580
Thanked 855 Times in 342 Posts
Default Re: LATEST threat

If you have opened a file like this, Most virus scanners have not released a patch for this file. I would suggest running a program called Trend Micro Housecall. Its free of charge and can be found here. http://housecall.trendmicro.com/
__________________
It takes only a moment to say I love you and a lifetime to say goodbye.
Reply With Quote
  #11  
Old 04-13-2007, 03:18 PM
Craig A's Avatar
Craig A Craig A is offline
Sponsor
 
Join Date: Nov 2004
Location: Wisconsin USA
Posts: 6,172
Images: 18
Thanks: 2,527
Thanked 2,956 Times in 1,084 Posts
Default Re: LATEST threat

Well THAT was quick!!!!!!!!!!!!
Thanks!
I figured it was a trojan of some sort...............but it could have as easily been a boot sector virus too..........
Thanks again!

Craig
Reply With Quote
  #12  
Old 05-27-2007, 09:19 AM
Tom Lumpkins Tom Lumpkins is offline
Registered-I
 
Join Date: May 2007
Location: Woodlawn Tn
Posts: 8
Thanks: 0
Thanked 0 Times in 0 Posts
Default Re: LATEST threat

I'm new to the site, But when I get email from someone I don't know I delete, I don't even open it up.and I never take attachments even from people I know, you get some emails that will have hundreds of emails on it from where it has been forwarded to death. I hate to have my name added to the list on those notes, A spammer gets hold of it, Then you get spammed to death.
Reply With Quote
  #13  
Old 05-27-2007, 12:46 PM
Nork's Avatar
Nork Nork is offline
Registered-II
 
Join Date: Oct 2005
Location: Eindhoven, Nethelands
Posts: 128
Thanks: 3
Thanked 0 Times in 0 Posts
Exclamation Re: LATEST threat

Hi every one, a spatially Craig,

Be warned that spammers never use their own home/business email address. If you have one that works its either a victim that has that mail opened and became a part of a drone network (net work of infected computers) or it ends up in a domain trashcan. There is a new initiative on making a new verification on emails and the servers but it will take 1 to 4 years before it is fully implemented. Maybe then we’ll get less spam and spam with Trojans.

I would like to get rid rather yesterday than today but their a real plague. But I also have to warn for some nifty helping files and programs. I have found that some well known systems their names are used in bad programs to be found around. Lava soft with ad-aware is one of them. A other program that I use is “Spyware Doctor” from PC Tools. This in combination with a virus scanner (in my case McAfee) is a good protection for what the virus scanner didn’t see spy dr. will pick up and visa versa. I do have to warn that this all costs memory and a big load on the CPU.

I have no problems and it seems pretty clean on my systems. So no doubt there be some on there but not half as many that are installed on an average PC

NorK
Reply With Quote
  #14  
Old 05-27-2007, 02:50 PM
Craig A's Avatar
Craig A Craig A is offline
Sponsor
 
Join Date: Nov 2004
Location: Wisconsin USA
Posts: 6,172
Images: 18
Thanks: 2,527
Thanked 2,956 Times in 1,084 Posts
Default Re: LATEST threat

Yesterday I recieved 6 identical spams that escaped my filter as MY email address was listed as the sender.......
I did IP traces on all of them and they orginated in: Amsterdam, Russia, Argentina and I forgot the other three.
I reported the ones that turned up an abuse reporting address and personally replied to the others, none of which bounced back........
You don't want to know the content of the emails I sent...............
In addition to forwarding to the abuse center I also forward them, WITH HEADERS, to spamcop.
I know it won't do any good as they use disposable addresses anyway but it makes me feel a little better...........
Reply With Quote
  #15  
Old 05-27-2007, 08:22 PM
Ackman's Avatar
Ackman Ackman is offline
Subscriber
 
Join Date: Nov 2004
Location: Cadott, WI
Posts: 636
Images: 22
Thanks: 133
Thanked 350 Times in 87 Posts
Default Re: LATEST threat

I NEVER , repeat NEVER open an E-mail that I don't recognize!!! I have 3 different E-mail addresses, one of which, is getting to be a BIG PIA, due to all the DAMN SPAM & other CRAP I've been getting, lately!!! (I'm sure that Craig knows "which one" I'm talking about. ) & I'm going to be dropping that E-mail account VERY soon!
Reply With Quote
  #16  
Old 05-27-2007, 09:14 PM
BDMelon BDMelon is offline
Subscriber
 
Join Date: Oct 2005
Location: USA
Posts: 1,426
Images: 11
Thanks: 161
Thanked 136 Times in 48 Posts
Default Re: LATEST threat

Quote:
Originally Posted by Randy Ackley View Post
I NEVER , repeat NEVER open an E-mail that I don't recognize!!! I have 3 different E-mail addresses, one of which, is getting to be a BIG PIA, due to all the DAMN SPAM & other CRAP I've been getting, lately!!! (I'm sure that Craig knows "which one" I'm talking about. ) & I'm going to be dropping that E-mail account VERY soon!
Don' forget to tell you freindly Melon you changes
(EEEEKKKK) ------lol
Reply
Reply


Similar Threads Chosen at Random
Thread Thread Starter F o r u m Replies Last Post
latest toy P Loomis Antique Gas Engine Discussion 0 07-19-2006 06:53 PM
Warning about a virus threat oldironcollector Antique Gas Engine Discussion 0 01-09-2006 10:03 PM
Latest creation John Willis Antique Gas Engine Discussion 5 06-19-2005 07:06 PM
Latest new toy Tom Winland Stationary Steam & Traction Engines 8 02-15-2004 11:40 PM
Latest find Todd Osborne Antique Engine Archives 0 04-21-2002 06:34 PM


Thread Tools
Display Modes

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is On
HTML code is Off
F o r u m Jump


All times are GMT -4. The time now is 06:06 AM.


All use is subject to our TERMS OF SERVICE
SMOKSTAK® is a Registered Trade Mark
A Community of Antique Engine Enthusiasts
Copyright © 2000 - 2009 by Harry Matthews
P.O. Box 5612 - Sarasota, FL 34277