Virus Info

greenspun.com : LUSENET : Country Families : One Thread

Mitch, as I know you didn't send me mail, particularly with the attachment I received, I'd say you have a virus. The attachment was Napster......mp3

-- Rick (Rick_122@hotmail.com), December 01, 2001

Answers

I went into my trash, and these are the headers shown on my suspected virus e-mail:

Attachment: New_Napster_Site.MP3.PIF

MIME-Version: 1.0 Received: from [207.173.229.137] by hotmail.com (3.2) with ESMTP id MHotMailBDD22C1700A54004310FCFADE5890D520; Sat, 01 Dec 2001 05:54:36 -0800 Received: from aol.com ([170.215.144.139]) by mrtwig.citlink.net (InterMail vK.4.03.04.00 201-232-130 license a3e2d54ac3b1df4217e834deb9d77e31) with SMTP id <20011201135858.DMVR60244.mrtwig@aol.com> for ; Sat, 1 Dec 2001 07:58:58 -0600 From moopups@citlink.net Sat, 01 Dec 2001 05:54:57 -0800 X-Priority: 3 X-MSMail-Priority: Normal X-Unsent: 1 Message-Id: <20011201135858.DMVR60244.mrtwig@Aol.com

-- Rick (Rick_122@hotmail.com), December 01, 2001.


Rick, I do not know how to interpuret what is written above, can you explain? Also, how does one empty the trash at email? This morning I tried the norton virus scan program, it took about 40 minutes and turned up nothing. I also posted the question about stacked pages on CS and got wide versions of answers, the thread is named "My puter is too full". During the norton scan there was a check in the box saying, "Your master boot has changed...." so I put it back to original before running the scan and also did a tempoary file delete as suggested by poster on CS.

-- mitch hearn (moopups@citlink.net), December 01, 2001.

Mitch:

Attachment: New_Napster_Site.MP3.PIF

This is the name of the offending virus (I believe).

As far as the rest goes, it's greek to me too! I do see IP addresses [207.173.229.137], aol.com ([170.215.144.139]),which may help someone track down a culprit. I see aol.com above, and mrtwig@aol.com which appears to be a mrtwig at aol.com. Could he be impersonating you. If so then you might not have a virus. I also see mrtwig.citlink.net which fuses mrtwig onto your isp - citlink.net

"how does one empty the trash at email?

What email do you use. My netscape messenger area has a trash folder. Here you can click an e-mail, hit delete to delete trash 1 by 1. hold down ctrl key to highlight multiple items to delete all at one time.

This morning I tried the norton virus scan program, it took about 40 minutes and turned up nothing.

If your norton program is updated regularly, maybe you don't have a virus. If it has never been updated, then it may not know the new viruses.

Go to hotmail.com, and sign up!!

Speaking of signing up, wasn't a Master Boot something to avoid in the service?????

-- Rick (Rick_122@hotmail.com), December 01, 2001.


For whatever help it may be, below is the header info generated by an honest, lusenet robot generated forum email.

Received: from [66.37.213.170] by hotmail.com (3.2) with ESMTP id MHotMailBDD2339C004F40042A194225D5AA0C8E0; Sat, 01 Dec 2001 06:26:37 -0800 Received: (qmail 22960 invoked from network); 1 Dec 2001 14:27:35 -0000 Received: from unknown (HELO AOLserver?www.greenspun.com) (127.0.0.1) by localhost.lcs.mit.edu with SMTP; 1 Dec 2001 14:27:35 -0000 From moopups@citlink.net Sat, 01 Dec 2001 06:27:52 -0800

-- Rick (Rick_122@hotmail.com), December 01, 2001.


Rick and Mitch,

It appears Mitch has the Bad TransB virus (W32.Badtrans.B@mm). List of some attachment names are:

Pics * images * README * New_Napster_Site * news_doc * HAMSTER * YOU_are_FAT! * stuff * SETUP * Card * Me_nude * Sorry_about_yesterday * info * docs * Humor * fun

Please see following webpage at Symantec, it will give removal instructions.

http://securityresponse.symantec.com/avcenter/venc/data/w32.b adtrans.b@mm.html

Good luck.

-- Rheba (rhebabeall@hotmail.com), December 01, 2001.



Mitch

This should be ok to check... do a find / file / napster and see if the file is on your hard drive. Don't click on it if there is one. The one that I received that said you sent it was a PIF file.

-- Rick (Rick_122@hotmail.com), December 01, 2001.


Mitch, This is how I empty my discarded E-mails, when using outlook.

Go from inbox,double click "INBOX" and scroll down to deleted items. Double click, and open up file. Hold down CTRL button and click on each item to the end.

They will highlight blue. Open EDit, and click delete. If your fingers ache ( mine usually do) then just delete the highlighted ones and repeat.

This will permanently remove previously deleted E-mail. If there are tons of discards then it might be as well to do a defrag.

Go to programs, Accessories, System tools, Disc Defragmenter. Then follow the wizard. This seams to help sort out the rubbish into a better order. Here my knowledge ends.

Best wishes, and I hope this helps.

Alison

-- Alison Homa (Alisonhoma@hotmail.com), December 01, 2001.


Moderation questions? read the FAQ