Advertisement
If you have a new account but are having problems posting or verifying your account, please email us on hello@boards.ie for help. Thanks :)
Hello all! Please ensure that you are posting a new thread or question in the appropriate forum. The Feedback forum is overwhelmed with questions that are having to be moved elsewhere. If you need help to verify your account contact hello@boards.ie
Hi there,
There is an issue with role permissions that is being worked on at the moment.
If you are having trouble with access or permissions on regional forums please post here to get access: https://www.boards.ie/discussion/2058365403/you-do-not-have-permission-for-that#latest

Ann: Virus Targeted at Irish Users

  • 05-03-2004 6:54pm
    #1
    Registered Users, Registered Users 2 Posts: 477 ✭✭


    I received the following email virus today.

    Didn't infect me as I didn't open the attached .pif file, this is just a warning to other Esat and other Irish ISP users as I see in ie.comp that at least one other person using Oceanfree got a different version of this.

    This is the first time I have seen a virus specifically targeted at Irish users. I would be concerned that users of Irish ISP's may have families using email accounts with them, who do not fully appreciate the problem of viruses and the need not to open attachments.


    Martin Harran

    (Mods: if you think this is OT then feel free to move it, I just thought it worthwhile giving an early warning to other users and wasn't sure what was best forum to post it)

    Hello user of Esatclear.ie e-mail server,

    Your e-mail account will be disabled because of improper using in next
    three days, if you are still wishing to use it, please, resign your
    account information.

    Advanced details can be found in attached file.

    Have a good day,
    The Esatclear.ie team


Comments

  • Registered Users, Registered Users 2 Posts: 6,007 ✭✭✭Moriarty


    Moved to security.

    It looks like its a generic script that sticks in the tld of your email addy and appends an admin@ to it making it look like its from your provider, rather than anything thats targeting irish people specifically.


  • Registered Users, Registered Users 2 Posts: 815 ✭✭✭mickeyboymel


    Norton have stopped 6 emails similiar to this as described only preporting to be from Eircom in my case, this afternoon.,(infect=W32BEAGLE), in the form or undeliverable email notification and security issues:



    Dear user of "Eircom.net" mailing system,

    Some of our clients complained about the spam (negative e-mail content)
    outgoing from your e-mail account. Probably, you have been infected by
    a proxy-relay trojan server. In order to keep your computer safe,
    follow the instructions.

    For details see the attach.

    In order to read the attach you have to use the following password: 56376.

    Sincerely,
    The Eircom.net team

    also

    Hi. This is the qmail-send program at eircom.net.
    I'm afraid I wasn't able to deliver your message to the following addresses.
    This is a permanent error; I've given up. Sorry it didn't work out.



    EDIT - sorry did not realise a similar post/thread appears further down


  • Moderators, Recreation & Hobbies Moderators, Science, Health & Environment Moderators, Technology & Internet Moderators Posts: 92,986 Mod ✭✭✭✭Capt'n Midnight


    Originally posted by DonegalMan
    Hello user of [Insert Domain name] e-mail server,
    
    Your e-mail account will be disabled because of improper using in next
    three days,[u] if you are still wishing to use it, please, resign your[/u]
    account information.
    
    Advanced details can be found in attached file.
    
    Have a good day,
    The [Insert Domain name] team
    

    improper using ?
    wishing to use it ?
    resign ?

    Not the sort of diction / grammer you would expect from someone in these parts - that in and of itself should set alarms ringing ! A grammer checker would remove a lot of viruses and spam - if script kiddies ever learn to speak propper - we're screwed :D


  • Closed Accounts Posts: 5,756 ✭✭✭demanufactured


    Scan result: Virus "W32.Netsky.D@mm" found.
    The file attached to this message was infected with a virus that we were unable to clean. You can not download this attachment.

    Been gettin that in my yahoo mail for 2 weeks , from loads of different addresses


  • Banned (with Prison Access) Posts: 13,018 ✭✭✭✭jank


    yea i got that too,
    spotted it a mile off

    and im getting fecking "microsoft" patches updates too for the last 2 months now


  • Advertisement
  • Closed Accounts Posts: 1,819 ✭✭✭K!LL!@N


    I read an email from someone who replied to one of those emails saying they'd been unable to open the attachment so they took it to a computer repair guy who was able to open the zip file and run the file inside. They added that running the file didn't seem to do anything. And they asked for advice on how to proceed. :rolleyes:

    Killian


  • Registered Users, Registered Users 2 Posts: 10,846 ✭✭✭✭eth0_


    Originally posted by Capt'n Midnight
    A grammer checker would remove a lot of viruses and spam - if script kiddies ever learn to speak propper - we're screwed :D


    haha :) So true. If anyone fell for that first mail, they need a smack in the face.


  • Moderators, Recreation & Hobbies Moderators, Science, Health & Environment Moderators, Technology & Internet Moderators Posts: 92,986 Mod ✭✭✭✭Capt'n Midnight


    Originally posted by K!LL!@N
    I read an email from someone who replied to one of those emails saying they'd been unable to open the attachment so they took it to a computer repair guy who was able to open the zip file and run the file inside. They added that running the file didn't seem to do anything. And they asked for advice on how to proceed. :rolleyes:

    Killian
    It's either NetSky or Bagle - and it's all over your system

    It didn't seem to do anything - but it did.....


  • Closed Accounts Posts: 1,819 ✭✭✭K!LL!@N


    Originally posted by Capt'n Midnight
    It's either NetSky or Bagle - and it's all over your system

    It didn't seem to do anything - but it did.....


    Read my post again. ;)

    I was talking about someone else.

    Killian


  • Registered Users, Registered Users 2 Posts: 68,317 ✭✭✭✭seamus


    Originally posted by mickeyboymel
    also

    Hi. This is the qmail-send program at eircom.net.
    I'm afraid I wasn't able to deliver your message to the following addresses.
    This is a permanent error; I've given up. Sorry it didn't work out.
    That's a valid email. That's the response you get from eircom.net's servers when it can't deliver a mail. Chances are your address was included in a spoofed email, but the mail-to address was invalid.


  • Advertisement
Advertisement