Site Suggestions & Problems Bring up any suggestions, questions or problems concerning ClubLexus. If you need to test a forum feature, post here too. Note - questions about your Lexus do not belong in this forum!

possible virus?

Thread Tools
 
Search this Thread
 
Old 05-13-04, 04:11 PM
  #1  
TGRich
Lexus Champion
Thread Starter
 
TGRich's Avatar
 
Join Date: May 2002
Location: California
Posts: 1,957
Likes: 0
Received 2 Likes on 2 Posts
Default possible virus?

I just got an email from "Knowlton" ( knowlton1@clublexus.com) with the subject of "forum notify". There was an attachment titled text_document.com with the size of 20.8k

Does anyone know what this is?
Old 05-14-04, 06:32 AM
  #2  
DaveGS4
Forum Administrator

iTrader: (2)
 
DaveGS4's Avatar
 
Join Date: Feb 2001
Location: North Carolina
Posts: 31,530
Received 2,252 Likes on 1,366 Posts
Default

That's not a valid CL email address, but I've received lots of these similar spoof emails at my work account and also some on my personal accounts.

Do not open the file, if you have you should immediately update your virus signature file and run a full scan.

The virus sounds very similar to the beagle virus, probably a variant.

http://securityresponse.symantec.com...agle.a@mm.html
Old 05-14-04, 07:03 AM
  #3  
TGRich
Lexus Champion
Thread Starter
 
TGRich's Avatar
 
Join Date: May 2002
Location: California
Posts: 1,957
Likes: 0
Received 2 Likes on 2 Posts
Default

Thanks Dave. It's wierd though b/c I ran my virus scanner over it (which updates automatically) and it didn't catch anything.
Old 05-14-04, 02:54 PM
  #4  
TGRich
Lexus Champion
Thread Starter
 
TGRich's Avatar
 
Join Date: May 2002
Location: California
Posts: 1,957
Likes: 0
Received 2 Likes on 2 Posts
Default

This is an email from my ISP that I got today You were right, the bagle virus. What I would like to know though is how this dude uses the clublexus.com domain name??


Tim


An email was sent to you that we have identified as containing a virus. Below find the details of the infected message:

From: knowlton1@clublexus.com
Date: Fri, 14 May 2004 13:18:04 -0400
Virus Name: W32/Bagle.ab@MM
Infected Attachments: 000002bf.EML, /Details.com

To protect you from destructive Internet viruses, your *** High Speed Internet service now includes a free anti-virus security enhancement. This security enhancement detects and prevents the delivery of most viruses transmitted via email so that your personal computers will not be harmed.

This is an auto-generated message. Please do not reply. For more information on how this security enhancement works, please visit *** Customer Support at the following location:

http://usercenter.***.net/rsuite/sdc...fety/virus.htm

Please note that *** does not read the content (text) of your email messages. This security enhancement only detects known viruses.

This anti-virus security enhancement of your *** High Speed Internet service is applied when your email comes through our email servers and is intended to provide protection against most identified viruses transmitted via email. In order to complete your anti-virus protection, it is recommend that you install and use PC-based anti-virus software on your PC; this will protect you from viruses transmitted through Web sites, Internet downloads, and via diskettes, portable drives, etc. *** High Speed Internet's email anti-virus security enhancement will not prevent downloading of virus-infected files, nor will it remove viruses already present on your computer.

Sincerely,

The *** High Speed Internet Team
Old 05-14-04, 03:05 PM
  #5  
DaveGS4
Forum Administrator

iTrader: (2)
 
DaveGS4's Avatar
 
Join Date: Feb 2001
Location: North Carolina
Posts: 31,530
Received 2,252 Likes on 1,366 Posts
Default

The virus just spoofs the domain, it's not really sent from CL. Just like spammers make it look like emails come from AOL, etc.
Old 05-15-04, 01:10 PM
  #6  
Captain Bone
Lexus Champion
 
Captain Bone's Avatar
 
Join Date: Jul 2002
Location: Hamilton, NJ
Posts: 4,104
Likes: 0
Received 0 Likes on 0 Posts
Default

Originally posted by DaveGS4
The virus just spoofs the domain, it's not really sent from CL. Just like spammers make it look like emails come from AOL, etc.
Dave is right. Most of these people use Anonymous mailers that mask the real address and put in a fake one.

-Anthony
Related Topics
Thread
Thread Starter
Forum
Replies
Last Post
Blue98Gs3
Site Suggestions & Problems
4
01-20-11 05:20 PM
Richie
Site Suggestions & Problems
9
10-18-01 07:33 AM



Quick Reply: possible virus?



All times are GMT -7. The time now is 09:42 PM.