Forum     

Go Back   Digit Technology Discussion Forum > Software > Software Q&A
Register FAQ Calendar Mark Forums Read

Software Q&A Having trouble with software? Find solutions here


Closed Thread
 
LinkBack Thread Tools Display Modes
Old 20-09-2004, 08:06 PM   #1 (permalink)
Rebooting
 
Choto Cheeta's Avatar
 
Join Date: Aug 2004
Location: 220.225.82.33
Posts: 6,266
Default Mail from Symantec ??? with virus


From past few days i'm getting emails on my yahoomail from support@symantec.com saing that...

"The sample file you sent contains a new virus version of buppa.k.
Please update your virus scanner with the attached dat file.

Best Regards,
Keria Reynolds"

but the attach file it self contails virus....... but yahoo online scan dont detects those viruses but my system does....... what is going on......

what should i do??

i use NAV04
Choto Cheeta is offline  
Advertisements. Register and be a member of the community to get rid of them.
Advertisement

Old 20-09-2004, 08:51 PM   #2 (permalink)
Right Off the Assembly Line
 
Join Date: Sep 2004
Location: Calcutta
Posts: 23
Default

Dear Saurav,
The mails, which you are getting are not from Symantec at all. Someone else is sending you those mails by faking the Symantec ID. The attachments are virus infected, indeed. Please put the ID support@symantec.com to your block list and never download any attachment from any unknown source.
__________________
Souvik Sinha
SouvikSinha is offline  
Old 09-08-2005, 04:44 PM   #3 (permalink)
Rebooting
 
Choto Cheeta's Avatar
 
Join Date: Aug 2004
Location: 220.225.82.33
Posts: 6,266
Default

well the emails r back again... from this IP 202.141.21.245

__________________
rebooting
ChotoCheeta.com
Choto Cheeta is offline  
Old 09-08-2005, 04:55 PM   #4 (permalink)
Rebooting
 
Choto Cheeta's Avatar
 
Join Date: Aug 2004
Location: 220.225.82.33
Posts: 6,266
Default

Quote:
IP address:
Looking for '202.141.21.245'

Server reply [1022 bytes in raw data]:

inetnum: 202.141.20.0 - 202.141.23.255
netname: ERNET-SATWAN
country: IN
descr: ERNET India
descr: Department of Information Technology
descr: Electronics Niketan
descr: 6, CGO Complex
descr: New Delhi - 110003
admin-c: AS384-AP
tech-c: AS384-AP
status: ASSIGNED NON-PORTABLE
changed: apnic@eis.ernet.in 20040903
mnt-by: MAINT-AP-ERNET-INDIA
changed: hm-changed@apnic.net 20040903
source: APNIC

person: Anupam Srivastava
nic-hdl: AS384-AP
e-mail: anupam@eis.ernet.in
address: ERNET India
address: Electronics Niketan, 6 C.G.O Complex
address: New Delhi-110003
address:
phone: +91-11-24361329
fax-no: +91-11-24362924
country: IN
changed: apnic-maintainer-alarm@eis.ernet.in 20041229
mnt-by: MAINT-IN-CUSTOMER-ERNET
source: APNIC



---
guyes... check the IP trace... humm Department of Information Technology..... well as a reciever of this email do i have right to complain... but if i do then whom to complain??
__________________
rebooting
ChotoCheeta.com
Choto Cheeta is offline  
Old 09-08-2005, 05:04 PM   #5 (permalink)
Wise Old Owl
 
Join Date: Jul 2004
Location: Bangalore
Posts: 1,208
Default

just ignore them. There is no point in blocking these mails either. As they will appear from different ID's which all will sound extremely credible (such as admin@symantec.com and so on). Just delete them and forget abt it. If you are using yahoo then turn on your junk mail filters. They are very very good.
__________________
AMD 64 3500+ Venice
DFI Lan Party Ultra-D
2* 512 MB PdP Memory with 2-2-5L timings
XFX 7900GT 256 MB Card
icecoolz is offline  
Old 09-08-2005, 05:08 PM   #6 (permalink)
Rebooting
 
Choto Cheeta's Avatar
 
Join Date: Aug 2004
Location: 220.225.82.33
Posts: 6,266
Default

Quote:
Originally Posted by icecoolz
just ignore them
which i have did a year back... emails were stoped then... but they r back again... so what about this??

Quote:
Originally Posted by I
guyes... check the IP trace... humm Department of Information Technology..... well as a reciever of this email do i have right to complain... but if i do then whom to complain??
__________________
rebooting
ChotoCheeta.com
Choto Cheeta is offline  
Old 09-08-2005, 06:53 PM   #7 (permalink)
Right Off the Assembly Line
 
Join Date: Nov 2004
Location: bunker
Posts: 27
Default

yes..

I used to get it long before. delete it as soon as u get
thats the safe way.
and dont forget to enmpty trash.
Cleanup(delete) the quarentine stuff if any

Do nothin else
thats the safe way out as Saurav said
__________________
hell\'s full so I\'m back!
---------------------------------
CPU 2GHz +AGP 128MB+ RAM 512 DDR
just for an OS ! heh !
Intruder is offline  
Old 09-08-2005, 07:00 PM   #8 (permalink)
Commander in Chief
 
QwertyManiac's Avatar
 
Join Date: Jul 2005
Posts: 6,658
Default

Wait i think ur infected file if anny has been autosent by nav to sym, thus the mail...
__________________
Harsh J
www.harshj.com
QwertyManiac is offline  
Old 09-08-2005, 07:07 PM   #9 (permalink)
Human Spambot
 
expertno.1's Avatar
 
Join Date: May 2005
Location: Expert Planet
Posts: 2,480
Default ????????

Quote:
Originally Posted by QwertyManiac
Wait i think ur infected file if anny has been autosent by nav to sym, thus the mail...
what do you meant ?
__________________
Off From Digit Forum for some months.....busy
expertno.1 is offline  
Old 09-08-2005, 08:25 PM   #10 (permalink)
Alpha Geek
 
mariner's Avatar
 
Join Date: Dec 2003
Location: mumbai
Posts: 522
Default

dumo it straight !!!!!!!!
mariner is offline  
Old 09-08-2005, 08:27 PM   #11 (permalink)
Alpha Geek
 
mariner's Avatar
 
Join Date: Dec 2003
Location: mumbai
Posts: 522
Default

dump it straight to the kachra bin !!!!!!!!
mariner is offline  
Old 09-08-2005, 08:51 PM   #12 (permalink)
Commander in Chief
 
QwertyManiac's Avatar
 
Join Date: Jul 2005
Posts: 6,658
Default Re: ????????

Quote:
Originally Posted by expertno.1
Quote:
Originally Posted by QwertyManiac
Wait i think ur infected file if anny has been autosent by nav to sym, thus the mail...
what do you meant ?
I meant that sometimes when an unknown virus is detected by NAV or it cant repair then it sends it to SYM for verification and free repair, this has an auto mode too... Thus it reminds again via mail...

Edit :
Bout the yahoo non detection, it has NAV 2005 from sym and thus it trusts the SYM server for thier mail wont it ? (backdoor in NAV ?)
__________________
Harsh J
www.harshj.com
QwertyManiac is offline  
Old 10-08-2005, 01:12 AM   #13 (permalink)
Wise Old Owl
 
aadipa's Avatar
 
Join Date: Feb 2004
Location: Palghar, Mumbai
Posts: 1,000
Default

Norton never sends mail to its users.. These all mails are SPAM and virus itself.
__________________
i generally prefer quality over quantity
1 aadi + 1 aadi = 1 full ;)
aadipa is offline  
Old 10-08-2005, 06:48 AM   #14 (permalink)
Alpha Geek
 
sidewinder's Avatar
 
Join Date: Jul 2004
Location: West Bengal
Posts: 625
Default Re: Mail from Symantec ??? with virus

Quote:
Originally Posted by saurav_cheeta
From past few days i'm getting emails on my yahoomail from support@symantec.com saing that...

"The sample file you sent contains a new virus version of buppa.k.
Please update your virus scanner with the attached dat file.

Best Regards,
Keria Reynolds"

but the attach file it self contails virus....... but yahoo online scan dont detects those viruses but my system does....... what is going on......

what should i do??

i use NAV04
Dear Saurav this mail itsellllllf is a virus.just delete it
__________________
Bombina rocks
sidewinder is offline  
Old 10-08-2005, 02:40 PM   #15 (permalink)
Rebooting
 
Choto Cheeta's Avatar
 
Join Date: Aug 2004
Location: 220.225.82.33
Posts: 6,266
Default

@sidewinder the messege u queted... was writen by me a year ago.. so i did deleted them, i did IGGY them... no problem with that...


but From the IP which i wrote... trace that one.. see where it leads u.. is that a privet Company?? GOV office or ISP... as they r sending that email (may b they anware of it)... so thought notifing them... & also Symantec.... so do one has the right to complain??

& also can we really call it spam?? as its not advertising some thing.... rather its an attack...

& yes the NAV of YAHOO cant find that virus....

Quote:
Originally Posted by QwertyManiac
I meant that sometimes when an unknown virus is detected by NAV or it cant repair then it sends it to SYM for verification and free repair, this has an auto mode too... Thus it reminds again via mail...
well i used to use NAV long time ago... but for previous 10 or 8 months i am useing KAV 5.0.372.... so no question of my system sending some thing to their server....

Quote:
Originally Posted by aadipa
Norton never sends mail to its users..
r u sure mate... as i see u have a brainiac tag so i am not going to argue with u... but i saw when some one donwloads any Trail product from sysmantec.... he/she gets mail from symantec notifing them about how many days r left.... what will it cost... about new product update... & guess what?? their address is same...
__________________
rebooting
ChotoCheeta.com
Choto Cheeta is offline  
Old 10-08-2005, 09:47 PM   #16 (permalink)
Broken In
 
selva1966's Avatar
 
Join Date: Jun 2004
Posts: 164
Default

When I was using Norton some months back I did send a virus as attachment to them and also gave my email id. First an acknowledgment was received auto generated then after 1 or 2 day another mail saying that particular virus is not a big problem and advising virus update. So symentec does send email.

But if you are not using norton someone somewhere is trying to send a virus. After all norton is most popular anti virus so the probability reaching someone who is using norton is more.


Poor fellows don't know saurav_cheeta is smart and digitized
__________________
WHEN THERE IS LIFE, THERE IS HOPE...
TILL THERE IS BREATH, THERE IS HOPE

Give free food with one click to a poor Indian.
http://www.bhookh.com/
selva1966 is offline  
Old 10-08-2005, 11:18 PM   #17 (permalink)
In The Zone
 
Join Date: Sep 2004
Posts: 433
Default

I would use a tracert then notify abuse @ each node I find. Usually I have found that they will reply. If I don't get a reply I will go up each node and no admin wants to get 1000 emails complaining about someone who rents/leases/uses their network is causing problems so they will do something. Especially one of the big ISP's.

I usually start with the last node itself, usually it is the local ISP from where the virus was sent and he would know who was sending it out and block their access. It is not good to go to regional levels. Then not only that ISP but everyone else sharing those lines might get blocked.

Now some of these guys think they are big shots, which is why block lists came into being. No one wants to get on a block list. Because then zillions of people who use automatic block-lists will automatically be blocked from their domains. So no one wants to piss off anyone these days.

I looked at Peer guardian, It blocks over 80% of the internet.
AlienTech is offline  
Old 11-08-2005, 11:03 AM   #18 (permalink)
Wise Old Owl
 
aadipa's Avatar
 
Join Date: Feb 2004
Location: Palghar, Mumbai
Posts: 1,000
Default

This is a virus... For further info have a look at

http://securityresponse.symantec.com...tsky.p@mm.html
__________________
i generally prefer quality over quantity
1 aadi + 1 aadi = 1 full ;)
aadipa is offline  
Old 11-08-2005, 11:20 AM   #19 (permalink)
Wise Old Owl
 
aadipa's Avatar
 
Join Date: Feb 2004
Location: Palghar, Mumbai
Posts: 1,000
Default

[quote=aadipa]"saurav_cheeta
Quote:
Originally Posted by aadipa
Norton never sends mail to its users..
r u sure mate... as i see u have a brainiac tag so i am not going to argue with u... but i saw when some one donwloads any Trail product from sysmantec.... he/she gets mail from symantec notifing them about how many days r left.... what will it cost... about new product update... & guess what?? their address is same...[/quote:52166fe0a3]

The senders address can be fished with so don't trust it. BTW I was wrong on the claim that Norton/Symantec will not send _any_ email. Infact they do send. But they don't think they send patches/virus definition updates by email.
__________________
i generally prefer quality over quantity
1 aadi + 1 aadi = 1 full ;)
aadipa is offline  
Old 11-08-2005, 04:29 PM   #20 (permalink)
Rebooting
 
Choto Cheeta's Avatar
 
Join Date: Aug 2004
Location: 220.225.82.33
Posts: 6,266
Default

Quote:
Originally Posted by aadipa
This is a virus... For further info have a look at
yup... but that virus has a host... a computer whos owner doesnt know about it... & he/she might have my email address on his/her address list... thats why i was asking u guess for a trace or who is look up... i did by my self & posted that here...

Quote:
Originally Posted by Aadipa
The senders address can be fished with so don't trust it. BTW I was wrong on the claim that Norton/Symantec will not send _any_ email. Infact they do send. But they don't think they send patches/virus definition updates by email.
thats the point.... there r telnet email sending procidure from that u can send an email from any ones address.... thats i know.... so the big question that comes to my mind is how to know...?? the way i know any one can impliment it to send an email with the name of my email..... so how to ID the emails??
__________________
rebooting
ChotoCheeta.com
Choto Cheeta is offline  
Old 12-08-2005, 07:46 AM   #21 (permalink)
In The Zone
 
Join Date: Sep 2004
Posts: 433
Default

good luck TELNETting into symantec, breaking into their systems and trying to send out virii using their SMTP servers.

Its not impossible to do.
AlienTech is offline  
Old 12-08-2005, 10:35 PM   #22 (permalink)
Rebooting
 
Choto Cheeta's Avatar
 
Join Date: Aug 2004
Location: 220.225.82.33
Posts: 6,266
Default

@AlienTech i am not doing any thing with symantec... knowing the programme doesnt mean u have to use it... u might know how to open a car without a KEY.... but that doesnt mean u r going to open cars parked in street... r u??

my reply was.... how to know that the email the is in my inbox addressing from my frnds email address.... is his?? not some one used the TELNET to send that email...
__________________
rebooting
ChotoCheeta.com
Choto Cheeta is offline  
Old 14-08-2005, 06:11 PM   #23 (permalink)
In The Zone
 
Join Date: Jul 2005
Location: Hyderabad
Posts: 231
Default

keep in mind 1 thing ppl never download any file that has a double extension as in this case it is

.doc.pif
__________________
fighting for peace is like ****ing for virginity
cryptid is offline  
Closed Thread

Bookmarks

Thread Tools
Display Modes

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is On
HTML code is Off
Trackbacks are On
Pingbacks are On
Refbacks are On


 
Latest Threads
- by topgear
- by abhidev
- by clmlbx
- by Sarath

Advertisement




All times are GMT +5.5. The time now is 03:28 AM.


Powered by vBulletin® Version 3.8.7
Copyright ©2000 - 2012, vBulletin Solutions, Inc.

Search Engine Optimization by vBSEO 3.3.2