 |
20-09-2004, 08:06 PM
|
#1 (permalink)
|
|
Rebooting
Join Date: Aug 2004
Location: 220.225.82.33
Posts: 6,266
|
Mail from Symantec ??? with virus
From past few days i'm getting emails on my yahoomail from support@symantec.com saing that...
"The sample file you sent contains a new virus version of buppa.k.
Please update your virus scanner with the attached dat file.
Best Regards,
Keria Reynolds"
but the attach file it self contails virus....... but yahoo online scan dont detects those viruses but my system does....... what is going on......
what should i do??
i use NAV04
|
|
|
|
Advertisements. Register and be a member of the community to get rid of them.
|
|
Advertisement
|
|
20-09-2004, 08:51 PM
|
#2 (permalink)
|
|
Right Off the Assembly Line
Join Date: Sep 2004
Location: Calcutta
Posts: 23
|
Dear Saurav,
The mails, which you are getting are not from Symantec at all. Someone else is sending you those mails by faking the Symantec ID. The attachments are virus infected, indeed. Please put the ID support@symantec.com to your block list and never download any attachment from any unknown source.
__________________
Souvik Sinha
|
|
|
09-08-2005, 04:44 PM
|
#3 (permalink)
|
|
Rebooting
Join Date: Aug 2004
Location: 220.225.82.33
Posts: 6,266
|
well the emails r back again... from this IP 202.141.21.245
__________________
rebooting
ChotoCheeta.com
|
|
|
09-08-2005, 04:55 PM
|
#4 (permalink)
|
|
Rebooting
Join Date: Aug 2004
Location: 220.225.82.33
Posts: 6,266
|
Quote:
IP address:
Looking for '202.141.21.245'
Server reply [1022 bytes in raw data]:
inetnum: 202.141.20.0 - 202.141.23.255
netname: ERNET-SATWAN
country: IN
descr: ERNET India
descr: Department of Information Technology
descr: Electronics Niketan
descr: 6, CGO Complex
descr: New Delhi - 110003
admin-c: AS384-AP
tech-c: AS384-AP
status: ASSIGNED NON-PORTABLE
changed: apnic@eis.ernet.in 20040903
mnt-by: MAINT-AP-ERNET-INDIA
changed: hm-changed@apnic.net 20040903
source: APNIC
person: Anupam Srivastava
nic-hdl: AS384-AP
e-mail: anupam@eis.ernet.in
address: ERNET India
address: Electronics Niketan, 6 C.G.O Complex
address: New Delhi-110003
address:
phone: +91-11-24361329
fax-no: +91-11-24362924
country: IN
changed: apnic-maintainer-alarm@eis.ernet.in 20041229
mnt-by: MAINT-IN-CUSTOMER-ERNET
source: APNIC
---
|
guyes... check the IP trace... humm Department of Information Technology..... well as a reciever of this email do i have right to complain... but if i do then whom to complain??
__________________
rebooting
ChotoCheeta.com
|
|
|
09-08-2005, 05:04 PM
|
#5 (permalink)
|
|
Wise Old Owl
Join Date: Jul 2004
Location: Bangalore
Posts: 1,208
|
just ignore them. There is no point in blocking these mails either. As they will appear from different ID's which all will sound extremely credible (such as admin@symantec.com and so on). Just delete them and forget abt it. If you are using yahoo then turn on your junk mail filters. They are very very good.
__________________
AMD 64 3500+ Venice
DFI Lan Party Ultra-D
2* 512 MB PdP Memory with 2-2-5L timings
XFX 7900GT 256 MB Card
|
|
|
09-08-2005, 05:08 PM
|
#6 (permalink)
|
|
Rebooting
Join Date: Aug 2004
Location: 220.225.82.33
Posts: 6,266
|
Quote:
|
Originally Posted by icecoolz
just ignore them
|
which i have did a year back... emails were stoped then... but they r back again... so what about this??
Quote:
|
Originally Posted by I
guyes... check the IP trace... humm Department of Information Technology..... well as a reciever of this email do i have right to complain... but if i do then whom to complain??
|
__________________
rebooting
ChotoCheeta.com
|
|
|
09-08-2005, 06:53 PM
|
#7 (permalink)
|
|
Right Off the Assembly Line
Join Date: Nov 2004
Location: bunker
Posts: 27
|
yes..
I used to get it long before. delete it as soon as u get
thats the safe way.
and dont forget to enmpty trash.
Cleanup(delete) the quarentine stuff if any
Do nothin else
thats the safe way out as Saurav said
__________________
hell\'s full so I\'m back!
---------------------------------
CPU 2GHz +AGP 128MB+ RAM 512 DDR
just for an OS ! heh !
|
|
|
09-08-2005, 07:00 PM
|
#8 (permalink)
|
|
Commander in Chief
Join Date: Jul 2005
Posts: 6,658
|
Wait i think ur infected file if anny has been autosent by nav to sym, thus the mail...
__________________
Harsh J
www.harshj.com
|
|
|
09-08-2005, 07:07 PM
|
#9 (permalink)
|
|
Human Spambot
Join Date: May 2005
Location: Expert Planet
Posts: 2,480
|
????????
Quote:
|
Originally Posted by QwertyManiac
Wait i think ur infected file if anny has been autosent by nav to sym, thus the mail...
|
what do you meant ?
__________________
Off From Digit Forum for some months.....busy
|
|
|
09-08-2005, 08:25 PM
|
#10 (permalink)
|
|
Alpha Geek
Join Date: Dec 2003
Location: mumbai
Posts: 522
|
dumo it straight !!!!!!!!
|
|
|
09-08-2005, 08:27 PM
|
#11 (permalink)
|
|
Alpha Geek
Join Date: Dec 2003
Location: mumbai
Posts: 522
|
dump it straight to the kachra bin !!!!!!!!
|
|
|
09-08-2005, 08:51 PM
|
#12 (permalink)
|
|
Commander in Chief
Join Date: Jul 2005
Posts: 6,658
|
Re: ????????
Quote:
|
Originally Posted by expertno.1
Quote:
|
Originally Posted by QwertyManiac
Wait i think ur infected file if anny has been autosent by nav to sym, thus the mail...
|
what do you meant ?
|
I meant that sometimes when an unknown virus is detected by NAV or it cant repair then it sends it to SYM for verification and free repair, this has an auto mode too... Thus it reminds again via mail...
Edit :
Bout the yahoo non detection, it has NAV 2005 from sym and thus it trusts the SYM server for thier mail wont it ? (backdoor in NAV ?)
__________________
Harsh J
www.harshj.com
|
|
|
10-08-2005, 01:12 AM
|
#13 (permalink)
|
|
Wise Old Owl
Join Date: Feb 2004
Location: Palghar, Mumbai
Posts: 1,000
|
Norton never sends mail to its users.. These all mails are SPAM and virus itself.
__________________
i generally prefer quality over quantity
1 aadi + 1 aadi = 1 full ;)
|
|
|
10-08-2005, 06:48 AM
|
#14 (permalink)
|
|
Alpha Geek
Join Date: Jul 2004
Location: West Bengal
Posts: 625
|
Re: Mail from Symantec ??? with virus
Quote:
|
Originally Posted by saurav_cheeta
From past few days i'm getting emails on my yahoomail from support@symantec.com saing that...
"The sample file you sent contains a new virus version of buppa.k.
Please update your virus scanner with the attached dat file.
Best Regards,
Keria Reynolds"
but the attach file it self contails virus....... but yahoo online scan dont detects those viruses but my system does....... what is going on......
what should i do??
i use NAV04
|
Dear Saurav this mail itsellllllf is a virus.just delete it
__________________
Bombina rocks
|
|
|
10-08-2005, 02:40 PM
|
#15 (permalink)
|
|
Rebooting
Join Date: Aug 2004
Location: 220.225.82.33
Posts: 6,266
|
@ sidewinder the messege u queted... was writen by me a year ago.. so i did deleted them, i did IGGY them... no problem with that...
but From the IP which i wrote... trace that one.. see where it leads u.. is that a privet Company?? GOV office or ISP... as they r sending that email (may b they anware of it)... so thought notifing them... & also Symantec.... so do one has the right to complain??
& also can we really call it spam?? as its not advertising some thing.... rather its an attack...
& yes the NAV of YAHOO cant find that virus....
Quote:
|
Originally Posted by QwertyManiac
I meant that sometimes when an unknown virus is detected by NAV or it cant repair then it sends it to SYM for verification and free repair, this has an auto mode too... Thus it reminds again via mail...
|
well i used to use NAV long time ago... but for previous 10 or 8 months i am useing KAV 5.0.372.... so no question of my system sending some thing to their server....
Quote:
|
Originally Posted by aadipa
Norton never sends mail to its users..
|
r u sure mate... as i see u have a brainiac tag so i am not going to argue with u... but i saw when some one donwloads any Trail product from sysmantec.... he/she gets mail from symantec notifing them about how many days r left.... what will it cost... about new product update... & guess what?? their address is same...
__________________
rebooting
ChotoCheeta.com
|
|
|
10-08-2005, 09:47 PM
|
#16 (permalink)
|
|
Broken In
Join Date: Jun 2004
Posts: 164
|
When I was using Norton some months back I did send a virus as attachment to them and also gave my email id. First an acknowledgment was received auto generated then after 1 or 2 day another mail saying that particular virus is not a big problem and advising virus update. So symentec does send email.
But if you are not using norton someone somewhere is trying to send a virus. After all norton is most popular anti virus so the probability reaching someone who is using norton is more.
Poor fellows don't know saurav_cheeta is smart and digitized
__________________
WHEN THERE IS LIFE, THERE IS HOPE...
TILL THERE IS BREATH, THERE IS HOPE
Give free food with one click to a poor Indian.
http://www.bhookh.com/
|
|
|
10-08-2005, 11:18 PM
|
#17 (permalink)
|
|
In The Zone
Join Date: Sep 2004
Posts: 433
|
I would use a tracert then notify abuse @ each node I find. Usually I have found that they will reply. If I don't get a reply I will go up each node and no admin wants to get 1000 emails complaining about someone who rents/leases/uses their network is causing problems so they will do something. Especially one of the big ISP's.
I usually start with the last node itself, usually it is the local ISP from where the virus was sent and he would know who was sending it out and block their access. It is not good to go to regional levels. Then not only that ISP but everyone else sharing those lines might get blocked.
Now some of these guys think they are big shots, which is why block lists came into being. No one wants to get on a block list. Because then zillions of people who use automatic block-lists will automatically be blocked from their domains. So no one wants to piss off anyone these days.
I looked at Peer guardian, It blocks over 80% of the internet.
|
|
|
11-08-2005, 11:03 AM
|
#18 (permalink)
|
|
Wise Old Owl
Join Date: Feb 2004
Location: Palghar, Mumbai
Posts: 1,000
|
__________________
i generally prefer quality over quantity
1 aadi + 1 aadi = 1 full ;)
|
|
|
11-08-2005, 11:20 AM
|
#19 (permalink)
|
|
Wise Old Owl
Join Date: Feb 2004
Location: Palghar, Mumbai
Posts: 1,000
|
[quote=aadipa]"saurav_cheeta
Quote:
|
Originally Posted by aadipa
Norton never sends mail to its users..
|
r u sure mate... as i see u have a brainiac tag so i am not going to argue with u... but i saw when some one donwloads any Trail product from sysmantec.... he/she gets mail from symantec notifing them about how many days r left.... what will it cost... about new product update... & guess what?? their address is same...[/quote:52166fe0a3]
The senders address can be fished with so don't trust it. BTW I was wrong on the claim that Norton/Symantec will not send _any_ email. Infact they do send. But they don't think they send patches/virus definition updates by email.
__________________
i generally prefer quality over quantity
1 aadi + 1 aadi = 1 full ;)
|
|
|
11-08-2005, 04:29 PM
|
#20 (permalink)
|
|
Rebooting
Join Date: Aug 2004
Location: 220.225.82.33
Posts: 6,266
|
Quote:
|
Originally Posted by aadipa
This is a virus... For further info have a look at
|
yup... but that virus has a host... a computer whos owner doesnt know about it... & he/she might have my email address on his/her address list... thats why i was asking u guess for a trace or who is look up... i did by my self & posted that here...
Quote:
|
Originally Posted by Aadipa
The senders address can be fished with so don't trust it. BTW I was wrong on the claim that Norton/Symantec will not send _any_ email. Infact they do send. But they don't think they send patches/virus definition updates by email.
|
thats the point.... there r telnet email sending procidure from that u can send an email from any ones address.... thats i know.... so the big question that comes to my mind is how to know...?? the way i know any one can impliment it to send an email with the name of my email..... so how to ID the emails??
__________________
rebooting
ChotoCheeta.com
|
|
|
12-08-2005, 07:46 AM
|
#21 (permalink)
|
|
In The Zone
Join Date: Sep 2004
Posts: 433
|
good luck TELNETting into symantec, breaking into their systems and trying to send out virii using their SMTP servers.
Its not impossible to do.
|
|
|
12-08-2005, 10:35 PM
|
#22 (permalink)
|
|
Rebooting
Join Date: Aug 2004
Location: 220.225.82.33
Posts: 6,266
|
@AlienTech i am not doing any thing with symantec... knowing the programme doesnt mean u have to use it... u might know how to open a car without a KEY.... but that doesnt mean u r going to open cars parked in street... r u??
my reply was.... how to know that the email the is in my inbox addressing from my frnds email address.... is his?? not some one used the TELNET to send that email...
__________________
rebooting
ChotoCheeta.com
|
|
|
14-08-2005, 06:11 PM
|
#23 (permalink)
|
|
In The Zone
Join Date: Jul 2005
Location: Hyderabad
Posts: 231
|
keep in mind 1 thing ppl never download any file that has a double extension as in this case it is
.doc.pif
__________________
fighting for peace is like ****ing for virginity
|
|
|
| Thread Tools |
|
|
| Display Modes |
Linear Mode
|
Posting Rules
|
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts
HTML code is Off
|
|
|
|
|
|