|
BbSupport Forums :: Tech Support :: I regularly receive a Trojan Horse virus when I access this site.
Who's Online :: Stats :: Search :: Lost Password :: BbChat
Please read this thread about free boards being deleted.
If you cannot log in please check the date and time on your computer because that will prevent you from logging in properly.
Just a reminder that all customization questions will be moved to the BbHelper's CCT forum. This forum is only for Tech Support issues relating to your BbBoard or user account. If your topic appears to be missing, check the other forums in case it was moved there, or alternatively, merged with another thread on the same topic in this forum. If you believe you've encountered a bug, please read here before posting a bug report in the proper forum. If you start a new thread or post in someone else's, please be sure to click the "Notify" button after posting - that way you will know when replies are made to it. We are locking threads that are resolved so if you have a issue that you feel is unresolved that was posted in a locked thread, please begin a new one. Thank you all for you BbSupport!

Welcome, Register :: Log In | | Users active in this forum: | Users active in this thread: |
fionah Offline 17 posts Newbie
Reply
|
I regularly receive a Trojan Horse virus when I access this site. ( 11:39:36 FriApr 2 2004 ) | |
Board Plan: Fixed
Why?
Board URL: http://frost.bbboy.net/generalmalaise
|
fionah Offline 17 posts Newbie
Reply
|
Re: I regularly receive a Trojan Horse virus when I access this site. ( 15:25:08 FriApr 9 2004 ) | |
When I access our site, I sometimes receive a Trojan horse virus -" Achtung" something. It's always the same virus, and i only receive it when I open our Bbboy site.
|
fionah Offline 17 posts Newbie
Reply
|
Re: I regularly receive a Trojan Horse virus when I access this site. ( 12:31:13 SatApr 10 2004 ) | |
It only emerges when I access this site. Norton Anti-Virus always catches it (I hope). I googled the "Achtung" virus, and all listed sites were in German.
|
debbey Offline 5 posts Newbie

 Mood Now:  Reply
|
Re: I regularly receive a Trojan Horse virus when I access this site. ( 18:49:36 SatApr 10 2004 ) | |
ok.... here is the message I receive... from Norton.. Norton AntiVirus removed the attachment: message.scr. The W32.Netsky.P@mm threat was detected in the attachment. This is the virus your data base is sending out..  Cheers!
|
debbey Offline 5 posts Newbie

 Mood Now:  Reply
|
Re: I regularly receive a Trojan Horse virus when I access this site. ( 22:04:10 SatApr 10 2004 ) | |
from members actual email addresses.. with an attachment.. it's the attachment Norton keeps deleting.. per my previous post.. They have various reference lines.. Itnerary... or For Your Info... they are not spam.. they are coming from actual email addresses.. I will post the link to the virus description at Norton.. you can read about it http://securityresponse.symantec.com/avcenter/venc/data/w32.netsky.p@mm.htmlI just received another one: -----Original Message----- From: kimmi_vy@hotmail.com [mailto:kimmi_vy@hotmail.com] Sent: April 10, 2004 5:07 PM To: debbey@canadianstarsrock.ca Subject: Re: Secure SMTP Message ESMTP [Secure Mail System #334]: Secure message is attached. Cheers!
|
debbey Offline 5 posts Newbie

 Mood Now:  Reply
|
Re: I regularly receive a Trojan Horse virus when I access this site. ( 22:08:53 SatApr 10 2004 ) | |
From Norton:
W32.Netsky.P@mm Discovered on: March 21, 2004 Last Updated on: March 31, 2004 11:58:01 AM
As of March 22, 2004, due to an increase in submission rate, Symantec Security Response has upgraded W32.Netsky.P@mm (also known as W32.Netsky.Q@mm) to a Category 3 level threat from a Category 2 threat.
W32.Netsky.P@mm is a mass-mailing worm that uses its own SMTP engine to send itself to the email addresses it finds when scanning the hard drives and mapped drives. The worm also tries to spread through various file-sharing programs by copying itself into various shared folders.
The From line of the email is spoofed, and its Subject line and message body of the email vary. The attachment name varies with the .exe, .pif, .scr, or .zip file extension.
This worm also uses the Incorrect MIME Header Can Cause IE to Execute E-mail Attachment vulnerability to cause unpatched systems to auto-execute the worm when reading or previewing an infected message.
This threat is compressed with FSG.
-------------------------------------------------------------------------------- Note: Symantec Consumer products that support Worm Blocking functionality automatically detect this threat. The worm's executable has a static MD5 hash value of 0x0A9FFA57D65083C92E0D3D69B00F2F0D. Rapid release definitions dated March 21, 2004 or March 22, 2004 may detect this threat as W32.Netsky.Q@mm. Symantec Security Response has developed a removal tool to clean the infections of W32.Netsky.P@mm.
--------------------------------------------------------------------------------
Also Known As: W32.Netsky.Q@mm, W32/Netsky.p@MM [McAfee], Win32.Netsky.P [Computer Associates], NetSky.P [F-Secure], W32/Netsky.P.worm [Panda], W32/Netsky-P [Sophos], WORM_NETSKY.P [Trend] Type: Worm Infection Length: 29,568 bytes Systems Affected: Windows 2000, Windows 95, Windows 98, Windows Me, Windows NT, Windows Server 2003, Windows XP Systems Not Affected: DOS, Linux, Macintosh, OS/2, UNIX, Windows 3.x CVE References: CVE-2001-0154
Wild:
Number of infections: 50 - 999 Number of sites: More than 10 Geographical distribution: Medium Threat containment: Easy Removal: Moderate Threat Metrics Wild: High Damage: Medium Distribution: High
Damage
Payload Trigger: n/a Payload: n/a Large scale e-mailing: Sends itself to the email addresses retrieved from the file system. Deletes files: n/a Modifies files: n/a Degrades performance: n/a Causes system instability: n/a Releases confidential info: n/a Compromises security settings: n/a Distribution
Subject of email: Varies Name of attachment: Varies with the .exe, .pif, .scr, or .zip file extension. Size of attachment: Varies Time stamp of attachment: n/a Ports: n/a Shared drives: n/a Target of infection: n/a
|
Jollyfarmer Unavailable 53 posts Member
  
 Mood Now:  Post Mood:  Reply
|
Re: I regularly receive a Trojan Horse virus when I access this site. ( 22:17:26 MonApr 12 2004 ) | |
Achtung is different then the email problems others have stated. Achtung is a keylogger trojan. Keyloggers typically need to be in physically installed onto the computer that is infected. My guess would be that you already have the achtung.exe ON your computer, since it is a trojan that tries to log information such as passwords and the likes, Norton probably throws up the warning when you are the board because you are logging in triggering the trojan.... the board is not infected, your computer is.
As for the emails, netsky worm would not be embedded in bbboy's email servers anyway. I am quite sure they are guarded from such things as any major buisness/corporation is. I turn away, on average, at least 20 emails a day of the same virus with their attachments at my office email. The same goes for anyone else in this building that frequently receives emails in from infected people. Our company is not infected, it is those who've come infected with this special worm emailing us who are. As Nickdisc stated, it acts as a ghost, trying to make you think it is something legitamte from someone you know or has contacted you before. Again using the company I work for as an example, the virus sends an email out simular to what ours actually is. Example: ours would be something like administrator@thenet.com, we have found the virus ghosts that as theadministration@thenet.com which is in no way affiliated with anything of our company NOR sent out by our systems. Long rambling short, the chances you are receiving any of this stuff from bboy is extremely weak.
|
debbey Offline 5 posts Newbie

 Mood Now:  Reply
|
Re: I regularly receive a Trojan Horse virus when I access this site. ( 15:52:46 TueApr 13 2004 ) | |
Thank you for answering..  Ok.. I guess we just tolerate receiving the emails? and make sure our Norton is up to date? I guess I will contact my host server.. and ask if there is a way to have them deleted before they hit my email.. and how can I change my email address with BBBoy? is there a way of taking my addy your server..? Thank you again Debbey from: Rock n Rolla
|
fionah Offline 17 posts Newbie
Reply
|
Re: I regularly receive a Trojan Horse virus when I access this site. ( 10:38:24 WedApr 14 2004 ) | |
Another member of our board posted that she is receiving a virus when she accesses this site, too. And it only happens when we access this site. I do research on my home computer, and click on hundreds of links every week. The only time I receive a Norton virus warning is when I check my board, here.
|
people online in the last 15 minutes - 0 members, 0 anon and 0 guests. (Most ever was 129 at 22:49:41 Fri Oct 4 2002)
|
Total Members: 3336, Newest Member: Thagirion.
Can start a new thread. (Everyone)Can't start a new poll. (Mods & Admins)Can add a reply. (Everyone)Can't edit your posts. (Mods & Admins) | Register :: Log In :: In Power
The time is now 12:21:08 Mon May 16 2022
| Powered By BbBoard V1.4.2
© 2001-2007 BbBoy.net
| |