When is a virus not a virus...?
20-05-2004, 03:11
|
#1
|
Guest
|
When is a virus not a virus...?
Ok, here's a wierd one...
I got another one of those "This is a Micro$oft Update" e-mails seemingly trying to trick me into running the .exe attachment and infect my system.
Ho hum, thinks I, and I'm about to delete it when I suddenly realise that the message *doesn't* have a Norton AV warning of deletion in place of the attachment.
So I think "hello, that's odd" and get NAV to scan the attachment. To which it replies "it's clean".
Now this is strange, because it sure as hell *looks* like it's suspicious.
So I save the file, quarantine it, and send it off to Symantec for checking and get the reply back saying "this has been checked and it's the same as the official version of the install9.exe program"
This strikes me as totally bizarre. Someone sends out something that *looks* like a virus type message, but it's got perfectly legitimate content (and no other attachments), so what on *Earth* is the point?
Is someone *trying* to do me a favour by helping me to install updates on my system? (Not that I'd trust it anyway!) Is it a virus that's just really well concealed? (It doesn't seem to be)
Anyone got any ideas on this?
|
|
|
20-05-2004, 09:54
|
#2
|
Inactive
Join Date: Jul 2003
Posts: 2,820
|
Re: When is a virus not a virus...?
It could well be that Norton haven't identified it yet as a virus. It's worth sending them the email along with the attachment to do some testing on.
|
|
|
20-05-2004, 09:56
|
#3
|
cf.mega poster
Join Date: Jun 2003
Location: Up here
Posts: 36,520
|
Re: When is a virus not a virus...?
Or possibly it's someone trying to trick you in to thinking you've been sent something nasty without actually getting in to trouble themselves?
|
|
|
20-05-2004, 09:56
|
#4
|
Permanently Banned
Join Date: Apr 2004
Location: Salford(UK)
Age: 52
Posts: 976
|
Re: When is a virus not a virus...?
Hmm I'm always seeing people posting questions about virus's and for some reason its nearly always regarding Norton
|
|
|
20-05-2004, 16:30
|
#5
|
Inactive
Join Date: Oct 2003
Location: Bracknell
Age: 54
Services: NTL Telephone
3M Broadband - CM
Sky TV
Posts: 1,246
|
Re: When is a virus not a virus...?
Quote:
Originally Posted by andygrif
It could well be that Norton haven't identified it yet as a virus. It's worth sending them the email along with the attachment to do some testing on.
|
True, but Symantec said it was clean - and they are pretty quick at identifying virii once they are released...
Does seem strange though- Microsoft have never (to my knowledge) sent out any updates by Email.
Hmmm - a bit of googling tells me that this looks rather like the swen worm : see symantec's page - bit wierd that symantec said it looked ok though....
|
|
|
20-05-2004, 17:14
|
#6
|
Eva Longoria Fan
Join Date: Jun 2003
Location: Essex
Age: 36
Services: Sky multiroom (Sky Q)
Sky Fibre Unlimited
Sky Landline
Posts: 8,851
|
Re: When is a virus not a virus...?
Quote:
Originally Posted by zovat
True, but Symantec said it was clean - and they are pretty quick at identifying virii once they are released...
Does seem strange though- Microsoft have never (to my knowledge) sent out any updates by Email.
Hmmm - a bit of googling tells me that this looks rather like the swen worm : see symantec's page - bit wierd that symantec said it looked ok though....
|
M$ do have this stated on their website somewhere. You are right, they never send out emails containing patches.
|
|
|
20-05-2004, 17:17
|
#7
|
Eva Longoria Fan
Join Date: Jun 2003
Location: Essex
Age: 36
Services: Sky multiroom (Sky Q)
Sky Fibre Unlimited
Sky Landline
Posts: 8,851
|
Re: When is a virus not a virus...?
Quote:
Originally Posted by Graham
Ok, here's a wierd one...
I got another one of those "This is a Micro$oft Update" e-mails seemingly trying to trick me into running the .exe attachment and infect my system.
Ho hum, thinks I, and I'm about to delete it when I suddenly realise that the message *doesn't* have a Norton AV warning of deletion in place of the attachment.
So I think "hello, that's odd" and get NAV to scan the attachment. To which it replies "it's clean".
Now this is strange, because it sure as hell *looks* like it's suspicious.
So I save the file, quarantine it, and send it off to Symantec for checking and get the reply back saying "this has been checked and it's the same as the official version of the install9.exe program"
This strikes me as totally bizarre. Someone sends out something that *looks* like a virus type message, but it's got perfectly legitimate content (and no other attachments), so what on *Earth* is the point?
Is someone *trying* to do me a favour by helping me to install updates on my system? (Not that I'd trust it anyway!) Is it a virus that's just really well concealed? (It doesn't seem to be)
Anyone got any ideas on this?
|
For someone to install updates for you, they would need access to your system.
|
|
|
20-05-2004, 17:20
|
#8
|
cf.mega poster
Join Date: Nov 2003
Location: Reading
Age: 39
Services: Virgin Media Broadband Size M
Posts: 6,546
|
Re: When is a virus not a virus...?
Quote:
Originally Posted by Graham
<snip>
Anyone got any ideas on this?
|
Have you tried running an online scan of the file with a different AV program, eg http://housecall.trenmicro.com/
MB
|
|
|
20-05-2004, 18:12
|
#9
|
Inactive
Join Date: Nov 2003
Location: Leeds - the dog house
Age: 46
Services: Email me for a current price list
Posts: 8,270
|
Re: When is a virus not a virus...?
Might be softening you up for the kill If someone's sent a non-nasty email and they run the attachment without problems, then they're more likely to run subsequent attachments and advise friends/relatives that those emails really are harmless.
|
|
|
20-05-2004, 18:27
|
#10
|
Inactive
Join Date: Jun 2003
Location: Milling around Milton Keynes
Age: 47
Posts: 12,969
|
Re: When is a virus not a virus...?
It could be a dialer rather than a virus
You know, the sort of thing that installs itself and tries to get your modem to call a premium rate number.
Its not a virus, so NAV wouldn't flag it up, tho it's still not a nice bit of software to have.
|
|
|
20-05-2004, 18:34
|
#11
|
Guest
|
Re: When is a virus not a virus...?
Quote:
Originally Posted by andygrif
It could well be that Norton haven't identified it yet as a virus. It's worth sending them the email along with the attachment to do some testing on.
|
Quote:
Originally Posted by Xaccers
Its not a virus, so NAV wouldn't flag it up
|
"So I save the file, quarantine it, and send it off to Symantec for checking and get the reply back saying "this has been checked and it's the same as the official version of the install9.exe program"
I can't see why they'd say this if it wasn't kosher, but it's just really odd.
|
|
|
20-05-2004, 18:36
|
#12
|
Guest
|
Re: When is a virus not a virus...?
Quote:
Originally Posted by monkeybreath
|
Thanks, but that address comes up "not found".
|
|
|
20-05-2004, 18:38
|
#13
|
Inactive
Join Date: Jun 2003
Location: Cambridge
Posts: 16,760
|
Re: When is a virus not a virus...?
Quote:
Originally Posted by Graham
Thanks, but that address comes up "not found".
|
Try http://housecall.trendmicro.com/
|
|
|
20-05-2004, 19:24
|
#14
|
Inactive
Join Date: Nov 2003
Location: Leeds - the dog house
Age: 46
Services: Email me for a current price list
Posts: 8,270
|
Re: When is a virus not a virus...?
Quote:
Originally Posted by Xaccers
It could be a dialer rather than a virus
You know, the sort of thing that installs itself and tries to get your modem to call a premium rate number.
Its not a virus, so NAV wouldn't flag it up, tho it's still not a nice bit of software to have.
|
I wonder what happens when a dialler tries dialling on a system without DUN installed, like most broadband connected PCs?? Crash the system maybe, or will Windows auto-install DUN??
|
|
|
20-05-2004, 22:22
|
#15
|
Eva Longoria Fan
Join Date: Jun 2003
Location: Essex
Age: 36
Services: Sky multiroom (Sky Q)
Sky Fibre Unlimited
Sky Landline
Posts: 8,851
|
Re: When is a virus not a virus...?
Check for any spyware.
|
|
|
Currently Active Users Viewing This Thread: 1 (0 members and 1 guests)
|
|
Posting Rules
|
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts
HTML code is Off
|
|
|
All times are GMT +1. The time now is 12:54.
|