Home News Forum Articles
  Welcome back Join CF
You are here You are here: Home | Forum | When is a virus not a virus...?

You are currently viewing our boards as a guest which gives you limited access to view most of the discussions, articles and other free features. By joining our Virgin Media community you will have full access to all discussions, be able to view and post threads, communicate privately with other members (PM), respond to polls, upload your own images/photos, and access many other special features. Registration is fast, simple and absolutely free so please join our community today.


Welcome to Cable Forum
Go Back   Cable Forum > Computers & IT > Security & Virus Discussion
Register FAQ Community Calendar

When is a virus not a virus...?
Reply
 
Thread Tools
Old 20-05-2004, 03:11   #1
Graham
Guest
 
Posts: n/a
When is a virus not a virus...?

Ok, here's a wierd one...

I got another one of those "This is a Micro$oft Update" e-mails seemingly trying to trick me into running the .exe attachment and infect my system.

Ho hum, thinks I, and I'm about to delete it when I suddenly realise that the message *doesn't* have a Norton AV warning of deletion in place of the attachment.

So I think "hello, that's odd" and get NAV to scan the attachment. To which it replies "it's clean".

Now this is strange, because it sure as hell *looks* like it's suspicious.

So I save the file, quarantine it, and send it off to Symantec for checking and get the reply back saying "this has been checked and it's the same as the official version of the install9.exe program"

This strikes me as totally bizarre. Someone sends out something that *looks* like a virus type message, but it's got perfectly legitimate content (and no other attachments), so what on *Earth* is the point?

Is someone *trying* to do me a favour by helping me to install updates on my system? (Not that I'd trust it anyway!) Is it a virus that's just really well concealed? (It doesn't seem to be)

Anyone got any ideas on this?
  Reply With Quote
Advertisement
Old 20-05-2004, 09:54   #2
andygrif
Inactive
 
Join Date: Jul 2003
Posts: 2,820
andygrif has a bronze arrayandygrif has a bronze arrayandygrif has a bronze array
andygrif has a bronze arrayandygrif has a bronze arrayandygrif has a bronze arrayandygrif has a bronze arrayandygrif has a bronze arrayandygrif has a bronze arrayandygrif has a bronze array
Re: When is a virus not a virus...?

It could well be that Norton haven't identified it yet as a virus. It's worth sending them the email along with the attachment to do some testing on.
andygrif is offline   Reply With Quote
Old 20-05-2004, 09:56   #3
Russ
cf.mega poster
 
Russ's Avatar
 
Join Date: Jun 2003
Location: Up here
Posts: 36,520
Russ has a golden aura
Russ has a golden auraRuss has a golden auraRuss has a golden aura
Re: When is a virus not a virus...?

Or possibly it's someone trying to trick you in to thinking you've been sent something nasty without actually getting in to trouble themselves?
__________________
https://youtu.be/-sciUJKjUfM?si=K8mL-RBH6V-duVku

Vote #AnyoneButTory
Russ is offline   Reply With Quote
Old 20-05-2004, 09:56   #4
Defiant
Permanently Banned
 
Defiant's Avatar
 
Join Date: Apr 2004
Location: Salford(UK)
Age: 52
Posts: 976
Defiant is a name known to allDefiant is a name known to allDefiant is a name known to allDefiant is a name known to allDefiant is a name known to allDefiant is a name known to allDefiant is a name known to allDefiant is a name known to all
Send a message via ICQ to Defiant Send a message via AIM to Defiant Send a message via MSN to Defiant Send a message via Yahoo to Defiant
Re: When is a virus not a virus...?

Hmm I'm always seeing people posting questions about virus's and for some reason its nearly always regarding Norton
Defiant is offline   Reply With Quote
Old 20-05-2004, 16:30   #5
zovat
Inactive
 
zovat's Avatar
 
Join Date: Oct 2003
Location: Bracknell
Age: 54
Services: NTL Telephone 3M Broadband - CM Sky TV
Posts: 1,246
zovat has reached the bronze age
zovat has reached the bronze agezovat has reached the bronze agezovat has reached the bronze agezovat has reached the bronze agezovat has reached the bronze agezovat has reached the bronze agezovat has reached the bronze agezovat has reached the bronze age
Send a message via MSN to zovat
Re: When is a virus not a virus...?

Quote:
Originally Posted by andygrif
It could well be that Norton haven't identified it yet as a virus. It's worth sending them the email along with the attachment to do some testing on.
True, but Symantec said it was clean - and they are pretty quick at identifying virii once they are released...

Does seem strange though- Microsoft have never (to my knowledge) sent out any updates by Email.

Hmmm - a bit of googling tells me that this looks rather like the swen worm : see symantec's page - bit wierd that symantec said it looked ok though....
zovat is offline   Reply With Quote
Old 20-05-2004, 17:14   #6
MadGamer
Eva Longoria Fan
 
MadGamer's Avatar
 
Join Date: Jun 2003
Location: Essex
Age: 36
Services: Sky multiroom (Sky Q) Sky Fibre Unlimited Sky Landline
Posts: 8,851
MadGamer has a nice shiny star
MadGamer has a nice shiny starMadGamer has a nice shiny star
Re: When is a virus not a virus...?

Quote:
Originally Posted by zovat
True, but Symantec said it was clean - and they are pretty quick at identifying virii once they are released...

Does seem strange though- Microsoft have never (to my knowledge) sent out any updates by Email.

Hmmm - a bit of googling tells me that this looks rather like the swen worm : see symantec's page - bit wierd that symantec said it looked ok though....
M$ do have this stated on their website somewhere. You are right, they never send out emails containing patches.
MadGamer is offline   Reply With Quote
Old 20-05-2004, 17:17   #7
MadGamer
Eva Longoria Fan
 
MadGamer's Avatar
 
Join Date: Jun 2003
Location: Essex
Age: 36
Services: Sky multiroom (Sky Q) Sky Fibre Unlimited Sky Landline
Posts: 8,851
MadGamer has a nice shiny star
MadGamer has a nice shiny starMadGamer has a nice shiny star
Re: When is a virus not a virus...?

Quote:
Originally Posted by Graham
Ok, here's a wierd one...

I got another one of those "This is a Micro$oft Update" e-mails seemingly trying to trick me into running the .exe attachment and infect my system.

Ho hum, thinks I, and I'm about to delete it when I suddenly realise that the message *doesn't* have a Norton AV warning of deletion in place of the attachment.

So I think "hello, that's odd" and get NAV to scan the attachment. To which it replies "it's clean".

Now this is strange, because it sure as hell *looks* like it's suspicious.

So I save the file, quarantine it, and send it off to Symantec for checking and get the reply back saying "this has been checked and it's the same as the official version of the install9.exe program"

This strikes me as totally bizarre. Someone sends out something that *looks* like a virus type message, but it's got perfectly legitimate content (and no other attachments), so what on *Earth* is the point?

Is someone *trying* to do me a favour by helping me to install updates on my system? (Not that I'd trust it anyway!) Is it a virus that's just really well concealed? (It doesn't seem to be)

Anyone got any ideas on this?
For someone to install updates for you, they would need access to your system.
MadGamer is offline   Reply With Quote
Old 20-05-2004, 17:20   #8
Chris W
cf.mega poster
 
Join Date: Nov 2003
Location: Reading
Age: 39
Services: Virgin Media Broadband Size M
Posts: 6,546
Chris W has a nice shiny star
Chris W has a nice shiny starChris W has a nice shiny starChris W has a nice shiny starChris W has a nice shiny starChris W has a nice shiny starChris W has a nice shiny starChris W has a nice shiny starChris W has a nice shiny starChris W has a nice shiny starChris W has a nice shiny starChris W has a nice shiny starChris W has a nice shiny starChris W has a nice shiny starChris W has a nice shiny starChris W has a nice shiny starChris W has a nice shiny starChris W has a nice shiny star
Send a message via MSN to Chris W
Re: When is a virus not a virus...?

Quote:
Originally Posted by Graham
<snip>
Anyone got any ideas on this?
Have you tried running an online scan of the file with a different AV program, eg http://housecall.trenmicro.com/

MB
Chris W is offline   Reply With Quote
Old 20-05-2004, 18:12   #9
greencreeper
Inactive
 
Join Date: Nov 2003
Location: Leeds - the dog house
Age: 46
Services: Email me for a current price list
Posts: 8,270
greencreeper has a nice shiny stargreencreeper has a nice shiny stargreencreeper has a nice shiny stargreencreeper has a nice shiny stargreencreeper has a nice shiny star
greencreeper has a nice shiny stargreencreeper has a nice shiny stargreencreeper has a nice shiny stargreencreeper has a nice shiny stargreencreeper has a nice shiny stargreencreeper has a nice shiny stargreencreeper has a nice shiny stargreencreeper has a nice shiny stargreencreeper has a nice shiny stargreencreeper has a nice shiny stargreencreeper has a nice shiny stargreencreeper has a nice shiny stargreencreeper has a nice shiny stargreencreeper has a nice shiny stargreencreeper has a nice shiny stargreencreeper has a nice shiny stargreencreeper has a nice shiny stargreencreeper has a nice shiny stargreencreeper has a nice shiny star
Re: When is a virus not a virus...?

Might be softening you up for the kill If someone's sent a non-nasty email and they run the attachment without problems, then they're more likely to run subsequent attachments and advise friends/relatives that those emails really are harmless.
greencreeper is offline   Reply With Quote
Old 20-05-2004, 18:27   #10
Xaccers
Inactive
 
Join Date: Jun 2003
Location: Milling around Milton Keynes
Age: 47
Posts: 12,969
Xaccers has a pair of shiny starsXaccers has a pair of shiny starsXaccers has a pair of shiny starsXaccers has a pair of shiny stars
Xaccers has a pair of shiny starsXaccers has a pair of shiny starsXaccers has a pair of shiny starsXaccers has a pair of shiny starsXaccers has a pair of shiny starsXaccers has a pair of shiny starsXaccers has a pair of shiny starsXaccers has a pair of shiny starsXaccers has a pair of shiny starsXaccers has a pair of shiny starsXaccers has a pair of shiny starsXaccers has a pair of shiny stars
Re: When is a virus not a virus...?

It could be a dialer rather than a virus
You know, the sort of thing that installs itself and tries to get your modem to call a premium rate number.
Its not a virus, so NAV wouldn't flag it up, tho it's still not a nice bit of software to have.
Xaccers is offline   Reply With Quote
Old 20-05-2004, 18:34   #11
Graham
Guest
 
Posts: n/a
Re: When is a virus not a virus...?

Quote:
Originally Posted by andygrif
It could well be that Norton haven't identified it yet as a virus. It's worth sending them the email along with the attachment to do some testing on.
Quote:
Originally Posted by Xaccers
Its not a virus, so NAV wouldn't flag it up
"So I save the file, quarantine it, and send it off to Symantec for checking and get the reply back saying "this has been checked and it's the same as the official version of the install9.exe program"

I can't see why they'd say this if it wasn't kosher, but it's just really odd.
  Reply With Quote
Old 20-05-2004, 18:36   #12
Graham
Guest
 
Posts: n/a
Re: When is a virus not a virus...?

Quote:
Originally Posted by monkeybreath
Have you tried running an online scan of the file with a different AV program, eg http://housecall.trenmicro.com/
Thanks, but that address comes up "not found".
  Reply With Quote
Old 20-05-2004, 18:38   #13
Tezcatlipoca
Inactive
 
Tezcatlipoca's Avatar
 
Join Date: Jun 2003
Location: Cambridge
Posts: 16,760
Tezcatlipoca has a pair of shiny starsTezcatlipoca has a pair of shiny starsTezcatlipoca has a pair of shiny starsTezcatlipoca has a pair of shiny starsTezcatlipoca has a pair of shiny stars
Tezcatlipoca has a pair of shiny starsTezcatlipoca has a pair of shiny starsTezcatlipoca has a pair of shiny starsTezcatlipoca has a pair of shiny starsTezcatlipoca has a pair of shiny starsTezcatlipoca has a pair of shiny stars
Re: When is a virus not a virus...?

Quote:
Originally Posted by Graham
Thanks, but that address comes up "not found".
Try http://housecall.trendmicro.com/
Tezcatlipoca is offline   Reply With Quote
Old 20-05-2004, 19:24   #14
greencreeper
Inactive
 
Join Date: Nov 2003
Location: Leeds - the dog house
Age: 46
Services: Email me for a current price list
Posts: 8,270
greencreeper has a nice shiny stargreencreeper has a nice shiny stargreencreeper has a nice shiny stargreencreeper has a nice shiny stargreencreeper has a nice shiny star
greencreeper has a nice shiny stargreencreeper has a nice shiny stargreencreeper has a nice shiny stargreencreeper has a nice shiny stargreencreeper has a nice shiny stargreencreeper has a nice shiny stargreencreeper has a nice shiny stargreencreeper has a nice shiny stargreencreeper has a nice shiny stargreencreeper has a nice shiny stargreencreeper has a nice shiny stargreencreeper has a nice shiny stargreencreeper has a nice shiny stargreencreeper has a nice shiny stargreencreeper has a nice shiny stargreencreeper has a nice shiny stargreencreeper has a nice shiny stargreencreeper has a nice shiny stargreencreeper has a nice shiny star
Re: When is a virus not a virus...?

Quote:
Originally Posted by Xaccers
It could be a dialer rather than a virus
You know, the sort of thing that installs itself and tries to get your modem to call a premium rate number.
Its not a virus, so NAV wouldn't flag it up, tho it's still not a nice bit of software to have.
I wonder what happens when a dialler tries dialling on a system without DUN installed, like most broadband connected PCs?? Crash the system maybe, or will Windows auto-install DUN??
greencreeper is offline   Reply With Quote
Old 20-05-2004, 22:22   #15
MadGamer
Eva Longoria Fan
 
MadGamer's Avatar
 
Join Date: Jun 2003
Location: Essex
Age: 36
Services: Sky multiroom (Sky Q) Sky Fibre Unlimited Sky Landline
Posts: 8,851
MadGamer has a nice shiny star
MadGamer has a nice shiny starMadGamer has a nice shiny star
Re: When is a virus not a virus...?

Check for any spyware.
MadGamer is offline   Reply With Quote
Reply


Currently Active Users Viewing This Thread: 1 (0 members and 1 guests)
 

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is On
HTML code is Off

Forum Jump


All times are GMT +1. The time now is 12:54.


Server: osmium.zmnt.uk
Powered by vBulletin® Version 3.8.11
Copyright ©2000 - 2024, vBulletin Solutions Inc.