From 'support@symantec.com'
Author
Discussion

simpo two

Original Poster:

91,574 posts

289 months

Friday 17th September 2004
quotequote all
The e-mail address may look correct but I never sent them anything! I'm guessing this is just another trick.

'The sample file you sent contains a new virus version of buppa.k.
Please update your virus scanner with the attached dat file.

Best Regards,
Keria Reynolds

++++ Attachment: No Virus found
++++ F-Secure AntiVirus - www.f-secure.com'

iaint

10,040 posts

262 months

Friday 17th September 2004
quotequote all
Some virus propogating itself will ahve used a fake email address as it's 'from' address. In this case yours! Therefore the 'yousent me a virus' email from the server will go to you.

Iain

zumbruk

7,848 posts

284 months

Friday 17th September 2004
quotequote all
And these "you sent me a virus" emails are strong evidence of utter cluelessness on the part of sender...

Podie

46,649 posts

299 months

Friday 17th September 2004
quotequote all
Simpo Two - given the frequency with which you post about virus and spam problems… perhaps it is time that you considered updating/changing your anti-virus, firewall and anti-spam solutions…?

Whoozit

3,865 posts

293 months

Friday 17th September 2004
quotequote all
And the ad next to Podie's post gives you a few alternatives . . .

simpo two

Original Poster:

91,574 posts

289 months

Friday 17th September 2004
quotequote all
Podie said:
Simpo Two - given the frequency with which you post about virus and spam problems… perhaps it is time that you considered updating/changing your anti-virus, firewall and anti-spam solutions…?


Antivirus: Norton AV with LiveUpdate

Firewall: ZoneAlarm (free version) + XP built-in firewall + Metronet (ISP)

Anti spyware: AdAware + SpyBot

Anti-spam: MailWasher 2.0 - which is remarkably effective at catching viruses at the server.

Anything else I'm missing?

Podie

46,649 posts

299 months

Friday 17th September 2004
quotequote all
Firstly, I'm not having a go - I am actually trying to help. I've noticed that you seem to have a number of virus and spam related concerns.

In theory, no you're not missing anything… adaware and spybot are certainly very good products, and I'm also a fan of zonealarm.

What I've not established from your postings is whether you are actually being hit with viruses, or whether your Norton is stripping them out…? If the latter is the case, then it may just be a case of living with it…

Not used MailWasher myself, so it's difficult to pass comment on that, but I have found that the McAfee anti-spam is particularly aggressive.

I've generally found that by keeping all the products under one roof (eg all Norton or all McAfee) is often a better solution than using multiple providers...

iaint

10,040 posts

262 months

Friday 17th September 2004
quotequote all
zumbruk said:
And these "you sent me a virus" emails are strong evidence of utter cluelessness on the part of sender...


Usually an automated action. Either by the server/hosting comapny or by the users anti-virus program.

Nothing to do with the 'sender' really. This kind of scenario is often an indication that someone who has yo in their address list had a virus/trojan on their computer.

As Podie points out - keeping anti-virus software up to date is massively important.

I used to use norton but it really bogged the system down and nw use AVG which, for personal use, is free!

simpo two

Original Poster:

91,574 posts

289 months

Friday 17th September 2004
quotequote all
No worries Podie ole bean, I have a few gurus who keep me pretty up to date with stuff (and of course PH!) - but you're doing frontline IT every day so if you'd spotted a weakness in the armoury that would be most helpful.

I wasn't concerned about the mail that generated the post; MailWasher caught it as usual. I just wanted to draw attention to the fact that even a mail purporting to come from Symantec can be dodgy - some people might open it without thinking.

MailWasher catches 99% of spam and viruses here. The only time one might get through is in the short gap bewteen running it and clicking Send and Receive in Outlook Express - in which case NAV acts as wicket keeper. On the odd occasion this happens, the virus is invariably Netsky.

I had almost no spam or viruses until January, shortly after I joined some Yahoo groups. Perhaps these are best avoided?

I know Norton do a firewall but received wisdom says ZoneAlarm is better, and if you're happy wih the mix, so am I

However, I do recommend MailWasher as an excellent way of catching, deleting and bouncing the filth before it even gets to the PC.

Simpo Two

Original Poster:

91,574 posts

289 months

Friday 17th September 2004
quotequote all
Just as an aside, I've updated everything manually and run a full scan - and nothing was found

chrisjl

787 posts

306 months

Friday 17th September 2004
quotequote all
iaint said:
Some virus propogating itself will ahve used a fake email address as it's 'from' address. In this case yours! Therefore the 'yousent me a virus' email from the server will go to you.

Iain


But in this case I think the apparent sender is significant. It's almost certainly not a stupid automated response from Symantec, but a trojan/worm/virus installer pretending to be them to give itself an air of authority, in the hope of kidding the user into running the attachment.

Ribol

11,894 posts

282 months

Saturday 18th September 2004
quotequote all
simpo two said:
I know Norton do a firewall but received wisdom says ZoneAlarm is better, and if you're happy wih the mix, so am I

Just a question, would Zone Alarm Pro be any better than the free version?

Ivan

simpo two

Original Poster:

91,574 posts

289 months

Saturday 18th September 2004
quotequote all
chrisjl said:
But in this case I think the apparent sender is significant. It's almost certainly not a stupid automated response from Symantec, but a trojan/worm/virus installer pretending to be them to give itself an air of authority, in the hope of kidding the user into running the attachment.

Precisely what I thought - just like the ones from 'microsoft.com' last year. Hence my warning. However as people in this forum are clued up, perhaps it would have been better in GG - but then it would have been moved back here anyway...!

cosmoschick

7,977 posts

273 months

Sunday 19th September 2004
quotequote all
Podie said:
...and I'm also a fan of zonealarm.


Yup. Me too.