Urgent Help Neded With Virus

A few months ago I emailed DA for permission to upload the Fella Cursor I made. I got the response from Hexentanz @ DA and haven't communictaed since. About 2 weeks ago, I started recieving emails from hexentanz with an attachment that is infected. They have since been coming more and more frequently. I emailed her to stop and got a reply today that she is recieving the same email from me and that her computer is virus/addware free. As far as I know, mine is, too.

Here is a copy of the dissinfected email. If anyone is familiar with this and can help, I would appreciate it.


Hexentanz wrote:
> *Execute attachment to load a movie*
> A stranger came to the door at eve,
> And he spoke the bridegroom fair.
> He bore a green-white stick in his hand,
> And, for all burden, care.
> He asked with the eyes more than the lips
> For a shelter for the night,
> And he turned and looked at the road afar
> Without a window light.
>
> The bridegroom came forth into the porch
> With, "Let us look at the sky,
> And question what of the night to be,
> Stranger, you and I.
> "The woodbine leaves littered the yard,
> The woodbine berries were blue,
> Autumn, yes, winter was in the wind;
> "Stranger, I wish I knew."
>
> Within, the bride in the dusk alone Bent over the open fire,
> Her face rose-red with the glowing co!
> al
> And the thought of the heart's desire.
> The bridegroom looked at the weary road,
> Yet saw but her within,
> And wished her heart in a case of gold
> And pinned with a silver pin.
>
> The bridegroom thought it little to give
> A dole of bread, a purse,
> A heartfelt prayer for the poor of God,
> Or for the rich a curse;
> But whether or not a man was asked
> To mar the love of two
> by harboring woe in the bridal house,
> The bridegroom wished he knew.
>
>
>
> ------------------------------------------------------------------------
>
>
>
> ---
> avast! Antivirus: Inbound message INFECTED:
> \love_me_now.zl9#1196454526 (Win32:Beagle-IH [Wrm]) was deleted from the message.
>
> Virus Database (VPS): 0609-1, 03/01/2006
> Tested on: 3/2/2006 8:39:12 AM
> avast! - copyright (c) 1988-2005 ALWIL Software.
3,580 views 22 replies
Reply #1 Top
Bump
Reply #2 Top
Try this from the MS site
http://www.microsoft.com/security/malwareremove/default.mspx

And try this from Trend
http://housecall.trendmicro.com/
Reply #3 Top
Thanks. Just ran it and it sya I am clean. I think the problem here is figuring which one of us (me or Hexentanz) is the carrier. As far as I know, we are passing this back and forth just between the 2 of us.

I'm running the Trend scan right now.
I also ran AVASTS virus cleaner for this particular worm, and that too says I am clean.
Reply #4 Top
The email address is most likely being spoofed by an infected machine that has both email addresses in the address book. Check the complete email header to see where it's 'really' coming from.

I use MailWasher to check my mail "before" I actually download anything. I can read the email, check for attachments, check the headers, while the email is still on the server. I can set up Blacklists, Whitelists, and Filters. Phising links show up 'undisguised', and so on... I've been using MW so long, I'd be lost without it...... it's really worth checking out. http://firetrust.com/firetrustpro.html

Reply #5 Top
Po' As much as you bring this topic up "ie:AV/SW and what software is best"
It probably wouldnt hurt for you to build yourself a UBCD disk for windows...
http://www.ubcd4win.com/

All it really takes is a blank CD,CD Burner and a little time to read the instructions carefully so the program builds the ISO with no issues...
Or,
You could Email me and I can send you an ISO thats already built, you will just need to burn it to a CD...

The advatage to using the CD is that you can run the scans from your CD ROM while your hard drive is not in use,, sometimes that makes a HUGE difference...

Anyway, just a thought...
Reply #6 Top
@ Koasati
I just checked the link-- had no idea that MailWasher deals with problems at the server. I may have to check it out. At present, my spam is so bad that I am using my mail servers' approved-list-only spam-blocker. Hardly ideal...
Reply #7 Top
You could Email me and I can send you an ISO thats already built, you will just need to burn it to a CD.

This would be best. I read about the BartsPE disc when it first was introduced. My problem with this and making a 'Slipstream' disc is that WINXP cam embedded in the system and I have no disc to work from to make either.

I ran the Trend scan. It found 1 thing but 'could not' give me it's identity.
The email address is most likely being spoofed by an infected machine that has both email addresses in the address book. Check the complete email header to see where it's 'really' coming from.


This is what Hexentanz believes as well. But we cannot find the info you mentioned. Unfortunately, I have a feeling it may go back to someone from WC who may not know they are the cause. The email account this is eminating from is my secondary account and I don't use it often, but had used it with Bushman. All of this started when he began sending me 'forwarded' jokes or something. At that time, I hadn't had AVAST configured to scan my email.

I use MailWasher

Unfortunately, new software isn't in the budget. I don't know for sure how good AVAST is with email. Since configuring the email scanning on it, it has been catching this particular problem, where Roadrunner would only catch it 50% of the time with it's own so-called scan.
I'm still hunting for the cause of all this, so any help is apreciated.
Reply #8 Top
Po' ...last time I checked, (admittedly a while back) there was a free version of mailwasher ...perhaps try a search for it.

If you can get a hold of it, you'll be well protected. I've also been using this program for a number of years, and have nothing but praise for the creators. When I got Mailwasher years ago, it was donationware ...might still be the case now, but not sure.

Good luck.
Reply #9 Top
his would be best. I read about the BartsPE disc when it first was introduced. My problem with this and making a 'Slipstream' disc is that WINXP cam embedded in the system and I have no disc to work from to make either.


Actually PO' LoL..After further review... I cant Email the ISO to you, unzipped it's almost 400MB, Zipped I can get it down to about 180mb but thats still waaaaaaay to big.. Would be uploading and downloading for days, LoL!

Ah well, Sorry, didnt mean to get your hopes up, just a case of me not "thinking"...again.
Reply #10 Top
Hey, Po'
You might want to fix that title before Jafo gets back... Image Hosted by ImageShack.us

Reply #11 Top
Try using Panda online scan....its free and works good. Though if Avast is catching it, I don't think you all are infected. The Anti is working like it is suppose to and it is actually stripping the infected portion of the email off....if you have the option of setting up a junk/spam mail filter by blocking the offending address that is sending it. Also as said before check the header and it should give the address it is truly coming from. Hope this helps. If you let me know what kind of email client you are using maybe I can help you set up the filter, that is if you need it.
Reply #12 Top
I hate spoofed addresses. I get emails from nonexistant addresses from my own domain. I wish I knew how to prevent it.
Reply #13 Top
Ah well, Sorry, didnt mean to get your hopes up, just a case of me not "thinking"

The other thing is that I think you have to have the drivers for the PC you would be using it on..on the disk.
.last time I checked, (admittedly a while back) there was a free version of mailwasher

It's a trial version now and you have to pay 39.99 when it's up.

Hope this helps. If you let me know what kind of email client you are using maybe I can help you set up the filter, that is if you need it

My service is through Roadrunner, but I get/check the mail through Thunderbird.



You might want to fix that title before Jafo gets back.

I'm heavily medicated on Viciden and have a doctors note.



Thanks for all the assists. Hexentanz and I agree with the general consesus, that it is a spoof. (I have no idea what they are or how they got mine and hers addy's) We are both awaiting the next email so we can save more info. We have been deleting them as they came in, not realizing quite what was happening.
Reply #14 Top
Just found this link on the worm that's been hitting my email. It has the 'poem' that has been in my email along with the attachment. I am not knowledgable enough to get all the details on iy, or the link at the bottom on how to remove it. Anyone?
Link
Reply #15 Top
That's why I keep telling people to use windows with regular user account. Use admin account just for stuff that required admin access, such as installing, removing programs, etc.
Reply #16 Top
The other thing is that I think you have to have the drivers for the PC you would be using it on..on the disk.


No the CD is "PC independant" I have used it on a few PC's already without a problem... Too bad you couldnt have someone you know create one for you..I know that they are sold on Ebay "Illegally" but it's done..LoL

As for the "remedy" what is there to fix? I am under the impression from reading through the thread that it is determined you are getting "Spoofed" Email Po..
If thats the case then your PC is not infected...
Reply #17 Top
If thats the case then your PC is not infected...

Yes, you're right. I just need to wait for the next one so I can configure my email to block it.
Reply #18 Top
Yes, you're right. I just need to wait for the next one so I can configure my email to block it.


LoL, Just configure it not to accept any mail from yourself...

Seriously you need to block the "sender" if that happens to be your friends "nick" then perhaps s/he has another email addy you guys could use to communicate through?

Just quick "fix's"
Reply #19 Top
Seriously you need to block the "sender" if that happens to be your friends "nick" then perhaps s/he has another email addy you guys could use to communicate through

That's the wierd thing. She's an admin at DA and we only emailed twice when I was getting permissions to upload my fella cursor. And that was back in December. Other than that and this, we have never emailed.

Reply #20 Top
You can take Wizop Koasati's words on MailWasher to the bank. I have been using it for years. It has never let me down yet.
Reply #21 Top
try this is free !!! (similar has MailWasher)
http://www.poptray.org/screenshots.php

or ezpop !!!(include also spam list )
Reply #22 Top

I've used Mailwasher for a long time too. It's great for bouncing mail from spammers, plus you can delete any mail you don't like the look of while it's still on the server. Don't delay, get it today! Highly recommended.

My ISP filters out all viruses, so I've never seen one via e-mail.