Forum Home
Press F1
 
Thread ID: 138556 2014-12-16 23:01:00 virus doing the rounds in NZ TODAY 1101 (13337) Press F1
Post ID Timestamp Content User
1390349 2014-12-16 23:01:00 Just an FYI

Theres a virus doing the rounds in Ak at the mo (ie right now).
It will be from an email adress from generally a known or recognised contact
It will mass mail everyone in your Outlook contacts , possibly in the NK2 as well, mabee(??). Exchange que veiwer will show
alot of emails in the que, retrying

NOD32 doesnt detect it. No more info at the mo, I have infected PC's coming in to be scanned & checked out.
Just a heads up for the techs out there . Usual story though, OK if you dont open it.
1101 (13337)
1390350 2014-12-16 23:14:00 yep got one through a short while back from a supplier but the email said it was from supplier.com, where I know its .co.nz, stating the invoice was attached for 4,972 ---- in a zipped file -- yeah right ;) wainuitech (129)
1390351 2014-12-16 23:18:00 Cheers, no reports here as of yet.
Just what we need on this lovely wet day!
CYaBro (73)
1390352 2014-12-16 23:26:00 Cheers, no reports here as of yet.
Just what we need on this lovely wet day! Wet day ? Wrong end of the country Mate :p Nice and fine here at the moment.

Heres part of the mail

6087
wainuitech (129)
1390353 2014-12-17 00:27:00 If you don't want the $4,972, wire it my way mate :D Could do with a bit more before Christmas... Chilling_Silence (9)
1390354 2014-12-17 00:57:00 I have some infected PC's here

Updated Nod wont detect it, but will detect its leftovers in tmp files (instantly after update) . Ive submitted the file to Nod, so next update should get it (i would hope)
Mbytes will detect & remove: easy to spot , its a random jibberish .exe in C:\Windows , also creates a 'googleupdate' service (that may be false positive?)

seemed too easy to remove...have a nagging feeling may be bits left in there .
1101 (13337)
1390355 2014-12-17 01:35:00 Disable system restore then run adwcleaner Speedy Gonzales (78)
1390356 2014-12-17 03:08:00 Been getting them for months from random email addresses, first time I have seen them coming from legit looking sources. Mail Marshal stops them all the same. Alex B (15479)
1390357 2014-12-17 03:29:00 Just an FYI

Theres a virus doing the rounds in Ak at the mo (ie right now).
It will be from an email adress from generally a known or recognised contact
It will mass mail everyone in your Outlook contacts , possibly in the NK2 as well, mabee(??). Exchange que veiwer will show
alot of emails in the que, retrying

NOD32 doesnt detect it. No more info at the mo, I have infected PC's coming in to be scanned & checked out.
Just a heads up for the techs out there . Usual story though, OK if you dont open it.

Got it this afternoon in Nelson from a legit private address - googled it - some guy in Timaru - obviously spoofed address.
Looked sooo sus. Don't open crap like that - PDF zipped ??
Msg test as here "We have sent you a Wire Transfer for amount 4,972.00. Please view attachment for details."
</html
Cheers
Woody (710)
1390358 2014-12-17 04:18:00 Work got it but our system detected it and removed the attachment(s) gary67 (56)
1 2