win32/Mytob.EA Worm Solution!

Discussion in 'NOD32 version 2 Forum' started by irnux, Jul 11, 2005.

Thread Status:
Not open for further replies.
  1. irnux

    irnux Registered Member

    Joined:
    Mar 28, 2005
    Posts:
    24
    Location:
    Tehran
    We have a network protected with NOD32 Enterprise, have protected our Exchange Server with NOD32 XMON also...

    Some of our clients get some emails contaning `win32/Mytob.EA Worm', the emails come from non-real (info, administrator,webmaster,support &...) users from our own local domain...
    NOD32 cleans the infected mails and delete the worm, But how should we get rid of this worm and don't receive this kind of mail...

    The worm sends our clients emails containing non-real information and ... an email like below...

    ------------------------------------------------------------
    From: info@domain.com [mailto:info@domain.com]
    Sent: 27/Jun/2005 12:00 AM
    To: Nasiri, Tofigh
    Subject: [virus Win32/Mytob.EA worm] bpbzwqw


    Dear Domain Member,

    We have temporarily suspended your email account nasiri@domain.com.

    This might be due to either of the following reasons:

    1. A recent change in your personal information (i.e. change of address).
    2. Submiting invalid information during the initial sign up process.
    3. An innability to accurately verify your selected option of subscription due to an internal error within our processors.
    See the details to reactivate your Mapna account.

    Sincerely,The Domain Support Team


    __________ NOD32 EMON 1.1155 (20050626) Warning __________

    Warning, NOD32 antivirus system found the following in the message:
    email important-details.zip - Win32/Mytob.EA worm - unable to clean - deleted

    http://www.eset.com


    --------------------------------------------------------------------
     
  2. mrtwolman

    mrtwolman Eset Staff Account

    Joined:
    Dec 5, 2002
    Posts:
    613
    Uhm, the problem is, as you told, fake email addy. It is generated by a worm and most likely comes from outside your company.... i am afraid there not too much to do with this.
     
  3. webyourbusiness

    webyourbusiness Registered Member

    Joined:
    Nov 16, 2004
    Posts:
    2,662
    Location:
    Throughout the USA and Canada
    but setup your mailserver to NOT handle bounces... it's a pitr...
     
Thread Status:
Not open for further replies.
  1. This site uses cookies to help personalise content, tailor your experience and to keep you logged in if you register.
    By continuing to use this site, you are consenting to our use of cookies.