Suspicious email

Discussion in 'NOD32 version 2 Forum' started by Hod, Dec 26, 2003.

Thread Status:
Not open for further replies.
  1. Hod

    Hod Registered Member

    Joined:
    Dec 1, 2003
    Posts:
    10
    I've received this email today:

    "Warning: This message has had one or more attachments removed
    Warning: (gzhbptqa.exe, msg-26136-143.html).
    Warning: Please read the "accessway.ph-Attachment-Warning.txt" attachment(s) for more information."

    It looks highly suspicious but wasn't marked as a virus by NOD.

    Has anyone else had this?
     
  2. LowWaterMark

    LowWaterMark Administrator

    Joined:
    Aug 10, 2002
    Posts:
    17,876
    Location:
    New England
    What does the attached text file "accessway.ph-Attachment-Warning.txt" actually say? Does it have more information?

    If this warning (and the removal of the infected pieces) occurred at your ISP or somewhere else prior to the email reaching your system, then that email is not infected so NOD won't warn you about it. It was already cleaned elsewhere.
     
  3. Hod

    Hod Registered Member

    Joined:
    Dec 1, 2003
    Posts:
    10
    You are right.

    The Message Source includes this:

    "This is a message from the MailScanner E-Mail Virus Protection Service
    ----------------------------------------------------------------------
    The original e-mail attachment "gzhbptqa.exe"
    was believed to be infected by a virus and has been replaced by this warning
    message.

    If you wish to receive a copy of the *infected* attachment, please
    e-mail helpdesk and include the whole of this message
    in your request. Alternatively, you can call them, with
    the contents of this message to hand when you call.

    At Fri Dec 26 09:42:25 2003 the virus scanner said:
    SophosSAVI: gzhbptqa.exe was infected by W32/Gibe-F
    F-Prot: gzhbptqa.exe Infection: W32/Swen.A@mm

    Note to Help Desk: Look on the MailScanner in /var/spool/MailScanner/quaran=
    tine/20031226 (message hBQ1adC8001303).
    --=20
    Postmaster
    MailScanner thanks transtec Computers for their support"

    Nice to know there are some guardian angels about!
     
Thread Status:
Not open for further replies.