Donate SIGN UP

Oh no, I think I have a virus... can anyone technical help me?

Avatar Image
Polotoo | 18:11 Tue 25th Apr 2006 | Technology
22 Answers

Hi all, I have my email account with hotmail and today it sent a load of emails to everyone in my address book, that said the following:


Hi! How are you?
You know I've created my own website!
Can you check how it works?
It's
Can you see video?
Bye!


Well, its not from me and I have no idea what it is, other than I think its something dodgy!! Unfortunately several friends tried to open it, but only got a white screen - I don't know if thats good or not?


Can anyone clever shed any light on this, and perhaps how to fix it and how to stop it happening again?


Thanks a lot, a very stressed Polotoo!

Gravatar

Answers

1 to 20 of 22rss feed

1 2 Next Last

Best Answer

No best answer has yet been selected by Polotoo. Once a best answer has been selected, it will be shown here.

For more on marking an answer as the "Best Answer", please visit our FAQ.
Question Author
Ops, didn't realise the link would be live - please don't click on it, just in case!!!

Google doesn't give any hits fot this url but whois gives the following data and as you see it is a newly created domain (yesterday in fact!).


Domain Name: LOPIGAX.COM

Registrant:
goresxa
n/a ([email protected])
461 Monroe Turnpike
Monroe
null,06468
US
Tel. +1.2036837445

Creation Date: 24-Apr-2006
Expiration Date: 24-Apr-2007

Domain servers in listed order:
ns4.klikdomains.com
ns3.klikdomains.com
ns2.3fn.net
dns195.3fn.net


Administrative Contact:
goresxa
n/a ([email protected])
461 Monroe Turnpike
Monroe
null,06468
US
Tel. +1.2036837445

Technical Contact:
goresxa
n/a ([email protected])
461 Monroe Turnpike
Monroe
null,06468
US
Tel. +1.2036837445

Billing Contact:
goresxa
n/a ([email protected])
461 Monroe Turnpike
Monroe
null,06468
US
Tel. +1.2036837445

Status:ACTIVE

Needless to say 'goresxa' gets no hits in google either.

It doesn't sound good to me.


Question Author

Hi gen2.


Me either, I'm panicing about my friends really more than me...... especially those who tried to access it whilst as work....


I have to say most of what you have written doesn't make any sense to me (sorry I can use it but don't really understand how it works!!)


Any ideas on what I can do to sort it out, or do I need to set up a different email account and then not use the old one?

Changing your email address is not the answer. If this really is a virus, then you will need to get a removal program, but this is so new that no antivirus program will have written any code for it yet. If you don't have any other symptoms, I would just stay cautious for a day or so and see if anyone else reports the same symptoms. Do any of the recipients of the email have any symptoms? Has it been forwarded to their address book contents?

If you use a regular antivirus program, then you could try sending the details to them by email. If it is a new virus then someone has to report it.


To explain what I posted above:
When anyone wants a domain name for themselves, it has to be registered so that it is recognised on the internet. What I posted were the registration details for the domain LOPIGAX . COM
So, someone called 'goresxa' registered the site. They live Monroe in the USA. The site was first registered on the 24th April 2006 (yesterday). Their email is on yahoo.com


hi lopigax might not have sent the emails. Many people can use fake email programs and bulk send them. Its easy with hotmail as I could make up 1000 names put hotmail.com or co.uk at the end and press send. You'd be guaranteed that the message got delivered to some of the 1000 names.
Question Author

Hi guys or gals!


Thanks for your answers. Gen2 - I think I get what you are saying! Will keep my eyes peeled and see what happens.


Jason1980-I'm a little confused! (believe me it doesn't take a lot where technology is concerned!!) These emails appear to have been sent from my email inbox and have gone to everyone in my contacts lists, my friends and relatives have then clicked on the link thinking its something I have sent them. I know there are programmes to guess emails addresses, but this has been very definate. And has targeted my address book, I have seen the email a colleague at work recieved - and you would think it was from me, and clearly shows the others it was sent to, who are all people I know. It has only sent to small numbers at a time and in different emails.


I don't understand where this has come from or how, and how to get rid of it?!?!?!?! Especially worried about having infected others.

The link in your email does indeed link to a malicious website. I emailed the AnswerBank Editor to ask for its removal before anyone else infected themselves. That has now been done. The security on my computer at work recognises the site as malicious and blocks it.

It is almost certain that your computer has been infected with a virus which has then sent the emails. It could have come from an email sent to you, from a downloaded file, from an internet site or directly over the internet from another infected computer. My advice to you is to get a good AntiVirus program and keep it up to date.
Question Author

Hi Gen2


Thankyou for taking the time to look at this for me. I really appreciate it - ands thanks to the Ed for removing the link - I was worried about as didn't realise it would be live when posted as wasn't when previewed.


I have Norton Anti-Virus, which is up to date, so don't understand how these things get under them! But I guess its just one of those things.... Is there any anti-virus software you would recommend or is Norton ok? (It came with the computer and I never changed it)


I will let my friends know and get them to do some virus sweeping - hopefully we can nip this in the bud now!


Its so worrying, I don't know why people want to cause people these headaches and so many problems.


But thanks so much for your help and advice.

Hi Polotoo, I use Norton myself but didn't dare click on the link at home. I got an infection once about 2 years ago - the day before the 'cure' was released. Whatever AV software you have, you can always be at risk from a new virus or a modification of an existing virus. The AV companies are always playing catch-up.

I have no experience of using other AV programs so sorry, I'm not in a position to recommend anything else.


This exploit is pretty fresh as I could only find 2 Google listings for it.

To safely see what is going on, enter the suspect web address at http://www.rexswain.com/httpview.html

This page will show you what the source HTML of the mystery link includes. I see an encoded javascript that tries to open a framed page. I think the deviant did not encode properly because the framed page is for a malformed domain address.

Based on the other Google search result and what I found in my mailbox, the links vary - - but the message within is identical.
I think it is something that is affecting Hotmail. I received the same message from a friend of mine, and I know for a fact that she doesn't even own a computer...
I had the same thing from an email address I have not used in 14 months. I would have known nothing about it isf a few people whos email addresses in the hotmail list were still valid and asked me what it was. I know for a fact its not my PC, as I dont use that address, and have not done in around 4 months.

Also it was only sent to people in that exact hotmail address book, totally diffrent from the address book in my current outlook.

Looks like hotmail have a problem here. I forwarded the email onto sophos.
http://virusscan.jotti.org/ reports the file it is downloaded as the following :

NOD32 Found a variant of Win32/TrojanDownloader.Zlob.MO

No other AV software catches it

U can download a trial version of the software that catches it at this url:

http://www.nod32.com/download/index.php

Hope I helped
Question Author

Arghh..... third time I've typed this hopefully I won't loose it this time!!


Thanks Spamjim for the link-I'm afraid its all greek to me, I managed to run it in the link, but couldn't understand what it came up with, apologies, I'm a bit of a novice.


Thanks abrown1982 for all the info - what is Sophos, and how do I report it to them/him/it?


I've downloaded NOD and uninstalled my other antivirus software to run it. I'm now struggling with it! I've run it and told it to delete anything it identified, but it didn't come up with the trojandownloader thing you mentioned, so not sure if I did it right. I tried the virusscan link too, but didn't know where it would be on my system and it seemed to want me to check individual files.


I'm feeling really thick - can anyone point me in the right direction of what to do next?


Thanks again for all the responses, I'm just sorry my computer literacy is so poor!!


This has just happened to me too - but different website. fizasox dot com forward slash video. I'm using zonealarm, AVG and adaware and my system is clean. Surely must be a hotmail problem?


Have changed all passwords, but hadn't done so for a while. Maybe that was the problem?

Question Author
Thanks Northerner. I've changed my password too, am hoping that will fix the problem, have been keeping an eye on my account and it doesn't seem to have sent any more message, so perhaps that has cured it?
This has infected my hotmail account and sent itself to all my contacts. Cant believe it. Neither avg or Norton detect anything.

Hi guys,


I got this on my laptop, Norton can't find it (not to mention no info of it on their website) and my adware / spy ware can't find it either. It has yet again, e-mailed everyone in my hotmail account!!!!! I've had to delete all the e-mail addresses to stop it e-mailing everyone, but it's still there!!!!! I've left a bogus e-mail addy in the contacts to keep track how many times it tries to e-mail it (i get a failed report back saying it can't deliver)


Now, my question is this...... what the hell is it??? Is it a virus? Does it keep track of info you type, and report back to the host? What does it do??????


I could seriously do with some help guys, as i've tried everything i can think of!!!!! :-(


Any clues would be greatly appreciated :-)


Cheers all....

Question Author

Hi bighousebric


I don't know if anyone else is still watching this q - so you might want to post a new one for yourself (you can link back to this if you like).


I'm not technical (as you could probably tell by the above posts) but since the first day when it sent all the emails, I'm pleased to report that I've had no further problems. I've downloaded NOD as recommended, and cleared up my system, changed my hotmail password. And touch wood, no further emails have been sent.


As far as I know, no one who did try to click the link had any problems, but don't know if we were just lucky?


Apologies this probably isn't much use, but I've sort of just ignored it - and it seems to have gone away?


1 to 20 of 22rss feed

1 2 Next Last

Do you know the answer?

Oh no, I think I have a virus... can anyone technical help me?

Answer Question >>

Related Questions

Sorry, we can't find any related questions. Try using the search bar at the top of the page to search for some keywords, or choose a topic and submit your own question.