Author Topic: a new virus ? upsnotify  (Read 10135 times)

0 Members and 1 Guest are viewing this topic.

mrreg

  • Guest
a new virus ? upsnotify
« on: March 25, 2011, 01:33:28 AM »
i found this email in my spam folder, from upsnotify.rar.  not waiting on a parcel from the states, i avoided clicking on any links and got suspicious of it. so checked it out on google and well, i think it's a brand new virus included in the email,,, a variant of w32:pilleuz . i just deleted it to be safe.

http://news.softpedia.com/news/Fake-UPS-Email-Campaign-Serves-Malware-Cocktail-191161.shtml

Offline Lisandro

  • Avast team
  • Certainly Bot
  • *
  • Posts: 67194
Re: a new virus ? upsnotify
« Reply #1 on: March 25, 2011, 01:46:55 AM »
You could have submitted it to www.virustotal.com
You could have added to avast Chest and send them helping improving detection.
The best things in life are free.

mrreg

  • Guest
Re: a new virus ? upsnotify
« Reply #2 on: March 25, 2011, 01:51:26 AM »
that's easy for you to say. :) honestly, i'm a mechanic, not terribly clever @ computing.

mrreg

  • Guest
Re: a new virus ? upsnotify
« Reply #3 on: March 25, 2011, 01:57:10 AM »
i'm sort of wondering if i'm all that good a mechanic too, lately. :)

Offline Lisandro

  • Avast team
  • Certainly Bot
  • *
  • Posts: 67194
Re: a new virus ? upsnotify
« Reply #4 on: March 25, 2011, 02:04:32 AM »
Don't worry mrreg.
Thanks for posting and sharing.
Hope the programmers take a look on it.
Enjoy the forum!
The best things in life are free.

Offline polonus

  • Avast Überevangelist
  • Probably Bot
  • *****
  • Posts: 33900
  • malware fighter
Re: a new virus ? upsnotify
« Reply #5 on: March 25, 2011, 10:06:07 PM »
Cybersecurity is more of an attitude than anything else. Avast Evangelists.

Use NoScript, a limited user account and a virtual machine and be safe(r)!

Offline Lisandro

  • Avast team
  • Certainly Bot
  • *
  • Posts: 67194
Re: a new virus ? upsnotify
« Reply #6 on: March 25, 2011, 10:20:30 PM »
Indeed, the report increased from 17 to 34... Thanks Polonus.
The best things in life are free.

Offline DavidR

  • Avast Überevangelist
  • Certainly Bot
  • *****
  • Posts: 89059
  • No support PMs thanks
Re: a new virus ? upsnotify
« Reply #7 on: March 25, 2011, 10:29:48 PM »
This UPS notify thing isn't new (avast has been detecting most of these as trojan-gen for some time), just another variant on a common theme, social engineering trying to get you to open an email attachment. This also goes for the other fake emails for the express parcel carrier of your choice.

Which if you have any common sense you would know the email is fake and wouldn't open the email much less any attachment. Lets assume for a moment that you were even expecting a package, if there was a problem with delivery, etc. how the h*ll would they know your email address.

Unfortunately there must be enough people who fall for this or they wouldn't do it.
Windows 10 Home 64bit/ Acer Aspire F15/ Intel Core i5 7200U 2.5GHz, 8GB DDR4 memory, 256GB SSD, 1TB HDD/ avast! free 24.3.6108 (build 24.3.8975.762) UI 1.0.801/ Firefox, uBlock Origin, uMatrix/ MailWasher Pro/ Avast! Mobile Security

Offline polonus

  • Avast Überevangelist
  • Probably Bot
  • *****
  • Posts: 33900
  • malware fighter
Re: a new virus ? upsnotify
« Reply #8 on: March 25, 2011, 11:04:37 PM »
Hi davidR,

mmreg reported the issue here, and good, again users were warned against this, but with a bit of googling he could have found out that avast is already protecting against this, as I have demonstrated in my earlier posting. People, use that "search" function to a good end, it can help you to get so many right answers,

polonus
Cybersecurity is more of an attitude than anything else. Avast Evangelists.

Use NoScript, a limited user account and a virtual machine and be safe(r)!

Offline apeka

  • Jr. Member
  • **
  • Posts: 32
Re: a new virus ? upsnotify
« Reply #9 on: March 28, 2011, 04:00:22 PM »
Hello,

I'm getting the same UPS message with attachement every other day.. Problem is, that upon avast detecting this as a possible Trojan warning and moves it to the chest, Outlook 2007 stops working and closes, so I'm not able to delete this message. It's also remarkable that when this happens, all my incoming mails are duplicated in the inbox..Like it's echoing back and forth with the mail server..
The only work around I could think of, is temporarily close the avast mail shield (Outlook keeps stable) and then remove the suspicious message and attachment by hand form the inbox...After that I reenable the shield again..
Anybody knows of a better, permanent solution to get rid of this annoying stuff? (Besides changing my e-mailaddress of course :-))
Thanks

Offline polonus

  • Avast Überevangelist
  • Probably Bot
  • *****
  • Posts: 33900
  • malware fighter
Re: a new virus ? upsnotify
« Reply #10 on: March 28, 2011, 06:31:35 PM »
Go to the SAS site and download their free software from: http://www.superantispyware.com Update and run an in depth scan. Being free, you must perform a manual update daily.

According to independent security consultant Dancho Danchev, the threats associated with this attack include a fake antivirus, a Gbot backdoor and a variant of W32.Pilleuz which currently has a low detection rate, source:
http://ddanchev.blogspot.com/2011/03/spamvertised-united-parcel-service.html

The fake-av in the coctail changed the following registry keys which, when the malware is removed, may prevent internet access from functioning normally, so what to do additionally?


1. Temporarily Disable System Restore
2. Update the virus definitions.
3. Reboot computer in SafeMode
4. Run a full system scan and clean/delete all infected files
5. Delete/Modify any values added to the registry. [how to edit registry]

Navigate to and delete the following registry entries:
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\Current Version\Winlogon\”Taskman” = “%SystemDrive%\RECYCLER\[SID]\sysdate.exe”

HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings
ProxyServer
http=127.0.0.1:50370

HKLM\SYSTEM\CurrentControlSet\Hardware Profiles\Current\Software\Microsoft\windows\CurrentVersion\Internet Settings
ProxyEnable
0x00000001

6. Exit registry editor and restart the computer,
These Internet settings will likely need to be restored, through this MS fix: http://go.microsoft.com/?linkid=9664547

polonus
Cybersecurity is more of an attitude than anything else. Avast Evangelists.

Use NoScript, a limited user account and a virtual machine and be safe(r)!

Offline apeka

  • Jr. Member
  • **
  • Posts: 32
Re: a new virus ? upsnotify
« Reply #11 on: March 29, 2011, 01:06:57 PM »
Wow.. That seems serious..
I never openened the suspected message though.. Does this still mean that my pc is infected? I'm not familiar with these kinds of actions and don't know if I dare to do this... Isn't there a simple way to fix this (not reinstalling Windows)?

Offline DavidR

  • Avast Überevangelist
  • Certainly Bot
  • *****
  • Posts: 89059
  • No support PMs thanks
Re: a new virus ? upsnotify
« Reply #12 on: March 29, 2011, 02:49:45 PM »
So long as you didn't open the email or run the attachment you should be good. You do however need to find the offending email if it is in Outlook, it will most likely also have *** VIRUS *** or similar placed in the Subject and avast would normally have removed the attachment.

Search for virus in the subject and see if that relates to the same time frame and delete it without opening the email. Then clear the deleted items folder and compact your folders.
Windows 10 Home 64bit/ Acer Aspire F15/ Intel Core i5 7200U 2.5GHz, 8GB DDR4 memory, 256GB SSD, 1TB HDD/ avast! free 24.3.6108 (build 24.3.8975.762) UI 1.0.801/ Firefox, uBlock Origin, uMatrix/ MailWasher Pro/ Avast! Mobile Security

Offline apeka

  • Jr. Member
  • **
  • Posts: 32
Re: a new virus ? upsnotify
« Reply #13 on: March 29, 2011, 03:35:39 PM »
I never opened the message or the attachment. Just selected it in Outlook and deleted it right away.. Problem is that every so often, this message is received again and avast blocks it (as it should). This crashes Outlook (see my previous posts here). At the moment the message is moved to the avast virus chest and I let it sit there. Just wondered if I could find a permanent solution for not crashing Outlook upon receiving this..

Offline DavidR

  • Avast Überevangelist
  • Certainly Bot
  • *****
  • Posts: 89059
  • No support PMs thanks
Re: a new virus ? upsnotify
« Reply #14 on: March 29, 2011, 04:16:03 PM »
I don't know why it crashed Outlook, unfortunately I can't help with Outlook as I don't use it.

I don't know what your Outlook settings are especially since it also has the avast plug-in and an anti-spam plug-in I believe. So I don't know if there would be any conflicting interaction in this. So that would have to be investigated by someone with Outlook experience.

Me, I have used MailWasher Pro for many years, a paid anti-spam which say this as spam and I noticed it as most likely malicious and could have flagged it for deletion at the email server end. That way it wouldn't have been downloaded to trigger avast.
Windows 10 Home 64bit/ Acer Aspire F15/ Intel Core i5 7200U 2.5GHz, 8GB DDR4 memory, 256GB SSD, 1TB HDD/ avast! free 24.3.6108 (build 24.3.8975.762) UI 1.0.801/ Firefox, uBlock Origin, uMatrix/ MailWasher Pro/ Avast! Mobile Security