Notices
Computer & Technology Related Post here for help and discussion of computing and related technology. Internet, TVs, phones, consoles, computers, tablets and any other gadgets.

Weird virus alert

Thread Tools
 
Search this Thread
 
Old 04 August 2003, 11:04 PM
  #1  
EvilBevel
Scooby Regular
Thread Starter
 
EvilBevel's Avatar
 
Join Date: Oct 1999
Posts: 3,491
Likes: 0
Received 0 Likes on 0 Posts
Post

Don't have the English text, but Outlook Express (I know, I know) suddenly refused to send mail (well, my ISP does) because I supposedly have a virus called Trojan.IframeExec.


Kan het bericht niet verzenden omdat één van de geadresseerden door de server is geweigerd. Het geweigerde e-mailadres is xxxxxxxx@xxxxx.com (removed for privacy) Onderwerp 'Re: stickers', Account: 'Pandora', Server: 'smtp.pandora.be', Protocol: SMTP, Reactie van server: '550 <D577990F.kabel.telenet.be[213.119.153.15]>: Client host rejected: uw computer is besmet met een virus, zie http://helpdesk.telenet.be/veiligheid/faqvirus.htm voor meer informatie!! Virusinfo: Trojan.IframeExec', Poort: 25, Beveiligd(SSL): Nee, Serverfout: 550, Foutnummer: 0x800CCC79


Searches on MacAfee and Symantec on this virus show no hits, nor does my Kasperski Antivirus software. ZoneAlarm is installed as well, and Shields Up reports my PC as being 100 % stealth.

So what's happening ?

Theo
Old 04 August 2003, 11:54 PM
  #2  
JackClark
Scooby Senior
 
JackClark's Avatar
 
Join Date: Dec 2000
Location: Overdosed on LCD
Posts: 20,852
Received 51 Likes on 34 Posts
Post

The only Antivirus I can find that uses that name is Dr Web. If I could understand Russian I could confirm that they have a false alarm problem.

Give this a go FreeScan let me know what it says.
Old 05 August 2003, 06:32 AM
  #3  
EvilBevel
Scooby Regular
Thread Starter
 
EvilBevel's Avatar
 
Join Date: Oct 1999
Posts: 3,491
Likes: 0
Received 0 Likes on 0 Posts
Post

Thanks Jack,

Freescan does find a virus :


C:\WINDOWS\...\MailWasher\socketlog2273.txt Exploit-MIME.gen.exe


Really confused now, this is quite an old virus (11/14/2001) so should really be detected by Kasperski (daily -paying- updates etc) ? I have IE6/OE6, downloaded Iframe/Mime patches yonks ago.

The files that are supposedly infected are all log files from Mailwasher.

Welp ?
Old 05 August 2003, 08:11 AM
  #4  
mannyo
Scooby Regular
 
mannyo's Avatar
 
Join Date: May 2002
Posts: 401
Likes: 0
Received 0 Likes on 0 Posts
Post

Rough online translation, from dutch > english

It doesnot can send reported because one of the addressees have been refused by the server. The refused e mailadres are xxxxxxxx@xxxxx.com (removed for privacy) subject re: stickers, Account: ' Pandora ', server: smtp.Pandora.be, protocol: SMTP, response of server: 550 < D577990F.cable.telenet.be[213.119.153.15 ] >: Client leaps about rejected: your computer it has been contaminated with a virus, to see http://helpdesk.telenet.be/veiligheid/faqvirus.htm for further information!! virus information: Trojan.IframeExec, poort: 25. Protected (SSL): No, Serverfout: 550. Foutnummer: 0x800CCC79
Old 05 August 2003, 08:38 AM
  #5  
JackClark
Scooby Senior
 
JackClark's Avatar
 
Join Date: Dec 2000
Location: Overdosed on LCD
Posts: 20,852
Received 51 Likes on 34 Posts
Post

Kasperski probably didn't find that file as it's a txt file. May just be a remnant anyhow. I trust Kasperski and our detection rates over any Antivirus available, if you scan with both and find nothing then I say you're not infected.
Old 05 August 2003, 02:54 PM
  #6  
EvilBevel
Scooby Regular
Thread Starter
 
EvilBevel's Avatar
 
Join Date: Oct 1999
Posts: 3,491
Likes: 0
Received 0 Likes on 0 Posts
Post

Thanks guys. Email started working again this morning without me doing anything, so I'm pretty sure it was a boo-boo on the ISP side of things.

As if we don't have enough hoaxes floating around
Related Topics
Thread
Thread Starter
Forum
Replies
Last Post
smunns
ScoobyNet General
286
01 October 2015 11:51 AM
StueyBII
General Technical
4
26 September 2015 12:35 PM
StueyBII
General Technical
0
25 September 2015 05:58 PM
smunns
Dealer and Third Party Supplier Queries
5
14 September 2015 08:08 PM



Quick Reply: Weird virus alert



All times are GMT +1. The time now is 10:46 AM.