PDA

View Full Version : How can my webmail account send out a virus?


AbuMubarak
10-06-04, 01:06 AM
i have a webmail account (meaning, its like a yahoo account) not connected with my computer, other than when i sign onto the web

it sent out two viruses, with my name, at a time i was not at the computer

Name of File TextDocument.zip
Virus Scan Result Virus Scan Incomplete
Note: The file TextDocument.zip could not be scanned for viruses because it is password protected.



how does that happen?

ZawjatuRaafi
10-06-04, 01:35 AM
There is a worm that has passed through the kids email system from school, this was a seperate setup email system as well. This passed a virus to everyone on the schools address books, all saying that the virus was passed by the student to everyone on the address book. It is a type of worm strain that runs through your system then sends the virus from your address(the webmail one) to everyone on the address book, this goes on until it spreads into someone elses email system and it grabs the addresses on theirs, then it will move on and say it was from them. This is what happened in this case anyhow. There is such thing as getting a virus on a webmail, not much you can do about it though I dont think, the best thing I could think is to email the company who you have your email with and alert them of what your problem is and see what they suggest you do....

Inshaa Allah that helps

AbuMubarak
10-06-04, 03:33 AM
http://us.mcafee.com/virusInfo/default.asp?id=description&virus_k=101058

Virus Information
Name: Keylog-Briss
Risk Assessment
- Home Users: Low
- Corporate Users: Low
Date Discovered: 2/6/2004
Date Added: 2/27/2004
Origin: Unknown
Length: 40,960 Bytes
Type: Trojan
SubType: Remote Access
DAT Required: 4326



Virus Characteristics

This is a trojan that installs itself on the victim's system for the purpose of logging any keys pressed and sending this log to a remote computer. By doing this, it allow the attacker to grab sensitive information, including usernames and passwords.

Note: This was earlier detected as BackDoor-CCG, but has since been renamed to KeyLog-Briss.

Installation

Upon execution, the trojan modifies the registry to automatically load itself into memory at the next startup.

HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\Curr entVersion\Run
"systray" = C:\test\A.EXE

Note: The keylogging behavior was not observed during testing.



Indications of Infection

Presence of the file and registry entry mentionned above.



Method of Infection

Trojans do not self-replicate. They are spread manually, often under the premise that the executable is something beneficial. Distribution channels include IRC, peer-to-peer networks, newsgroup postings, email, etc.




Removal Instructions

AVERT recommends to always use latest DATs and engine . This threat will be cleaned if you have this combination.
Additional Windows ME/XP removal considerations



Aliases

BackDoor-CCG, TrojanSpy.Win32.Briss (AVP)

sajid
10-06-04, 03:00 PM
Abu

basically what tht problem is someoen who u have in ur address book has a virus on their pc..it basically sends out viruses to all those in that address book..

it happens to me all the time and its really annoying too :|

sajid