Canreef Aquatics Bulletin Board  

Go Back   Canreef Aquatics Bulletin Board > Other > Lounge

Reply
 
Thread Tools Display Modes
  #11  
Old 01-27-2004, 04:29 PM
wayner's Avatar
wayner wayner is offline
Member
 
Join Date: Jan 2002
Location: Calgary, McKenzie Towne SE
Posts: 634
wayner is on a distinguished road
Default

I got it too, called shimgapi.dll, I have Mcaffee scans e-mail & system, I did a system virus scan & it deleted 3 but could not delete the one above.

It resides in my C/windows/system 32, how do I get rid of it, it won't allow me to delete it?
Reply With Quote
  #12  
Old 01-27-2004, 04:31 PM
Chad's Avatar
Chad Chad is offline
Member
 
Join Date: May 2003
Location: Surrey
Posts: 1,031
Chad is on a distinguished road
Default

My office here got a couple.. but so far nothing on my home email.
__________________
Chad

Reply With Quote
  #13  
Old 01-27-2004, 04:32 PM
Chad's Avatar
Chad Chad is offline
Member
 
Join Date: May 2003
Location: Surrey
Posts: 1,031
Chad is on a distinguished road
Default

Quote:
Originally Posted by wayner
I got it too, called shimgapi.dll, I have Mcaffee scans e-mail & system, I did a system virus scan & it deleted 3 but could not delete the one above.

It resides in my C/windows/system 32, how do I get rid of it, it won't allow me to delete it?
Follow the instructions in this link

http://securityresponse.symantec.com...varg.a@mm.html
__________________
Chad

Reply With Quote
  #14  
Old 01-28-2004, 12:04 AM
Samw's Avatar
Samw Samw is offline
Member
 
Join Date: Nov 2001
Location: Yaletown Vancouver
Posts: 2,651
Samw is on a distinguished road
Default

Ah crap. It apears that someone has been able to hijack my Linux mail server and send emails to people and make it appear to be coming from me.
Reply With Quote
  #15  
Old 01-28-2004, 12:09 AM
Chad's Avatar
Chad Chad is offline
Member
 
Join Date: May 2003
Location: Surrey
Posts: 1,031
Chad is on a distinguished road
Default

That sucks.. tho I thought this virus could not infect the linux OS? A different virus?
__________________
Chad

Reply With Quote
  #16  
Old 01-28-2004, 12:16 AM
Samw's Avatar
Samw Samw is offline
Member
 
Join Date: Nov 2001
Location: Yaletown Vancouver
Posts: 2,651
Samw is on a distinguished road
Default

Oops. Scratch that. It isn't doing what I thought it was doing. It turns out that I have added some procmail rules on my Linux account to filter Email with program attachments.



So whenever someone with an infected computer tries to send me an Email with an attachment, I send a message back telling them that I don't accept program attachments. So no one has hijacked me. I had thought that because I started getting copies of empty messages with the email address of the person who tried to send me the virus. So I thought someone was hijacking my computer to send outbound Email. Not the case.

But I do know who has the infected computer trying to infect me though.
Reply With Quote
  #17  
Old 01-28-2004, 02:00 AM
Aquattro's Avatar
Aquattro Aquattro is offline
Just a guy..
 
Join Date: Aug 2001
Location: Victoria, BC
Posts: 18,053
Aquattro is a jewel in the roughAquattro is a jewel in the roughAquattro is a jewel in the roughAquattro is a jewel in the rough
Default

Quote:
Originally Posted by Samw

But I do know who has the infected computer trying to infect me though.
You did notify them, right?
__________________
Brad
Reply With Quote
  #18  
Old 01-28-2004, 02:20 AM
EmilyB's Avatar
EmilyB EmilyB is offline
Member
 
Join Date: Mar 2002
Location: Scenic Acres NW Calgary
Posts: 4,253
EmilyB is on a distinguished road
Default

It's not me
Reply With Quote
  #19  
Old 01-28-2004, 02:44 AM
AJ_77's Avatar
AJ_77 AJ_77 is offline
Member
 
Join Date: Mar 2002
Location: Calgary NW
Posts: 2,772
AJ_77 is on a distinguished road
Default

Quote:
Originally Posted by EmilyB
some people have gotten an emai from me, including myself, even thought I do not have their emails on my system.
Apparently someone else had your email address on their system, and now the worm is spoofing your address as the "from".

From the Symantec site:
Quote:
Attempts to send email messages using its own SMTP engine. The worm looks up the mail server that the recipient uses before sending the email. If it is unsuccessful, it will use the local mail server instead.


The email will have the following characteristics:

From: May be a spoofed from address.
So even though your updated antivirus software may have caught them all, Deb (as mine seems to have), you may still get msgs back from "Mailer-Daemon" and "Mail Subsystem" at other ISPs because they are sending it back to you. Don't sweat it, you're likely fine.

Kind of freaky though... "Hey, I didn't send that! Did I??..."
__________________
----------------------
Alan
Reply With Quote
  #20  
Old 01-28-2004, 02:46 AM
Aquattro's Avatar
Aquattro Aquattro is offline
Just a guy..
 
Join Date: Aug 2001
Location: Victoria, BC
Posts: 18,053
Aquattro is a jewel in the roughAquattro is a jewel in the roughAquattro is a jewel in the roughAquattro is a jewel in the rough
Default

Right. The from feild is spoofed, therefore it gets sent back to you. I've gotten so many back it isn't funny anymore. The headers indicated the source IP of some, so I did send a PM to that person.
Even though your system is clean, you can still get these non delivery reports.
__________________
Brad
Reply With Quote
Reply


Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is On
HTML code is Off
Forum Jump


All times are GMT. The time now is 08:00 PM.


Powered by vBulletin® Version 3.7.3
Copyright ©2000 - 2025, Jelsoft Enterprises Ltd.