February 13, 2012, 10:49:56 AM *
Welcome, Guest. Please login or register.
Did you miss your activation email?

Login with username, password and session length
News: SMF - Just Installed!
 
   Home   Help Search Login Register  

"Look sophisticated on your vacation" Thunderbird


AddThis Social Bookmark Button AddThis Feed Button
Pages: [1]
  Print  
Author Topic: "Look sophisticated on your vacation" Thunderbird  (Read 3212 times)
oliverjames
Newbie
*
Posts: 3


View Profile
« on: July 03, 2008, 05:39:55 AM »

I have a problem with incoming mail. I use both WinXP and Linux operating systems. Thunderbird is my mail programme for both OSs

I use gmail accounts but Thunderbird pulls these messages from the server via POP and stores them in my central message folder; this is on a fat32 partition (my main data partition for both OSs).

About 1 month ago incoming mail under WinXP and Linux had the correct initial header and expected sender, however in the message window the subject is "Look sophisticated on your vacation" and the sender Ernest Terutah, recipient address is my former now cancelled email account with Wanadoo (confirmed inactive). Sometimes the message would be blank. Reading mesage information showed a lot of links which were common to urls on my machine.

I then ran adaware, and spybot scans on the WinXP partitions (including the email partition). Now I can receive emails that appear OK, in TBird under Windows but they are still being hijacked in the same way if I attempt this under Linux. I note that hijacked mails received under Linux can now  be opened and read normally under WinXP.

It seems I have a nasty bit of malware in my email message directory.

Can anyone help me to remove this annoying problem?
Logged
Bobby
Administrator
Newbie
*****
Posts: 290



View Profile
« Reply #1 on: July 03, 2008, 11:52:48 PM »

hello there,
i might be missing some point but i don't understand why you think you have a malware? i see you got spam, but that's not necessary a sign of malware. could you provide more details about what is going on on your computer?
Logged

I reccomend Spyware Doctor and Malwarebytes’ Anti-malware as ultimate protection.
oliverjames
Newbie
*
Posts: 3


View Profile
« Reply #2 on: July 04, 2008, 12:32:03 AM »

Hello Bobby,

Messages are received by Thunderbird under the Linux OS that have the message replaced by one headed "Look sophisticated on your vacation" (Search for that on the web, you'll find a variant of the message body that is presented).

I have to reboot under the WinXP OS and open Tbird in order to read the message. This happened initially under WinXP as well but adaware and spybot seem to have rendered the offending item powerless under this OS.

Given that Tbird in both OSs point at the same message directory I conclude that there is perhaps a piece of (java?) script that is operating on the incoming message under Linux to cause this.

Whatever is the cause I'd like to restore the system to its previous expected behaviour pattern.

Changed anti virus from Zone alarm to Avast. Avast has detected virus Win32.Faker-M virus in mail directory. Need to get rid of that and then re-check.
Logged
oliverjames
Newbie
*
Posts: 3


View Profile
« Reply #3 on: July 09, 2008, 04:12:59 AM »

I switched Antivirus from Zone Alarm to Avast and immediately turned up the trojan Win32;Faker-M lurking in my Tbird inbox. Furthermore found a compression bomb in the send file.

Cured by moving all needed messages to relevant Tbird archive folder. Then, as root under Linux, created new mail folder and moved all files except the infected inbox and sent files to this new mail folder. Then deleted the folders from CLI as root before renaming the mail folder a nd reopening Tbird to recreate inbox and sent files.

Tbird now works as expected under WinXP and Linux.
Logged
Bobby
Administrator
Newbie
*****
Posts: 290



View Profile
« Reply #4 on: July 09, 2008, 11:25:42 PM »

sounds great! thank you for sharing your experience, i hope it will be useful for others who got similar problems.
Logged

I reccomend Spyware Doctor and Malwarebytes’ Anti-malware as ultimate protection.
Pages: [1]
  Print  
 
Jump to:  




Recommended software:
STOPzilla
(90/100)
STOPzilla is a powerful anti-spyware program that detects, blocks, and removes malicious software allowing users to surf the Web not worrying about spyware, Trojan horses,...
Malwarebytes Anti Malware
(88/100)
There are loads of malware removers on the net today and most of them are lightweight applications, which usually means they’re fast and don’t...
Spyware Doctor
(87/100)
Spyware Doctor is a very powerful, but yet highly user-friendly spyware remover, made by PC Tools, reputable computer security experts. This product provides effective and...
SpyHunter
(86/100)
SpyHunter is a quite simple, but yet highly effective spyware remover with an easy-to-use interface. This program is an excellent choice for users, who are...
XoftSpySE Anti Spyware
(84/100)
XoftSpySE, an anti-spyware program made by ParetoLogic, Inc., is a simple, but effective on-demand scanner with the typical set of functions but very easy to...
Encyclopedia of parasites:

Spreading the knowledge:

It is very hard to fight Computer parasites alone in internet space. If you have a website we would be more than happy if you would help us to spread the knowledge about latest threats. You can help your visitors to manage their Computer system manually without aditional expences. Knowledge is the power, we just need to spread it.
add text box
rss feed
help other