Print Page | Close Window

Email Virus Attack

Printed From: Web Wiz Forums
Category: General Discussion
Forum Name: General Discussion
Forum Description: General discussion and chat on any topic.
URL: https://forums.webwiz.net/forum_posts.asp?TID=11575
Printed Date: 31 March 2026 at 11:59am
Software Version: Web Wiz Forums 12.08 - https://www.webwizforums.com


Topic: Email Virus Attack
Posted By: zMaestro
Subject: Email Virus Attack
Date Posted: 19 August 2004 at 1:28am

I have a mail box that is attacked heavily by virus emails, more than 250 email, anyone else is facing this now?




Replies:
Posted By: Mart
Date Posted: 19 August 2004 at 4:02am
Mines virus and spam free atm, don't know how. I usually get loads of viruses and spam


Posted By: WebWiz-Bruce
Date Posted: 19 August 2004 at 4:38am
I get over a 1,000 a day, these not much that can be done about it.

Viruses now scan the entire infected persons computer for email addresses in text files, web pages, addresses books, etc. You just have to be careful where you leave your email address.

The only solution I have had to do to cut the amount from over 2,000 a day is to get rid of all catch all email accounts and those that get allot of viruses and spam sent is to delete the mail and send an auto-responder back saying the email address is no longer in use and directing the person to an on-line form if they urgently need to contact me.


-------------
https://www.webwiz.net/web-wiz-forums/forum-hosting.htm" rel="nofollow - Web Wiz Forums Hosting
https://www.webwiz.net/web-hosting/windows-web-hosting.htm" rel="nofollow - ASP.NET Web Hosting


Posted By: the boss
Date Posted: 19 August 2004 at 5:38am
by sending a response back u r giving an impression that this address is valid!!

-------------
http://www.web2messenger.com/theboss">


Posted By: WebWiz-Bruce
Date Posted: 19 August 2004 at 6:17am
Yes, but if I just completly remove an email addresses to this site listed in the software etc. then people will not be able to contact the site at all.

At least this way when a legitmate person trys to email the site they get back an auto-response letting them know a valid way to contact the site through an online form. Otherwise they may just think that their email is ignored or it maybe an important issue and the person has no valid way of contact me.


-------------
https://www.webwiz.net/web-wiz-forums/forum-hosting.htm" rel="nofollow - Web Wiz Forums Hosting
https://www.webwiz.net/web-hosting/windows-web-hosting.htm" rel="nofollow - ASP.NET Web Hosting


Posted By: Mart
Date Posted: 19 August 2004 at 6:54am

You could also report the message to their ISP, open up the message headers and look for the

X-OriginatingIP header, from this you can get the senders IP address. Then do a whois on the IP and report the message to the abuse address listed in the whois. There are programs that do this for you



Posted By: dpyers
Date Posted: 19 August 2004 at 11:48am

Getting rid of catchall accounts helped me a lot. Don't bother to send a response back as in my situation, if a valid user sees a kick-back, they look up the proper email address.

Also, upstream virus blocking by the web host - like spamhaus, spam assassin, etc. helped a lot.

I use Outlook 2003 and Norton Anti-Spam on the local PC. Going to let the Norton Anti-Spam subscription drop as Outlook catches 99% of the spam that hits my pc and Norton Anti-Virus catches all the virus emails.

I get about 40 spam's a day, and maybe 1 virus email every few weeks. Use a couple of dozen email addresses. Most of spam/virus emails go to two email addresses - the one used for my major isp, and one that I've been using for about 10 years. The one I've been using for 10 years used to be on web pages as a "mail:to" link, and I also used to post to news groups with it.

Now, I never use mail:to links - only web forms -  and I post to news groups using a hotmail account that deletes all incoming mail. some people claim that url encoding a mail:to link keeps the email address harvesters from gettin your address, but I don't think it's a great leap for a spam harvester to look for an encoded @ instead of a character one.

EDIT: Did a test for a client a while back who wanted his email address in text instead of using an image of it linked to a form. He got a spam within an hour of putting a test email address on a page. I've read of people who got a spam within 10 minutes of posting an address.



-------------

Lead me not into temptation... I know the short cut, follow me.


Posted By: Rudster
Date Posted: 21 July 2005 at 5:49pm
I'm getting bombarded with emails to ficticious members with a virus 'important-details.zip' attached. (I-Worm/Mytob.IF.)
 
The emails contain standard webwiz text...
 
'your account suspended'
'password reset'
'warning: your services near to be close'
 
Why is this?
 
Is there anyway of tracing there origin?
 
J


-------------
http://www.sportsregister.co.uk">


Posted By: dpyers
Date Posted: 21 July 2005 at 9:15pm
You can check the headers but the place they're sent from is not always they place they originate from. Awful lot of pc's out there infected with zombie mailers.

-------------

Lead me not into temptation... I know the short cut, follow me.


Posted By: zMaestro
Date Posted: 22 July 2005 at 1:29pm
this thread is 1 year old... we are getting old very fast Dead


Posted By: dpyers
Date Posted: 22 July 2005 at 1:49pm
Older, but much finer!

Rudster - forgot to mention... make sure you don't have a "catch all" mailbox. You'll have no need for one and all it turns into is a spam pit.


-------------

Lead me not into temptation... I know the short cut, follow me.


Posted By: Rudster
Date Posted: 25 July 2005 at 9:33am
Thanks dpyers, I will speak to my email host
 
All the spam I am receiving are webwiz standard email, so this must be because I am running a webwiz site?  Does eveybody get this problem?  If so, why is webwiz under attack?
 
Confused
 
JR


-------------
http://www.sportsregister.co.uk">


Posted By: dpyers
Date Posted: 25 July 2005 at 10:57am
Other than  'password reset', the other two -  'your account suspended' and 'warning: your services near to be close' are not standard wwf text.

Sounds like someone's on a phishing expedition similar to the phony emails from Paypall. I consistently get email that's supposedly from a bank asking me to verify my personal account info for a bank I never heard of. Examination of the url for the link that you're supposed to click on will reveal a faked url.

You're getting the phishing info so someone can obtain your password to your wwf site. They can get your forum specific mail address in one of three ways...
  1. You have "Allow members to send me email" checked in your profile. Always use PM, that's what it's there for.
  2. You didn't secure your access db. In which case one or more people got the email addresses of everyone registered for your forum.
  3. You posted your email address in the forum.


-------------

Lead me not into temptation... I know the short cut, follow me.



Print Page | Close Window

Forum Software by Web Wiz Forums® version 12.08 - https://www.webwizforums.com
Copyright ©2001-2026 Web Wiz Ltd. - https://www.webwiz.net