E-mails cloaked as coming from Pbnation.com staff containing a virus - PbNation
Find fields & stores near you!
Find fields and stores
Zipcode
PbNation News
PbNation News
Community Focus
Community Focus

 
Archived Thread - Cannot Edit  
Old 03-04-2004, 12:40 AM #1
Deceit
What?
 
Deceit's Avatar
 
Join Date: Feb 2001
Deceit is a Supporting Member
 has been a member for 10 years
E-mails cloaked as coming from Pbnation.com staff containing a virus

Recently many members have been complaining of the Pbnation.com mailer sending e-mail with attachments containing a virus.

The body of the e-mail goes something like:

Quote:
Hello user of Pbnation.com e-mail server,

We warn you about some attacks on your e-mail account. Your computer may
contain viruses, in order to keep your computer and e-mail account safe,
please, follow the instructions.

Please, read the attach for further details.

For security purposes the attached file is password protected. Password is "52568".

Sincerely,
The Pbnation.com team http://www.pbnation.com
Also they might say something pertaining to your e-mail being discontinued.

Recent e-mail were cloaked to appear to be coming from support@pbnation.com and staff@pbnation.com. We urge you if you recieve any e-mail making a claim besides your regularly sent e-mail (thread subscriptions and private message notifications) that you delete it immediately.

Pbnation.com will never send you an e-mail containing attachments. Be suspicious if it makes claims and requires you to read an attachment for more information. If you are unsure please contact Abuse@Pbnation.com.

The Pbnation.com e-mail server is not hacked. Whomever is sending them is cloaking their e-mails with our e-mail addresses. Be sure to read the full header to verify.

The recent addresses are:

lucey4@aol.com (HELO jared)


The file name of the virus is:

pigbdpyaj.exe zipped into a file named TextFile.zip and it will be 12-13k in size.

Scan type: Realtime Protection Scan
Event: Virus Found!
Virus name: W32.Beagle.A@mm
File: C:\DOCUME~1\User\LOCALS~1\Temp\Temporary Directory 1 for TextFile.zip\pigbdpyaj.exe
Location: Quarantine
Computer: YOUR-SMYLJR82PW
User: User
Action taken: Quarantine succeeded : Access denied
Date found: Thursday, March 04, 2004 12:37:48 AM


If you have any new information please e-mail it to Abuse@Pbnation.com or Kyle.
__________________
Mike
Deceit is offline  
Old Sponsored Links Remove Advertisement
Advertisement
Old 03-04-2004, 01:18 AM #2
AyanamiRei (Banned)
yuo liek teh brasseire??/
 
AyanamiRei's Avatar
 
Join Date: Nov 2003
 has been a member for 10 years
O______O track those mofos down and slap em silleh
AyanamiRei is offline  
Old 03-04-2004, 01:40 AM #3
ns20
 
 
ns20's Avatar
 
Join Date: Jul 2003
Location: what?
ns20 is a Supporting Member
 has been a member for 10 years
I just got one today. Good thing im lazy and didnt feel like clicking on the attachment and following the steps. See being lazy sometimes pays off.
ns20 is offline  
Old 03-04-2004, 05:52 AM #4
Not a former member
Needs a team
 
Join Date: Sep 2003
Location: (Nor*859*Ken)
 has been a member for 10 years
and thus shows why i never open pbnation mails


i just delete em all.... dont feel like taking the time i guess



oh well i got that email but deleted it... haha stupid hackers
__________________
Get with the program strip to the slow jam slip on a Trojan kissin' the toes and move to the knees go back, repeat the job ain't done 'til you ruin the sheets
Not a former member is offline  
Old 03-04-2004, 06:33 AM #5
VApaintballer400
Business Instead of Game
 
VApaintballer400's Avatar
 
Join Date: Apr 2002
Location: *703*
VApaintballer400 is a Supporting Member
 has been a member for 10 years
Wow dammit, I got the same thing from my ISP. It was from Support@cox.net saying that people have complained about the spam coming out of my outbox and that i probabaly have a Trojan. Well it sent me the text file with the password, and i downloaded it. Dammit i suck. How can i get rid of it?
__________________
::Feedback::
VApaintballer400 is offline  
Old 03-04-2004, 06:55 AM #6
ShortStroke
*925* Word.
 
ShortStroke's Avatar
 
Join Date: Jul 2003
Location: Afghanistan
 has been a member for 10 years
Yeah, I got banned from AOL after somebody used my email to send about 200 emails containing a porno virus (spams your comp w/ porno pop ups until it can no longer function properly) or something. Hope you guys can get them.
__________________
destroy.

My Feedback
ShortStroke is offline  
Old 03-04-2004, 07:42 AM #7
spencer069
 
 
spencer069's Avatar
 
Join Date: May 2002
Location: DFW TX & Tulsa OK
 has been a member for 10 years
ya i got it from yahoo.
spencer069 is offline  
Old 03-04-2004, 09:03 AM #8
aspazatak
 
 
aspazatak's Avatar
 
Join Date: Nov 2003
Location: Oviedo, FL
aspazatak is a Supporting Member
 has been a member for 10 years
Everyone, I work for an IP carrier and the best rules to follow I can give you all is this.

1. Your ISP will never send you an annoucement such as in this thread with an attachment. They should alway just type whatever they want to say in the body of the message.

2. Your ISP will never ask for your password

3. Do not open attachments if you were not expecting to receive them. Used to you could open them from people you knew, but with the worm virus's today it's really hard to tell.

4. Use a Mail program that doesn't open the email on a preview without sanitizing it. I.E. No Outlook prior to 2003, and no outlook express.

5. Use a spam filtering program to weed out a lot of the garbage. Personally I use Spambayes because it's free and it catches about 95% of the spam I receive with about a 5% false positive rating.

6. Keep your computer up to date with critical updates and security patches

7. Run a virus scanner all the time. Personal choice is Mcafee, but if money is a concern you can to to grisoft.com and they provide one for free.

I also received one of these messages, but the funny thing was the virus spoofed my email as the sender. So it was obivously questionable when I received a mail from myself telling me something was wrong with my mailbox and instructing me to open an attachment to clean it.
__________________
Yes I'm a ref!
aspazatak is offline  
Old 03-04-2004, 09:13 AM #9
MeRcaNtiCo
OGDT 12/29
 
MeRcaNtiCo's Avatar
 
Join Date: Jul 2003
Location: Portland, OR
MeRcaNtiCo is a Supporting Member
 has been a member for 10 years
tell me if you need any help finding them or tracking them down.
__________________
`mErc

I like alcohol
MeRcaNtiCo is offline  
Old 03-04-2004, 09:25 AM #10
*NiTr0*
Ex *********
 
*NiTr0*'s Avatar
 
Join Date: May 2003
Location: Maryland.
*NiTr0* is a Supporting Member
 has been a member for 10 years
Actually, My parents have gotten this from Comcast, and i got about 5 of them from Yahoo.com, Its everywhere.
__________________
cyanide RIP
hometown heroes coming to a town near you

Ex moderator
*NiTr0* is offline  
Old 03-04-2004, 09:27 AM #11
kookiemonstar
Manager- bosco paintball
 
kookiemonstar's Avatar
 
Join Date: Nov 2003
Location: Jersey...
 has been a member for 10 years
Information on "virus" I got this strain yesterday from a friend. It's the j@mm strain, your sending the A@mm strain, but it's the same basic thing. I'm having a hard time getting rid of it. It messed up my norton auto-update files so I had to reinstall that before i updated and removed it. It's actually a worm your sending out.
kookiemonstar is offline  
Old 03-04-2004, 10:16 AM #12
miney
Westwood Addict
 
miney's Avatar
 
Join Date: Mar 2002
Location: philadelphia
miney is a Supporting Member
 has been a member for 10 years
Quote:
Originally posted by kookiemonstar
Information on "virus" I got this strain yesterday from a friend. It's the j@mm strain, your sending the A@mm strain, but it's the same basic thing. I'm having a hard time getting rid of it. It messed up my norton auto-update files so I had to reinstall that before i updated and removed it. It's actually a worm your sending out.
They're not sending anything out, that's the whole point. The virus is forging message headers. Pbnation, like many other domains, is a victim by association. They're not infected with anything nor are they sending anything out.
__________________
Shocktech w/ eblade for sale!

..and you've eaten your pen. simply tunning.

www.drexelpaintball.com
miney is offline  
Old 03-04-2004, 12:55 PM #13
Bunkerboy707
Gun Runner
 
Bunkerboy707's Avatar
 
Join Date: Dec 2003
Location: "the Farm" 707 vacaville
 has been a member for 10 years
I got one today also..
__________________
DEATH OR GLORY.
[G00N][SO*BROKE][HKD]
Bunkerboy707 is offline  
Old 03-04-2004, 01:12 PM #14
::TraumaheaD::
 
Join Date: Jun 2003
 has been a member for 10 years
I open most of my pbnation emails... is it safe to click on the link for the thread? or Should we be looking for a specific name to avoid. ( a name on the "PBnation" emial)
::TraumaheaD:: is offline  
Old 03-04-2004, 01:59 PM #15
TanGo404
 
 
TanGo404's Avatar
 
Join Date: Mar 2002
Location: Montreal
 has been a member for 10 years
Holy crap

I got one of these emails this morning from noreply@thrill-tech.com, saying that my account has been suspended due to unauthorized use, with an attached .pif that was said to go into further detail. Frustrated by the fact that outlook xp was blocking all my attachments from being downloaded, I looked for a good 30-45 min on how to actually modify the list of accepted file types. As I came across the solution, my mom dragged my off the comp to go to school before I actually had a chance to download the .pif. I was angry at her at first, but now I will go home and thank her!
__________________
http://www.thrill-tech.com
Custom low pressure parts
TanGo404 is offline  
Old 03-04-2004, 04:36 PM #16
mauikalohe
 
 
mauikalohe's Avatar
 
Join Date: Jan 2004
Location: NC San Deigo
mauikalohe is a Supporting Member
 has been a member for 10 years
Yeah I run a mail server too, we got the same problem. Pretty cleaver the way they did that, dumb idiots for doing it though, get a life people
mauikalohe is offline  
Old 03-04-2004, 07:27 PM #17
bgnorm69
Vagatarian
 
bgnorm69's Avatar
 
Join Date: Nov 2002
Location: Central Florida
bgnorm69 is a Supporting Member
 has been a member for 10 years
yea i got that **** too loaded my comp with viruses that beagle crap took me hours to remove that **** i was pissed thinking it came from the nation ,yahoo sent me the same thing too

Last edited by bgnorm69 : 03-04-2004 at 07:30 PM.
bgnorm69 is offline  
Old 03-04-2004, 09:35 PM #18
c|w (Banned)
Random Hero
 
c|w's Avatar
 
Join Date: Oct 2002
Location: maine
 has been a member for 10 years
somsone send this to SP
c|w is offline  
Old 03-04-2004, 10:20 PM #19
PBguy889
 
 
PBguy889's Avatar
 
Join Date: Jun 2003
Location: Birmingham, AL
 has been a member for 10 years
dude i got that same virus except it was from the "yahoo administration" the only thing they didnt know is anything from yahoo to a yahoo account wont go into the bulk folder and its always highlighted blue. so anyone who has a yahoo email address you might have gotten the same virus.
__________________
Warning: Pringles may cause loose stool.

Elwood Blues - "It"s 106 miles to Chicago. We've got a full tank of gas, half a pack of cigarettes, its dark and were wearing sunglasses."

Jake Blues - "Hit it"
PBguy889 is offline  
Old 03-04-2004, 10:40 PM #20
dirty-resdogs
Too Dirrty
 
Join Date: Jan 2004
Location: Guelph, ON
 has been a member for 10 years
Thats crazy!
Exact same one was going around my school - University of Guelph.
3 different bodys however
__________________
Guelph, Ont
-------------------
Reservoir Dogs
Sponsored by : AKA! | VBW -AKA parts in Ont | XBN Paintball Park
www.KevinHibma.com - Paintball and Sporting Photography
dirty-resdogs is offline  
Old 03-05-2004, 02:57 AM #21
mrtodd13
 
 
mrtodd13's Avatar
 
Join Date: Nov 2001
Location: Lake Oswego, Oregon
mrtodd13 is a Supporting Member
 has been a member for 10 years
Nasty.

I happen to be a co-owner of paintballnorthwest.com

Got an email on a personal AOL account from - guess who - info@paintballnorthwest - with all that jazz. The irony! They sent it to the wrong person! Hah.

Creepy; they've got into my website and pbnations .

-Todd
__________________
______Pbnw___________
Nurv - AKA - BoneBrake
mrtodd13 is offline  
 




Posting Rules
Forum Jump