Welcome to SecurityForumz.com!
FAQFAQ      ProfileProfile    Private MessagesPrivate Messages   Log inLog in

Advice please.....W32.Beagle.X@mm

 
   Security Forums (Home) -> General Discussions RSS
Next:  Unresolved sites when browsing- virus-related???  
Author Message
John L

External


Since: Dec 15, 2004
Posts: 5



(Msg. 1) Posted: Thu Dec 16, 2004 5:14 am
Post subject: Advice please.....W32.Beagle.X@mm
Archived from groups: alt>comp>anti-virus (more info?)

Hi everyone,

Could someone please have look at this returned mail message ?

1. I didn't send the email.
2. I don't know the recipient at all.

Some background-
My Win2K OS was trashed by the CWW trojan a couple of
weeks ago. I reformatted my HDD and re-installed Win2K, grabbed
a CDROM from a friend, and installed SpywareBlaster, Spybot S & D,
AdAware, ZoneAlarm, and the evaluation version of bitdefender 8
(Standard).

According to bitdefender, my system is clean. In fact, the only
thing identifiedon my system is Alexa, which I haven't removed yet
(paranoid about messing with registry until I learn more about it).

The text below is a copy of the returned mail mssg I received. (I've
placed the asterisks to preserve anonymity)
This is the 3rd such email - the previous 2 emails had the virus
identified as W32.Beagle@xx!mm.

Any ideas / comments much appreciated.
Thanks,
John

****************************

Date: Thu, 16 Dec 2004 06:36:23 -0500 (EST)
From: Mail Delivery Subsystem <MAILER-DAEMON.RemoveThis@nymx02.mgw.rr.com>
To: <p****@erols.com>
Subject: Returned mail: see transcript for details
Auto-Submitted: auto-generated (failure)


The original message was received at Thu, 16 Dec 2004 06:36:11 -0500
(EST)
from pool-68-***-225-80.nwrk.east.verizon.net [68.***.225.80]


----- The following addresses had permanent fatal errors -----
<r****@twcny.rr.com>
(reason: 550 5.1.6 Recipient no longer on server:
rdp518.RemoveThis@twcny.rr.com)


----- Transcript of session follows -----
.... while talking to ms-mta-02-fn.nyroc.rr.com.:
>>> DATA
<<< 550 5.1.6 Recipient no longer on server: rdp518.RemoveThis@twcny.rr.com
550 5.1.1 <r****@twcny.rr.com>... User unknown
<<< 554 5.5.0 No recipients have been specified.
Reporting-MTA: dns; nymx02.mgw.rr.com
Received-From-MTA: DNS; pool-68-***-225-80.nwrk.east.verizon.net
Arrival-Date: Thu, 16 Dec 2004 06:36:11 -0500 (EST)


Final-Recipient: RFC822; r****@twcny.rr.com
Action: failed
Status: 5.1.6
Remote-MTA: DNS; ms-mta-02-fn.nyroc.rr.com
Diagnostic-Code: SMTP; 550 5.1.6 Recipient no longer on server:
rdp518.RemoveThis@twcny.rr.com
Last-Attempt-Date: Thu, 16 Dec 2004 06:36:23 -0500 (EST)
Received: from SYSTEM.net (pool-68-***-225-80.nwrk.east.verizon.net
[68.***.225.80])
by nymx02.mgw.rr.com (8.12.10/8.12.Cool with SMTP id
iBGBa8mE005603
for <r****@twcny.rr.com>; Thu, 16 Dec 2004 06:36:11 -0500 (EST)
Date: Thu, 16 Dec 2004 06:36:05 -0500
To: "R**" <r****@twcny.rr.com>
From: "P***" <p****@erols.com>
Subject: New changes
Message-ID: <i************t@twcny.rr.com>
MIME-Version: 1.0
Content-Type: multipart/mixed;
boundary="--------eiaeblfzkklvjddktxuz"
X-Virus-Scanned: Symantec AntiVirus Scan Engine
X-Virus-Scan-Result: Repaired 33994 W32.Beagle.X@mm

 >> Stay informed about: Advice please.....W32.Beagle.X@mm 
Back to top
Login to vote
John L

External


Since: Dec 15, 2004
Posts: 5



(Msg. 2) Posted: Thu Dec 16, 2004 8:38 am
Post subject: Re: Advice please.....W32.Beagle.X@mm [Login to view extended thread Info.]
Archived from groups: per prev. post (more info?)

Hi aD,

Since my system is clean (it IS and old virus - and bitdefender seems
to be held in very high regard) I feel confident that what I received
was the result of the virus spoofing my addy from elsewhere, something
I didn't know viruses could do.

Thanks very much for your reply,
John.

 >> Stay informed about: Advice please.....W32.Beagle.X@mm 
Back to top
Login to vote
aD

External


Since: Oct 30, 2004
Posts: 16



(Msg. 3) Posted: Thu Dec 16, 2004 1:25 pm
Post subject: Re: Advice please.....W32.Beagle.X@mm [Login to view extended thread Info.]
Archived from groups: per prev. post (more info?)

John L wrote:
> Hi everyone,
>
> Could someone please have look at this returned mail message ?
>
> 1. I didn't send the email.
> 2. I don't know the recipient at all.

If you know for a fact your computer didn't send the email, then ignore it.

I personally have had a few bounced email saying I tried to send a
virus/spam, and know of lots of other people who have had the same - even
when they have never had any dealings with the recipient address, ever.

It's a trait of a lot of mass-mailing viruses to spoof their From: address,
I don't worry about it and I'd say you don't need to either Smile


aD
 >> Stay informed about: Advice please.....W32.Beagle.X@mm 
Back to top
Login to vote
Display posts from previous:   
Related Topics:
can't get rid of w32.beagle.n - Hi, Can't seem to get rid of the above virus. Used the virus removal tool from Symantec and TrendMicro (in Safe mode on a Millenium PC). Both find the virus (100's of infections) and says everything is cleaned up. Upon reboot same thing. The removal too...

Beagle Info?? - I understand that when members of a mail list get the Beagle virus delivered it is not likely from the account who's name appears and that it is just sending out to someone's address book from another name in that address book. What I'm not clear on,..

W32.Beagle.AG@mm Virus - Can anyone direct me to a link that explains the headers in emails? I've been getting a daily virus email that seems to be coming from the same IP address, indicating the sender has the subject virus above. Here's the first "from" line in th...

W32.beagle.dl@mm question - I'm working with someone in Chat who contracted above ref'd infector on a PC running Windows 98SE, and Nortons Antivirus. We removed Beagle successfully in safe mode, however when Norton runs in normal mode, it keeps finding/detecting something (a fil...

Beagle infection ? - subject = Hi, Re:, Hello, Thanks, ... Message body = :), :)) Attachment= price.exe, price.scr, joke.exe, joke.com, joke.scr OS : Win98SE OE & IE : Ver 5.5 SP2 I receive them on....
   Security Forums (Home) -> General Discussions All times are: Pacific Time (US & Canada) (change)
Page 1 of 1

 
You can post new topics in this forum
You can reply to topics in this forum
You cannot edit your posts in this forum
You cannot delete your posts in this forum
You cannot vote in polls in this forum



[ Contact us | Terms of Service/Privacy Policy ]