New Virus Appears as PayPal Scam

JGREGORY

Lieutenant
Joined
Jun 1, 2003
Messages
1,412
New Virus Appears as PayPal Scam<br />Mon Nov 17,12:00 PM ET Add Technology - PC World to My Yahoo! <br /> <br /><br />Lincoln Spector, special to PCWorld.com <br /><br />If you get an e-mail message warning you that your PayPal account is about to expire, don't open it. If you open it, don't double-click the attachment. If you double-click the attachment, don't complete the form asking for your credit card information. And if you do fill in the form, call your credit card company immediately.<br /><br />And don't blame PayPal. The problem is an e-mail virus, Mimail.I, first spotted on November 13. Most viruses are sick jokes; this one's out to steal your money.<br /><br />How It Works<br /><br />Mimail (pronounced "my mail") arrives in an e-mail that appears to be from PayPal. In very convincing language, it states that your account will expire soon unless you resubmit your credit card information. "We apologize for any inconvenience that this may cause," the text politely reads.<br /><br />The letter even appears concerned about your privacy: "Please do not send your personal information through e-mail, as it will not be as secure." Instead, it asks that you run the attached program. That's where you enter your valuable information, which it then sends to four different e-mail addresses.<br /><br />It also scours your hard drive for new e-mail addresses to send the same bogus message. These messages, like the one you got, are "spoofed" to appear as if they came from PayPal.<br /><br />"It appears to be another step in the advancement of spam," says David E. Sorkin, an associate professor with the Center for Information Technology and Privacy Law, at John Marshall Law School. "A few months ago there was talk about spammers using viruses to send spam. Now they're using them for fraud."<br /><br />Bryson Gordon, senior product manager for McAfee's Security Consumer Division, finds this "far more sophisticated in social engineering [than previous worms]... We're starting to see marked change in the battle with viruses: a worm for profit."<br /><br />Slow-Moving Pest<br /><br />Luckily Mimail hasn't spread very far--at least not yet.<br /><br />"It's not a major event. We're seeing less than a hundred infections overall," says Vincent Weafer, a senior director at antivirus vendor Symantec Security Response.<br /><br />As Weafer notes, that can change. "103259 Klez sat around for about a week and then shot up," he says. But he doubts this one will spread like Klez. Mimail is a "relatively easy one to explain. You can say 'If you see this, delete it.'"<br /><br />But justice is not likely to be served. According to Weafer, the culprits will get caught "Only if they're stupid." The logical trail to follow, of course, is the four e-mail addresses embedded in the code, but it's possible to set up anonymous e-mail accounts without identifying yourself, or set up an account with a stolen credit card.<br /><br />What to Do<br /><br />One thing is for certain: We'll see this sort of trick again, so it pays to take precautions.<br /><br />Be suspicious of any e-mail that asks for personal information, security experts advise.<br /><br />PayPal promises it "will never ask for your password or account information in an e-mail," and most other companies on the Internet do likewise. If an e-mail message contains a link to a form, examine the URL closely--it could be just one letter away from the correct domain name.<br /><br />Report suspicious e-mail to the company that is allegedly its source. PayPal has an e-mail address, spoof@paypal.com, for just this purpose.<br /><br />And, of course, keep your antivirus applications and definitions up to date. Users of Symantec's Norton AntiVirus products, as well as security programs from BitDefender and Network Associates, were able to download the appropriate protection by last Friday morning. In addition, both BitDefender and Network Associates offer free Mimail fixes on their Web sites.
 

wikelam

Chief Petty Officer
Joined
Apr 21, 2003
Messages
543
Re: New Virus Appears as PayPal Scam

thanks for the heads up. Just got my laptop back from shop, got a virus and had to have hard drive completely reformatted. big pain in the caboose. wife likes to open every email she gets.
 

Homerr

Commander
Joined
Mar 4, 2002
Messages
2,294
Re: New Virus Appears as PayPal Scam

Thanks for the heads up.<br /><br />Keep your anti-virus software updated. That is the best defense, and don't open ANY .exe attachments in your e-mail that you are not expecting.<br />People who don't run current anti-virus software are just asking for trouble (imo).<br />True, there are some viruses that can get around anti-virus software, but they are rare.<br /><br />I use Norton Anti-virus, Zone Alarm Pro, and a router w/built in firewall.... I don't get viruses!<br />Although I don't subscribe to it, my ISP offers a service that scans all your incoming and outgoing email for viruses. I assume other ISP's may offer the same.<br /><br />If you suspect your on-board virus scanner has a problem, go here and use this on-line one. It works great. I try to scan at least once a month with this one as well as my Norton.<br /><br /> Trend Micro "House Call" On-line Virus Scanner <br /><br />H.
 

Boomyal

Supreme Mariner
Joined
Aug 16, 2003
Messages
12,072
Re: New Virus Appears as PayPal Scam

I guess I don't need to bother forwarding my copy to PayPal. My wife received that email on Juno yesterday. I had to chuckle when it said "Do not reply to PayPal.com"
 

splugeeman

Petty Officer 2nd Class
Joined
Apr 12, 2003
Messages
179
Re: New Virus Appears as PayPal Scam

I got that email...I opened it...knowing what it was. I filled out what they wanted with a bunch of nonesense numbers! When I filled out the name part I told them my name was BITEME!.<br />Makes me feel just as good as wasting the telemarkerters time when they call.
 

Homerr

Commander
Joined
Mar 4, 2002
Messages
2,294
Re: New Virus Appears as PayPal Scam

There ya go Splugeeman...<br />I like to do that too!<br /><br />I also like to leave the local pizza parlor number, or the courthouse, or something of that nature.<br /><br />Find Bill Gates address and leave that!<br /><br />Hey...forward the message to me..I'd like to mess with it too!<br /><br />Homersplace@angelfire.com<br /><br />LOL!<br /><br />H.
 
Top