Looks like a scam? THIS IS A VIRUS!

The machines we love to hate

Moderator: Wiz Feinberg

Roy McKinney
Posts: 1169
Joined: 14 Oct 1999 12:01 am
Location: Ontario, OR
State/Province: Oregon
Country: United States

Looks like a scam? THIS IS A VIRUS!

Post by Roy McKinney »

I have been receving emails like this from Fedex also. Interesting fact is that all of the "addressed to:" are yahoo accounts! I have not tried to open any of them, being I haven't ordered anything to be shipped by either of them.????

Mon, March 21, 2011 4:12:50 AMUnited Parcel Service notification
From: United Parcel Service <infos>Add to Contacts
To: rsdouthit@yahoo.com

UPS notification.zip (5KB)


--------------------------------------------------------------------------------


Dear customer.

The parcel was sent your home address.
And it will arrive within 7 business day.

More information and the tracking number are attached in document below.

Thank you.
© 1994-2011 United Parcel Service of America, Inc.
Last edited by Roy McKinney on 21 Mar 2011 5:07 am, edited 1 time in total.
Roy McKinney
Posts: 1169
Joined: 14 Oct 1999 12:01 am
Location: Ontario, OR
State/Province: Oregon
Country: United States

Post by Roy McKinney »

This is a VIRUS and will lock up your computer with a program called "SYSTEM TOOLS"
Can't do anything now with my cmptr that is running Win7. Too the shop with it.
User avatar
Wiz Feinberg
Posts: 6117
Joined: 8 Jan 1999 1:01 am
Location: Mid-Michigan, USA
State/Province: Michigan
Country: United States

Post by Wiz Feinberg »

This FedEx scam is part of what are called Courier Scams. They arrive in spam emails with subjects and From lines claiming to be from UPS, FedEx, DHL, and Post Office Express, and other couriers. They always contain an attachment which purports to have a receipt, tracking code, failed delivery notice, or invoice, which needs to be printed out and taken to the "office." The file in said attachment is always a Trojan Horse; usually a botnet installer, Zeus/Spy-eye bank credential keylogger, Koobface, or a rogue security program.

People infected with System Tools and the likes can use Malwarebytes' Anti-Malware to combat it. You will almost certainly need to fight it after rebooting into Safe Mode With Networking. Often, a companion program known as Rkill is required to halt active rootkits and big brother protector processes. Rkill is available from BleepingComputer.com.

This misery can be avoided in the first place by keeping a registered version of Malwarebytes' Anti-Malware running with realtime protection and automatic updates enabled. The cost of the licensed version is minuscule compared to the cost of having your computer repaired in a shop.
"Wiz" Feinberg, Moderator SGF Computers Forum
Security Consultant
Twitter: @Wizcrafts
Main web pages: Wiztunes Steel Guitar website | Wiz's Security Blog | My Webmaster Services | Wiz's Security Blog