What's this?

HideInLight

Expert Member
Joined
Oct 31, 2006
Messages
4,600
Reaction score
1,061
Trying to help someone remove a possible virus. They received this message from telkom. When she called them they said that they detected R500 of international calls being made via a web dialer. The lady on the end of the line is from the telkom fraud unit.

Afternoon Telkom detected on line 056471008 that when using the internet that there is a virus on the computer.This is dailling to International destination. take nothe that telkom do not credit these call as its via web dialer.
Mrs Coetzee
0123117459

Also received this email, might have a connection to what ever is happening.

> PLEASE READ & FORWARD !
>
> Hi All,
>
> I checked with Norton Anti-Virus, and they are gearing up for this
> virus!
> I checked Snopes, and it is for real Get this E-mail message sent
> around to all your contacts ASAP.
>
> PLEASE FORWARD THIS WARNING AMONG YOUR FRIENDS, FAMILY AND
CONTACTS!
>
>
> You should be alert during the next few days. Do not open any
message
> with an attachment entitled 'POSTCARD FROM HALLMARK ,'regardless of
> who sent it to you.. It is a virus which opens A POSTCARD IMAGE ,
> which 'burns' the whole hard disc C drive of your computer.
>
> This virus will be received from someone who has your e-mail
address
> on his/her contact list. That is the reason why you need to send
this
> e-mail to all your contacts. It is better to receive this message
25
> times than to receive the virus and open it!
>
> If you receive a mail called' POSTCARD ,' even if it is sent to
you
> by a friend, do not open it! Shut down your computer immediately.
> This is the worst virus announced by CNN.
>
> It has been classified by Microsoft as the most destructive virus
> ever. This virus was discovered by McAfee yesterday, and there is
no
> repair yet for this kind of virus. This virus simply destroys the
> Zero Sector of the Hard Disc, where the vital information is
kept..
>
> COPY THIS E-MAIL, AND SEND IT TO YOUR FRIENDS.
> REMEMBER: IF YOU SEND IT TO THEM, YOU WILL BENEFIT ALL OF US
>
>


I am using the Free version of SPAMfighter.
We are a community of 6 million users fighting spam.
SPAMfighter has removed 249 of my spam emails to date.
The Professional version does not have this message.



__________ Information from ESET NOD32 Antivirus, version of virus signature database 4760 (20100111) __________

The message was checked by ESET NOD32 Antivirus.

http://www.eset.com

Which might have something to do with it. Can someone confirm if Spamfighter is indeed a legit program.
 
Oh come on! Surely you can see this is a scam??? Doesn't the bad spelling and grammar give it away?

The second email is a typical chain email. Don't legitimise it by forwarding it, please.
 
Oh come on! Surely you can see this is a scam??? Doesn't the bad spelling and grammar give it away?

Not really. This does happen and I have seen it before. Some service runs in the background making your old analogue modem dial premium number overseas so the fsckers generate money from calls received. I don't see this working with a adsl modem though as I do not think it's capable of passing on dtmf tones.

I would follow up on this one as it might be legit but do not surrender any personal details or bank details etc. The phone number range 012 311-xxxx is used by Telkom in Pretoria head office.
 
Oh come on! Surely you can see this is a scam??? Doesn't the bad spelling and grammar give it away?

As far as I can tell, that was a voice message (perhaps?). In which case bad grammar could be excused, especially considering the caller was a Mrs Coetzee (traditionally Afrikaans name).

The logical thing to do would be to call Telkom directly and perhaps run a virus scan!
 
Anyone care to tell me what the "Zero Sector" of a hard drive is? Maybe you can build a GUI in Visual Basic to trace the IP...
 
> COPY THIS E-MAIL, AND SEND IT TO YOUR FRIENDS.
> REMEMBER: IF YOU SEND IT TO THEM, YOU WILL BENEFIT ALL OF US

US. Not you or your friends...

lol
 
Yeah was a on a modem (busniness line)
Had found a few virusses on their computer. They somehow got pass Kaspersky...
There's now problem with their email. They're unable to send any email, getting an error message from their ISP's server.
"Rejected or to. many conccurrent connections"

There's a big change that the virus came from their ISP through the email server. The email might of seemed legit because it was from someone she knew.
 
Top
Sign up to the MyBroadband newsletter
X