<?xml version="1.0" encoding="UTF-8"?><!-- generator="wordpress/2.3.3" -->
<rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	>
<channel>
	<title>Comments on: An official looking e-mail from the IRS may be a virus</title>
	<link>http://www.spamstopshere.com/blog/2008/04/04/an-official-looking-e-mail-from-the-irs-may-be-a-virus/</link>
	<description>IT and security blog</description>
	<pubDate>Thu, 20 Nov 2008 14:59:34 +0000</pubDate>
	<generator>http://wordpress.org/?v=2.3.3</generator>
		<item>
		<title>By: John</title>
		<link>http://www.spamstopshere.com/blog/2008/04/04/an-official-looking-e-mail-from-the-irs-may-be-a-virus/#comment-2000</link>
		<dc:creator>John</dc:creator>
		<pubDate>Thu, 03 Jul 2008 20:51:27 +0000</pubDate>
		<guid>http://www.spamstopshere.com/blog/2008/04/04/an-official-looking-e-mail-from-the-irs-may-be-a-virus/#comment-2000</guid>
		<description>Try uploading the file/attachment to this virus scanner:
http://www.virustotal.com</description>
		<content:encoded><![CDATA[<p>Try uploading the file/attachment to this virus scanner:<br />
<a href="http://www.virustotal.com" rel="nofollow">http://www.virustotal.com</a></p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Heads-up: IRS Spam Now in the Wild &#8212; MiPro Unfiltered</title>
		<link>http://www.spamstopshere.com/blog/2008/04/04/an-official-looking-e-mail-from-the-irs-may-be-a-virus/#comment-1978</link>
		<dc:creator>Heads-up: IRS Spam Now in the Wild &#8212; MiPro Unfiltered</dc:creator>
		<pubDate>Wed, 02 Jul 2008 17:38:16 +0000</pubDate>
		<guid>http://www.spamstopshere.com/blog/2008/04/04/an-official-looking-e-mail-from-the-irs-may-be-a-virus/#comment-1978</guid>
		<description>[...] Deeper research shows that it quite possibly might be a trojan horse that installs a virus; if you read the comments in the previous link, you&#8217;ll see different delivery mechanisms. Some are PDFs, some ZIP files, some DOCs. Regardless, it seems as if the object, regardless of its wrapper, installs some sort of malicious payload. [...]</description>
		<content:encoded><![CDATA[<p>[&#8230;] Deeper research shows that it quite possibly might be a trojan horse that installs a virus; if you read the comments in the previous link, you&#8217;ll see different delivery mechanisms. Some are PDFs, some ZIP files, some DOCs. Regardless, it seems as if the object, regardless of its wrapper, installs some sort of malicious payload. [&#8230;]</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Monique</title>
		<link>http://www.spamstopshere.com/blog/2008/04/04/an-official-looking-e-mail-from-the-irs-may-be-a-virus/#comment-1201</link>
		<dc:creator>Monique</dc:creator>
		<pubDate>Sun, 18 May 2008 10:47:35 +0000</pubDate>
		<guid>http://www.spamstopshere.com/blog/2008/04/04/an-official-looking-e-mail-from-the-irs-may-be-a-virus/#comment-1201</guid>
		<description>This spam mail is also active in The Netherlands!</description>
		<content:encoded><![CDATA[<p>This spam mail is also active in The Netherlands!</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Andy</title>
		<link>http://www.spamstopshere.com/blog/2008/04/04/an-official-looking-e-mail-from-the-irs-may-be-a-virus/#comment-147</link>
		<dc:creator>Andy</dc:creator>
		<pubDate>Thu, 24 Apr 2008 15:04:12 +0000</pubDate>
		<guid>http://www.spamstopshere.com/blog/2008/04/04/an-official-looking-e-mail-from-the-irs-may-be-a-virus/#comment-147</guid>
		<description>My head Accountant recieved this messsage just minutes ago, nothing was opened or extracted but it is a concern of course, you would think my spam filter would have caught this...</description>
		<content:encoded><![CDATA[<p>My head Accountant recieved this messsage just minutes ago, nothing was opened or extracted but it is a concern of course, you would think my spam filter would have caught this&#8230;</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Mark Adams</title>
		<link>http://www.spamstopshere.com/blog/2008/04/04/an-official-looking-e-mail-from-the-irs-may-be-a-virus/#comment-88</link>
		<dc:creator>Mark Adams</dc:creator>
		<pubDate>Wed, 16 Apr 2008 17:52:27 +0000</pubDate>
		<guid>http://www.spamstopshere.com/blog/2008/04/04/an-official-looking-e-mail-from-the-irs-may-be-a-virus/#comment-88</guid>
		<description>Steven,

The removal requirements could vary. I would recommend hiring your local IT security response company with experience with removing viruses. If you still have a copy of the virus, it will be easier. You may also try a commercial anti-virus product and giving the vendor a call for assistance.

You may also want to see this &lt;a href="http://www.microsoft.com/emea/spotlight/sessionh.aspx?videoid=359" rel="nofollow"&gt;presentation&lt;/a&gt; from Microsoft on advanced malware removal.</description>
		<content:encoded><![CDATA[<p>Steven,</p>
<p>The removal requirements could vary. I would recommend hiring your local IT security response company with experience with removing viruses. If you still have a copy of the virus, it will be easier. You may also try a commercial anti-virus product and giving the vendor a call for assistance.</p>
<p>You may also want to see this <a href="http://www.microsoft.com/emea/spotlight/sessionh.aspx?videoid=359" rel="nofollow">presentation</a> from Microsoft on advanced malware removal.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Steven</title>
		<link>http://www.spamstopshere.com/blog/2008/04/04/an-official-looking-e-mail-from-the-irs-may-be-a-virus/#comment-82</link>
		<dc:creator>Steven</dc:creator>
		<pubDate>Tue, 15 Apr 2008 19:55:11 +0000</pubDate>
		<guid>http://www.spamstopshere.com/blog/2008/04/04/an-official-looking-e-mail-from-the-irs-may-be-a-virus/#comment-82</guid>
		<description>OH, here is what the e-mail 

From: jim.lanton@irs.gov [mailto:jim.lanton@irs.gov] 
Sent: Tuesday, April 15, 2008 11:14 AM
To: Steven
Subject: Re:company report for ABC PLLC

------------------------------------------------------------------------------- (These lines were the IRS logo)

To : Steven
The report is attached.

You need to complete the fields about Watson &#38; McDonell PLLC income.

Jim Lanton
IRS Fraud Department
  
© 2008 Internal Revenue Service All Rights Reserved.</description>
		<content:encoded><![CDATA[<p>OH, here is what the e-mail </p>
<p>From: <a href="mailto:jim.lanton@irs.gov">jim.lanton@irs.gov</a> [mailto:jim.lanton@irs.gov]<br />
Sent: Tuesday, April 15, 2008 11:14 AM<br />
To: Steven<br />
Subject: Re:company report for ABC PLLC</p>
<p>&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;- (These lines were the IRS logo)</p>
<p>To : Steven<br />
The report is attached.</p>
<p>You need to complete the fields about Watson &amp; McDonell PLLC income.</p>
<p>Jim Lanton<br />
IRS Fraud Department</p>
<p>© 2008 Internal Revenue Service All Rights Reserved.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Steven</title>
		<link>http://www.spamstopshere.com/blog/2008/04/04/an-official-looking-e-mail-from-the-irs-may-be-a-virus/#comment-81</link>
		<dc:creator>Steven</dc:creator>
		<pubDate>Tue, 15 Apr 2008 19:41:59 +0000</pubDate>
		<guid>http://www.spamstopshere.com/blog/2008/04/04/an-official-looking-e-mail-from-the-irs-may-be-a-virus/#comment-81</guid>
		<description>Hi,
I found your site because I opened a samilar e-mail with the company_report.zip file and now I am pretty sure it has infected my computer.  IE is really slow and takes up 25% of the CPU process when I open it.  There is a lot of svchost.exe processes.  I have not been able to find anything removal tips. I found an artical at Symantec for Backdoor.Robofo, aka, TROJ_AGENT.AZZZ, but I am not so sure it is the same thing.  I check the files and registry and didn't see any of the entries suggested by symantec that Backdoor.bobofo would drop or modify.

any ideas?</description>
		<content:encoded><![CDATA[<p>Hi,<br />
I found your site because I opened a samilar e-mail with the company_report.zip file and now I am pretty sure it has infected my computer.  IE is really slow and takes up 25% of the CPU process when I open it.  There is a lot of svchost.exe processes.  I have not been able to find anything removal tips. I found an artical at Symantec for Backdoor.Robofo, aka, TROJ_AGENT.AZZZ, but I am not so sure it is the same thing.  I check the files and registry and didn&#8217;t see any of the entries suggested by symantec that Backdoor.bobofo would drop or modify.</p>
<p>any ideas?</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Andrea</title>
		<link>http://www.spamstopshere.com/blog/2008/04/04/an-official-looking-e-mail-from-the-irs-may-be-a-virus/#comment-49</link>
		<dc:creator>Andrea</dc:creator>
		<pubDate>Mon, 07 Apr 2008 22:14:20 +0000</pubDate>
		<guid>http://www.spamstopshere.com/blog/2008/04/04/an-official-looking-e-mail-from-the-irs-may-be-a-virus/#comment-49</guid>
		<description>Thank you for taking the time to post this.  I had this in my inbox 1 day after filing and was suspicious of it.  I know better than to open attachments, but when you see IRS and taxes, you just want to do what needs to be done to make it go away:)  Thanks again.</description>
		<content:encoded><![CDATA[<p>Thank you for taking the time to post this.  I had this in my inbox 1 day after filing and was suspicious of it.  I know better than to open attachments, but when you see IRS and taxes, you just want to do what needs to be done to make it go away:)  Thanks again.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Nick S.</title>
		<link>http://www.spamstopshere.com/blog/2008/04/04/an-official-looking-e-mail-from-the-irs-may-be-a-virus/#comment-48</link>
		<dc:creator>Nick S.</dc:creator>
		<pubDate>Mon, 07 Apr 2008 20:08:54 +0000</pubDate>
		<guid>http://www.spamstopshere.com/blog/2008/04/04/an-official-looking-e-mail-from-the-irs-may-be-a-virus/#comment-48</guid>
		<description>Our accounting person received exactly the same e-mail (with our correct company name filled in) on the afternoon of the 3rd. I was just informed about it this afternoon.

Symantec Antivirus Corporate Edition v8 didn't detect it either. (I know, it's from 2002- but the definitions still get updated- current definition file is dated 4/4/2008.) I scanned the .zip first, then opened it in 7-Zip and extracted the .scr file, and scanned that as well. No warnings.

It has the correct company name, and it's addressed to the correct person at our organization- maybe a workstation inside the IRS is compromised and sending mail to people that agent has been in contact with? Maybe the agent's name is Timothy Johnson...? It would make it more legitimate if people actually had contact with somebody by that name previously.</description>
		<content:encoded><![CDATA[<p>Our accounting person received exactly the same e-mail (with our correct company name filled in) on the afternoon of the 3rd. I was just informed about it this afternoon.</p>
<p>Symantec Antivirus Corporate Edition v8 didn&#8217;t detect it either. (I know, it&#8217;s from 2002- but the definitions still get updated- current definition file is dated 4/4/2008.) I scanned the .zip first, then opened it in 7-Zip and extracted the .scr file, and scanned that as well. No warnings.</p>
<p>It has the correct company name, and it&#8217;s addressed to the correct person at our organization- maybe a workstation inside the IRS is compromised and sending mail to people that agent has been in contact with? Maybe the agent&#8217;s name is Timothy Johnson&#8230;? It would make it more legitimate if people actually had contact with somebody by that name previously.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Mark Adams</title>
		<link>http://www.spamstopshere.com/blog/2008/04/04/an-official-looking-e-mail-from-the-irs-may-be-a-virus/#comment-26</link>
		<dc:creator>Mark Adams</dc:creator>
		<pubDate>Sat, 05 Apr 2008 00:58:32 +0000</pubDate>
		<guid>http://www.spamstopshere.com/blog/2008/04/04/an-official-looking-e-mail-from-the-irs-may-be-a-virus/#comment-26</guid>
		<description>It's always a good idea to report e-mail borne malware and spam to the orginating IP address's ISP. However, not everyone has time to do this, or the knowledge necessary to determine which IP address connected to their e-mail server or who to report it to. Luckily, it sounds like you do have that knowledge. Although it's unlikely to lead to the culprit, it can slow down the spread of the e-mail and may even result in someone finding out that they had a security problem, as most of these are sent from compromised computers where the computer owner had no idea.</description>
		<content:encoded><![CDATA[<p>It&#8217;s always a good idea to report e-mail borne malware and spam to the orginating IP address&#8217;s ISP. However, not everyone has time to do this, or the knowledge necessary to determine which IP address connected to their e-mail server or who to report it to. Luckily, it sounds like you do have that knowledge. Although it&#8217;s unlikely to lead to the culprit, it can slow down the spread of the e-mail and may even result in someone finding out that they had a security problem, as most of these are sent from compromised computers where the computer owner had no idea.</p>
]]></content:encoded>
	</item>
</channel>
</rss>
