Symantec Virus Warnings (phony)

Symantec Virus Warnings (phony)

Secure Home | Search | About
 Anti-Virus Software    Post an article   get this group's latest topics as an RSS feed add this group's latest topics to your My MSN content add this group's latest topics to your My Yahoo content add this group's latest topics to your Google content
Subject Author Date
Symantec Virus Warnings (phony) Oregano 09-06-2007
Posted by Oregano on September 6, 2007, 9:06 am
If you were  Registered and logged in, you could reply and use other advanced thread options
I am regularly being spammed by a "tool" that tells me a file I sent had a
virus attached to it and the "warning" comes from ses.symantec.com. I
genuinely suspect this is bogus and were I to click on the link (I'm
replicating one of the "emails" below) then I'd probably be hijacked. I've
gone onto Symantec's site and tried to notify them of the thing, sending the
IP from which it comes. I'm using Outlook 2003 and I've set a junk mail
filter so they're automatically deleted. BUT THEY ARE ANNOYING. What's even
more annoying is Symantec's lack of a link anywhere on their websites so you
can "talk" to them. That's why I dropped Norton/Symantec years ago. I'm
protected with F-Secure, rebranded by my ISP as if it's their own. Works for
me.

Is there anything else I can do? Am I doing the right thing? It just goes on
and on and on. Been almost a year now. You'd think the buggers who get tired
when they got no response from my IP. But then maybe a computer never gets
tired...or gives up.

Replicated:
This message has been processed by Symantec's AntiVirus Technology.
message.scr was infected with the malicious virus W32.Sality.U and has been
deleted because the file cannot be cleaned.

For more information on antivirus tips and technology, visit
http://ses.symantec.com/





Posted by Vanguard on September 6, 2007, 4:56 pm
If you were  Registered and logged in, you could reply and use other advanced thread options
> I am regularly being spammed by a "tool" that tells me a file I sent
> had a virus attached to it and the "warning" comes from
> ses.symantec.com. I genuinely suspect this is bogus and were I to
> click on the link (I'm replicating one of the "emails" below) then
> I'd probably be hijacked. I've gone onto Symantec's site and tried
> to notify them of the thing, sending the IP from which it comes. I'm
> using Outlook 2003 and I've set a junk mail filter so they're
> automatically deleted. BUT THEY ARE ANNOYING. What's even more
> annoying is Symantec's lack of a link anywhere on their websites so
> you can "talk" to them. That's why I dropped Norton/Symantec years
> ago. I'm protected with F-Secure, rebranded by my ISP as if it's
> their own. Works for me.
>
> Is there anything else I can do? Am I doing the right thing? It just
> goes on and on and on. Been almost a year now. You'd think the
> buggers who get tired when they got no response from my IP. But then
> maybe a computer never gets tired...or gives up.
>
> Replicated:
> This message has been processed by Symantec's AntiVirus Technology.
> message.scr was infected with the malicious virus W32.Sality.U and
> has been deleted because the file cannot be cleaned.
>
> For more information on antivirus tips and technology, visit
> http://ses.symantec.com/


Your, ahem, "copy" of the e-mail is worthless to anyone except you.
You show no headers. You don't indicate if what you pasted was from
the rendering of an HTML-formatted e-mail or if the e-mail was in
plain text. Obviously the URL that *you* show here is in the Symantec
domain but then we don't know if that is where the URL points in an
HTML-formatted e-mail.

Since only you have a copy of the purported e-mail, check the IP
address in the Received header for the sender to see if it belongs to
Symantec. If it is coming from Symantec then there is a very good
chance that you have submitted a file for them to analyze. For all we
know, you configured the Symantec software to forward a copy of
whatever you quarantine so they can analyze it.


Posted by Oregano on September 6, 2007, 7:33 pm
If you were  Registered and logged in, you could reply and use other advanced thread options
>> I am regularly being spammed by a "tool" that tells me a file I sent had
>> a virus attached to it and the "warning" comes from ses.symantec.com. I
>> genuinely suspect this is bogus and were I to click on the link (I'm
>> replicating one of the "emails" below) then I'd probably be hijacked.
>> I've gone onto Symantec's site and tried to notify them of the thing,
>> sending the IP from which it comes. I'm using Outlook 2003 and I've set a
>> junk mail filter so they're automatically deleted. BUT THEY ARE ANNOYING.
>> What's even more annoying is Symantec's lack of a link anywhere on their
>> websites so you can "talk" to them. That's why I dropped Norton/Symantec
>> years ago. I'm protected with F-Secure, rebranded by my ISP as if it's
>> their own. Works for me.
>>
>> Is there anything else I can do? Am I doing the right thing? It just goes
>> on and on and on. Been almost a year now. You'd think the buggers who get
>> tired when they got no response from my IP. But then maybe a computer
>> never gets tired...or gives up.
>>
>> Replicated:
>> This message has been processed by Symantec's AntiVirus Technology.
>> message.scr was infected with the malicious virus W32.Sality.U and has
>> been deleted because the file cannot be cleaned.
>>
>> For more information on antivirus tips and technology, visit
>> http://ses.symantec.com/
>
>
> Your, ahem, "copy" of the e-mail is worthless to anyone except you. You
> show no headers. You don't indicate if what you pasted was from the
> rendering of an HTML-formatted e-mail or if the e-mail was in plain text.
> Obviously the URL that *you* show here is in the Symantec domain but then
> we don't know if that is where the URL points in an HTML-formatted e-mail.
>
> Since only you have a copy of the purported e-mail, check the IP address
> in the Received header for the sender to see if it belongs to Symantec.
> If it is coming from Symantec then there is a very good chance that you
> have submitted a file for them to analyze. For all we know, you
> configured the Symantec software to forward a copy of whatever you
> quarantine so they can analyze it.

Wow. Tacky response or what? Excuse me! Ok. Mr. Techy. I don't know how to
access the source code in Outlook 2003. It's easy in Outlook Express but
it's beyond me in Outlook 2003.



Posted by Virus Guy on September 6, 2007, 8:20 pm
If you were  Registered and logged in, you could reply and use other advanced thread options
Oregano wrote:

> I don't know how to access the source code in Outlook 2003.
> It's easy in Outlook Express but it's beyond me in Outlook 2003.

You will get little sympathy here from those of us that recognize that
outlook (and OE while we're at it) is a horrible e-mail (and usenet)
client program.

Posted by Vanguard on September 6, 2007, 10:39 pm
If you were  Registered and logged in, you could reply and use other advanced thread options
>
> "Vanguard" wrote ...
>>
>> "Oregano" wrote ...
>>> I am regularly being spammed by a "tool" that tells me a file I
>>> sent had a virus attached to it and the "warning" comes from
>>> ses.symantec.com. I genuinely suspect this is bogus and were I to
>>> click on the link (I'm replicating one of the "emails" below) then
>>> I'd probably be hijacked. I've gone onto Symantec's site and tried
>>> to notify them of the thing, sending the IP from which it comes.
>>> I'm using Outlook 2003 and I've set a junk mail filter so they're
>>> automatically deleted. BUT THEY ARE ANNOYING. What's even more
>>> annoying is Symantec's lack of a link anywhere on their websites
>>> so you can "talk" to them. That's why I dropped Norton/Symantec
>>> years ago. I'm protected with F-Secure, rebranded by my ISP as if
>>> it's their own. Works for me.
>>>
>>> Is there anything else I can do? Am I doing the right thing? It
>>> just goes on and on and on. Been almost a year now. You'd think
>>> the buggers who get tired when they got no response from my IP.
>>> But then maybe a computer never gets tired...or gives up.
>>>
>>> Replicated:
>>> This message has been processed by Symantec's AntiVirus
>>> Technology.
>>> message.scr was infected with the malicious virus W32.Sality.U and
>>> has been deleted because the file cannot be cleaned.
>>>
>>> For more information on antivirus tips and technology, visit
>>> http://ses.symantec.com/
>>
>>
>> Your, ahem, "copy" of the e-mail is worthless to anyone except you.
>> You show no headers. You don't indicate if what you pasted was
>> from the rendering of an HTML-formatted e-mail or if the e-mail was
>> in plain text. Obviously the URL that *you* show here is in the
>> Symantec domain but then we don't know if that is where the URL
>> points in an HTML-formatted e-mail.
>>
>> Since only you have a copy of the purported e-mail, check the IP
>> address in the Received header for the sender to see if it belongs
>> to Symantec. If it is coming from Symantec then there is a very
>> good chance that you have submitted a file for them to analyze.
>> For all we know, you configured the Symantec software to forward a
>> copy of whatever you quarantine so they can analyze it.
>
> Wow. Tacky response or what? Excuse me! Ok. Mr. Techy. I don't know
> how to access the source code in Outlook 2003. It's easy in Outlook
> Express but it's beyond me in Outlook 2003.

From your original post, it didn't appear that you are a newbie in
using Outlook. It looked like you knew Outlook well enough to know
how to see the headers and HTML source and why I lambasted you for
omitting them. Claiming what an e-mail said without showing headers
(munge out any personal info, like your e-mail address) along with the
raw source for the body is like walking into a car shop and saying
"It's broke" without providing any details or proof. I over-estimated
your expertise with Outlook.

To view the headers, use View -> Options (I use OL2002 so menu
navigation may differ in OL2003). If the e-mail is HTML formatted,
right-click in the body to use View Source. If that is too laborious
or you simply want some other navigation to get at the same info, get
the PocketKnife Peek add-on to Outlook
(http://www.xintercept.com/pkpeek.htm) which gives you a toolbar
button to open a separate tabbed window to look at headers and the raw
source of the body.

As for there being no contact links on Symantec's web site, well,
can't see how you missed it. On several occasions in the past when I
still used their Norton products, I contacted them using their
"e-mail" web form whereupon they would respond within 3 business days
to start a discussion. I just went to their site and in a minute
found
http://www.symantec.com/home_homeoffice/support/productdetail/contact_ts.jsp?pvid=nav_2008
(this was for NAV 2008; you will need to navigate through their
support pages to select whatever product you want to discuss with
them).


Similar ThreadsPosted
NIS "unrecognized modules" bogus warnings from MSN Msger 7? August 16, 2005, 1:31 pm
Norton Program Control warnings on CCAPP, LUCOMS September 8, 2005, 10:06 am
Please help with Symantec Anti-Virus December 22, 2005, 2:53 pm
Symantec Anti-Virus Renewal June 7, 2006, 2:15 am
Please help with Symantec Client Secutiry / Anti-Virus January 21, 2006, 1:04 am
Symantec Anti-virus installation problem June 27, 2006, 8:35 am
Symantec failed at virus detection at Yahoo November 27, 2006, 3:07 pm
Symantec Norton Anti-Virus -- good? bad? July 1, 2008, 9:37 pm
Symantec "free" virus detection and security scan November 24, 2005, 6:26 pm
Symantec Not a Wise Choice of Anti-Virus Products December 22, 2005, 7:13 pm

The site map in XML format XML site map

Contact Us | Privacy Policy