We’d like to remind Forumites to please avoid political debate on the Forum.

This is to keep it a safe and useful space for MoneySaving discussions. Threads that are – or become – political in nature may be removed in line with the Forum’s rules. Thank you for your understanding.

📨 Have you signed up to the Forum's new Email Digest yet? Get a selection of trending threads sent straight to your inbox daily, weekly or monthly!
The Forum now has a brand new text editor, adding a bunch of handy features to use when creating posts. Read more in our how-to guide

Virus Checks and Government Departments

oneye14
oneye14 Posts: 1,596 Forumite
edited 18 September 2013 at 1:05PM in Techie Stuff
Virus Checks and Government Departments
I understand last Friday an email from the BIS (Business Innovation & Skills) set off anti-virus alarms with what appears to be, or a variation of:-

ZeroAccess botnet

It took until Monday to come back with the usual message of "Do not open attachments, Do not click on links" etc.
But
- Claimed the email had not been sent from BIS
- Customers should be assured that the data we have has not been compromised

This lead to a response of:
So, your email sevice has been hacked but everything else is fine ?

There has been no reply to this or any other comment.
Where has the Webmaster gone that used to be on Websites ...

I'm no expert on the subject but apparently ZeroAccess is a fairly virulent trojan that targets operating systems.
I get the impression that no one in BIS knows what is happening or what to do about it.
«13

Comments

  • How have you determined the email was sent through the BIS network? From: addresses can be spoofed in a matter of seconds.
    Starting Debt: ~£20,000 01/01/2009. DFD: 20/11/2009 :j
    Do something amazing. GIVE BLOOD.
  • oneye14
    oneye14 Posts: 1,596 Forumite
    How have you determined the email was sent through the BIS network? From: addresses can be spoofed in a matter of seconds.

    The recipient recognised the the name of the sender in their email address.
  • Unless you checked the headers to ensure this did come from BIS it is more likely someone just spoofed it.
    Starting Debt: ~£20,000 01/01/2009. DFD: 20/11/2009 :j
    Do something amazing. GIVE BLOOD.
  • joe134
    joe134 Posts: 3,336 Forumite
    oneye14 wrote: »
    Virus Checks and Government Departments
    I understand last Friday an email from the BIS (Business Innovation & Skills) set off anti-virus alarms with what appears to be, or a variation of:-

    ZeroAccess botnet

    It took until Monday to come back with the usual message of "Do not open attachments, Do not click on links" etc.
    But
    - Claimed the email had not been sent from BIS
    - Customers should be assured that the data we have has not been compromised

    This lead to a response of:


    There has been no reply to this or any other comment.
    Where has the Webmaster gone that used to be on Websites ...

    I'm no expert on the subject but apparently ZeroAccess is a fairly virulent trojan that targets operating systems.
    I get the impression that no one in BIS knows what is happening or what to do about it.
    As stated , I,ve just got rid of it on daughters pc, thanks to waddler, so, it certainly is going around.
    Don,t know where she got it, but not from, Bis;
  • oneye14
    oneye14 Posts: 1,596 Forumite
    Unless you checked the headers to ensure this did come from BIS it is more likely someone just spoofed it.


    I checked with the recipient -
    name of the sender in their email address.

    the senders email was expected with attachments - the header was correct too

    Would the spoofer know which email address to send from and get the timing right...

    My point is
    impression that no one in BIS knows what is happening or what to do about it
  • waddler_8
    waddler_8 Posts: 3,588 Forumite
    impression that no one in BIS knows what is happening or what to do about it
    There's not a lot anyone can do if a spammer is spoofing their address - it happens to all.
  • oneye14
    oneye14 Posts: 1,596 Forumite
    waddler_8 wrote: »
    There's not a lot anyone can do if a spammer is spoofing their address - it happens to all.
    Would the spoofer know which email address to send from and get the timing right...

    I'm not convinced it was spoofed
  • waddler_8
    waddler_8 Posts: 3,588 Forumite
    oneye14 wrote: »
    I'm not convinced it was spoofed

    It will have been - it happens all the time.
  • tronator
    tronator Posts: 2,859 Forumite
    Part of the Furniture 1,000 Posts Name Dropper
    oneye14 wrote: »
    ... the header was correct too

    What does this mean? What header? Post all "Received:" headers, but replace all sensitive information like email addresses.
    oneye14 wrote: »
    Would the spoofer know which email address to send from and get the timing right...

    Maybe the recipient's PC is already infected with some other virus. Then all information it needs are already there...
  • oneye14
    oneye14 Posts: 1,596 Forumite
    The BIS have eventually confirmed they sent the email on 13 September 2013 which set off the alarm......
    ..So nothing was compromised was it .......
    So, your email sevice has been hacked but everything else is fine ?

    No answer to that or any other explanation .... :cool:
This discussion has been closed.
Meet your Ambassadors

🚀 Getting Started

Hi new member!

Our Getting Started Guide will help you get the most out of the Forum

Categories

  • All Categories
  • 354.4K Banking & Borrowing
  • 254.4K Reduce Debt & Boost Income
  • 455.4K Spending & Discounts
  • 247.3K Work, Benefits & Business
  • 604.1K Mortgages, Homes & Bills
  • 178.5K Life & Family
  • 261.6K Travel & Transport
  • 1.5M Hobbies & Leisure
  • 16K Discuss & Feedback
  • 37.7K Read-Only Boards

Is this how you want to be seen?

We see you are using a default avatar. It takes only a few seconds to pick a picture.