Community Discussions and Support
Possible Virus infection Trojan Cryptic

[quote user="Annie Collins"]Can anyone tell me that capacity of Pegasus in size of mail in folders or all over ie how much historic mail can I keep in the program.  I am writting a book and am using it as a kinda database of information.[/quote]

The restrictions are in supported file sizes by your OS. But ... to keep Pegasus performant, you should have as less as possible mails in inbox or any folder with filtering rules.

bye   Olaf

 

<p>[quote user="Annie Collins"]Can anyone tell me that capacity of Pegasus in size of mail in folders or all over ie how much historic mail can I keep in the program.  I am writting a book and am using it as a kinda database of information.[/quote]</p><p>The restrictions are in supported file sizes by your OS. But ... to keep Pegasus performant, you should have as less as possible mails in inbox or any folder with filtering rules.</p><p>bye   Olaf</p><p> </p>

I have been posting because of problems with recently downloaded update.  I have just run a virus check and have been told possible virus.

Called Trojon Horse Cryptic CN in Admin folder FOL00E00.PMM called UPS.zip or UPS.exe

other description is of unknown VirusWin3   DH.FF840205

Please advise if this is a real virus or just software just panicking

Never seen Pegasus infected before

Annie

Queensland

<p>I have been posting because of problems with recently downloaded update.  I have just run a virus check and have been told possible virus.</p><p>Called Trojon Horse Cryptic CN in Admin folder FOL00E00.PMM called UPS.zip or UPS.exe </p><p>other description is of unknown VirusWin3   DH.FF840205</p><p>Please advise if this is a real virus or just software just panicking </p><p>Never seen Pegasus infected before</p><p>Annie </p><p>Queensland </p>

[quote user="Annie Collins"]Please advise if this is a real virus or just software just panicking  [/quote]

It's a folder file, so if there's malware it would be an attachment to a message, so you should find the suspicous message and either delete the attachment or the whole message. The alarm will only cease after compacting the folder afterwards, though. The name of a folder file (and its path) can be determined by right-clicking it and checking the Folder information.

And with regard to your above question: I don't think any of us can answer this, we all have to rely on what virus scanners tell us, so you better go to the AV scanner's website for checking the details (including possible false alarms).

<p>[quote user="Annie Collins"]Please advise if this is a real virus or just software just panicking  [/quote]</p><p>It's a folder file, so if there's malware it would be an attachment to a message, so you should find the suspicous message and either delete the attachment or the whole message. The alarm will only cease after compacting the folder afterwards, though. The name of a folder file (and its path) can be determined by right-clicking it and checking the <em>Folder information</em>.</p><p>And with regard to your above question: I don't think any of us can answer this, we all have to rely on what virus scanners tell us, so you better go to the AV scanner's website for checking the details (including possible false alarms).</p>
			Michael
--
IERenderer's Homepage
PGP Key ID (RSA 2048): 0xC45D831B
S/MIME Fingerprint: 94C6B471 0C623088 A5B27701 742B8666 3B7E657C

What AV product are you using?  One of these .exe attachments in side of a .zip got through my defenses and infected one of my users last week.  Of course it required the users help to actually infect but the fact that it was able to infect leaves me questioning my defenses.

 FWIW, we have seen a significant number of emails coming in with attachments containing a .exe file inside of .zip filet.  The messages reference either delivery notification or shipment tracking and have appeared to come from shippers like UPS, FEDEX and USPS.  I know that valid shipment related emails contain a tracking number in the body of the message and many of these bogus ones do not.  My suggestions are:  1)  You should not have to open a .zip file to see the tracking number so if there is no tracking number be extremely suspicious.  2)  Avoid following links even if there is a tracking number.  Use your browser to navigate to the tracking page of the designated shipper then copy and paste the tracking number.  If it's an invalid number or a shipment you don't recognize you should assume the email is malware.

<p>What AV product are you using?  One of these .exe attachments in side of a .zip got through my defenses and infected one of my users last week.  Of course it required the users help to actually infect but the fact that it was able to infect leaves me questioning my defenses. </p><p> FWIW, we have seen a significant number of emails coming in with attachments containing a .exe file inside of .zip filet.  The messages reference either delivery notification or shipment tracking and have appeared to come from shippers like UPS, FEDEX and USPS.  I know that valid shipment related emails contain a tracking number in the body of the message and many of these bogus ones do not.  My suggestions are:  1)  You should not have to open a .zip file to see the tracking number so if there is no tracking number be extremely suspicious.  2)  Avoid following links even if there is a tracking number.  Use your browser to navigate to the tracking page of the designated shipper then copy and paste the tracking number.  If it's an invalid number or a shipment you don't recognize you should assume the email is malware. </p>

I do not know how the virus came to be able to get in as I am stringent about what I open and do not have anything automatic going on . I have firewalls and two virus programs and I did not see any mail come in from anywhere I did not use before.

The only thing I did was installed a Driver upgrade program supposed to be from Norton before realising it was likely to be unsafe.

The guy writting in response to this seems to have had the same problem.

The reason I use Pegasus is because it is the safest email system I have known re spam and viruses so this was a shock

<p>I do not know how the virus came to be able to get in as I am stringent about what I open and do not have anything automatic going on . I have firewalls and two virus programs and I did not see any mail come in from anywhere I did not use before.</p><p>The only thing I did was installed a Driver upgrade program supposed to be from Norton before realising it was likely to be unsafe.</p><p>The guy writting in response to this seems to have had the same problem.</p><p>The reason I use Pegasus is because it is the safest email system I have known re spam and viruses so this was a shock </p>

I am using AVG and Microsoft and firewalls and have never had anything get into Pegasus in over 20 years and that is why I use and recommend it.

I am also poor so it helps on so many levels so I want to keep using it.

Everything you say happened with your user is what appears the same but I did not open any mail or see anything come thru from anywhere new.

The only thing I did that was new was to halfway intstall a program caller Driver Manager which was supposed to come from Norton. It seem to load an executable into my brower but I am not sure if this is where the exe and zip file came from.

I was having problems with windows in Pegasus but think that was a mouse hardware thing.

Thanks for your information and advice everyone

<p>I am using AVG and Microsoft and firewalls and have never had anything get into Pegasus in over 20 years and that is why I use and recommend it.</p><p>I am also poor so it helps on so many levels so I want to keep using it.</p><p>Everything you say happened with your user is what appears the same but I did not open any mail or see anything come thru from anywhere new.</p><p>The only thing I did that was new was to halfway intstall a program caller Driver Manager which was supposed to come from Norton. It seem to load an executable into my brower but I am not sure if this is where the exe and zip file came from.</p><p>I was having problems with windows in Pegasus but think that was a mouse hardware thing.</p><p>Thanks for your information and advice everyone </p>

Running multiple antivirus programs on any one machine is a very bad idea. You'd better uninstall one of them.

Cheers!

<p>Running multiple antivirus programs on any one machine is a very bad idea. You'd better uninstall one of them.</p><p>Cheers! </p>

I was not sure how good the Microsoft Security Essentials program is and as it cames with the program you do not seem to have choice.  Is this another case of Microsoft taking over another area of software and putting competitiors out of business eg use of Windows Live vis Pegasus etc ?

It also wants to send all the information back to them even personal stuff so really it seems like a spy program. I thought it was just to protect the operating system and not anything else.

Which one should I choose Microsoft or AVG

Neither of them picked up on the virus so how good are they really

<p>I was not sure how good the Microsoft Security Essentials program is and as it cames with the program you do not seem to have choice.  Is this another case of Microsoft taking over another area of software and putting competitiors out of business eg use of Windows Live vis Pegasus etc ?</p><p>It also wants to send all the information back to them even personal stuff so really it seems like a spy program. I thought it was just to protect the operating system and not anything else.</p><p>Which one should I choose Microsoft or AVG </p><p>Neither of them picked up on the virus so how good are they really </p>

Which should I use to protect Pegasus, the Microsoft Security Essentials or AVG free.i

I do not have money to buy anything, the laptop was a gift.

<p>Which should I use to protect Pegasus, the Microsoft Security Essentials or AVG free.i</p><p>I do not have money to buy anything, the laptop was a gift.</p>

> Which one should I choose Microsoft or AVG
> Neither of them picked up on the virus so how good are they really

I really like Avast!.  It's free and very configurable.  AVG gave me all sorts of problems so I dumped it.  I've not used the M$oft a-v.
<div>> Which one should I choose Microsoft or AVG</div><div>> </div><div>> Neither of them picked up on the virus so how good are they really</div><div> </div><div>I really like Avast!.  It's free and very configurable.  AVG gave me all sorts of problems so I dumped it.  I've not used the M$oft a-v.</div>

[quote user="Annie Collins"]I do not know how the virus came to be able to get in as I am stringent about what I open and do not have anything automatic going on .[/quote]

First of all: don't panic!!! The Virus is on you PC in a folderfile of Pegasus - may be an attachment of a mail. Obviously it is not activated because AV should have found it elsewhere. You didn't open the attachment and you shouldn't do it. Locate the folder and the relevant mail in it and delete the mail.

[quote]I have firewalls and two virus programs and I did not see any mail come in from anywhere I did not use before.[/quote]

Oh oh ... only ONE AV please!!! If there is a new virus and you get it (i.e. per mail) before programers of AV know about it, the AV isn't able to protect your PC. This may happen with every AV! But for shure there are some AV with good heuristics which may asume something to be a virus even if it is not yet known or the programers are very quick and your protection is immediately updated. But thoes are most times payware.

[quote]The only thing I did was installed a Driver upgrade program supposed to be from Norton before realising it was likely to be unsafe.[/quote]

Got that via mail? Delete the mail ... those tools are nothing worth and most times do more damage than helping keeping your PC uptodate.

[quote]The reason I use Pegasus is because it is the safest email system I have known re spam and viruses so this was a shock [/quote]

The reason for Pegasus to be save is that it won't run any script or open any attachment without you explicit opening it.

OK ... if you found the mail with virus  and delted it you have to compress the folder to eliminate it (at that point the mail is only marked deleted in local folder of Pegasus, but not physically removed).

bye   Olaf

 

<p>[quote user="Annie Collins"]I do not know how the virus came to be able to get in as I am stringent about what I open and do not have anything automatic going on .[/quote]</p><p>First of all: don't panic!!! The Virus is on you PC in a folderfile of Pegasus - may be an attachment of a mail. Obviously it is not activated because AV should have found it elsewhere. You didn't open the attachment and you shouldn't do it. Locate the folder and the relevant mail in it and delete the mail. </p><p>[quote]I have firewalls and two virus programs and I did not see any mail come in from anywhere I did not use before.[/quote]</p><p>Oh oh ... only <b>ONE AV </b>please!!! If there is a new virus and you get it (i.e. per mail) before programers of AV know about it, the AV isn't able to protect your PC. This may happen with every AV! But for shure there are some AV with good heuristics which may asume something to be a virus even if it is not yet known or the programers are very quick and your protection is immediately updated. But thoes are most times payware. </p><p>[quote]The only thing I did was installed a Driver upgrade program supposed to be from Norton before realising it was likely to be unsafe.[/quote]</p><p>Got that via mail? Delete the mail ... those tools are nothing worth and most times do more damage than helping keeping your PC uptodate. </p><p>[quote]The reason I use Pegasus is because it is the safest email system I have known re spam and viruses so this was a shock [/quote]</p><p>The reason for Pegasus to be save is that it won't run any script or open any attachment without you explicit opening it.</p><p>OK ... if you found the mail with virus  and delted it you have to compress the folder to eliminate it (at that point the mail is only marked deleted in local folder of Pegasus, but not physically removed).</p><p>bye   Olaf</p><p> </p>

I second Avast, it's what I use at home.  MS Security Essentials has gotten good reviews by editors of Windows Secrets but it's not as configurable as Avast.

I  have come to the conclusion that the infection that occurred here used social engineering to get a user to run an executable which appeared benign to my AV product.  Once run that executable phoned home and retrieved the payload.  I can't say that I know this for a fact but it explains how the infection could have occurred without being detected in the .exe file.  If true, I wonder if any AV product would have blocked it.  Your fake driver install may have worked the same way.

I second Avast, it's what I use at home.  MS Security Essentials has gotten good reviews by editors of Windows Secrets but it's not as configurable as Avast. I  have come to the conclusion that the infection that occurred here used social engineering to get a user to run an executable which appeared benign to my AV product.  Once run that executable phoned home and retrieved the payload.  I can't say that I know this for a fact but it explains how the infection could have occurred without being detected in the .exe file.  If true, I wonder if any AV product would have blocked it.  Your fake driver install may have worked the same way.

AVG deleted the file and I do not know how to work out how to connect the file name in the program with what I see when using the program.  They have numbers and my folders have names or am I stupid.

As I said I did not see any spam or unknown sender mail come in and no mail came in with an attachment I opened.

Pegasus and the people who support it are awesome, thanks for the time and help.

<p>AVG deleted the file and I do not know how to work out how to connect the file name in the program with what I see when using the program.  They have numbers and my folders have names or am I stupid.</p><p>As I said I did not see any spam or unknown sender mail come in and no mail came in with an attachment I opened. </p><p>Pegasus and the people who support it are awesome, thanks for the time and help.</p>

So what is the purpose of Microsoft Essentials because as you say it is not as developed as others?  I was worried that if I turned it off I would leave my operating system open and I did not know how connected it is to the daily updates from Microsoft,

I will do as all you advise and change programs and turn off Microsoft.

I love reducing programs on my hard drive, love to run lean and mean.

Can anyone tell me that capacity of Pegasus in size of mail in folders or all over ie how much historic mail can I keep in the program.  I am writting a book and am using it as a kinda database of information. 

<p>So what is the purpose of Microsoft Essentials because as you say it is not as developed as others?  I was worried that if I turned it off I would leave my operating system open and I did not know how connected it is to the daily updates from Microsoft,</p><p>I will do as all you advise and change programs and turn off Microsoft.</p><p>I love reducing programs on my hard drive, love to run lean and mean.</p><p>Can anyone tell me that capacity of Pegasus in size of mail in folders or all over ie how much historic mail can I keep in the program.  I am writting a book and am using it as a kinda database of information.  </p>

[quote user="Annie Collins"]AVG deleted the file[/quote]

Nice :-( ... so you should miss one folder :-(

Ist it deleted or just in quarantine? You should release it from quarantine if possible.

[quote]and I do not know how to work out how to connect the file name in the program with what I see when using the program.  They have numbers and my folders have names or am I stupid.[/quote]

Open HIERARCH:PM with an editor, search for FOL00E00 and in same line you will find the name of your foldre shown in folderlist at Pegasus.

bye   Olaf

 

<p>[quote user="Annie Collins"]AVG deleted the file[/quote]</p><p>Nice :-( ... so you should miss one folder :-(</p><p>Ist it deleted or just in quarantine? You should release it from quarantine if possible. </p><p>[quote]and I do not know how to work out how to connect the file name in the program with what I see when using the program.  They have numbers and my folders have names or am I stupid.[/quote]</p><p>Open HIERARCH:PM with an editor, search for FOL00E00 and in same line you will find the name of your foldre shown in folderlist at Pegasus. </p><p>bye   Olaf</p><p> </p>
live preview
enter atleast 10 characters
WARNING: You mentioned %MENTIONS%, but they cannot see this message and will not be notified
Saving...
Saved
With selected deselect posts show selected posts
All posts under this topic will be deleted ?
Pending draft ... Click to resume editing
Discard draft