Virus Alert – Clare Harding – purchasing@carterspackaging.com – Carters Packaging Ltd

Computer Virus Removal 600x315
()

You may have been receiving a huge amount of email spam this morning from Clare Harding at Carters Packaging Ltd with an invoice attachment called Purchase Order 0000035394.doc

Well, this is a virus and seems to be spreading around the internet like wild fire at the moment, so blacklist this email address:

purchasing@carterspackaging.com

NOTE

Obviously this is an impersonation attack and has not originated from Carters Packaging Ltd.

You should fully virus scan your machines using whichever anti-virus you have. In some cases, you may have to rebuild computers as this seems to run as a process.

The subject of the email will be similar to this:

Purchase Order 0000035394 customer 09221

A little more information on this virus attack

Rumoured download locations are:

  • malajsie.webzdarma.cz/45y3f34f/7jh4wqd.exe
  • fa31.linux-hosting.de/45y3f34f/7jh4wqd.exe
  • ankarasogukhavadepo.com/45y3f34f/7jh4wqd.exe
  • selimkaucuk.com/45y3f34f/7jh4wqd.exe

It also looks like it stores its executable file in the %temp% directory with a filename of httsser.exe

It could be generating traffic to this IP below so worth blocking that on your systems too:

221.132.35.56

COMMENTS

If you have been affected by this in anyway, we would like to hear from you so leave us a message below using our comments system.

How useful was this post?

Click on a star to rate it!

Average rating / 5. Vote count:

No votes so far! Be the first to rate this post.

We are sorry that this post was not useful for you!

Let us improve this post!

Tell us how we can improve this post?

About A.J. Armstrong

Founder of TechyGeeksHome and Head Editor for over eight years! IT expert in multiple areas for over 21 years. Sharing experience and knowledge whenever possible! Making IT Happen.

View all posts by A.J. Armstrong

Leave a Reply

Your email address will not be published.

This site uses Akismet to reduce spam. Learn how your comment data is processed.