Friday, 5 February 2016

Email from BP Fuel Card E-bill 0200442 for Account B216552 31/01/2016


Latest spam/scam email from Fuel Card Services <adminbur@fuelcardgroup.com>

Unlike most virus emails this one has an attachment called warning.txt so not a Word macro virus. I wonder whether the virus writer made an error with their programming so the attachment wasn't correct.

The details of the email are below:


Please note that this message was sent from an unmonitored mailbox which is unable to accept replies. If you reply to this e-mail your request will not be actioned. If you require copy invoices, copy statements, card ordering or card stopping please e-mail support@fuelcardservices.com quoting your account number which can be found in the e-mail below. If your query is sales related please e-mail info@fuelcardservices.com.
 
 
E-billing
-
 
 
Sent: Thu, 04 Feb 2016 16:54:57 +0300
Subject: BP Fuel Card E-bill 0200442 for Account B216552 31/01/2016
 
Account: B216552
 
Please find your e-bill 0200442 for 31/01/2016 attached.
 
To manage you account online please click http://eservices.fuelcardservices.com
 
If you would like to order more fuel cards please click http://www.fuelcard-group.com/cardorder/bp-burnley.pdf
 
If you have any queries, please do not hesitate to contact us.
 
Regards
 
Cards Admin.
Fuel Card Services Ltd
 
T 01282 410704
F 0844 870 9837

Thursday, 21 January 2016

Plan4print Letter Attached with Virus Trojan Email from Tim Speed

Latest virus being sent via Email pretends to come from Tim Speed at plan4print.co.uk. Again this is a faked email that has not come from Tim Speed. The Word document doc file attached contains a macro virus that will infect your computer so you shouldn't open it.

Tim Speed and Plan4print will have no knowledge of this email so you will only cause further problems by sending emails back to them. Other innocent companies affected in a similar way have received over a million email replies thus overloading their systems.

As always use a virus scanner and check your PC using software such as Malwarebytes from time to time.

Plan4print Letter Virus Email Tim Speed
Plan4print Letter Virus Email Tim Speed



Attachment 120205 Letter-response A3 2-2.doc

Hi
Please find estimate attached for Letter-response A3 2-2
Kind regards   
Tim Speed
Estimator / Account Handler

Tel: 0115 944 3377 Ext 104

Wednesday, 20 January 2016

O2 Business Contracts Lease Spam Virus Email - Your Device is on its way

If you receive an email supposedly from O2 Business Contracts titled "Your device is on its way" with a Word attachment CCACOnfirmedAgreement then don't open it as it's a Trojan virus that will try to install and steal passwords and banking details.

The email has NOT come from O2 so they have no knowledge of it and their systems have not been compromised. A virus scammer has just created an email spoofing the O2 email address  which isn't something that they can stop.

O2 Business Contracts Lease Spam Virus Email - Your Device is on its way
O2 Business Contracts Lease Spam Virus Email - Your Device is on its way




Email details as below:



O2 Lease <O2BusinessContracts@o2.com>
Your device is on its way


Hello


Great news, you've accepted the O2 Lease terms and conditions and the hire agreement.


We've put your order through. So we'll be sending your new device out in the next few days.
Best regards
O2 Customer Service

Friday, 15 January 2016

Drayton Manor Hotel Reservation 79501 - EMail Virus Spam

The latest email spam/virus appears to have been sent from Drayton Manor Hotel (Harry Ashbolt in Reservations) but this email address is faked and the email has nothing to do with them.


You do not need to contact Drayton Manor Hotel as the email was not sent by them.




The email contains an Excel attachment claiming to be a Reservation Confirmation number 79501. It is not a reservation and contains a virus that will try to steal your banking passwords. Just delete the email without opening.


If you have opened the email I'd strongly recommend that you scan your PC with a good free virus scanner such as AVG as well as MalwareBytes software which can clean Trojans and viruses from your computer.


If you have opened the email on a phone or Mac computer then you should be safe as the virus only infects Windows PCs.





Drayton Manor Hotel Reservation 79501 - EMail Virus Spam
Drayton Manor Hotel Reservation 79501 - EMail Virus Spam

Monday, 11 January 2016

Whos On Heart Name the Voices Competition 2016 - Win £100,000

The Whos on Heart competition has returned for another year. These are the 3 voices that you need to identify to win the massive cash prize this year.


Hear the previous year's Whos On Heart voices below. The other voices from Whos on Heart 2014 were Stevie Nicks and Ben Miller



Whos = Ben Miller
On = Stevie Nicks
Heart = Nigel Kennedy

Thursday, 3 December 2015

ICM Industrial Cleaning Materials - Invoice #2393 Scam Email

ICM - Invoice #2393 is a Scam virus email. As usual just delete this email. The attachment contains a virus that will try to load Trojan program to steal your bank login data.

Dear Customer,
Please find invoice 2393 attached.
Kind Regards,
ICM

Industrial Cleaning Materials
Unit 19 Highlode Ind Est
Stocking Fen Road
Ramsey
Huntingdon
Cambridgeshire
PE26 2RB
Tel: 01487 800011
fax 01487 812075


ICM - Invoice #2393 Scam Email
ICM - Invoice #2393 Scam Email

Tuesday, 1 December 2015

Cryptowall 4 Infection Website Compromised from Nuclear Exploit Kit (HELP_YOUR_FILES.PNG)

Until last week it appeared that Cryptowall 4 infection was only being seen from emails carrying the payload. It now appears it is also being delivered by websites compromised by the Nuclear Exploit Kit. The Nuclear EK operates by exploiting vulnerabilities in Java, Acrobat Reader, Flash, and Silverlight so it's essential that you have your PC fully patched up to date.



Cryptowall 4 is now being found in the wild delivered by hacked websites. If you find your files on your drives are encrypted and the file names are also encrypted then it's highly likely that you have been infected by Cryptowall 4 ransomware. You can see the file HELP_YOUR_FILES.PNG will be stored in the folder with all the encrypted files. Other help files may be HELP_YOUR_FILES.HTML, HELP_YOUR_FILES.TXT.





Even visiting an apparently innocuous website may lead to your PC being infected IF you have software that has vulnerabilities such as Adobe Flash. Even fairly recent versions from August 2015 are still vulnerable to infection.



More info on the Nuclear Exploit kit for Cryptowall 4 here.
How to recover from Cryptowall 4



 http://www.bleepingcomputer.com/virus-removal/cryptowall-ransomware-information



To check a website you can use: http://www.isithacked.com