On 27/02/2006, at 12:20 AM, Rob Davies wrote:


On 26Feb2006, at 8:02 pm, Ronda Brown wrote:


On 26/02/2006, at 7:23 PM, Robert Howells wrote:

HI Ronni,

There have been a number of scam    " Bank "    emails recently !

ANZ
Sunwaymetcorp
Combank

asking for you to login and confirm your details .
Banks do NOT ask for you to confirm details .
These are scam emails with " phishing"  addresses.

Hi Bob,

I never got this through an email. I'm well aware of the Bank Scam emails.
I would NEVER login & confirm my details from an email.

Cheers,
Ronni
Car'n The Pies

The fact that it is in Safari's cache does not suggest that it was acquired via a web address, but it is the link loading the relative information back to the hidden URL. All sources I have scoured about this Trojan suggest that it is usually delivered via email, and 100% windows based. Many variants of it i.e. the no's at end of the identifier are specific to whatever bank it is trying to emulate. Also the main point here is that you have to activate the URL to pass-on relevant information whilst using relevant OS, hence the tag phishing someone has to take the bait.

Just be sure in Safari and other browsers that the "open safe files after download" box is not selected. Also within the share/firewall/ advanced all these box's are selected, making it that bit more difficult to track back to your machine. Whilst the logs although basic will give you a reference point of all things transgressing your firewall.

Would not hurt to activate ClamXav Folder Sentry on the Library folder of user for next few days and see if anymore show up. I have had a few of these, but not on Mac. Mine have been caught via Firewall Box (IPcop) and programs that check email and most things passing through the open ports, things still do get through, damn Windows stuff definitely not OS X (Touch Wood). Although I do believe this stale mate will be abated by the Intel Macs coming online.

I do not believe you have been compromised, as Jame's wonderful inference suggested.

Cheers!
Rob...

A 'Huge' thank you to James, Rob, Nancy, Bob, I'm sorry Bob for doubting you :-( , Glenn & Peter for your excellent responses to my 'Mini Freak-out'.
I really appreciate your help.

I do have all selected as Rob suggests and will activate ClamXav Folder Sentry on my Library Folder. I also hope Rob you are correct & I have not been compromised ..... so far my money is still in my Bank (well, until I have to pay the Tax Man this month)?

Thanks again people.

Cheers,
Ronni
Car'n The Pies (at least the Pies had a Win yesterday)