♥ PosetteForever ♥
Whip The Admins... - Virus Warning...
Tormie [ Sunday, 16 May 2004, 06:59 PM ]
Post subject: Virus Warning...
Today I received an email with a virus in it: It looked like the message that was sent from me to all users when we changed the domain name. I scanned it with <a class="post-url" href="http://www.spamcop.net" target="_blank">www.spamcop.net</a> and it appears to come from the ntlworld.com domain.
<br />
I deleted the 2 users with that domain in the email address and blocked it.
<br />
<br />
Here is the original message with the headers, it was blocked by Norton:
<br />
<br />
<br />
X-Symantec-TimeoutProtection: 0
<br />
Return-path: <tormento@partners2.100mwh.com>
<br />
Envelope-to: <!-- no smilies start --><script type="text/javascript">
<!--
document.write('
</script><noscript>Posy [at] posetteforever [dot] com</noscript><!-- no smilies end -->
<br />
Delivery-date: Sun, 16 May 2004 11:05:10 -0600
<br />
Received: from tormento by partners2.100mwh.com with local-bsmtp (Exim 4.34)
<br />
id 1BPP4V-00069j-R2
<br />
for <!-- no smilies start --><script type="text/javascript">
<!--
document.write('
</script><noscript>Posy [at] posetteforever [dot] com</noscript><!-- no smilies end -->; Sun, 16 May 2004 11:05:10 -0600
<br />
Received: from [209.228.29.61] (helo=n064.sc1.cp.net)
<br />
by partners2.100mwh.com with esmtp (Exim 4.34)
<br />
id 1BPP4U-00069e-Ig
<br />
for <!-- no smilies start --><script type="text/javascript">
<!--
document.write('
</script><noscript>Posy [at] posetteforever [dot] com</noscript><!-- no smilies end -->; Sun, 16 May 2004 11:05:07 -0600
<br />
Received: from posetteforever.com (81.103.216.144) by n064.sc1.cp.net (7.0.027.3-1)
<br />
id 4089B512001849D8 for <!-- no smilies start --><script type="text/javascript">
<!--
document.write('
</script><noscript>Posy [at] posetteforever [dot] com</noscript><!-- no smilies end -->; Sun, 16 May 2004 17:04:58 +0000
<br />
Message-ID: <4089B512001849D8@n064.sc1.cp.net> (added by <!-- no smilies start --><script type="text/javascript">
<!--
document.write('
</script><noscript>postmaster [at] bouncemessage [dot] net</noscript><!-- no smilies end -->)
<br />
From: <!-- no smilies start --><script type="text/javascript">
<!--
document.write('
</script><noscript>Posy [at] posetteforever [dot] com</noscript><!-- no smilies end -->
<br />
To: <!-- no smilies start --><script type="text/javascript">
<!--
document.write('
</script><noscript>Posy [at] posetteforever [dot] com</noscript><!-- no smilies end -->
<br />
Subject: Re: Posetteforever temporary address!
<br />
Date: Sun, 16 May 2004 18:07:06 +0100
<br />
MIME-Version: 1.0
<br />
Content-Type: multipart/mixed;
<br />
boundary="----=_NextPart_000_0004_96E69A13.09F60AEB"
<br />
X-Priority: 3
<br />
X-MSMail-Priority: Normal
<br />
X-Mailer: Microsoft Outlook Express 6.00.2600.0000
<br />
X-MimeOLE: Produced By Microsoft MimeOLE V6.00.2600.0000
<br />
X-Spam-Checker-Version: SpamAssassin 2.63 (2004-01-11) on partners2.100mwh.com
<br />
X-Spam-Status: No, hits=2.1 required=5.0 tests=FORGED_MUA_OUTLOOK,
<br />
HTML_MESSAGE,NO_REAL_NAME,RCVD_IN_NJABL,RCVD_IN_SORBS autolearn=no
<br />
version=2.63
<br />
X-Spam-Level: **
<br />
<br />
This is a multi-part message in MIME format.
<br />
<br />
------=_NextPart_000_0004_96E69A13.09F60AEB
<br />
Content-Type: text/plain;
<br />
charset="Windows-1252"
<br />
Content-Transfer-Encoding: 7bit
<br />
<br />
<br />
----- Original Message -----
<br />
From: <!-- no smilies start --><script type="text/javascript">
<!--
document.write('
</script><noscript>Posy [at] posetteforever [dot] com</noscript><!-- no smilies end -->
<br />
To: <!-- no smilies start --><script type="text/javascript">
<!--
document.write('
</script><noscript>Posy [at] posetteforever [dot] com</noscript><!-- no smilies end -->
<br />
Subject: Posetteforever temporary address!
<br />
<br />
<br />
><!-- no smilies start --><script type="text/javascript">
<!--
document.write('
</script><noscript>Posy [at] posetteforever [dot] com</noscript><!-- no smilies end -->
<br />
>
<br />
>Include this full email (particularly the headers).
<br />
>
<br />
>Message sent to you follows:
<br />
>~~~~~~~~~~~~~~~~~~~~~~~~~~~~
<br />
>
<br />
>Hi, the transfer is done our new permanent address is
<br />
>
<br />
><a class="post-url" href="http://posetteforever.com" target="_blank">http://posetteforever.com</a>
<br />
>
<br />
>or
<br />
>
<br />
><a class="post-url" href="http://posetteforever.tk" target="_blank">http://posetteforever.tk</a>
<br />
>
<br />
>Best regards !
<br />
>
<br />
>AD>
<br />
><META http-equiv=3DContent-Type content=3D"text/html; charset=3Dus-asci=
<br />
>i">
<br />
><META content=3D"MSHTML 6.00.2462.0000" name=3DGENERATOR>
<br />
<br />
<br />
------=_NextPart_000_0004_96E69A13.09F60AEB
<br />
Content-Type: application/octet-stream;
<br />
name="13.zip"
<br />
Content-Transfer-Encoding: base64
<br />
Content-Disposition: attachment;
<br />
filename="13.zip"
<br />
<br />
UEsFBgAAAAAAAAAAAAAAAAAAAAAAAA==
<br />
------=_NextPart_000_0004_96E69A13.09F60AEB--
Anonymous [ Sunday, 16 May 2004, 09:21 PM ]
Post subject:
I got a strange email myself today..I deleted it...this email claimed to be a returned to sender something like that...I have`nt emailed anyone lately so I zapped it.
<br />
might be another bug out there.
Tormie [ Sunday, 16 May 2004, 10:12 PM ]
Post subject:
I hope that it isn't a mail from here....
JanReinar [ Monday, 17 May 2004, 01:40 AM ]
Post subject:
All is right with me! Only two normal replys from the form! <img src="https://www.posetteforever.com/images/smiles/smile.gif" alt="" />
JanReinar [ Monday, 17 May 2004, 01:43 AM ]
Post subject:
All is right with me! Only two normal replys from the forum! <img src="https://www.posetteforever.com/images/smiles/smile.gif" alt="" /> Sorry!I forgot the "u"! <img src="https://www.posetteforever.com/images/smiles/icon_redface.gif" alt="" />
tda42 [ Monday, 17 May 2004, 02:22 AM ]
Post subject:
I had something like that but stopped it before it went anywhere.I did not come from here. <img src="https://www.posetteforever.com/images/smiles/biggrin.gif" alt="" />
Anonymous [ Monday, 17 May 2004, 03:04 AM ]
Post subject:
It was`nt from here...my alternate email address got the same thing,
<br />
it will ethier email delivery failure or some type of returned email.
<br />
If you get something along these lines..DELETE IT.
<br />
if you did`nt send an email recently, ignore it.
<br />
Sometimes jokers drop viruses in these email so don`t open it.
<br />
Remember if you use windows 95/98/XP..etc..hackers and virus makers
<br />
love to reek havoc on these OS, for some reasom Mac and Linux seem to be safe for now.
<br />
but keep your gaurd up anyway.
ahjah [ Monday, 17 May 2004, 11:10 AM ]
Post subject:
Yes
<br />
there is a version of, I think, netsky at the moment
<br />
It comes by an attachment 49,9kb sized. I had 7 of them today <img src="https://www.posetteforever.com/images/smiles/eusa_wall.gif" alt="" />
<br />
be carefull <img src="https://www.posetteforever.com/images/smiles/eusa_think.gif" alt="" />
Tormie [ Monday, 17 May 2004, 12:34 PM ]
Post subject:
<img src="https://www.posetteforever.com/images/smiles/eusa_shifty.gif" alt="" /> <img src="https://www.posetteforever.com/images/smiles/eusa_shifty.gif" alt="" /> <img src="https://www.posetteforever.com/images/smiles/eusa_shifty.gif" alt="" />
Den Tracy [ Monday, 17 May 2004, 01:55 PM ]
Post subject:
Never open an email with attachments. When you do, all that you are doing
<br />
is spreading the email virus from you address book to everyone on the list
<br />
and so on.
<br />
If I don't know the sender, the email goes straight to the trash bin and is deleted.
<br />
<br />
The virus didn't originate from here, but it is possible that a member's email was infected
<br />
and it spread that way without their knowledge.
<br />
These things pop-up almost every few weeks, so we all have to be vigilant.
JanReinar [ Monday, 17 May 2004, 06:09 PM ]
Post subject:
A friend told me that if I don't use the Microsoft Outlook the virus don't work! Someone knows if it is true? <img src="https://www.posetteforever.com/images/smiles/confused.gif" alt="" /> <img src="https://www.posetteforever.com/images/smiles/confused.gif" alt="" /> <img src="https://www.posetteforever.com/images/smiles/confused.gif" alt="" />
Landman [ Monday, 17 May 2004, 06:51 PM ]
Post subject:
No it isn't. In order to infect your computer with a virus from e-mail, you HAVE to execute an attachment. You won't get infected for just viewing the text of the E-mail. The virus itself needs to be executed. As a rule, never execute any unknown attachments. Even some known ones for that matter. Another course of action for anyone using an NT based O/S. eg win XP, 2000, NT workstation, server etc. is to manually disable your tftp port. port 69. As many viruses eg. nimda, used this port to replicate itself over a network. Port 69 is used for tftp traffic, which is basically trafic to flash software images to e-proms on routers and other peripheral equipment. if you aren't doing anything like that, then there is no need for it to be open.
<br />
<br />
PM me for more info....
JanReinar [ Monday, 17 May 2004, 06:57 PM ]
Post subject:
Thanks Landman! <img src="https://www.posetteforever.com/images/smiles/smile.gif" alt="" />
Landman [ Monday, 17 May 2004, 08:13 PM ]
Post subject:
Anytime Jan...