Virus Warning... »  Show posts from    to     

♥ PosetteForever ♥


Whip The Admins... - Virus Warning...



Tormie [ Sunday, 16 May 2004, 06:59 PM ]
Post subject: Virus Warning...
Today I received an email with a virus in it: It looked like the message that was sent from me to all users when we changed the domain name. I scanned it with <a class="post-url" href="http://www.spamcop.net" target="_blank">www.spamcop.net</a> and it appears to come from the ntlworld.com domain. <br /> I deleted the 2 users with that domain in the email address and blocked it. <br /> <br /> Here is the original message with the headers, it was blocked by Norton: <br /> <br /> <br /> X-Symantec-TimeoutProtection: 0 <br /> Return-path: <tormento@partners2.100mwh.com> <br /> Envelope-to: <!-- no smilies start --><script type="text/javascript"> <!-- document.write(' </script><noscript>Posy [at] posetteforever [dot] com</noscript><!-- no smilies end --> <br /> Delivery-date: Sun, 16 May 2004 11:05:10 -0600 <br /> Received: from tormento by partners2.100mwh.com with local-bsmtp (Exim 4.34) <br /> id 1BPP4V-00069j-R2 <br /> for <!-- no smilies start --><script type="text/javascript"> <!-- document.write(' </script><noscript>Posy [at] posetteforever [dot] com</noscript><!-- no smilies end -->; Sun, 16 May 2004 11:05:10 -0600 <br /> Received: from [209.228.29.61] (helo=n064.sc1.cp.net) <br /> by partners2.100mwh.com with esmtp (Exim 4.34) <br /> id 1BPP4U-00069e-Ig <br /> for <!-- no smilies start --><script type="text/javascript"> <!-- document.write(' </script><noscript>Posy [at] posetteforever [dot] com</noscript><!-- no smilies end -->; Sun, 16 May 2004 11:05:07 -0600 <br /> Received: from posetteforever.com (81.103.216.144) by n064.sc1.cp.net (7.0.027.3-1) <br /> id 4089B512001849D8 for <!-- no smilies start --><script type="text/javascript"> <!-- document.write(' </script><noscript>Posy [at] posetteforever [dot] com</noscript><!-- no smilies end -->; Sun, 16 May 2004 17:04:58 +0000 <br /> Message-ID: <4089B512001849D8@n064.sc1.cp.net> (added by <!-- no smilies start --><script type="text/javascript"> <!-- document.write(' </script><noscript>postmaster [at] bouncemessage [dot] net</noscript><!-- no smilies end -->) <br /> From: <!-- no smilies start --><script type="text/javascript"> <!-- document.write(' </script><noscript>Posy [at] posetteforever [dot] com</noscript><!-- no smilies end --> <br /> To: <!-- no smilies start --><script type="text/javascript"> <!-- document.write(' </script><noscript>Posy [at] posetteforever [dot] com</noscript><!-- no smilies end --> <br /> Subject: Re: Posetteforever temporary address! <br /> Date: Sun, 16 May 2004 18:07:06 +0100 <br /> MIME-Version: 1.0 <br /> Content-Type: multipart/mixed; <br /> boundary="----=_NextPart_000_0004_96E69A13.09F60AEB" <br /> X-Priority: 3 <br /> X-MSMail-Priority: Normal <br /> X-Mailer: Microsoft Outlook Express 6.00.2600.0000 <br /> X-MimeOLE: Produced By Microsoft MimeOLE V6.00.2600.0000 <br /> X-Spam-Checker-Version: SpamAssassin 2.63 (2004-01-11) on partners2.100mwh.com <br /> X-Spam-Status: No, hits=2.1 required=5.0 tests=FORGED_MUA_OUTLOOK, <br /> HTML_MESSAGE,NO_REAL_NAME,RCVD_IN_NJABL,RCVD_IN_SORBS autolearn=no <br /> version=2.63 <br /> X-Spam-Level: ** <br /> <br /> This is a multi-part message in MIME format. <br /> <br /> ------=_NextPart_000_0004_96E69A13.09F60AEB <br /> Content-Type: text/plain; <br /> charset="Windows-1252" <br /> Content-Transfer-Encoding: 7bit <br /> <br /> <br /> ----- Original Message ----- <br /> From: <!-- no smilies start --><script type="text/javascript"> <!-- document.write(' </script><noscript>Posy [at] posetteforever [dot] com</noscript><!-- no smilies end --> <br /> To: <!-- no smilies start --><script type="text/javascript"> <!-- document.write(' </script><noscript>Posy [at] posetteforever [dot] com</noscript><!-- no smilies end --> <br /> Subject: Posetteforever temporary address! <br /> <br /> <br /> ><!-- no smilies start --><script type="text/javascript"> <!-- document.write(' </script><noscript>Posy [at] posetteforever [dot] com</noscript><!-- no smilies end --> <br /> > <br /> >Include this full email (particularly the headers). <br /> > <br /> >Message sent to you follows: <br /> >~~~~~~~~~~~~~~~~~~~~~~~~~~~~ <br /> > <br /> >Hi, the transfer is done our new permanent address is <br /> > <br /> ><a class="post-url" href="http://posetteforever.com" target="_blank">http://posetteforever.com</a> <br /> > <br /> >or <br /> > <br /> ><a class="post-url" href="http://posetteforever.tk" target="_blank">http://posetteforever.tk</a> <br /> > <br /> >Best regards ! <br /> > <br /> >AD> <br /> ><META http-equiv=3DContent-Type content=3D"text/html; charset=3Dus-asci= <br /> >i"> <br /> ><META content=3D"MSHTML 6.00.2462.0000" name=3DGENERATOR> <br /> <br /> <br /> ------=_NextPart_000_0004_96E69A13.09F60AEB <br /> Content-Type: application/octet-stream; <br /> name="13.zip" <br /> Content-Transfer-Encoding: base64 <br /> Content-Disposition: attachment; <br /> filename="13.zip" <br /> <br /> UEsFBgAAAAAAAAAAAAAAAAAAAAAAAA== <br /> ------=_NextPart_000_0004_96E69A13.09F60AEB--
Anonymous [ Sunday, 16 May 2004, 09:21 PM ]
Post subject: 
I got a strange email myself today..I deleted it...this email claimed to be a returned to sender something like that...I have`nt emailed anyone lately so I zapped it. <br /> might be another bug out there.
Tormie [ Sunday, 16 May 2004, 10:12 PM ]
Post subject: 
I hope that it isn't a mail from here....
JanReinar [ Monday, 17 May 2004, 01:40 AM ]
Post subject: 
All is right with me! Only two normal replys from the form! <img src="https://www.posetteforever.com/images/smiles/smile.gif" alt="" />
JanReinar [ Monday, 17 May 2004, 01:43 AM ]
Post subject: 
All is right with me! Only two normal replys from the forum! <img src="https://www.posetteforever.com/images/smiles/smile.gif" alt="" /> Sorry!I forgot the "u"! <img src="https://www.posetteforever.com/images/smiles/icon_redface.gif" alt="" />
tda42 [ Monday, 17 May 2004, 02:22 AM ]
Post subject: 
I had something like that but stopped it before it went anywhere.I did not come from here. <img src="https://www.posetteforever.com/images/smiles/biggrin.gif" alt="" />
Anonymous [ Monday, 17 May 2004, 03:04 AM ]
Post subject: 
It was`nt from here...my alternate email address got the same thing, <br /> it will ethier email delivery failure or some type of returned email. <br /> If you get something along these lines..DELETE IT. <br /> if you did`nt send an email recently, ignore it. <br /> Sometimes jokers drop viruses in these email so don`t open it. <br /> Remember if you use windows 95/98/XP..etc..hackers and virus makers <br /> love to reek havoc on these OS, for some reasom Mac and Linux seem to be safe for now. <br /> but keep your gaurd up anyway.
ahjah [ Monday, 17 May 2004, 11:10 AM ]
Post subject: 
Yes <br /> there is a version of, I think, netsky at the moment <br /> It comes by an attachment 49,9kb sized. I had 7 of them today <img src="https://www.posetteforever.com/images/smiles/eusa_wall.gif" alt="" /> <br /> be carefull <img src="https://www.posetteforever.com/images/smiles/eusa_think.gif" alt="" />
Tormie [ Monday, 17 May 2004, 12:34 PM ]
Post subject: 
<img src="https://www.posetteforever.com/images/smiles/eusa_shifty.gif" alt="" /> <img src="https://www.posetteforever.com/images/smiles/eusa_shifty.gif" alt="" /> <img src="https://www.posetteforever.com/images/smiles/eusa_shifty.gif" alt="" />
Den Tracy [ Monday, 17 May 2004, 01:55 PM ]
Post subject: 
Never open an email with attachments. When you do, all that you are doing <br /> is spreading the email virus from you address book to everyone on the list <br /> and so on. <br /> If I don't know the sender, the email goes straight to the trash bin and is deleted. <br /> <br /> The virus didn't originate from here, but it is possible that a member's email was infected <br /> and it spread that way without their knowledge. <br /> These things pop-up almost every few weeks, so we all have to be vigilant.
JanReinar [ Monday, 17 May 2004, 06:09 PM ]
Post subject: 
A friend told me that if I don't use the Microsoft Outlook the virus don't work! Someone knows if it is true? <img src="https://www.posetteforever.com/images/smiles/confused.gif" alt="" /> <img src="https://www.posetteforever.com/images/smiles/confused.gif" alt="" /> <img src="https://www.posetteforever.com/images/smiles/confused.gif" alt="" />
Landman [ Monday, 17 May 2004, 06:51 PM ]
Post subject: 
No it isn't. In order to infect your computer with a virus from e-mail, you HAVE to execute an attachment. You won't get infected for just viewing the text of the E-mail. The virus itself needs to be executed. As a rule, never execute any unknown attachments. Even some known ones for that matter. Another course of action for anyone using an NT based O/S. eg win XP, 2000, NT workstation, server etc. is to manually disable your tftp port. port 69. As many viruses eg. nimda, used this port to replicate itself over a network. Port 69 is used for tftp traffic, which is basically trafic to flash software images to e-proms on routers and other peripheral equipment. if you aren't doing anything like that, then there is no need for it to be open. <br /> <br /> PM me for more info....
JanReinar [ Monday, 17 May 2004, 06:57 PM ]
Post subject: 
Thanks Landman! <img src="https://www.posetteforever.com/images/smiles/smile.gif" alt="" />
Landman [ Monday, 17 May 2004, 08:13 PM ]
Post subject: 
Anytime Jan...


Powered by
Icy Phoenix based on phpBB