Today I received an email with a virus in it: It looked like the message that was sent from me to all users when we changed the domain name. I scanned it with www.spamcop.net and it appears to come from the ntlworld.com domain.
I deleted the 2 users with that domain in the email address and blocked it.
Here is the original message with the headers, it was blocked by Norton:
X-Symantec-TimeoutProtection: 0
Return-path: <tormento@partners2.100mwh.com>
Envelope-to:
Delivery-date: Sun, 16 May 2004 11:05:10 -0600
Received: from tormento by partners2.100mwh.com with local-bsmtp (Exim 4.34)
id 1BPP4V-00069j-R2
for ; Sun, 16 May 2004 11:05:10 -0600
Received: from [209.228.29.61] (helo=n064.sc1.cp.net)
by partners2.100mwh.com with esmtp (Exim 4.34)
id 1BPP4U-00069e-Ig
for ; Sun, 16 May 2004 11:05:07 -0600
Received: from posetteforever.com (81.103.216.144) by n064.sc1.cp.net (7.0.027.3-1)
id 4089B512001849D8 for ; Sun, 16 May 2004 17:04:58 +0000
Message-ID: <4089B512001849D8@n064.sc1.cp.net> (added by )
From:
To:
Subject: Re: Posetteforever temporary address!
Date: Sun, 16 May 2004 18:07:06 +0100
MIME-Version: 1.0
Content-Type: multipart/mixed;
boundary="----=_NextPart_000_0004_96E69A13.09F60AEB"
X-Priority: 3
X-MSMail-Priority: Normal
X-Mailer: Microsoft Outlook Express 6.00.2600.0000
X-MimeOLE: Produced By Microsoft MimeOLE V6.00.2600.0000
X-Spam-Checker-Version: SpamAssassin 2.63 (2004-01-11) on partners2.100mwh.com
X-Spam-Status: No, hits=2.1 required=5.0 tests=FORGED_MUA_OUTLOOK,
HTML_MESSAGE,NO_REAL_NAME,RCVD_IN_NJABL,RCVD_IN_SORBS autolearn=no
version=2.63
X-Spam-Level: **
This is a multi-part message in MIME format.
------=_NextPart_000_0004_96E69A13.09F60AEB
Content-Type: text/plain;
charset="Windows-1252"
Content-Transfer-Encoding: 7bit
----- Original Message -----
From:
To:
Subject: Posetteforever temporary address!
>
>
>Include this full email (particularly the headers).
>
>Message sent to you follows:
>~~~~~~~~~~~~~~~~~~~~~~~~~~~~
>
>Hi, the transfer is done our new permanent address is
>
>http://posetteforever.com
>
>or
>
>http://posetteforever.tk
>
>Best regards !
>
>AD>
><META http-equiv=3DContent-Type content=3D"text/html; charset=3Dus-asci=
>i">
><META content=3D"MSHTML 6.00.2462.0000" name=3DGENERATOR>
------=_NextPart_000_0004_96E69A13.09F60AEB
Content-Type: application/octet-stream;
name="13.zip"
Content-Transfer-Encoding: base64
Content-Disposition: attachment;
filename="13.zip"
UEsFBgAAAAAAAAAAAAAAAAAAAAAAAA==
------=_NextPart_000_0004_96E69A13.09F60AEB--