September 10, 2003, 02:17
|
#1
|
King
Local Time: 00:30
Local Date: November 2, 2010
Join Date: Nov 1999
Location: You think you're better than me? You've been handling my ass pennies!!!
Posts: 1,101
|
Disturbing Email
Ok, somebody tell me what this is. It was in my inbox. I have the latest version of McAfee Viruscan and it is and has been fully updated. It doesn't find anything, and it never has (it's scheduled to run once a week and scan everything just in case).
So... do I have a virus? Or where did this come from? It's buggin' me. Check it out. I'm damn sure the attachment is a virus.
Note - I don't use Outlook Express and never have, yet this says something about that being the mailer. And obviously if this thing did bounce, I never sent the original.
Quote:
|
This message was created automatically by mail delivery software.
A message that you sent could not be delivered to one or more of its
recipients. This is a permanent error. The following address(es) failed:
dan@apolyton.net
This message has been rejected because it has
a potentially executable attachment "thank_you.pif"
This form of attachment has been used by
recent viruses or other malware.
If you meant to send this file then please
package it up as a zip file and resend it.
------ This is a copy of the message, including all the headers. ------
Return-path:
Received: from [66.92.67.57] (helo=CIHET)
by settler.apolyton.net with esmtp (Exim 4.20)
id 19wu3F-0000PX-Mq
for dan@apolyton.net; Tue, 09 Sep 2003 21:45:47 -0400
From:
To:
Subject: Re: Details
Date: Tue, 9 Sep 2003 21:45:44 --0400
X-MailScanner: Found to be clean
Importance: Normal
X-Mailer: Microsoft Outlook Express 6.00.2600.0000
X-MSMail-Priority: Normal
X-Priority: 3 (Normal)
MIME-Version: 1.0
Content-Type: multipart/mixed;
boundary="_NextPart_000_06849F9A"
Message-Id:
This is a multipart message in MIME format
--_NextPart_000_06849F9A
Content-Type: text/plain;
charset="iso-8859-1"
Content-Transfer-Encoding: 7bit
See the attached file for details
--_NextPart_000_06849F9A
Content-Type: application/octet-stream;
name="thank_you.pif"
Content-Transfer-Encoding: base64
Content-Disposition: attachment;
filename="thank_you.pif"
|
__________________
"Luck's last match struck in the pouring down wind." - Chris Cornell, "Mindriot"
|
|
|
|
September 10, 2003, 02:24
|
#2
|
King
Local Time: 00:30
Local Date: November 2, 2010
Join Date: Nov 1999
Location: You think you're better than me? You've been handling my ass pennies!!!
Posts: 1,101
|
Oh, btw. Dan is not included in my address book. Hell, I don't even have an address book for my email, so I'm inclined to think that this didn't originate from my computer. That still doesn't change the fact that I have an unknown email with a virus and an @apolyton address in the same place.
__________________
"Luck's last match struck in the pouring down wind." - Chris Cornell, "Mindriot"
|
|
|
|
September 10, 2003, 02:24
|
#3
|
Local Time: 19:30
Local Date: November 2, 2010
Join Date: Aug 2001
Location: Skanky Father
Posts: 16,530
|
Someone else got something like this recently...?
Anyway, check your computer for viruses post-haste.
__________________
I'm building a wagon! On some other part of the internets, obviously (but not that other site).
|
|
|
|
September 10, 2003, 02:25
|
#4
|
Prince
Local Time: 01:30
Local Date: November 2, 2010
Join Date: Jun 2003
Location: of the purple hand
Posts: 585
|
I don't have the slightest clue what the cause may be, but I recommend deleting it and not opening the attachment.
It is probably targeted at Outlook users. Opening that attachment would probably screw up your computer. Delete it.
__________________
American by birth, smarter than the average tropical fruit by the grace of Me. -me
I try not to break the rules but merely to test their elasticity. -- Bill Veeck | Don't listed to the Linux Satanist, people. - St. Leo | If patching security holes was the top priority of any of us(no matter the OS), we'd do nothing else. - Me, in a tired and accidental attempt to draw fire from all three sides.
Posted with Mozilla Firebird running under Sawfish on a Slackware Linux install.:p
XGalaga.
|
|
|
|
September 10, 2003, 02:29
|
#5
|
King
Local Time: 00:30
Local Date: November 2, 2010
Join Date: Nov 1999
Location: You think you're better than me? You've been handling my ass pennies!!!
Posts: 1,101
|
What about this. Is it possible that this could have nothing to do with my computer at all, but rather one of the public computers at school. I know the universities were hit pretty hard by the latest wave of viruses. I regularly check my email and visit apolyton at school. Could that have caused this crap?
__________________
"Luck's last match struck in the pouring down wind." - Chris Cornell, "Mindriot"
|
|
|
|
September 10, 2003, 02:38
|
#6
|
Prince
Local Time: 01:30
Local Date: November 2, 2010
Join Date: Jun 2003
Location: of the purple hand
Posts: 585
|
Probably.
__________________
American by birth, smarter than the average tropical fruit by the grace of Me. -me
I try not to break the rules but merely to test their elasticity. -- Bill Veeck | Don't listed to the Linux Satanist, people. - St. Leo | If patching security holes was the top priority of any of us(no matter the OS), we'd do nothing else. - Me, in a tired and accidental attempt to draw fire from all three sides.
Posted with Mozilla Firebird running under Sawfish on a Slackware Linux install.:p
XGalaga.
|
|
|
|
September 10, 2003, 02:51
|
#7
|
King
Local Time: 00:30
Local Date: November 2, 2010
Join Date: Nov 1999
Location: You think you're better than me? You've been handling my ass pennies!!!
Posts: 1,101
|
...and one more scan for good measure. Still all clean. Task manager shows nothing unusual. Probably ASU's computers .
__________________
"Luck's last match struck in the pouring down wind." - Chris Cornell, "Mindriot"
|
|
|
|
September 10, 2003, 02:58
|
#8
|
Emperor
Local Time: 09:30
Local Date: November 2, 2010
Join Date: Mar 1999
Location: Zwolle, The Netherlands
Posts: 6,737
|
Sounds like the W32.Sobig.F virus. This virus sends emails to all addresses in the address book of an infected computer, and uses an address from the infected computer's address book as the sender. That means that you are not infected, but someone else was infected who has both your and DanQ's email address in his/her address book.
|
|
|
|
September 10, 2003, 04:36
|
#9
|
King
Local Time: 01:30
Local Date: November 2, 2010
Join Date: Dec 1969
Location: Melbourne
Posts: 2,963
|
I got an email like this as well. The virus sender has harvested your email, probably from someones address book and placed it in the return to field.
I think I started a topic just like this one. Gotta love Apolyton.
__________________
Hold my girlfriend while I kiss your skis.
|
|
|
|
September 10, 2003, 04:37
|
#10
|
King
Local Time: 01:30
Local Date: November 2, 2010
Join Date: Dec 1969
Location: Melbourne
Posts: 2,963
|
__________________
Hold my girlfriend while I kiss your skis.
|
|
|
|
September 10, 2003, 04:43
|
#11
|
Local Time: 19:30
Local Date: November 2, 2010
Join Date: Aug 2001
Location: Skanky Father
Posts: 16,530
|
Thought I remembered something similar to this thread!
__________________
I'm building a wagon! On some other part of the internets, obviously (but not that other site).
|
|
|
|
September 10, 2003, 05:07
|
#12
|
Emperor
Local Time: 20:30
Local Date: November 2, 2010
Join Date: Aug 2002
Location: Mad.
Posts: 4,142
|
Many of the ACS staff with @apolyton mail addresses has been affected by the Sobig.F virus.
|
|
|
|
September 10, 2003, 05:39
|
#13
|
Emperor
Local Time: 10:30
Local Date: November 2, 2010
Join Date: Mar 2000
Posts: 8,491
|
similar stuff has happened to me, mailer_daemon notices about emails not being processable to certain adresses that are not in my (empty) adress book but were a part of listed mail adresses that I replied to (forwarded mails). most disturbing is the fact that all the other people listed in the forward-list actually receive those mails. they must think I'm a spammer.
|
|
|
|
September 10, 2003, 05:40
|
#14
|
King
Local Time: 01:30
Local Date: November 2, 2010
Join Date: Dec 1969
Location: Melbourne
Posts: 2,963
|
you are a spammer
__________________
Hold my girlfriend while I kiss your skis.
|
|
|
|
September 10, 2003, 05:48
|
#15
|
Emperor
Local Time: 10:30
Local Date: November 2, 2010
Join Date: Mar 2000
Posts: 8,491
|
nah. at least not on emails to schoolmates.
|
|
|
|
September 10, 2003, 05:58
|
#16
|
Emperor
Local Time: 08:30
Local Date: November 2, 2010
Join Date: Mar 2002
Location: All Glory To The Hypnotoad!
Posts: 4,223
|
Quote:
|
Originally posted by Frozzy
Many of the ACS staff with @apolyton mail addresses has been affected by the Sobig.F virus.
|
I got 80-100 in a single day once.
__________________
If I'm posting here then Counterglow must be down.
|
|
|
|
September 10, 2003, 06:44
|
#17
|
Emperor
Local Time: 04:30
Local Date: November 2, 2010
Join Date: Mar 1999
Location: San Antonio, TX
Posts: 4,264
|
I had the same thing occur a few months ago, but it was with Markos' email, not Dan.
|
|
|
|
Posting Rules
|
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts
HTML code is On
|
|
|
All times are GMT -4. The time now is 04:30.
|
|