virus ?

The machines we love to hate

Moderator: Wiz Feinberg

Lyle Bradford
Posts: 1047
Joined: 16 Dec 1998 1:01 am
Location: Gilbert WV USA (deceased)

virus ?

Post by Lyle Bradford »

I keep getting a message from Lmlester and it will have an mp3 attached to it. I have never opened it. Is this a virus or do any of you ever get this message? It the subject line all it has is re.
User avatar
Wiz Feinberg
Posts: 6113
Joined: 8 Jan 1999 1:01 am
Location: Mid-Michigan, USA

Post by Wiz Feinberg »

This is probably a self mailing virus that is hiding the real extension name, either by including many spaces between the .mp3 and the real ext, or by relying on the recipient's not having changed the default file-folder view setting of "Hide the extensions of known file types." I recommend that you be sure that you're not hiding known extensions, then look at the filename again, after closing and reopening your email client.

You can also read the source code to see what is actually attached.

Wiz
User avatar
Ken Lang
Posts: 4708
Joined: 8 Jul 1999 12:01 am
Location: Simi Valley, Ca

Post by Ken Lang »

(Wiz. Here's another example for troubleshooting. I have recieved this in my email sometimes 4 times a day and at least once a day. I finally opened it on an older computer. It seems to have absolutely nothing to do with me. I emailed columbia with the following Image

Why do I keep getting these infernal messages for the last two months, sometimes 4 and 5 a day.

Please stop now. I have nothing to do with you or anyone listed in the email.


From: "Mail Delivery Subsy(stem" <MAILER-DAEMON@fathom.com> Add to Address Book
To: zebadia_1@yahoo.com
Subject: Warning: could not send message for past 4 hours

**********************************************
** THIS IS A WARNING MESSAGE ONLY **
** YOU DO NOT NEED TO RESEND YOUR MESSAGE **
**********************************************

The original message was received at Sat, 18 Dec 2004 07:38:55 -0500
from bgm-69-200-202-231.stny.rr.com [69.200.202.231]

----- The following addresses had transient non-fatal errors -----
<Rich@fathom.com>
(expanded from: <Rich@fathom.com>)

----- Transcript of session follows -----
<Rich@fathom.com>... Deferred: simple.fathom.com.: No route to host
Warning: message still undelivered after 4 hours
Will keep trying until message is 5 days old
Message/delivery-status
Reporting-MTA: dns; celia.fathom.com
Arrival-Date: Sat, 18 Dec 2004 07:38:55 -0500

Final-Recipient: RFC822; <Rich@fathom.com>
X-Actual-Recipient: RFC822; rich@simple.fathom.com
Action: delayed
Status: 4.4.1
Remote-MTA: DNS; simple.fathom.com
Last-Attempt-Date: Sat, 18 Dec 2004 16:21:36 -0500
Will-Retry-Until: Thu, 23 Dec 2004 07:38:55 -0500
Forwarded Message [ Save to my Yahoo! Briefcase | Download File ]

Date: Sat, 18 Dec 2004 08:43:13 -0500
To: Rich@fathom.com
Subject: Important notify about your e-mail account.
From: support@fathom.com
Plain Text Attachment [ Download File | Save to my Yahoo! Briefcase ]
Dear user of Fathom.com,

Your e-mail account has been temporary disabled because of
unauthorized access.

For details see the attached file.

Sincerely,
The Fathom.com team http://www.fathom.com


Attachment


Document.pif
.pif file
Attachment scanning provided by:

Scan and Download Attachment
Scan and Save to my Yahoo! Briefcase

DeleteReplyForwardSpamMove...
Previous | Next | Back to Messages Save Message Text

Thanks for your help in clearing up this matter.

Ken Lang


(Today I got another and promptly sent it to:
help@dkv.columbia.edu
where it seemed to have originated from.)

I have run pest patrol and McAfee virus. No problems detected.

Thanks for your ideas. Ken
Lyle Bradford
Posts: 1047
Joined: 16 Dec 1998 1:01 am
Location: Gilbert WV USA (deceased)

Post by Lyle Bradford »

How do I read the source code. I am just deleting them. I get 4or5 a day.
User avatar
Walter Stettner
Posts: 5771
Joined: 21 Nov 2003 1:01 am
Location: Vienna, Austria

Post by Walter Stettner »

I never go to the codes and read them - I always delete messages with unclear content or missing subject lines immediately, without exception. Also, my anti-virus software usually removes dangerous attachments from the beginning, I can only open or save them if I lower the security level on the PC (which I am only doing if I know that a friend is sending me something).

Kind Regards, Walter

www.lloydgreentribute.com
www.austriansteelguitar.at.tf

------------------
User avatar
Ken Lang
Posts: 4708
Joined: 8 Jul 1999 12:01 am
Location: Simi Valley, Ca

Post by Ken Lang »

I finally blocked the mail delivery system at fathom.com. No problem in the last two days.